🌐 Network Intelligence (NETINT)
Networks, Routing, and Internet Infrastructure
Cyber & Threat
Sources
0
0 no-auth
Mission domains
0
reach
Data points
0
covered
Related INT
0
disciplines
🔍 Lookup
📊 Pre-built Queries · Network Intelligence
📜 Playbook — Network Intelligence collection
- Direction — frame the requirement for Network Intelligence: what decision does this support, by when?
- Collection — collect from the 0 mapped sources (0 free) — filter the catalog by NETINT; capture provenance and observe OPSEC.
- Processing — normalize, de-duplicate and enrich the collected data.
- Analysis — correlate against local holdings; apply ACH; assign confidence.
- Dissemination — open a case, draft a report, share via STIX/MISP.
- Feedback — set an alert rule / watchlist to monitor for change.
⚡ AI Skills & Automation
Automate unattended via the cron pipeline (collect → ingest → resolve → enrich → score → alert).
🧩 Advanced Capabilities
✨ Enrichment pathways
🎯 Mission
Network Intelligence analyzes routing, traffic, and flow data to map internet infrastructure, detect anomalies, and attribute hosting and connectivity. It answers which ASNs and prefixes host a target, whether routing has been hijacked or leaked, and what TLS and flow fingerprints reveal about who controls a host.
📡 Collection methods
- BGP route and prefix monitoring to detect hijacks, leaks, and origin changes
- Netflow/IPFIX analysis to surface anomalous volumes, scanning, and beaconing
- PCAP and protocol inspection for deep traffic characterization
- ASN-to-IP and geolocation mapping to attribute hosting and connectivity
- JA3/JA3S TLS client-server fingerprinting to identify tooling and stacks
- RPKI validation and peering analysis to assess routing legitimacy
📚 Key sources & datasets
🎫 Data points produced
🔧 Tools & frameworks
- Wireshark
- Zeek
- Suricata
- BGPStream
- nfdump/NfSen
- ntopng
- tshark
- pmacct
📜 Network Intelligence Tradecraft
- Collect BGP updates, netflow, and packet captures scoped to target prefixes, ASNs, and monitored links
- Aggregate flows and decode traffic into sessions enriched with ASN, geo, and JA3/JA3S fingerprints
- Analyze baselines to isolate route anomalies, scanning, exfil, and beaconing patterns
- Attribute hosts and activity to an operator via ASN ownership, peering relationships, RPKI status, and fingerprint reuse
- Disseminate findings on hijacks, malicious ASNs, and anomalous flows to network defense and CTI
- Push blocklists/BGP filtering and IDS signatures, then monitor routing and flow to confirm the anomaly is contained
📊 Dashboard KPIs
ASNs monitoredRoute hijacks detectedAnomalous flowsMalicious ASNs flaggedJA3 fingerprint hits
🔍 Pre-built queries
🔗 Cross-discipline pivots
🧩 Advanced Capabilities
Workstation · Copilot · AI Skills · Automation · Playbooks · Lookups · Docs · Reports
🤖 AI Copilot
⚡ AI Skills
🔍 Lookup & Enrich
📚 Docs & Reports
💡 Recommendations
- Explore related tools below
- Automate recurring work via cron