📡 Signals Intelligence (SIGINT)
Intelligence from Intercepted Communications and Emissions
Technical
Sources
0
0 no-auth
Mission domains
0
reach
Data points
0
covered
Related INT
0
disciplines
🔍 Lookup
📊 Pre-built Queries · Signals Intelligence
📜 Playbook — Signals Intelligence collection
- Direction — frame the requirement for Signals Intelligence: what decision does this support, by when?
- Collection — collect from the 0 mapped sources (0 free) — filter the catalog by SIGINT; capture provenance and observe OPSEC.
- Processing — normalize, de-duplicate and enrich the collected data.
- Analysis — correlate against local holdings; apply ACH; assign confidence.
- Dissemination — open a case, draft a report, share via STIX/MISP.
- Feedback — set an alert rule / watchlist to monitor for change.
⚡ AI Skills & Automation
Automate unattended via the cron pipeline (collect → ingest → resolve → enrich → score → alert).
🧩 Advanced Capabilities
✨ Enrichment pathways
🎯 Mission
Signals Intelligence derives intelligence from communications and electronic signals through traffic analysis, protocol dissection and metadata fusion — in the open-source domain, from exposed services, telemetry and passive network signatures. It answers who is communicating with whom, how adversary infrastructure is structured, and where command-and-control patterns emerge.
📡 Collection methods
- Passive traffic capture and protocol dissection
- Traffic-analysis and metadata (netflow) flow correlation without content
- TLS/JA3, JA3S and HASSH client and server fingerprinting
- Communications externals analysis to map who-talks-to-whom
- Exposed telemetry harvesting (MQTT, SNMP, syslog, industrial protocols)
- Encrypted-traffic classification and periodic beacon detection
📚 Key sources & datasets
🎫 Data points produced
🔧 Tools & frameworks
- Wireshark
- Zeek
- Suricata
- tshark
- NetworkMiner
- nfdump / Argus
- JA3
- Maltego
📜 Signals Intelligence Tradecraft
- Capture traffic and enumerate exposed services and telemetry across the target networks
- Reassemble sessions, extract JA3/HASSH fingerprints and normalize netflow records
- Perform traffic analysis to map communicants, beacons and C2 patterns
- Fuse ASN, passive DNS and certificate pivots to attribute infrastructure to operators
- Issue a communications and electronic-OB report with the communication graph and indicators
- Push JA3 and C2 IOCs to hunting and cue CYBINT and RFINT
📊 Dashboard KPIs
Sessions analyzedJA3 matchesC2 beaconsComms links mappedASNs profiled
🔍 Pre-built queries
🔗 Cross-discipline pivots
🧩 Advanced Capabilities
Workstation · Copilot · AI Skills · Automation · Playbooks · Lookups · Docs · Reports
🤖 AI Copilot
⚡ AI Skills
🔍 Lookup & Enrich
📚 Docs & Reports
💡 Recommendations
- Explore related tools below
- Automate recurring work via cron