Disciplines

🚔 Criminal Intelligence (CRIMINT)

Intelligence Supporting Criminal Investigation
Law Enforcement

Sources

0
0 no-auth

Mission domains

0
reach

Data points

0
covered

Related INT

0
disciplines

🔍 Lookup

📜 Playbook — Criminal Intelligence collection

  1. Direction — frame the requirement for Criminal Intelligence: what decision does this support, by when?
  2. Collection — collect from the 0 mapped sources (0 free) — filter the catalog by CRIMINT; capture provenance and observe OPSEC.
  3. Processing — normalize, de-duplicate and enrich the collected data.
  4. Analysis — correlate against local holdings; apply ACH; assign confidence.
  5. Dissemination — open a case, draft a report, share via STIX/MISP.
  6. Feedback — set an alert rule / watchlist to monitor for change.

⚡ AI Skills & Automation

🤖 Copilot brief⚡ AI SkillsResolveEnrichAuto-CollectHuntReportExport

Automate unattended via the cron pipeline (collect → ingest → resolve → enrich → score → alert).

🎯 Mission

CRIMINT collects and analyzes intelligence on criminal networks, offenses, and illicit finance to support investigations and disruption. It answers who is involved in a criminal enterprise, how they operate and move money, and where intervention will have the most effect.

📡 Collection methods

  • Link analysis of associates, communications metadata, and financial transactions
  • Crime-series and hotspot analysis combining geospatial and temporal patterns
  • Court, arrest, and incident record aggregation for nominal enrichment
  • Darkweb marketplace and forum monitoring for vendors and contraband
  • Cryptocurrency transaction tracing and wallet clustering for illicit flows
  • Vehicle/ALPR and phone-linkage exploitation to place subjects together

🔧 Tools & frameworks

  • Maltego
  • i2 Analyst's Notebook
  • Breadcrumbs
  • Neo4j
  • Gephi
  • Tor Browser

📜 Criminal Intelligence Tradecraft

  1. Collect: aggregate records, comms metadata, and financial trails on the network
  2. Process: entity-resolve subjects and normalize incidents geospatially
  3. Analyze: map the network structure, roles, and crime hotspots/series
  4. Attribute: link crypto wallets and darkweb aliases to real identities
  5. Disseminate: brief investigators with a link chart and intelligence package
  6. Action: support warrants, seizures, and network-disruption operations

📊 Dashboard KPIs

Subjects linkedCases correlatedWallets tracedCrime hotspotsNominal records
Workstation · Copilot · AI Skills · Automation · Playbooks · Lookups · Docs · Reports

🤖 AI Copilot

🔍 Lookup & Enrich

💡 Recommendations

⚙ Automation

Cron: 0 * * * * php /home/zaptf0zdggll/public_html/threats/cron.php