Disciplines

📣 Disinformation Intelligence (DISINFOINT)

Detecting and Analyzing Information Manipulation
Information

Sources

2
2 no-auth

Mission domains

2
reach

Data points

2
covered

Related INT

1
disciplines

🔌 Sources for Disinformation Intelligence (2)

SourceCategoryAuthFormat
GNET (Global Network on Extremism & Tech)
Online extremism research hub.
ExtremismNONEhtmlhome↗
Tech Against Terrorism / TCAP
Terrorist content analytics platform.
ExtremismNONEhtmlhome↗

🔍 Lookup

📜 Playbook — Disinformation Intelligence collection

  1. Direction — frame the requirement for Disinformation Intelligence: what decision does this support, by when?
  2. Collection — collect from the 2 mapped sources (2 free) — filter the catalog by DISINFOINT; capture provenance and observe OPSEC.
  3. Processing — normalize, de-duplicate and enrich the collected data.
  4. Analysis — correlate against local holdings; apply ACH; assign confidence.
  5. Dissemination — open a case, draft a report, share via STIX/MISP.
  6. Feedback — set an alert rule / watchlist to monitor for change.

⚡ AI Skills & Automation

🤖 Copilot brief⚡ AI SkillsResolveEnrichAuto-CollectHuntReportExport

Automate unattended via the cron pipeline (collect → ingest → resolve → enrich → score → alert).

🔗 Pivot to related disciplines

SOCMINT Social Media Intelligence →

🎯 Mission

DISINFOINT detects and characterizes coordinated inauthentic behavior, influence operations, and narrative manipulation across platforms. It answers who is pushing a narrative, whether accounts are automated or coordinated, and how manipulated content propagates.

📡 Collection methods

  • Coordinated inauthentic behavior detection via temporal co-share/co-post clustering
  • Bot and automation scoring from posting cadence, account age, and content entropy
  • Narrative and claim tracking with framing analysis across languages and platforms
  • Network graph analysis of retweet/share cascades to surface amplification hubs
  • Cross-platform content fingerprinting via perceptual image hashing and near-duplicate text
  • Domain and hosting attribution of pink-slime and fabricated-news sites

🔧 Tools & frameworks

  • Gephi
  • NetworkX
  • Hoaxy
  • Botometer
  • Media Cloud
  • OpenRefine
  • Maltego

📜 Disinformation Intelligence Tradecraft

  1. Collect: harvest posts, accounts, and domains around a target narrative or hashtag
  2. Process: dedupe content, compute posting cadence, and build the interaction graph
  3. Analyze: detect coordination clusters, bot cohorts, and amplification hubs
  4. Attribute: link shared infrastructure and behavioral fingerprints to an operator or campaign
  5. Disseminate: publish an influence-operation assessment with annotated network maps
  6. Action: recommend platform reporting, content labeling, or counter-messaging

📊 Dashboard KPIs

CIB clustersBot-score avgNarrative reachAccounts flaggedNew domains
Workstation · Copilot · AI Skills · Automation · Playbooks · Lookups · Docs · Reports

🤖 AI Copilot

🔍 Lookup & Enrich

💡 Recommendations

⚙ Automation

Cron: 0 * * * * php /home/zaptf0zdggll/public_html/threats/cron.php