Disciplines

🚫 Sanctions Intelligence (SANCINT)

Screening, Designations, and Evasion Detection
Financial

Sources

1
1 no-auth

Mission domains

3
reach

Data points

2
covered

Related INT

1
disciplines

🔌 Sources for Sanctions Intelligence (1)

SourceCategoryAuthFormat
OFAC Sanctioned Crypto Addresses (0xB10C)
Machine-readable OFAC-designated wallet lists per chain.
Crypto SanctionsNONEtexthome↗ api↗

🔍 Lookup

📜 Playbook — Sanctions Intelligence collection

  1. Direction — frame the requirement for Sanctions Intelligence: what decision does this support, by when?
  2. Collection — collect from the 1 mapped sources (1 free) — filter the catalog by SANCINT; capture provenance and observe OPSEC.
  3. Processing — normalize, de-duplicate and enrich the collected data.
  4. Analysis — correlate against local holdings; apply ACH; assign confidence.
  5. Dissemination — open a case, draft a report, share via STIX/MISP.
  6. Feedback — set an alert rule / watchlist to monitor for change.

⚡ AI Skills & Automation

🤖 Copilot brief⚡ AI SkillsResolveEnrichAuto-CollectHuntReportExport

Automate unattended via the cron pipeline (collect → ingest → resolve → enrich → score → alert).

🔗 Pivot to related disciplines

CRYPTINT Cryptocurrency Intelligence →

🎯 Mission

Sanctions Intelligence collects designation lists, ownership aggregations, and evasion-network indicators to determine who is restricted and how they circumvent controls. It answers whether an entity is sanctioned directly or through the 50-percent ownership rule, how front companies and dark-fleet logistics enable evasion, and where secondary-sanctions exposure exists.

📡 Collection methods

  • Watchlist reconciliation and fuzzy name/alias screening
  • 50-percent-rule ownership aggregation across designated parties
  • Front-company and successor-entity detection
  • AIS-gap / dark-fleet and ship-to-ship transfer detection
  • Trade-diversion and dual-use goods routing analysis
  • Transliteration and alias normalization for cross-script matching
  • Aircraft and vessel re-flagging / ownership-change tracking

🔧 Tools & frameworks

  • OpenSanctions/yente
  • Maltego
  • Equasis
  • MarineTraffic
  • ADS-B Exchange
  • Jellyfish (name matching)
  • OpenRefine

📜 Sanctions Intelligence Tradecraft

  1. Collect all consolidated designation lists and target ownership/registry data
  2. Normalize aliases and transliterations, then screen entities with fuzzy matching
  3. Aggregate indirect ownership to apply the 50-percent rule and map front companies
  4. Attribute evasion via AIS gaps, re-flaggings, and transshipment to specific vessels and operators
  5. Issue a designation-exposure memo with match confidence and evasion evidence
  6. Push confirmed hits to screening systems and refer new evasion typologies to enforcement

📊 Dashboard KPIs

List entities screened50%-rule hits derivedDark-fleet vessels flaggedFront companies detectedEvasion typologies logged
Workstation · Copilot · AI Skills · Automation · Playbooks · Lookups · Docs · Reports

🤖 AI Copilot

🔍 Lookup & Enrich

💡 Recommendations

⚙ Automation

Cron: 0 * * * * php /home/zaptf0zdggll/public_html/threats/cron.php