Disciplines

🌐 Network Intelligence (NETINT)

Networks, Routing, and Internet Infrastructure
Cyber & Threat

Sources

0
0 no-auth

Mission domains

0
reach

Data points

0
covered

Related INT

0
disciplines

🔍 Lookup

📜 Playbook — Network Intelligence collection

  1. Direction — frame the requirement for Network Intelligence: what decision does this support, by when?
  2. Collection — collect from the 0 mapped sources (0 free) — filter the catalog by NETINT; capture provenance and observe OPSEC.
  3. Processing — normalize, de-duplicate and enrich the collected data.
  4. Analysis — correlate against local holdings; apply ACH; assign confidence.
  5. Dissemination — open a case, draft a report, share via STIX/MISP.
  6. Feedback — set an alert rule / watchlist to monitor for change.

⚡ AI Skills & Automation

🤖 Copilot brief⚡ AI SkillsResolveEnrichAuto-CollectHuntReportExport

Automate unattended via the cron pipeline (collect → ingest → resolve → enrich → score → alert).

🎯 Mission

Network Intelligence analyzes routing, traffic, and flow data to map internet infrastructure, detect anomalies, and attribute hosting and connectivity. It answers which ASNs and prefixes host a target, whether routing has been hijacked or leaked, and what TLS and flow fingerprints reveal about who controls a host.

📡 Collection methods

  • BGP route and prefix monitoring to detect hijacks, leaks, and origin changes
  • Netflow/IPFIX analysis to surface anomalous volumes, scanning, and beaconing
  • PCAP and protocol inspection for deep traffic characterization
  • ASN-to-IP and geolocation mapping to attribute hosting and connectivity
  • JA3/JA3S TLS client-server fingerprinting to identify tooling and stacks
  • RPKI validation and peering analysis to assess routing legitimacy

🔧 Tools & frameworks

  • Wireshark
  • Zeek
  • Suricata
  • BGPStream
  • nfdump/NfSen
  • ntopng
  • tshark
  • pmacct

📜 Network Intelligence Tradecraft

  1. Collect BGP updates, netflow, and packet captures scoped to target prefixes, ASNs, and monitored links
  2. Aggregate flows and decode traffic into sessions enriched with ASN, geo, and JA3/JA3S fingerprints
  3. Analyze baselines to isolate route anomalies, scanning, exfil, and beaconing patterns
  4. Attribute hosts and activity to an operator via ASN ownership, peering relationships, RPKI status, and fingerprint reuse
  5. Disseminate findings on hijacks, malicious ASNs, and anomalous flows to network defense and CTI
  6. Push blocklists/BGP filtering and IDS signatures, then monitor routing and flow to confirm the anomaly is contained

📊 Dashboard KPIs

ASNs monitoredRoute hijacks detectedAnomalous flowsMalicious ASNs flaggedJA3 fingerprint hits
Workstation · Copilot · AI Skills · Automation · Playbooks · Lookups · Docs · Reports

🤖 AI Copilot

🔍 Lookup & Enrich

💡 Recommendations

⚙ Automation

Cron: 0 * * * * php /home/zaptf0zdggll/public_html/threats/cron.php