📣 Disinformation Intelligence (DISINFOINT)
Detecting and Analyzing Information Manipulation
Information
Sources
2
2 no-auth
Mission domains
2
reach
Data points
2
covered
Related INT
1
disciplines
🔌 Sources for Disinformation Intelligence (2)
| Source | Category | Auth | Format | |
|---|---|---|---|---|
| GNET (Global Network on Extremism & Tech) Online extremism research hub. | Extremism | NONE | html | home↗ |
| Tech Against Terrorism / TCAP Terrorist content analytics platform. | Extremism | NONE | html | home↗ |
🎯 Mission Domains served
🎫 Data Points
🔍 Lookup
📊 Pre-built Queries · Disinformation Intelligence
📜 Playbook — Disinformation Intelligence collection
- Direction — frame the requirement for Disinformation Intelligence: what decision does this support, by when?
- Collection — collect from the 2 mapped sources (2 free) — filter the catalog by DISINFOINT; capture provenance and observe OPSEC.
- Processing — normalize, de-duplicate and enrich the collected data.
- Analysis — correlate against local holdings; apply ACH; assign confidence.
- Dissemination — open a case, draft a report, share via STIX/MISP.
- Feedback — set an alert rule / watchlist to monitor for change.
⚡ AI Skills & Automation
Automate unattended via the cron pipeline (collect → ingest → resolve → enrich → score → alert).
🧩 Advanced Capabilities
🔗 Pivot to related disciplines
✨ Enrichment pathways
🎯 Mission
DISINFOINT detects and characterizes coordinated inauthentic behavior, influence operations, and narrative manipulation across platforms. It answers who is pushing a narrative, whether accounts are automated or coordinated, and how manipulated content propagates.
📡 Collection methods
- Coordinated inauthentic behavior detection via temporal co-share/co-post clustering
- Bot and automation scoring from posting cadence, account age, and content entropy
- Narrative and claim tracking with framing analysis across languages and platforms
- Network graph analysis of retweet/share cascades to surface amplification hubs
- Cross-platform content fingerprinting via perceptual image hashing and near-duplicate text
- Domain and hosting attribution of pink-slime and fabricated-news sites
📚 Key sources & datasets
🎫 Data points produced
🔧 Tools & frameworks
- Gephi
- NetworkX
- Hoaxy
- Botometer
- Media Cloud
- OpenRefine
- Maltego
📜 Disinformation Intelligence Tradecraft
- Collect: harvest posts, accounts, and domains around a target narrative or hashtag
- Process: dedupe content, compute posting cadence, and build the interaction graph
- Analyze: detect coordination clusters, bot cohorts, and amplification hubs
- Attribute: link shared infrastructure and behavioral fingerprints to an operator or campaign
- Disseminate: publish an influence-operation assessment with annotated network maps
- Action: recommend platform reporting, content labeling, or counter-messaging
📊 Dashboard KPIs
CIB clustersBot-score avgNarrative reachAccounts flaggedNew domains
🔍 Pre-built queries
🔗 Cross-discipline pivots
🧩 Advanced Capabilities
Workstation · Copilot · AI Skills · Automation · Playbooks · Lookups · Docs · Reports
🤖 AI Copilot
⚡ AI Skills
🔍 Lookup & Enrich
📚 Docs & Reports
💡 Recommendations
- Explore related tools below
- Automate recurring work via cron