Disciplines

📡 Signals Intelligence (SIGINT)

Intelligence from Intercepted Communications and Emissions
Technical

Sources

0
0 no-auth

Mission domains

0
reach

Data points

0
covered

Related INT

0
disciplines

🔍 Lookup

📜 Playbook — Signals Intelligence collection

  1. Direction — frame the requirement for Signals Intelligence: what decision does this support, by when?
  2. Collection — collect from the 0 mapped sources (0 free) — filter the catalog by SIGINT; capture provenance and observe OPSEC.
  3. Processing — normalize, de-duplicate and enrich the collected data.
  4. Analysis — correlate against local holdings; apply ACH; assign confidence.
  5. Dissemination — open a case, draft a report, share via STIX/MISP.
  6. Feedback — set an alert rule / watchlist to monitor for change.

⚡ AI Skills & Automation

🤖 Copilot brief⚡ AI SkillsResolveEnrichAuto-CollectHuntReportExport

Automate unattended via the cron pipeline (collect → ingest → resolve → enrich → score → alert).

🎯 Mission

Signals Intelligence derives intelligence from communications and electronic signals through traffic analysis, protocol dissection and metadata fusion — in the open-source domain, from exposed services, telemetry and passive network signatures. It answers who is communicating with whom, how adversary infrastructure is structured, and where command-and-control patterns emerge.

📡 Collection methods

  • Passive traffic capture and protocol dissection
  • Traffic-analysis and metadata (netflow) flow correlation without content
  • TLS/JA3, JA3S and HASSH client and server fingerprinting
  • Communications externals analysis to map who-talks-to-whom
  • Exposed telemetry harvesting (MQTT, SNMP, syslog, industrial protocols)
  • Encrypted-traffic classification and periodic beacon detection

🔧 Tools & frameworks

  • Wireshark
  • Zeek
  • Suricata
  • tshark
  • NetworkMiner
  • nfdump / Argus
  • JA3
  • Maltego

📜 Signals Intelligence Tradecraft

  1. Capture traffic and enumerate exposed services and telemetry across the target networks
  2. Reassemble sessions, extract JA3/HASSH fingerprints and normalize netflow records
  3. Perform traffic analysis to map communicants, beacons and C2 patterns
  4. Fuse ASN, passive DNS and certificate pivots to attribute infrastructure to operators
  5. Issue a communications and electronic-OB report with the communication graph and indicators
  6. Push JA3 and C2 IOCs to hunting and cue CYBINT and RFINT

📊 Dashboard KPIs

Sessions analyzedJA3 matchesC2 beaconsComms links mappedASNs profiled
Workstation · Copilot · AI Skills · Automation · Playbooks · Lookups · Docs · Reports

🤖 AI Copilot

🔍 Lookup & Enrich

💡 Recommendations

⚙ Automation

Cron: 0 * * * * php /home/zaptf0zdggll/public_html/threats/cron.php