Financial Crime Intelligence

GhostCluster

AML FORENSICS & MULE NETWORK INTELLIGENCE SUITE

An institutional-grade forensic intelligence platform for detecting, tracing, and investigating complex money-laundering networks through transaction analysis, behavioral heuristics, network topology, evidence provenance, and AI-assisted compliance workflows.

Research / Prototype AML / BSA Network Forensics AI-Assisted Investigation Evidence Intelligence

Status note: GhostCluster is a research/engineering portfolio project run against synthetic and controlled demonstration data. It is not a deployed banking system, a FinCEN product, a law-enforcement system, or a certified compliance platform.

ghost-cluster.vercel.app — Overview Dashboard
GhostCluster forensic overview dashboard — prototype screenshot
Network Investigation
GhostCluster network investigation graph — prototype screenshot
Transaction Intelligence
GhostCluster transaction intelligence ledger — prototype screenshot
Evidence & Case Workspace
GhostCluster evidence and case workspace — prototype screenshot

Project Overview

What is GhostCluster?

GhostCluster combines transaction-level analytics, entity intelligence, graph-based network analysis, heuristic detection, evidence management, and regulatory auditability into one investigative environment. Rather than flagging isolated suspicious transactions, it reconstructs the relationships between accounts, entities, and fund flows — surfacing the structure of a network so an analyst can decide what it means.

Every module is built around the same premise: an automated system can surface signal, but an investigator makes the determination. The platform is explicit about that boundary throughout — in its language, its workflows, and its audit trail.

01Transaction Intelligence
02Network Analysis
03Entity Risk Scoring
04AML Typology Detection
05Evidence Provenance
06AI Investigation Assistant
07SAR Drafting
08Regulatory Audit Trail

Core Detection Engine

Multi-Dimensional AML Detection Engine

The platform evaluates transactions and entity relationships through multiple behavioral and structural signals. Every output below is a risk signal or investigative indicator — none of it independently proves criminal activity, and all of it requires analyst validation.

Sub-CTR Structuring Detection

Detects transaction clustering and repeated transactions designed to remain below applicable reporting thresholds.

Investigative indicator

Pass-Through Velocity

Identifies accounts receiving and rapidly sweeping funds while maintaining minimal residual balances.

Investigative indicator

Fan-In / Fan-Out Smurfing

Detects many-to-one and one-to-many transaction structures associated with coordinated fund movement.

Risk signal

Ghost Cluster Detection

Correlates account-level telemetry — device fingerprints, proxy IPs, user-agent overlaps — to identify potentially coordinated entities.

Potential typology

Round-Tripping & Cross-Border Sinks

Identifies circular transaction patterns and flows toward higher-risk jurisdictions or external liquidity destinations.

Requires analyst validation

None of these signals, alone or combined, constitute a finding. GhostCluster surfaces structure — investigators determine meaning.

Investigation Workspace

Nine investigation modules, one case lifecycle.

Each module below is expandable — the workspace moves a case from first flag to regulatory-ready documentation.

01

Overview Dashboard

Live forensic KPIs
  • Total monitored flow
  • High-risk entities
  • Structuring volume
  • Quarantined accounts
  • Average node velocity
  • Open alerts
  • "Why This Network Was Flagged" — evidence-backed risk drivers
Workflow: NEW → TRIAGE → INVESTIGATING → ESCALATED → SAR PREP → CLOSED
02

Network Graph

Interactive force-directed graph
  • Mule accounts, aggregators, pass-through entities
  • Shell entities and network endpoints
  • Transaction relationship edges
  • Risk heatmaps & jurisdiction grouping
  • Cluster isolation & node inspection
  • Transaction-path highlighting
03

Transaction Forensic Ledger

Search, filter, trace, export
  • Transaction search & account filtering
  • Channel filtering — SWIFT, Fedwire, ACH, P2P, crypto
  • Status filtering & structuring indicators
  • Network tracing across linked accounts
  • CSV export
04

Entities & Mule Matrix

Risk-scored entity registry
  • Risk score, account type, relationship count
  • Inflow / outflow velocity, network exposure
  • Account types — Consumer, Shell LLC, Crypto Exchange, Hub

Note: Administrative actions such as "Freeze Account" operate only against synthetic/demo data — this workspace is not connected to a real authorized banking system.

05

Typology Analytics

Pattern & cluster dossiers
  • Smurfing, rapid layering, structuring
  • Crypto liquidation & pass-through behavior
  • Cluster dossiers — estimated volume, node composition, primary channels
  • Risk indicators & recommended investigative actions
06

Live Alerts

Real-time triage stream
  • Critical · High · Medium severity tiers
  • Review, Investigate, Escalate, Dismiss actions

Note: Alert actions in this portfolio build are simulated and do not trigger any real-world enforcement.

07

Evidence Workspace

Provenance & chain-of-custody
  • Evidence records with verification timestamps
  • Confidence scores per artifact
  • SHA-256 hashes & source references
  • Chain-of-custody metadata
08

Case Notes Docket

Chronological investigation record
  • Note categories — Finding, Hypothesis, Regulatory Action, Evidence Log
  • Investigator pinning
  • Chronological case history
09

Regulatory Audit Trail

Tamper-evident action log
  • Action, investigator, timestamp
  • Previous hash / current hash chaining
  • Regulatory reference per entry

Network Forensics

See the money. Understand the network.

Every case moves through the same investigative chain — from a single transaction to a filed narrative.

TRANSACTION↓ ENTITY↓ RELATIONSHIP↓ CLUSTER↓ TYPOLOGY↓ EVIDENCE↓ CASE
SOURCE ENTITY ENTITY ENTITY AGGREGATOR PASS-THROUGH SHELL MULE HUB SHELL ENDPOINT
Illustrative cluster topology — synthetic demonstration data High-risk edgeStandard edge

AI-Assisted Investigation

AI Investigation Copilot

The AI layer assists investigators — it does not replace them.

Summarizing network structures
Explaining detected risk signals
Answering investigation questions
Generating investigation hypotheses
Identifying relevant transaction paths
Assisting with case narratives
Drafting structured SAR narrative components
Query → "Summarize the relationship between the flagged aggregator and its three downstream shell entities, and cite the supporting transactions."

Important: AI-generated outputs are investigative assistance and require qualified human review before regulatory submission or operational action. The system does not independently determine criminality.

Reporting Workflow

AI-Assisted SAR Preparation

Structured around FinCEN SAR Form 111 and related BSA/AML regulatory context. The system assists with preparation — it does not automatically file reports.

01EvidenceCollected artifacts and verified sources.
02Subject IDEntities and accounts named in the case.
03ChronologyOrdered transaction timeline.
04Typology AnalysisPattern classification with supporting signals.
05Investigator ReviewHuman validation of every finding.
06SAR Narrative DraftAI-assisted, human-edited draft.
07Compliance ApprovalFinal sign-off before submission.

Evidence & Provenance

Evidence you can audit.

Provenance is designed to support reproducibility, auditability, and investigator review — SHA-256 integrity hashes, timestamped records, source metadata, and chain-of-custody sequencing on every artifact.

Evidence IDEVD-2026-08-0417
Sourcetransaction_ledger.export.csv
Timestamp2026-08-19T14:02:11Z
Confidence0.91
SHA-2563f9a2e1c…b47d9081
Verified ByInvestigator — analyst_042

Simulation Environment

Controlled Forensic Simulation

GhostCluster runs entirely on synthetic investigation scenarios — no real customer banking data is used anywhere in this build.

Metro Smurfing Ring

A coordinated fan-in structuring pattern across a metro-area account cluster.

Cross-Border Layering Corridor

Sequential transfers routed through intermediary jurisdictions before consolidation.

Shell LLC Aggregator Syndicate

Multiple shell entities feeding a single aggregator account.

Live transaction simulator Synthetic transaction injector Threshold testing Alert generation Graph behavior simulation Custom JSON/CSV import

All examples on this page are synthetic / demonstration data. GhostCluster does not have access to real customer banking data.

System Design

Technical Architecture

Request and data flow from ingestion through investigator-facing workspace.

Data Sources
↓
Ingestion Layer
↓
Normalization
↓
Heuristic Detection Engine
↓
Risk Scoring
↓
Graph Intelligence
↓
Evidence / Provenance Layer
↓
AI Investigation Layer
↓
Investigator Workspace
↓
Reporting / Audit
D3-style graph rendering Google GenAI / Gemini Vercel Serverless API JSON / CSV SHA-256

Deployment

Deployment & Operational Design

Browser→ Vercel→ Application→ Serverless API→ AI Gateway→ Detection Engine
Vercel deployment
Serverless API routes
SPA routing
API health endpoint
AI gateway
Synthetic data environment
Offline heuristic fallback

Design Principles

Six principles behind the build.

01

Human-in-the-Loop

Analysts remain responsible for investigative conclusions and regulatory actions.

02

Evidence First

Every significant risk signal should be traceable to underlying evidence.

03

Explainable Risk

Risk scores should expose their contributing signals.

04

Auditability

Important actions should produce durable audit records.

05

Synthetic Testing

Detection logic should be testable without exposing real customer information.

06

Operational Restraint

Automated systems should assist investigators rather than independently impose enforcement decisions.

Portfolio Impact

Why I Built GhostCluster

Modern financial crime increasingly involves distributed accounts, rapid transaction chains, synthetic identities, cross-platform coordination, and complex networks — rather than isolated suspicious transactions.

GhostCluster explores how graph intelligence, behavioral heuristics, evidence provenance, and AI-assisted investigation can be combined into a unified forensic workflow. It's a research and engineering exercise in building investigative infrastructure that stays explainable and auditable as it scales — not a claim to have solved money laundering or to detect criminals automatically.

Key Takeaways

What the system is built around.

NETWORK-FIRST

Transaction relationships become investigative context.

EXPLAINABLE

Risk indicators are linked to observable signals.

EVIDENCE-AWARE

Investigative artifacts maintain provenance metadata.

HUMAN-CENTRIC

AI supports investigators rather than replacing regulatory judgment.

Explore GhostCluster

Explore the Intelligence System

Walk through the detection engine, network graph, evidence workspace, and AI-assisted investigation workflow — running entirely on synthetic demonstration data.

GhostCluster is presented as a research/engineering portfolio project using synthetic or controlled demonstration data.

Scroll to Top