When a fresh fraud hits and we have a 48-hour freeze window, I map flows in Neo4j off MT103/199 and camt.053, then pivot in Maltego on IBANs and directors before the subpoenas; anyone running a tighter combo? I’m considering ditching i2 for Linkurious after a case with 3 jurisdictions and 8 banks; what cut your time-to-freeze?
What cut our time-to-freeze was a small apoc.trigger in Neo4j that, on ingest of MT103/199 and camt.053, normalizes IBAN/BIC, builds the correspondent chain, and pushes a Linkurious Alert with a prefilled bank-specific preservation letter ready to send. LKE does beat i2 here, but you’ll want a full‑text index for names to avoid messy merges inside the “48-hour freeze window.” If you switch, are you planning to lean on LKE Alerts or keep pivots in Maltego for the directors hop?
Building on @amiller92: we cut hours by going “UETR-first, then IBAN” to stitch MT103/199 with camt.053, then a quick Neo4j GDS PageRank on the last‑24h subgraph to rank last‑mile accounts for immediate orders — like sorting fire exits before the smoke. If UETR’s missing, we fall back to a 90‑minute value/time window across BIC chains to infer the corridor. Are you getting reliable UETR from all three jurisdictions?
But biggest gain for us was wiring the graph to auto-generate preservation letters with the right bank escalation contacts per BIC/jurisdiction, and tagging legs as in‑flight vs posted via the SWIFT gpi tracker API (https://developer.swift.com) so we only call the two banks that matter. If you go Linkurious, Alerts + saved queries are great for that push, but i2 still wins for pretty disclosure bundles. Are you already pulling gpi status or just statements — ‘don’t chase settled legs’ saved us hours.
In a “48-hour” window across 3 jurisdictions, the biggest speedup for us was a cutoff-aware playbook: auto-rank legs by local bank cutoff/holidays and correspondent path, then fire freezes in that order. Neo4j still does the map, but a tiny scheduler hits Asia/nostros first while the legal templates trail; shaving hours mattered more than swapping i2 for Linkurious. Do you maintain a BIC→cutoff/escalation matrix, or rebuild it per case?