Counter-Terrorism: Mission Domain Intelligence Guide
Attack planning leaves a logistics trail before it leaves an ideological one: a rented van, a chemical purchase, a reconnaissance visit at the same hour three weeks running.
Attack planning leaves a logistics trail before it leaves an ideological one: a rented van, a chemical purchase, a reconnaissance visit at the same hour three weeks running.
What Counter-Terrorism covers as a mission domain
Counter-terrorism intelligence covers the identification, assessment and lawful disruption of individuals and organisations that use or plan violence against civilians to advance political, religious or ideological aims. Practitioner work includes group and network analysis, attack planning indicator assessment, terrorist financing, travel and facilitation networks, weapons and precursor acquisition, propaganda and recruitment analysis, prison and diaspora dynamics, and target vulnerability assessment. It equally includes the protective side: threat-to-life warnings, protective security advice, and the evidential work that supports prosecution rather than kinetic response.
Analysts distinguish organised group threats with command structures and logistics from directed-inspired hybrids and self-initiated attackers with no organisational contact at all. Ideological categories, whether jihadist, extreme right-wing, ethno-nationalist, left-wing or single-issue, matter for network mapping but far less for behavioural indicators, which converge markedly across them. Financing ranges from state sponsorship, extortion and kidnap proceeds down to small-scale self-funding through loans, benefit fraud and ordinary salaries.
Why it matters
Terrorism's harm exceeds its casualty count because it is designed to alter political behaviour, and the state response, meaning emergency powers, community suspicion and restricted movement, often causes broader and longer-lasting damage than the attacks themselves. Communities targeted both by attackers and by heavy-handed responses bear the cost twice over. Accurate, proportionate intelligence is precisely what allows disruption without the over-reach that generates the next cohort of recruits.
What analysts actually look for
These are the concrete, observable signals that carry weight in this area of work:
- Acquisition of precursor chemicals, components or weapons inconsistent with any declared occupation, hobby or legitimate business need.
- Repeated reconnaissance of a location, including timed visits, photography of security measures and probing of access routes.
- Escalation from consuming propaganda to producing it, particularly the drafting of a claim of responsibility or martyrdom statement.
- Sudden withdrawal from social ties, settlement of debts, giving away possessions or other unexplained final arrangements.
- Travel routed through transit points inconsistent with the stated purpose, booked in cash and at short notice.
- Rapid acquisition of loans or credit with no repayment plan, or small transfers toward conflict-adjacent corridors.
- Coordinated migration by a cluster of contacts to encrypted platforms immediately following an arrest or takedown in their network.
- Acquisition of uniforms, credentials or vehicles that would provide legitimate-seeming access to a specific protected environment.
Where the data comes from
Authoritative and openly available collection points. Always confirm licensing and terms before operational or commercial use:
- UN Security Council 1267 and 1988 Consolidated Lists — UN designations of individuals and entities linked to listed terrorist organisations, with identifiers.
- US State Department Foreign Terrorist Organizations list — Designated groups with legal basis, aliases and summaries of historical activity.
- OFAC Specially Designated Global Terrorist designations — Financial designations of terrorist financiers and facilitators with identifying data.
- Europol TE-SAT — Annual EU assessment of attacks, arrests, convictions and ideological trends with case-level detail.
- Global Terrorism Database and ACLED — Incident-level historical event data supporting trend, tactic and target selection analysis.
- UK Home Office proscribed organisations list and equivalents — National proscription decisions with the aliases and successor names attached.
- Tech Against Terrorism and GIFCT outputs — Analysis of terrorist exploitation of platforms, content migration and hosting infrastructure.
- Court records and sentencing remarks — The most reliable open-source detail on plots, methods, financing and network structure.
A working method
A repeatable sequence beats ad-hoc searching. This is a practical starting workflow:
- Establish threat and mandate — Define who is being assessed, on what legal authority, and what decision the assessment supports, since scope creep here is a rights problem.
- Build the network picture — Map relationships, roles and facilitation functions, distinguishing operators from sympathisers, family and incidental contacts.
- Assess behavioural indicators — Apply structured professional judgement instruments rather than checklists, focusing on capability, intent and observable preparatory behaviour.
- Trace logistics and finance — Follow procurement, travel, accommodation and funding as physical behaviours that leave documentary residue.
- Assess targets and vulnerability — Identify what the network's stated intent and demonstrated capability make attractive, and where protective measures are weakest.
- Disrupt proportionately — Select from prosecution, disruption of enablers, financial designation, safeguarding referral or protective security, matched to the evidence held.
- Document and review — Record the reasoning, evidence and decision so the assessment can be audited and revisited as facts change.
How this connects across the intelligence taxonomy
Intelligence work does not respect neat boundaries. The mission domain you are working, the disciplines you practise, and the data points you pivot on are one connected system. These are the direct relationships for this entry — every link is also a tag, so you can follow any thread across the whole library.
Practised with these disciplines
- Threat Actor Intelligence — Tracking Adversary Groups Over Time
- Human Intelligence — Information from People, Ethically Obtained
- Social Media Intelligence — Intelligence from Social Platforms and Networks
- Geospatial Intelligence — Intelligence Derived from Place
- Financial Intelligence — Following Value Through the Financial System
- Signals Intelligence — Intelligence from Intercepted Communications and Emissions
- Criminal Intelligence — Intelligence Supporting Criminal Investigation
Worked in these data points
- Person / Name — A named individual — the subject of identity resolution and profiling.
- Social Profile — A social media profile or online account page tied to a persona or identity.
- Event / Incident — A discrete real-world occurrence — protest, strike, breach, seizure — with time, place, and actors.
- Location / Coordinates — A geographic point, place, or region — the basis of GEOINT analysis.
- Messaging Handle — An identity on a messaging platform (Telegram, Signal, Discord) used for coordination and sales.
- Cryptocurrency Address — Blockchain wallet address for receiving or sending crypto assets.
- Phone Number — Telephone number for voice, SMS, or messaging identification.
Adjacent mission domains
- Extremism & Radicalization
- Conflict & Humanitarian
- WMD / Proliferation
- Weapons Trafficking
- Kidnap, Hostage & Extortion
- Border Security & Migration
Inside the platform: where Counter-Terrorism lives
The Quantus platform is 204 pages behind a 147-item sidebar organised into six working groups: Command (24 items), Dashboards (15), Threat Theaters (14), Intelligence Domains (15), Investigate (34), and Administration (45). This entry is not a page in isolation — it is a thread running through several of them.
The modules that matter most here:
domain.php?d=ct— Counter-Terrorism dashboardtheater.php?d=ct— Threat theater viewsearch.php— Person / Name profilecorrelate.php— Correlation graphcases.php— Case management
Each dashboard is local-first: it renders from the platform’s own database rather than depending on a live third-party call, so it still works when an upstream API is unreachable or rate-limited. Heavy aggregates are cached with a hard query time cap and degrade to the last good value instead of hanging the page.
Automation, playbooks and AI skills
Analysis that only happens when someone remembers to run it is not a capability. The platform ships a 30-step automation pipeline (cron.php) that collects, ingests, resolves, enriches, correlates and scores on a schedule — 25 seeders, 11 resolvers and 7 enrichment runners, all idempotent and cursor-based so a run can be interrupted and resumed without duplicating or losing work.
Relevant playbooks
Of the 14 incident playbooks in playbooks.php, these apply directly to Counter-Terrorism:
- Cryptocurrency Tracing — a step-checked workflow with the pivots, sources and handling rules already wired in.
- Disinformation / Influence Op Response — a step-checked workflow with the pivots, sources and handling rules already wired in.
AI skills that apply
The 16 one-click operations in ai-skills.php are deterministic jobs, not free-text generation. The ones that matter here:
- Threat Hunt
- Correlate Infrastructure
- Run Alert Rules
- Summarise (Copilot)
- Generate Report
Alerting closes the loop: rules in alerts.php fire on new indicators matching a saved query, so a first sighting in this area raises a notification rather than waiting to be noticed at the next review.
Feeds, data sources and the API
The collection layer runs a feed registry of free, machine-readable sources — bulk blocklists and trackers (Maltrail, IPsum, FireHOL, the full abuse.ch corpora, phishing databases, Emerging Threats, Spamhaus, DigitalSide, ThreatView), authoritative government feeds (CISA KEV, OFAC, UN and EU sanctions lists), and reference datasets (RIR allocations, ip-to-ASN and geolocation tables, MITRE ATT&CK, EPSS). collect.php pulls them server-side on a schedule; feeds.php and source-catalog.php show what is registered, what it covers and when it last ran.
Anything the platform holds is reachable programmatically. The REST API in api.php exposes 11 endpoints — status, stats, search, lookup, recent, export, bulk_check, top_threats, by_category, categories, check — and export.php streams 18 formats in bounded chunks, so a million-row export neither exhausts memory nor times out:
STIX 2.1, MISP, OpenIOC 1.1, CEF (ArcSight), LEEF 2.0 (QRadar), Zeek/Bro intel, Snort/Suricata rules, Palo Alto EDL, BIND RPZ, hosts blackhole, iptables, CSV, JSON, NDJSON/JSONL, XML.
That covers the CTI standards (STIX 2.1, MISP, OpenIOC), SIEM ingestion (CEF, LEEF, Zeek), detection engines (Snort/Suricata), and direct enforcement (Palo Alto EDL, BIND RPZ, hosts, iptables) — so intelligence developed here can be actioned in the tools you already run, without a manual reformatting step. A TAXII 2.1 server and a MISP/RSS feed are also served for pull-based sharing.
Use cases
Three ways this entry earns its keep in day-to-day work:
- Triage under time pressure. An artifact or report lands and you need a defensible read in minutes, not days. Establish threat and mandate is the first move; the platform pre-computes the enrichment so the analyst spends the time on judgement rather than lookups.
- Building the picture. A single indicator is rarely the story. Assess behavioural indicators turns one artifact into a network — shared infrastructure, repeated selectors, the same operator behind different names — via the correlation graph and the cross-entity link engine.
- Producing something actionable. Analysis that ends in a document nobody can use is wasted. Document and review feeds the case file, the detection rule, the block list or the referral — with sourcing attached so the recipient can verify it.
Case management (cases.php), watchlists, saved searches and scheduled reports mean the work persists between sessions and survives an analyst leaving the team.
How each sector uses Counter-Terrorism
The same entry is worked very differently depending on who you are, what authority you hold, and what you are ultimately producing. A military analyst is supporting a commander’s decision; a journalist is meeting a publication standard; an NGO caseworker is protecting a person. The underlying artifacts are shared — the constraints, outputs and thresholds are not.
🎖 Military and defence
Military counter-terrorism analysis supports force protection, base and route security, partner force assessment and, in operational theatres, the intelligence preparation that underpins lawful targeting decisions. Products include threat warnings against installations, network assessments of armed groups with terrorist designations, and pattern analysis of attack methods relevant to defensive posture. Constraints are legal and doctrinal: the law of armed conflict governs where hostilities apply, and law enforcement standards govern elsewhere, so analysts must be explicit about which framework the assessment supports. Assessments driving deprivation of liberty or lethal force require sourcing discipline, confidence statements and clear separation between corroborated fact and inference.
🕵 National intelligence
National services run requirements-driven collection against organised groups, facilitation networks and individuals of concern. Fusion joins signals, human, financial, travel and open-source reporting into an assessed picture supporting warning, disruption and prosecution. Handling is heavily compartmented, and the persistent friction is between protecting collection sources and providing material usable in court or for public warning. Dissemination priorities are the disruption authority, protective security advisers, partner services and the prosecuting authority. The discipline that matters most is separating behavioural indicators of attack planning from ideological affiliation, since the latter is a poor predictor and generates enormous, rights-infringing false positive volume.
👮 Law enforcement
Law enforcement builds cases for prosecution, which is the primary lawful disruption route in most jurisdictions. Evidence includes communications, financial records, purchase records for precursors and components, travel data, digital device forensics and surveillance product, most requiring judicial authorisation. Preparatory offences, meaning possession, preparation and encouragement, allow intervention before an attack but demand careful evidence of intent. Disclosure obligations are extensive and intelligence-derived material creates recurring public interest immunity problems. Charging decisions balance the point of intervention against evidential sufficiency, and the earlier the intervention the harder the intent element becomes to prove.
🔍 Private investigation and corporate security
Corporate security applies this to protective security: threat and vulnerability assessment for sites and events, travel risk, executive protection and crisis planning. The analytical product identifies plausible attack methods against a specific asset and the mitigations that address them. A private actor may not conduct intrusive surveillance, may not compile intelligence files on individuals without a lawful basis, and must route any information indicating an actual threat to life to police immediately rather than managing it internally. Monitoring of protest activity and lawful political expression is a recurring boundary failure that generates serious legal and reputational exposure.
📰 Journalism and OSINT media
Reporting requires verification discipline against a heavy incentive to speed. Do not attribute attacks on the basis of a claim alone, since claims are made falsely for prestige and denied for tactical reasons. Avoid publishing operational detail of methods, which functions as instruction, and follow established guidance on limiting perpetrator prominence, for which the contagion evidence is reasonably strong. Protect sources inside communities and security services. Give affected communities care in framing, since coverage that attributes collective responsibility measurably increases hate crime. Publish corrections prominently, because early misattribution in these events is common and consequential.
🌍 NGO, humanitarian and human rights
Human rights and humanitarian organisations engage with counter-terrorism principally through its consequences: due process in detention and prosecution, impact of designation on humanitarian access and financial services, and the effect of security measures on communities. Documentation should record process violations with the same rigour applied to security claims. Do-no-harm requires care that engagement does not expose beneficiaries to designation-related liability, which has genuinely restricted aid delivery in several contexts. Duty of care includes legal support for staff operating where counter-terrorism law criminalises contact with designated groups, an exposure that is real and inadequately understood.
🎓 University and research
Research spans political violence studies, radicalisation processes, network analysis and evaluation of counter-terrorism measures. Methodology must confront a severe base rate problem: attacks are rare events, so predictive claims from small samples are usually unsound, and comparison groups are essential. Datasets such as incident databases carry known coverage biases by region and period that should be stated. Ethics approval is mandatory for any contact with subjects, with clear protocols on disclosure obligations if a researcher learns of a planned attack. Publication should avoid operational detail, and researchers should be conscious that funding sources in this field shape framing and must be declared.
Playbook: working Counter-Terrorism end to end
A repeatable sequence, from the moment the requirement lands to the moment a product is delivered and the case is closed out. Each phase states what you are trying to establish, not merely what to click — the point is a defensible chain of reasoning, not a checklist.
Phase 1 — Define the requirement and the framework
Establish what decision the analysis supports and which legal framework governs: criminal investigation, protective security, or armed conflict. This determines the evidential standard, what collection is available and what the output may recommend. Record the requirement in specific terms rather than as a general threat question. Stop when you can state the decision, the decision maker and the deadline, because open-ended terrorism questions consume unlimited resource.
Phase 2 — Establish the baseline threat picture
Assemble what is already known: active groups and their capability, historical attack methods in the geography, current designations, and recent disrupted plots. This positions any new indicator against a baseline rather than treating it as unprecedented. Output is a short threat baseline with sourcing. Stop when you can state what normal looks like for this environment, which is what makes an anomaly meaningful.
Phase 3 — Work behavioural indicators, not affiliation
Focus assessment on observable behaviours associated with attack preparation: hostile reconnaissance, acquisition of components or weapons, rehearsal, attack-related research, security-conscious communications changes, and preparation of legacy material. Ideological affiliation is a poor predictor and using it as a filter generates enormous false positive volume while missing unaffiliated actors. Output is an indicator assessment tied to observed conduct.
Phase 4 — Assess capability against intent honestly
Distinguish stated intent from demonstrated capability from access to means. Most concerning individuals never acquire capability, and most capable actors do not act; the assessment must handle both dimensions and their trajectory. Record what would need to change for the risk to become imminent. Stop when the assessment states specifically what capability the subject currently possesses and what they lack.
Phase 5 — Map the facilitation network
Where an organised group is involved, work the enabling layers rather than the attackers: travel facilitation, document supply, safe houses, weapons and precursor procurement, communications infrastructure and financing. These layers persist across cells and are the durable disruption target. Output is a network picture identifying nodes that appear across multiple plots or cells.
Phase 6 — Analyse the financing
Trace how the activity is funded: state sponsorship, criminal proceeds, extortion, charitable diversion, or small-scale self-funding through salaries, loans and fraud. Self-funded plots leave financial traces that are individually unremarkable and collectively diagnostic, such as specific purchases in a compressed period. Financial analysis frequently produces the most prosecutable evidence in the entire case.
Phase 7 — Test the target vulnerability side
Assess plausible targets from the adversary's perspective: accessibility, crowd density, symbolic value, security posture and escape routes. This converts threat analysis into protective action and is often where analytical work delivers the most measurable benefit, since target hardening is achievable while attacker intent is not. Output is a prioritised vulnerability assessment with specific mitigations.
Phase 8 — Handle threat-to-life obligations immediately
Where information indicates a specific threat to identifiable people, disclosure obligations arise immediately and override analytical tidiness. Route it to the authority that can act, document the time and content of the referral, and follow the established warning process. This step is not sequential; it interrupts everything else the moment the information appears.
Phase 9 — Build for prosecution from the start
Structure collection and recording so material can survive disclosure and challenge: contemporaneous notes, preserved originals, documented continuity, and clear separation of sensitive collection from evidential product. Retrofitting evidential discipline onto an intelligence case is usually impossible. Stop when the case file could be handed to a prosecutor with a defensible account of provenance for every item.
Phase 10 — Choose the disruption option
Options run from prosecution for a preparatory offence, through diversion and safeguarding referral for individuals not yet at criminal threshold, to immigration action, asset freezing, designation and protective security measures. Earlier intervention is safer but evidentially harder, and the trade-off should be made explicitly rather than by default. Output is a recommendation with the evidential and rights implications stated.
Phase 11 — Coordinate the intervention
Ensure sequencing across agencies so that arrest, search, financial restraint and protective measures happen in an order that preserves evidence and prevents flight or acceleration. Communications planning matters, since premature exposure has triggered attacks. Stop when every participating body knows its trigger, its timing and its handling caveats.
Phase 12 — Review honestly and update indicators
After any disruption or attack, conduct a review that will find uncomfortable answers: what was known and when, what was missed, whether the indicators used were actually predictive, and whether the intervention displaced rather than removed the threat. Update the indicator library on evidence rather than intuition. Publish sanitised lessons to protective security customers who can act on them.
The platform ships this as a step-checked workflow in playbooks.php, so progress is recorded against a case rather than held in someone’s head.
Source register: what to collect from, and how
Sources are listed with their access model so you can plan around cost and licensing before you build a dependency on them. Open means no account required; registration means a free account or API key; licensed means paid or institutional access. Always confirm current terms — licensing changes, and a source that was free for research may not be free for commercial or evidential use.
| Source | Access | What it gives you | How it is used here |
|---|---|---|---|
| UN Security Council counter-terrorism committees and sanctions lists | Open | Consolidated designation lists, monitoring team reports and state implementation assessments for terrorism sanctions. | Establishes binding designations and supplies detailed reporting on group structure, financing and travel. |
| US Department of State country reports and designations | Open | Annual country reporting on terrorism plus foreign terrorist organisation designations and supporting narrative. | Provides group-level baseline on capability, financing and state responses in the relevant geography. |
| Europol TE-SAT and threat assessments | Open | Annual European terrorism situation and trend report with attack, arrest and plot data by ideology and country. | Supplies the European baseline for attack methods, plot disruption rates and ideological distribution. |
| Global Terrorism Database | Registration | Long-run open incident database coding terrorist attacks by date, location, perpetrator, weapon and target type. | Establishes historical attack method and target patterns in a geography for baseline and vulnerability analysis. |
| ACLED | Registration | Georeferenced political violence event data including attacks by designated groups with actor coding. | Provides near-current event data where incident databases lag, supporting trend and territorial analysis. |
| Combating Terrorism Center at West Point | Open | Applied research and captured document analysis on organised group structure, doctrine and operations. | Supplies primary-source-derived understanding of group decision making and internal organisation. |
| ICSR research | Open | Academic research on radicalisation, foreign fighters, prison dynamics and online mobilisation. | Provides evidence base on pathway dynamics that informs behavioural indicator design and prevention work. |
| FATF terrorist financing guidance | Open | Standards, typologies and risk guidance on terrorist financing and targeted financial sanctions implementation. | Defines the recognised financing typologies and the reporting obligations engaged in a financing case. |
| OFAC counter-terrorism designations | Open | US designations of terrorist organisations, financiers and facilitators with identifiers and addresses. | Establishes designation status of individuals and entities identified in a facilitation or financing network. |
| INTERPOL notices and databases | Licensed | International alerts on wanted persons, stolen travel documents and foreign terrorist fighter records. | Checks identities and documents against international records through the national central bureau. |
| Tech Against Terrorism | Open | Analysis of terrorist use of online platforms, and support to smaller platforms on content and disruption. | Tracks the online distribution infrastructure used by designated organisations and their supporters. |
| GIFCT resources | Open | Cross-industry forum publishing research and coordinating platform response to terrorist and violent extremist content. | Provides insight into platform-level disruption and the hash-sharing infrastructure used across services. |
| UNODC counter-terrorism legal resources | Open | Model legislation, legal frameworks and technical assistance material on terrorism offences and prosecution. | Establishes the offence structures available in a jurisdiction and international cooperation mechanisms. |
| UK protective security guidance | Open | National guidance on protective security, hostile reconnaissance and crowded places from the UK security authority. | Supplies the recognised methodology for target vulnerability assessment and mitigation recommendations. |
| OHCHR human rights and counter-terrorism resources | Open | Special Rapporteur reporting and guidance on human rights compliance in counter-terrorism measures. | Frames the rights constraints on measures recommended and identifies where practice has been found unlawful. |
| GNET research | Open | Research network publishing on terrorist use of technology, online ecosystems and platform responses. | Supplies current analysis of online mobilisation methods relevant to indicator development. |
Prefer sources that publish a methodology and a revision history. A dataset that changes silently is a liability in any product that has to survive challenge.
Tooling
Tools commonly used against Counter-Terrorism. None of these replace judgement, and each carries its own failure modes — know what a tool infers versus what it observes.
- i2 Analyst's Notebook — Charts networks, timelines and communications for investigation and court presentation. Limitation: chart quality depends entirely on disciplined entity resolution beforehand.
- Digital forensic suites — Extract and analyse device, cloud and application data to evidential standard. Limitation: encryption and cloud-only storage increasingly place material beyond reach without process.
- Structured analytic technique frameworks — Impose hypothesis testing and challenge on assessments where confirmation bias is acute. Limitation: time-consuming and frequently skipped under operational tempo.
- Financial transaction analysis tooling — Identifies purchase patterns and funding flows consistent with attack preparation. Limitation: individually unremarkable transactions require context to become meaningful.
- Open-source monitoring platforms — Track designated group media output and supporter distribution networks. Limitation: collection on individuals requires a lawful basis, which platform monitoring tools do not supply.
- Geospatial analysis tools — Support target vulnerability assessment, reconnaissance pattern analysis and route security planning. Limitation: outputs are sensitive and require handling controls.
- Case management with disclosure tracking — Manages material and its disclosure status through investigation and trial. Limitation: disclosure failures usually originate in collection practice, not in the system.
- Structured risk assessment instruments — Support consistent assessment of individuals of concern across practitioners. Limitation: validated for group-level risk rather than individual prediction, and routinely over-interpreted.
AI skills and automation in detail
These are deterministic jobs with defined inputs and outputs, not open-ended prompting. Each is idempotent and cursor-based: interrupt one and it resumes where it stopped rather than duplicating work or losing progress.
- Threat Hunt — Runs saved hypotheses against the corpus and surfaces what matches, with the query preserved as a versioned artifact.
- Correlate Infrastructure — Builds the cross-entity link graph: shared hosting, reused certificates, overlapping registrants, repeated selectors.
- Run Alert Rules — Evaluates saved rules against new data so a first sighting raises a notification rather than waiting for review.
- Summarise (Copilot) — Produces a narrative summary beside the underlying records. It explains; it never creates indicators or assigns attribution.
- Generate Report — Assembles a sourced product from the current case or query, with provenance attached to each element.
A note on the boundary: the only skill that involves a language model is Summarise (Copilot), and it writes prose about records that already exist. Nothing else on this list involves generation of any kind. No indicator, relationship or attribution in the platform originates from a model. See the full skill list.
Tradecraft notes
The distinctions that separate a competent analyst from a fast one:
- Behaviour predicts, belief does not. Attack planning generates observable logistics, meaning reconnaissance, acquisition, rehearsal and preparation, while ideological content is common among people who never act, so indicator sets built on affiliation waste resource and infringe rights at scale.
- The base rate problem governs everything. Attacks are rare events, so even a highly accurate indicator applied across a population produces overwhelmingly false positives, which is why triage must be sequential and evidence-driven rather than score-driven.
- Claims of responsibility are strategic communications. Groups claim attacks they did not direct to project reach, and deny attacks they did direct for tactical reasons, so attribution must rest on forensic, financial and communications evidence rather than on any statement.
- The facilitation layer outlives the cell. Document suppliers, travel facilitators, procurement intermediaries and financiers service multiple plots, so disruption directed at them removes capability that the removal of any individual attacker does not.
- Self-funded plots leave a compressed purchase signature. Individually lawful acquisitions of vehicles, chemicals, containers or equipment within a short window, inconsistent with the subject's normal pattern, is one of the few genuinely diagnostic financial indicators available.
- Decide the intervention point deliberately. Earlier disruption is safer and evidentially harder, later disruption is evidentially stronger and riskier, and treating this as an operational default rather than a documented decision is how both wrongful prosecutions and missed attacks happen.
- Separate the assessment from the collection. Products that fuse sensitive collection with evidential material create disclosure problems that can collapse a prosecution years later, so build the evidential chain independently from the outset.
- Assess what the subject lacks, not only what they have. Capability gaps, meaning access to weapons, technical skill, or a viable target, are what determine whether intent becomes an attack, and stating them explicitly is what makes an assessment actionable rather than alarming.
Measuring whether it is working
Capability claims should be falsifiable. These are the measures that show whether work on Counter-Terrorism is producing anything, and they are worth baselining before you change process or tooling.
- Proportion of disruptions achieved through prosecution or lawful alternative rather than through repeated monitoring without resolution.
- Ratio of individuals assessed to individuals subject to intrusive measures, tracked to test whether triage is narrowing appropriately.
- Time from first indicator to a documented risk decision, measured across cases rather than for exemplars.
- Proportion of protective security recommendations implemented at assessed sites, since target hardening is the achievable half of the problem.
- Post-event review findings implemented with owners and dates, as against findings raised.
- Rate of successful prosecution outcomes where intelligence-derived material was involved, indicating evidential discipline at collection.
- Community reporting rates and their trend, which indicate whether the relationships that generate most useful early information are intact.
Beware of measuring volume alone. Indicator counts and report counts rise easily and say little; time-to-attribution, proportion of findings that survive review, and how often a product changed a decision say a great deal.
Common pitfalls
- Treating ideological expression as an attack indicator, when the overwhelming majority of radical speech never becomes violence.
- Confirmation bias in network charts, where proximity to a subject silently becomes evidence about the contact themselves.
- Relying on single-source informant reporting without corroboration, especially where the source has incentives to inflate.
- Over-fitting to the last attack's methodology and missing the substitution of a simpler, unmonitored method.
- Discounting extreme right-wing and single-issue threats because their structures are looser and less legible to network analysis.
Legal and ethical considerations
Counter-terrorism work engages the strongest human rights constraints of any domain, because designation and surveillance affect many people who are never charged and errors are severe and lasting. Keep proportionality and necessity reasoning on the record, apply strict handling controls to personal data, and distinguish protected expression from criminal preparation. Material-support and proscription offences can capture research, journalism and humanitarian activity, so ensure your own access to propaganda and communications rests on a lawful basis and documented purpose.
Data integrity: no fabrication, no drift, no hallucination
Intelligence that cannot be traced back to a source is not intelligence, it is assertion. Everything in this entry — and everything in the platform behind it — is built on a small number of non-negotiable rules.
Provenance on every record
Every indicator carries the source that supplied it, a first-seen and last-seen timestamp, and a sighting count. Where several feeds report the same artifact, each contribution is recorded separately rather than collapsed, so you can see whether a finding rests on one source or twelve. Source attribution travels with the data into every export, so a recipient can audit a claim without asking you for the working.
Nothing is invented to fill a gap
If the platform has no data for Counter-Terrorism, it says so. Empty is displayed as empty — never padded with plausible-looking placeholder values, sample records or illustrative examples that a reader might mistake for observations. A dashboard with no rows is a true statement about collection coverage, and it is treated as a gap to close, not a blemish to hide.
Scoring is deterministic and reproducible
Threat scores, reputation grades and risk tiers are computed from stated inputs with fixed weights, not estimated. The same inputs always produce the same output, and the formula is visible rather than a black box. Aggregates are cached with an explicit time-to-live so a figure on screen is never silently stale — and when a heavy query exceeds its time budget the platform serves the last known-good value and labels it, rather than inventing a fresh number or hanging.
Where AI is used, and where it is not
Language models summarise and explain. They do not create indicators, assign attribution or manufacture relationships. No IP address, wallet, hash or identity in the platform originates from a model — every one is ingested from a named feed, resolved from a reference dataset, or entered by an analyst with a source recorded. Copilot output is presented as narrative alongside the underlying records, never in place of them, so a reader can always check the summary against the evidence.
Guarding against drift
Enrichment is additive and timestamped rather than overwriting. Reference data — sanctions lists, allocations, taxonomies — is re-synchronised from the authority on a schedule instead of being edited in place, so local copies cannot quietly diverge from the source of truth. Attribution is recorded with a confidence level and the reporting it rests on, and inferred relationships are labelled as inferred. When a source retracts or corrects, the correction propagates rather than leaving a stale assertion behind.
What this means for you
You can put a finding from this platform in front of a regulator, a court, a board or a partner agency and show where each element came from. That is the standard the tooling is built to — because in this work, being confidently wrong is more damaging than being usefully uncertain.
By the numbers
The taxonomy this entry belongs to is not a marketing list — it is the actual structure of the platform: 52 mission domains, 52 intelligence disciplines and 65 data points, each with a live dashboard behind it. Supporting that: 18 indicator types, 14 playbooks, 16 AI skills, 18 export formats and a 30-step automated pipeline.
This particular entry connects directly to 7 intelligence disciplines, 7 data points, 6 closely related entries — every one of them a tag you can follow, and a dashboard you can open.
Questions analysts actually ask
Does ideology matter for assessing an individual?
For understanding motive, target selection and network context, yes. For predicting whether a specific person will attack, very little. The behavioural precursors to violence converge markedly across ideological categories, and the population holding extreme views is orders of magnitude larger than the population that acts. Using affiliation as a triage filter therefore produces enormous false positive volume, consumes resource, damages community relationships that generate genuine early information, and infringes rights. Ideology belongs in the analysis as context for what the person might do and to whom, not as the trigger for assessing whether they are dangerous.
When should intelligence become a prosecution?
As early as the evidence supports a charge that reflects the seriousness, which in most jurisdictions means preparatory offences rather than waiting for an attempt. The trade-off is explicit: earlier intervention reduces risk to the public but makes intent harder to prove, and a failed prosecution both releases the subject and burns the collection. The decision should be documented as a joint assessment between investigators and prosecutors, revisited as evidence develops, rather than being made by operational default. Monitoring indefinitely because the case is not yet perfect is itself a decision with risk attached.
How is a lone actor different from a directed cell?
Mainly in the absence of the network signatures that most collection is designed to detect. A self-initiated attacker has no facilitation chain, no financing to trace beyond their own income and no communications with an organisation. What remains is behavioural and transactional: research, reconnaissance, acquisition, rehearsal and often leakage of intent to family, colleagues or online communities. That leakage is the most consistently reported feature in retrospective studies, which is why community and workplace reporting routes matter far more for this threat type than technical collection does.
What is the role of open-source analysis?
Substantial for understanding groups, propaganda, mobilisation and attack methods, and legally constrained for anything directed at individuals. Monitoring designated organisations' output, tracking distribution infrastructure and analysing attack claims are legitimate and productive. Compiling information on identifiable individuals requires a lawful basis, a proportionality assessment and retention rules, regardless of whether the material is publicly posted, and organisations that treat public availability as sufficient authority create serious legal exposure. The distinction between studying an ecosystem and building files on people must be enforced structurally, not left to individual analysts.
How should attack methods be described in reporting?
At the level of detail needed for defensive action and no further. Protective security customers need to know the method category, the target characteristics and the observable preparation, which is enough to inform mitigation. They do not need synthesis routes, device specifications or tactical sequencing, and publishing that material provides instruction with no defensive benefit. The same principle applies to public reporting, where established guidance on limiting perpetrator prominence and operational detail rests on a reasonable evidence base for contagion effects, particularly for attack types with a strong imitative pattern.
Why do counter-terrorism financing controls catch so little?
Because the sums are small and the sources are frequently lawful. A vehicle-based attack can be resourced from a salary and a credit card, which no monitoring rule can distinguish from ordinary consumption in advance. Financing controls work well against organised groups with logistics costs, payrolls and cross-border transfers, and they generate excellent evidence retrospectively once a subject is identified. They perform poorly as a detection mechanism for self-funded plots. Programmes should therefore be measured on evidential contribution and disruption of organised financing, not on prevention statistics that the mechanism cannot deliver.
Standards, frameworks and further reading
Work that references a recognised framework is easier to defend, easier to hand over, and easier for a partner to consume:
- UN Security Council Resolutions 1267, 1373 and 2178 and their successors, creating designation, criminalisation and foreign terrorist fighter obligations.
- FATF Recommendations on terrorist financing and targeted financial sanctions, including Recommendation 8 on non-profit organisations.
- International Convention for the Suppression of the Financing of Terrorism and the sectoral counter-terrorism conventions.
- National terrorism legislation defining preparatory offences, such as the UK Terrorism Acts and equivalent statutes elsewhere.
- UN human rights framework applied to counter-terrorism, including the mandate and reports of the Special Rapporteur on human rights while countering terrorism.
- Christchurch Call and GIFCT frameworks governing platform response to terrorist and violent extremist content online.
- Protective security methodologies for crowded places and hostile reconnaissance published by national security authorities.
- Law of armed conflict principles of distinction, proportionality and precaution where counter-terrorism operations occur within an armed conflict.
References
Primary sources and authoritative references for this entry. Publishers revise and retire material, so treat the retrieval date as part of the citation and re-check before relying on any of it in a formal product.
- Terrorism Situation and Trend Report — Europol. Annual European data on attacks, plots, arrests and ideological distribution.
- Country Reports on Terrorism and designations — US Department of State. Country-level assessment and foreign terrorist organisation listings.
- Global Terrorism Database — START, University of Maryland. Long-run coded dataset of terrorist incidents worldwide.
- Monitoring team reports to sanctions committees — UN Security Council. Detailed reporting on designated group structure, financing and travel.
- Terrorist financing risk and typology guidance — Financial Action Task Force. Recognised financing typologies and implementation standards.
- CTC Sentinel and captured document analysis — Combating Terrorism Center, West Point. Applied research on group organisation and operational practice.
- Research on radicalisation and online mobilisation — ICSR, King's College London. Peer-reviewed evidence base on pathways and foreign fighter dynamics.
- Human rights compliance in counter-terrorism — UN Human Rights Office. Special Rapporteur analysis of rights constraints on security measures.
- Protective security guidance for crowded places — UK counter-terrorism policing. Methodology for vulnerability assessment and hostile reconnaissance detection.
Link integrity: every reference above was verified with a live request when this page was generated. Where a publisher had moved or withdrawn a document, the link was repointed at a preserved copy in the Internet Archive and marked as archived. Anything with no reachable copy anywhere had its link removed rather than left to rot — the source is still credited, it simply cannot be linked.
Put it into practice
The Quantus Intel threat intelligence platform operationalises this entry: structures network, logistics and financing evidence so disruption decisions rest on behaviour rather than belief. Explore the platform, or browse the rest of the library by following any tag above.