Playbooks
9.6K
generated + curated
Mission domains
52
theaters
Disciplines
52
tradecraft
Data points
65
selectors
📜 Playbook Library
The full operational catalog spanning every mission domain, discipline and data point, plus curated incident-response workflows. Each playbook opens the command center where its intel-cycle steps run.
9.6K matches page 3/161
DNS Record ExploitationData Point
An individual DNS resource record (A, MX, TXT, NS, CNAME) exposing hosting and mail posture.
TLS / JA3 Fingerprint ExploitationData Point
A hash of TLS client-hello parameters used to fingerprint clients, malware, and C2 frameworks.
Person / Name ExploitationData Point
A named individual — the subject of identity resolution and profiling.
Email Address ExploitationData Point
Electronic mail address tied to an individual or organization.
Username / Handle ExploitationData Point
Screen name or handle used across online platforms and services.
Phone Number ExploitationData Point
Telephone number for voice, SMS, or messaging identification.
Physical Address ExploitationData Point
A physical or mailing address tied to a person, company, or registered entity.
Social Profile ExploitationData Point
A social media profile or online account page tied to a persona or identity.
Device / Advertising ID ExploitationData Point
A mobile advertising or device identifier used in adtech data to track and locate devices.
National ID Number ExploitationData Point
A government-issued personal identification number — highly sensitive PII.
Biometric Identifier ExploitationData Point
Face, fingerprint, iris, gait, or voice templates used for identification — most sensitive PII class.
File Hash ExploitationData Point
Cryptographic fingerprint of a file, used for malware identification.
CVE / Vulnerability ExploitationData Point
Common Vulnerabilities and Exposures identifier for a known flaw.
SSL/TLS Certificate ExploitationData Point
A digital certificate binding a public key to an identity.
Malware Family ExploitationData Point
A named class of related malicious software.
File / Document ExploitationData Point
A file or document artifact — malware sample, leaked document, image, or email attachment.
Onion / Hidden Service ExploitationData Point
A Tor hidden service address on the dark web.
Data Breach ExploitationData Point
A known data breach or leak incident with exposed records.
Password / Credential ExploitationData Point
An exposed password or credential pair from leaks or dumps.
Company / Organization ExploitationData Point
A legal entity — corporation, LLC, NGO, or business.
Patent ExploitationData Point
An intellectual property filing granting invention rights.
Legal Entity Identifier ExploitationData Point
A 20-character global identifier for a legal entity participating in financial transactions.
Corporate Filing ExploitationData Point
A regulatory or corporate filing (SEC, Companies House, court).
Tax ID / VAT Number ExploitationData Point
A jurisdiction-issued tax registration number for a person or entity.
Cryptocurrency Address ExploitationData Point
Blockchain wallet address for receiving or sending crypto assets.
Transaction Hash ExploitationData Point
A blockchain transaction identifier for tracing fund flows.
Stock Ticker / Security ExploitationData Point
An exchange-listed security symbol, pivoting to filings, ownership, and market data.
Sanction / Watchlist Entry ExploitationData Point
An entry on a sanctions list, watchlist, or PEP database.
Bank Account / IBAN ExploitationData Point
A bank account identifier (IBAN, SWIFT/BIC, routing + account) central to financial tracing.
Location / Coordinates ExploitationData Point
A geographic point, place, or region — the basis of GEOINT analysis.
GPS Coordinates ExploitationData Point
Precise latitude/longitude coordinates identifying an exact point on Earth — the atomic unit of GEOINT analysi
Facility / Site ExploitationData Point
A physical installation — plant, base, port, data centre — with a fixed footprint and function.
Satellite Imagery ExploitationData Point
Overhead imagery of an area of interest, used for change detection and site analysis.
HS Commodity Code ExploitationData Point
The Harmonized System code classifying a traded good — the key to trade-flow analysis.
Shipment / Bill of Lading ExploitationData Point
A consignment record linking shipper, consignee, goods, and route.
Shipping Container ExploitationData Point
An ISO container identifier — trackable across ports, vessels, and customs events.
Vessel / Ship ExploitationData Point
A maritime vessel identified by IMO, MMSI, or call sign.
Aircraft ExploitationData Point
An aircraft identified by tail number, ICAO hex, or registration.
Vehicle Identification Number ExploitationData Point
A 17-character globally unique vehicle identifier encoding manufacturer, model, and year.
License Plate ExploitationData Point
A jurisdiction-issued vehicle registration mark — the primary field identifier for a vehicle.
Cell Tower / Cell ID ExploitationData Point
A mobile network cell identifier (MCC/MNC/LAC/CID) usable for coarse device geolocation.
IMEI / Device Identifier ExploitationData Point
A unique mobile-equipment identifier; the TAC prefix identifies make and model.
Image / Photograph ExploitationData Point
A still image — carries EXIF metadata and is the primary artifact for visual verification.
Video ExploitationData Point
A video file or stream — the core artifact for incident verification and chronolocation.
Court Case / Docket ExploitationData Point
A filed legal proceeding — the authoritative record of disputes, judgments, and enforcement.
Real Property / Parcel ExploitationData Point
A land or building record — deeds, title, valuation, and ownership history.
Messaging Handle ExploitationData Point
An identity on a messaging platform (Telegram, Signal, Discord) used for coordination and sales.
Email Header ExploitationData Point
Full message headers exposing routing, originating IP, authentication, and mailer artifacts.
Detection Signature ExploitationData Point
A YARA/Sigma/Snort rule encoding detection logic for a malware family or behavior.
Credential / API Token ExploitationData Point
An exposed secret — API key, token, or JWT — granting access to systems and data.
Code Repository ExploitationData Point
A source-code repository — leaks secrets, reveals developers, and anchors supply-chain risk.
Software Package ExploitationData Point
A published dependency (npm, PyPI, Maven) — the vector for supply-chain compromise.
Keyword / Narrative ExploitationData Point
A search term, topic, hashtag, or narrative tracked across media and platforms.
Event / Incident ExploitationData Point
A discrete real-world occurrence — protest, strike, breach, seizure — with time, place, and actors.
Flight Number / Route ExploitationData Point
A scheduled flight designator and its route — pivots to aircraft, operator, and movement history.
Radio Callsign ExploitationData Point
A licensed radio identifier for a station, vessel, aircraft, or operator.
Paste / Leak Post ExploitationData Point
Text posted to a paste site or leak forum — a frequent first appearance of stolen data.
Attack Surface Intelligence for Nation StateFusion
Apply Attack Surface Intelligence tradecraft to the Nation State mission
Breach Intelligence for Nation StateFusion
Apply Breach Intelligence tradecraft to the Nation State mission
Certificate Intelligence for Nation StateFusion
Apply Certificate Intelligence tradecraft to the Nation State mission
Workstation · Copilot · AI Skills · Automation · Playbooks · Lookups · Docs · Reports
🤖 AI Copilot
⚡ AI Skills
🔍 Lookup & Enrich
📚 Docs & Reports
💡 Recommendations
- Explore related tools below
- Automate recurring work via cron