Disinformation / IO: Mission Domain Intelligence Guide
Two hundred accounts posted the same seven-word phrase within ninety seconds. None of them had existed six weeks earlier. The message was unremarkable; the choreography was the evidence.
Two hundred accounts posted the same seven-word phrase within ninety seconds. None of them had existed six weeks earlier. The message was unremarkable; the choreography was the evidence.
What Disinformation / IO covers as a mission domain
Disinformation and influence operations analysis is the investigation of deliberate, coordinated attempts to manipulate audiences through deceptive means. The analytic object is behaviour and infrastructure rather than the truth value of any single claim: account creation patterns, posting synchronisation, asset reuse, domain and hosting relationships, funding and amplification. Practitioners distinguish state-directed operations from commercial manipulation-for-hire, hack-and-leak operations that pair intrusion with laundered publication, and organic misinformation that spreads without coordination and requires an entirely different response.
Sub-areas include coordinated inauthentic behaviour detection, network and infrastructure attribution, narrative laundering analysis tracing content from fringe outlets into mainstream reporting, synthetic media detection, and the study of hired amplification markets. Actor types include state intelligence services and their contractors, public relations firms selling influence services commercially, ideological communities operating without central direction, and financially motivated operators who generate engagement for advertising revenue with no political goal at all.
Why it matters
The measurable damage is rarely mass persuasion. It is erosion of shared reference points, targeted harassment that removes journalists, officials and researchers from public life, and the exploitation of crises when authoritative information lags demand. Operations are cheap and scale globally, and generative tools have removed the language and production constraints that once limited reach. Platforms, regulators, newsrooms and civil society all need behavioural evidence rather than assertion, because assertion is itself contested ground.
What analysts actually look for
These are the concrete, observable signals that carry weight in this area of work:
- Account creation dates clustering into a narrow window, then dormancy, then simultaneous activation around a single topic.
- Near-identical text posted within seconds across many accounts, including copied typographical errors that reveal a shared source document.
- Domain clusters sharing registrar, registration date, nameserver, analytics identifier or TLS certificate despite presenting as unrelated outlets.
- Narrative seeding order that runs consistently from fringe forums to aligned outlets to mainstream pickup, a laundering signature.
- Profile images that are generated or stolen, detectable through reverse search failure combined with characteristic facial alignment artefacts.
- Engagement asymmetry, where share counts vastly exceed plausible organic reach for the account's follower graph and history.
- Sudden multilingual expansion of a single narrative with translation artefacts consistent with machine translation from one source language.
- Recycled media presented as current, identifiable by weather, foliage, signage, licence plates or shadow angle inconsistent with the claimed date.
Where the data comes from
Authoritative and openly available collection points. Always confirm licensing and terms before operational or commercial use:
- EUvsDisinfo and EU DisinfoLab — Case databases and investigations of pro-Kremlin and other influence operations with narrative and infrastructure detail.
- Meta Adversarial Threat Reports — Periodic takedown disclosures with country attribution, asset counts and behavioural description of removed networks.
- Google Threat Analysis Group bulletins — Quarterly coordinated influence operation removals across search, video and advertising surfaces with attribution.
- DFRLab and academic research archives — Published open source investigations with reproducible methodology for network and narrative analysis.
- GDELT Project — Machine-coded global news event and tone data with translation, useful for narrative volume and spread measurement.
- Media Cloud — Open media ecosystem analysis for tracking story propagation across outlets, countries and time.
- Certificate Transparency logs and passive DNS — Infrastructure pivoting to link sites, hosting and registration patterns behind ostensibly independent outlets.
- Platform ad libraries and transparency centres — Paid amplification records including funder, spend, targeting parameters and creative for political advertising.
A working method
A repeatable sequence beats ad-hoc searching. This is a practical starting workflow:
- Define the object of study — Fix the narrative, the network or the incident precisely, and decide up front what would constitute evidence of coordination.
- Collect with provenance — Archive posts, media and pages with timestamps and hashes immediately, since deletion follows exposure and removes your evidence base.
- Analyse behaviour first — Examine timing, creation dates, posting cadence and content duplication before considering claim veracity, which is a separate question.
- Pivot on infrastructure — Move from accounts to domains, hosting, certificates, analytics identifiers and payment traces to find the connective tissue between assets.
- Trace laundering pathways — Reconstruct how content moved from origin through intermediaries to mainstream pickup, identifying the bridging accounts and outlets.
- Assess impact honestly — Measure authentic engagement, downstream reporting and observable behaviour change, and report clearly when impact appears negligible.
- Report and coordinate — Share indicators with platforms and affected parties, and publish in a way that does not itself amplify the underlying content.
How this connects across the intelligence taxonomy
Intelligence work does not respect neat boundaries. The mission domain you are working, the disciplines you practise, and the data points you pivot on are one connected system. These are the direct relationships for this entry — every link is also a tag, so you can follow any thread across the whole library.
Practised with these disciplines
- Disinformation Intelligence — Detecting and Analyzing Information Manipulation
- Social Media Intelligence — Intelligence from Social Platforms and Networks
- News Intelligence — Media Reporting as an Intelligence Source
- Threat Actor Intelligence — Tracking Adversary Groups Over Time
- Open Source Intelligence — Publicly Available Information, Systematically Collected
- Election Intelligence — Electoral Processes, Integrity, and Threats
Worked in these data points
- Keyword / Narrative — A search term, topic, hashtag, or narrative tracked across media and platforms.
- Social Profile — A social media profile or online account page tied to a persona or identity.
- Username / Handle — Screen name or handle used across online platforms and services.
- Domain Name — Human-readable address that maps to IP infrastructure via DNS.
- URL — Uniform Resource Locator pointing to a web resource.
- Video — A video file or stream — the core artifact for incident verification and chronolocation.
- Image / Photograph — A still image — carries EXIF metadata and is the primary artifact for visual verification.
Adjacent mission domains
- Election Security & PSYOP
- Nation State
- Extremism & Radicalization
- Conflict & Humanitarian
- Transnational Repression
- Emerging Technology & AI Security
Inside the platform: where Disinformation / IO lives
The Quantus platform is 204 pages behind a 147-item sidebar organised into six working groups: Command (24 items), Dashboards (15), Threat Theaters (14), Intelligence Domains (15), Investigate (34), and Administration (45). This entry is not a page in isolation — it is a thread running through several of them.
The modules that matter most here:
disinformation.php— Disinformation / IO dashboarddomain.php?d=disinfo— Mission domain hubtheater.php?d=disinfo— Threat theater viewurl-profile.php— Domain Name profilesearch.php— Advanced search, filter and pivotcorrelate.php— Correlation graphcases.php— Case management
Each dashboard is local-first: it renders from the platform’s own database rather than depending on a live third-party call, so it still works when an upstream API is unreachable or rate-limited. Heavy aggregates are cached with a hard query time cap and degrade to the last good value instead of hanging the page.
Automation, playbooks and AI skills
Analysis that only happens when someone remembers to run it is not a capability. The platform ships a 30-step automation pipeline (cron.php) that collects, ingests, resolves, enriches, correlates and scores on a schedule — 25 seeders, 11 resolvers and 7 enrichment runners, all idempotent and cursor-based so a run can be interrupted and resumed without duplicating or losing work.
Relevant playbooks
Of the 14 incident playbooks in playbooks.php, these apply directly to Disinformation / IO:
- Disinformation / Influence Op Response — a step-checked workflow with the pivots, sources and handling rules already wired in.
AI skills that apply
The 16 one-click operations in ai-skills.php are deterministic jobs, not free-text generation. The ones that matter here:
- Threat Hunt
- Correlate Infrastructure
- Run Alert Rules
- Sync Intel Domains
- Summarise (Copilot)
- Generate Report
Alerting closes the loop: rules in alerts.php fire on new indicators matching a saved query, so a first sighting in this area raises a notification rather than waiting to be noticed at the next review.
Feeds, data sources and the API
The collection layer runs a feed registry of free, machine-readable sources — bulk blocklists and trackers (Maltrail, IPsum, FireHOL, the full abuse.ch corpora, phishing databases, Emerging Threats, Spamhaus, DigitalSide, ThreatView), authoritative government feeds (CISA KEV, OFAC, UN and EU sanctions lists), and reference datasets (RIR allocations, ip-to-ASN and geolocation tables, MITRE ATT&CK, EPSS). collect.php pulls them server-side on a schedule; feeds.php and source-catalog.php show what is registered, what it covers and when it last ran.
Anything the platform holds is reachable programmatically. The REST API in api.php exposes 11 endpoints — status, stats, search, lookup, recent, export, bulk_check, top_threats, by_category, categories, check — and export.php streams 18 formats in bounded chunks, so a million-row export neither exhausts memory nor times out:
STIX 2.1, MISP, OpenIOC 1.1, CEF (ArcSight), LEEF 2.0 (QRadar), Zeek/Bro intel, Snort/Suricata rules, Palo Alto EDL, BIND RPZ, hosts blackhole, iptables, CSV, JSON, NDJSON/JSONL, XML.
That covers the CTI standards (STIX 2.1, MISP, OpenIOC), SIEM ingestion (CEF, LEEF, Zeek), detection engines (Snort/Suricata), and direct enforcement (Palo Alto EDL, BIND RPZ, hosts, iptables) — so intelligence developed here can be actioned in the tools you already run, without a manual reformatting step. A TAXII 2.1 server and a MISP/RSS feed are also served for pull-based sharing.
Use cases
Three ways this entry earns its keep in day-to-day work:
- Triage under time pressure. An artifact or report lands and you need a defensible read in minutes, not days. Define the object of study is the first move; the platform pre-computes the enrichment so the analyst spends the time on judgement rather than lookups.
- Building the picture. A single indicator is rarely the story. Analyse behaviour first turns one artifact into a network — shared infrastructure, repeated selectors, the same operator behind different names — via the correlation graph and the cross-entity link engine.
- Producing something actionable. Analysis that ends in a document nobody can use is wasted. Report and coordinate feeds the case file, the detection rule, the block list or the referral — with sourcing attached so the recipient can verify it.
Case management (cases.php), watchlists, saved searches and scheduled reports mean the work persists between sessions and survives an analyst leaving the team.
How each sector uses Disinformation / IO
The same entry is worked very differently depending on who you are, what authority you hold, and what you are ultimately producing. A military analyst is supporting a commander’s decision; a journalist is meeting a publication standard; an NGO caseworker is protecting a person. The underlying artifacts are shared — the constraints, outputs and thresholds are not.
🎖 Military and defence
Defence analysts study influence operations as part of the information environment assessment, covering adversary messaging aimed at partner populations, at deployed forces and at domestic audiences in ways that affect operations. Work supports understanding of narrative terrain, protection of force morale and reputation against targeted campaigns, and recognition of hostile activity aimed at fracturing coalitions. Products feed information environment assessments and civil-military communication planning. Constraints are significant and legally grounded: military organisations in most democracies may not collect on or target domestic audiences, and analysis must remain observational rather than becoming an influence capability aimed at domestic populations.
🕵 National intelligence
National intelligence requirements cover state-directed influence operations, their contractors and proxies, hack-and-leak activity, and the infrastructure and finance behind them. The analytic object is behaviour and infrastructure rather than the truth of any claim, which keeps the work on defensible ground. Fusion combines platform disclosures, infrastructure telemetry, financial reporting and liaison material. Domestic political speech is typically outside the collection mandate, and the boundary must be maintained explicitly in tasking and in review. Attribution should distinguish clearly between infrastructure attribution, behavioural attribution and state responsibility, which are separate claims with separate evidence.
👮 Law enforcement
Law enforcement involvement arises where influence activity crosses into offences: computer intrusion in hack-and-leak operations, fraud and payment offences in commercial amplification services, foreign agent registration breaches, harassment and threats, and impersonation of officials or media. Evidence requires early preservation with hashes and timestamps, lawful process for subscriber and payment records, and mutual legal assistance for foreign infrastructure. Expression itself is generally protected, so cases must rest on the conduct rather than the content. Charging typically involves computer misuse, fraud, registration and harassment offences rather than disinformation as such.
🔍 Private investigation and corporate security
Corporate security teams handle influence activity as brand, executive and market manipulation risk: coordinated campaigns attacking a company or its leadership, fabricated documents circulated to investors, and manipulation-for-hire services engaged by competitors or activists. Legitimate work covers detection of coordination targeting the organisation, infrastructure attribution, evidence preservation for platform reporting and litigation, and executive protection where harassment escalates. Private actors must not run counter-influence operations, must not create inauthentic accounts, and must not profile individuals by political view. Findings support platform reporting, legal action and communications response.
📰 Journalism and OSINT media
Newsrooms both investigate and are targeted by this activity. Verification standards should focus on the coordination evidence rather than the plausibility of the content: account creation patterns, synchronisation, asset reuse, infrastructure relationships and funding. Publishing that a campaign exists risks amplifying it, so weigh reach before and after publication. Protect sources, including platform employees and researchers who face legal and employment risk. Provide right of reply to named individuals and companies, and be careful attributing to a state, which is a serious claim requiring evidence beyond alignment of message with a government's interests.
🌍 NGO, humanitarian and human rights
Civil society organisations research influence operations, support targeted communities and document harassment campaigns against journalists, activists and minority groups. Practice is victim centred: people targeted by coordinated harassment need protective support before they need analysis, and documentation should be built with their consent. Do-no-harm includes not amplifying the campaign, not publishing details that enable further targeting, and avoiding framing that stigmatises the communities being manipulated. Documentation for accountability should preserve evidence with proper provenance. Duty of care matters acutely because researchers in this field are themselves frequent targets of coordinated harassment.
🎓 University and research
Research faces a structural problem: platform data access has narrowed sharply, which limits reproducibility and biases the field toward the platforms that still provide access. Be explicit about sampling frames, collection windows and the platforms excluded, and avoid generalising from one platform to the information environment. Ethics approval is required for research on individuals and communities, including scraped public data in many institutions. Publish coding rules, classifier performance and code, cite dataset snapshots by date, and distinguish carefully between coordination detected, inauthenticity demonstrated and attribution established, which are three separate evidentiary standards.
Playbook: working Disinformation / IO end to end
A repeatable sequence, from the moment the requirement lands to the moment a product is delivered and the case is closed out. Each phase states what you are trying to establish, not merely what to click — the point is a defensible chain of reasoning, not a checklist.
Phase 1 — Define the object of study
State precisely what you are investigating: a suspected coordinated network, a narrative and its propagation, a targeted individual or organisation, or a commercial amplification market. The analytic object determines the method, and conflating narrative analysis with network investigation produces work that satisfies neither. Fix the time window and the platforms in scope, and record which platforms are excluded and why. A good output is a scoping note with object, window, platforms and exclusions. Stop when the question can be answered false as well as true.
Phase 2 — Preserve first, analyse second
Capture everything before it disappears: posts, profiles, media, page source, timestamps and platform identifiers, with hashes and collection metadata. Deletion is routine, both by the operators and by platform enforcement, and unpreserved evidence cannot be recovered. Record collection time in a single consistent timezone across the investigation. A good output is an evidence store with per-artefact provenance and a documented collection method. Stop when nothing central to the finding exists only as a screenshot without metadata.
Phase 3 — Establish coordination signatures
Look for behavioural evidence rather than content agreement: account creation clustering, posting synchronisation within narrow windows, identical or near-identical text across accounts, coordinated follow patterns, asset reuse such as shared images and profile pictures, and activity rhythms that match a working day in a particular timezone. People agreeing is not coordination. A good output is a coordination assessment with the specific signatures quantified. Stop before calling coordination on content similarity alone.
Phase 4 — Assess authenticity carefully
Distinguish inauthentic accounts, meaning accounts misrepresenting who is behind them, from authentic accounts amplifying a message they genuinely believe. Campaigns typically combine both, and treating genuine participants as bots is both wrong and politically damaging. Assess persona construction, biography reuse, activity patterns inconsistent with a real person and identity theft of real photographs. A good output is an authenticity judgment per cluster with the indicators listed. Stop before labelling any identifiable individual as inauthentic without strong evidence.
Phase 5 — Pivot on infrastructure
Move from accounts to the technical layer: domains, registration records, certificate issuance, hosting, analytics and advertising identifiers, shared content management fingerprints and cross-linking patterns. Infrastructure reuse is the most durable evidence in this field because it is expensive for operators to change. Beware shared hosting and common services, which create false relationships. A good output is an infrastructure graph with the strength of each link characterised. Stop when each pivot is documented with the query and date that produced it.
Phase 6 — Reconstruct laundering pathways
Trace how content moves from origin into mainstream circulation: fringe site to aggregator to partisan outlet to mainstream citation, or forum to influencer to broadcast. Identify the specific bridge nodes where credibility is acquired, since these are where intervention is possible. Preserve each hop with its timestamp. A good output is a laundering pathway diagram with dated hops and named bridges. Stop when the earliest traceable appearance is established or the trail is documented as cold.
Phase 7 — Assess reach and impact honestly
Measure what the campaign actually achieved rather than what it attempted: engagement relative to the platform baseline, whether authentic communities picked it up, whether it reached mainstream media, and whether any observable behaviour changed. Most operations achieve very little, and overstating impact both misinforms decision makers and rewards the operators. A good output is an impact assessment with baselines and the null result stated where applicable. Stop when the assessment is willing to conclude that the campaign failed.
Phase 8 — Attribute in layers
Separate three claims with three evidence standards: that a network is coordinated, that it is inauthentic, and that a specific actor or state is responsible. Infrastructure and behavioural attribution can be strong; state responsibility usually requires evidence beyond open sources and should be expressed with explicit confidence. Alignment of a narrative with a government's interest is not attribution. A good output is a layered attribution statement with confidence per layer. Stop at the layer the evidence supports.
Phase 9 — Weigh publication against amplification
Before publishing, assess the campaign's existing reach and whether reporting it will spread it further, which is a genuine risk with low-reach operations. Consider whether to describe rather than quote, whether to name targeted individuals, and whether platform reporting achieves more than publication. Coordinate with platforms and affected parties where appropriate. A good output is a publication decision with the amplification assessment recorded. Stop when the public interest in disclosure clearly exceeds the amplification cost, and not before.
Phase 10 — Report, refer and track recurrence
Send findings to platforms through their reporting channels, to affected organisations and individuals, and to regulators or law enforcement where offences are indicated. After enforcement, watch for reconstitution: the same infrastructure, personas and content reappearing under new accounts, which is the normal outcome. A good output is a referral package plus a recurrence watch keyed on durable infrastructure indicators. Stop when the watch has run long enough to catch a reconstitution cycle.
The platform ships this as a step-checked workflow in playbooks.php, so progress is recorded against a case rather than held in someone’s head.
Source register: what to collect from, and how
Sources are listed with their access model so you can plan around cost and licensing before you build a dependency on them. Open means no account required; registration means a free account or API key; licensed means paid or institutional access. Always confirm current terms — licensing changes, and a source that was free for research may not be free for commercial or evidential use.
| Source | Access | What it gives you | How it is used here |
|---|---|---|---|
| EUvsDisinfo | Open | Searchable database of documented pro-Kremlin disinformation cases with original sources, narrative categorisation and dates. | Reference set of recurring narratives and outlets, useful for recognising reactivation of known themes. |
| EU DisinfoLab | Open | Investigations, methodology publications and detailed case documentation on influence operations affecting Europe and its information space. | Methodological reference and documented case precedent for network investigation, infrastructure pivoting and laundering pathway reconstruction. |
| Meta adversarial threat reporting | Open | Periodic disclosures of coordinated inauthentic behaviour takedowns with actor descriptions, indicators and sometimes datasets. | Primary documented record of enforcement actions and a source of indicators for further pivoting. |
| Google Threat Analysis Group reporting | Open | Reporting on coordinated influence operation terminations and state-linked threat activity across Google services. | Cross-platform confirmation of campaigns and additional indicators for infrastructure pivoting beyond a single platform's disclosures. |
| Digital Forensic Research Lab | Open | Published open-source investigations into influence operations with detailed methodology and preserved evidence. | Case precedent and methodological benchmarks for coordination detection and laundering pathway reconstruction. |
| GDELT Project | Open | Large-scale monitoring of global news in many languages with event coding, themes and network extraction. | Tracks narrative propagation across mainstream media at scale and detects synchronised coverage patterns. |
| Media Cloud | Registration | Open platform for studying media coverage and attention across large collections of news sources over time. | Measures whether a narrative crossed from fringe outlets into mainstream coverage and when. |
| Certificate Transparency logs via crt.sh | Open | Public logs of issued TLS certificates searchable by domain and organisation, revealing related and newly created sites. | Infrastructure pivoting to find sibling domains created by the same operator, often before content appears. |
| Passive DNS and domain intelligence services | Licensed | Historical DNS resolution records linking domains to addresses and revealing hosting relationships over time. | Establishes durable infrastructure links between sites that share hosting or migrate together. |
| Platform ad libraries and transparency centres | Open | Records of paid political and issue advertising including payer, spend range, targeting and creative content. | Reveals funded amplification and the entities paying for it, which unpaid activity conceals. |
| Internet Archive and archiving services | Open | Historical snapshots of web pages allowing recovery of deleted content and demonstration of change over time. | Recovers deleted origin content and establishes what a site said at a specific date. |
| OpenCorporates and company registries | Registration | Company registration and officer data used to identify the entities behind commercial influence and public relations firms. | Resolves manipulation-for-hire firms, their officers and their clients wherever corporate structures remain visible in public registries. |
| ACLED and protest event data | Registration | Geolocated political violence and protest events with actor coding and source documentation. | Tests whether online mobilisation translated into observable offline activity, which most campaigns do not. |
| Academic influence operations research archives | Open | Peer-reviewed and preprint research on coordination detection, platform manipulation and effects measurement. | Methodological grounding, particularly for impact measurement, which is where informal investigative practice is consistently weakest. |
Prefer sources that publish a methodology and a revision history. A dataset that changes silently is a liability in any product that has to survive challenge.
Tooling
Tools commonly used against Disinformation / IO. None of these replace judgement, and each carries its own failure modes — know what a tool infers versus what it observes.
- Hunchly — Captures every page visited with hashes and timestamps during an investigation. Essential for provenance, though it captures rendered pages rather than underlying data.
- Certificate transparency and passive DNS search — Pivots between related domains and hosting. Shared infrastructure at large providers generates false relationships that require corroboration.
- Maltego or graph analysis tooling — Visualises account, domain and entity relationships. Attractive graphs can outrun evidence, so link strength must be characterised on every edge.
- Python with pandas and network libraries — Detects posting synchronisation, creation clustering and community structure at scale. Thresholds are analytic choices that must be documented.
- Media Cloud and GDELT interfaces — Measures narrative spread across news media. Source coverage varies by language and country, biasing cross-national comparison.
- Archiving services and the Internet Archive — Recovers deleted content and establishes historical page states. Coverage is opportunistic, so proactive archiving is still required.
- Reverse image and media forensics tools — Identifies reused imagery and manipulated media. Detection of synthetic media remains unreliable, so absence of a detection proves little.
- Secure evidence stores with access control — Holds preserved material with integrity and restricted access. Necessary because investigations attract legal challenge and researcher harassment.
AI skills and automation in detail
These are deterministic jobs with defined inputs and outputs, not open-ended prompting. Each is idempotent and cursor-based: interrupt one and it resumes where it stopped rather than duplicating work or losing progress.
- Threat Hunt — Runs saved hypotheses against the corpus and surfaces what matches, with the query preserved as a versioned artifact.
- Correlate Infrastructure — Builds the cross-entity link graph: shared hosting, reused certificates, overlapping registrants, repeated selectors.
- Run Alert Rules — Evaluates saved rules against new data so a first sighting raises a notification rather than waiting for review.
- Sync Intel Domains — Refreshes the reference and country-level intelligence datasets from their authorities.
- Summarise (Copilot) — Produces a narrative summary beside the underlying records. It explains; it never creates indicators or assigns attribution.
- Generate Report — Assembles a sourced product from the current case or query, with provenance attached to each element.
A note on the boundary: the only skill that involves a language model is Summarise (Copilot), and it writes prose about records that already exist. Nothing else on this list involves generation of any kind. No indicator, relationship or attribution in the platform originates from a model. See the full skill list.
Tradecraft notes
The distinctions that separate a competent analyst from a fast one:
- Investigate behaviour and infrastructure, not truth. The moment your finding rests on whether a claim is false rather than on whether the network is coordinated and inauthentic, you have moved onto contested ground you cannot defend.
- People agreeing is not coordination. Organic communities produce synchronised posting, shared phrases and rapid amplification, so require creation clustering, asset reuse or infrastructure links before calling a network coordinated.
- Infrastructure is the durable evidence. Accounts are cheap and disposable, but domains, hosting, analytics identifiers and content management fingerprints persist and are expensive for operators to change.
- Measure impact honestly, including the null result. Most operations achieve almost nothing, and overstating reach misinforms decision makers, rewards the operators and eventually discredits the field.
- Separate the three attribution layers: coordinated, inauthentic, and attributable to a named actor. Each has a different evidence standard, and collapsing them is the most common failure in published work.
- Publication can be amplification. For a low-reach operation, reporting it may deliver the audience it failed to earn, so assess reach before and after publication and consider platform referral instead.
- Expect reconstitution rather than defeat. Networks return with new accounts on the same infrastructure within weeks, so build the recurrence watch on durable indicators at the same time as the takedown referral.
Measuring whether it is working
Capability claims should be falsifiable. These are the measures that show whether work on Disinformation / IO is producing anything, and they are worth baselining before you change process or tooling.
- Proportion of published network findings supported by infrastructure or creation-pattern evidence rather than content similarity alone.
- Share of investigations where impact was measured against a platform baseline, including cases concluding minimal reach.
- Time from detection of a coordinated network to a referral package reaching the relevant platform or authority.
- Recurrence detection rate, meaning the proportion of reconstituted networks identified through durable infrastructure indicators after an enforcement action.
- Proportion of attribution statements that explicitly separate coordination, inauthenticity and actor responsibility with confidence per layer.
- Completeness of evidence preservation, measured as the share of central artefacts held with hashes and collection metadata.
- Number of publication decisions where amplification risk was formally assessed against measured reach and recorded before release.
Beware of measuring volume alone. Indicator counts and report counts rise easily and say little; time-to-attribution, proportion of findings that survive review, and how often a product changed a decision say a great deal.
Common pitfalls
- Coordination is not proof of inauthenticity. Genuine activists, fandoms and campaigns organise and post in synchrony all the time.
- Attribution to a state requires infrastructure or funding evidence; narrative alignment alone is the weakest possible basis for a claim.
- Bot detection tools have high false positive rates and disproportionately misclassify accounts in non-English and low-activity contexts.
- Amplifying an operation through debunking is a real and measurable cost, and often exceeds the reach the operation achieved unaided.
- Impact is routinely overstated because reach metrics are easy to collect and persuasion effects are difficult and usually small.
- Mislabelling sincere political speech as an influence operation causes serious harm and hands the adversary a legitimate grievance.
Legal and ethical considerations
The line between analysing manipulation and surveilling political speech is thin and consequential. Study behaviour and infrastructure rather than building profiles of individuals expressing lawful opinions, and apply particular caution with private individuals, minors and members of vulnerable communities. Platform terms of service govern collection and are enforced, and scraping may carry legal exposure separately. Publication naming individuals as operatives can be defamatory and can trigger harassment, so hold that bar high and consider notification.
Data integrity: no fabrication, no drift, no hallucination
Intelligence that cannot be traced back to a source is not intelligence, it is assertion. Everything in this entry — and everything in the platform behind it — is built on a small number of non-negotiable rules.
Provenance on every record
Every indicator carries the source that supplied it, a first-seen and last-seen timestamp, and a sighting count. Where several feeds report the same artifact, each contribution is recorded separately rather than collapsed, so you can see whether a finding rests on one source or twelve. Source attribution travels with the data into every export, so a recipient can audit a claim without asking you for the working.
Nothing is invented to fill a gap
If the platform has no data for Disinformation / IO, it says so. Empty is displayed as empty — never padded with plausible-looking placeholder values, sample records or illustrative examples that a reader might mistake for observations. A dashboard with no rows is a true statement about collection coverage, and it is treated as a gap to close, not a blemish to hide.
Scoring is deterministic and reproducible
Threat scores, reputation grades and risk tiers are computed from stated inputs with fixed weights, not estimated. The same inputs always produce the same output, and the formula is visible rather than a black box. Aggregates are cached with an explicit time-to-live so a figure on screen is never silently stale — and when a heavy query exceeds its time budget the platform serves the last known-good value and labels it, rather than inventing a fresh number or hanging.
Where AI is used, and where it is not
Language models summarise and explain. They do not create indicators, assign attribution or manufacture relationships. No IP address, wallet, hash or identity in the platform originates from a model — every one is ingested from a named feed, resolved from a reference dataset, or entered by an analyst with a source recorded. Copilot output is presented as narrative alongside the underlying records, never in place of them, so a reader can always check the summary against the evidence.
Guarding against drift
Enrichment is additive and timestamped rather than overwriting. Reference data — sanctions lists, allocations, taxonomies — is re-synchronised from the authority on a schedule instead of being edited in place, so local copies cannot quietly diverge from the source of truth. Attribution is recorded with a confidence level and the reporting it rests on, and inferred relationships are labelled as inferred. When a source retracts or corrects, the correction propagates rather than leaving a stale assertion behind.
What this means for you
You can put a finding from this platform in front of a regulator, a court, a board or a partner agency and show where each element came from. That is the standard the tooling is built to — because in this work, being confidently wrong is more damaging than being usefully uncertain.
By the numbers
The taxonomy this entry belongs to is not a marketing list — it is the actual structure of the platform: 52 mission domains, 52 intelligence disciplines and 65 data points, each with a live dashboard behind it. Supporting that: 18 indicator types, 14 playbooks, 16 AI skills, 18 export formats and a 30-step automated pipeline.
This particular entry connects directly to 6 intelligence disciplines, 7 data points, 6 closely related entries — every one of them a tag you can follow, and a dashboard you can open.
Questions analysts actually ask
How do I tell coordination from organic agreement?
Look for evidence that would be improbable without coordination. Account creation clustered in a narrow window, posting synchronised to the second across accounts with no prior relationship, identical text including identical typographical errors, reuse of the same profile images or stock photographs across a cluster, shared infrastructure behind linked sites, and activity rhythms matching a working day in a single timezone. Organic communities produce shared phrases and rapid amplification too, so content similarity alone proves nothing. Quantify the signatures you found, state the thresholds you used, and be willing to conclude that a cluster is organic.
Can influence operations be attributed to a state?
Sometimes, and rarely from open sources alone. Open work can usually establish coordination and inauthenticity with confidence, and can often establish infrastructure links between assets. Attributing to a state normally requires either a platform or government disclosure, financial or contractual evidence, or intelligence that will not appear publicly. Alignment between a narrative and a government's interests is not attribution, since many actors amplify convenient messages. Publish the layers separately with explicit confidence for each, and resist pressure to state the conclusion that the audience wants at a confidence the evidence does not support.
Does reporting on a campaign amplify it?
It can, and this is a real professional dilemma rather than a theoretical one. A campaign with negligible organic reach may gain far more attention from a well-read investigation than it ever generated itself, and coverage can also validate the narrative for audiences predisposed to it. Assess existing reach against platform baselines before publishing, consider describing rather than quoting content, avoid reproducing effective imagery, and weigh whether platform referral and private notification to affected parties would achieve more. Where publication is warranted, focus the story on the coordination and the operators rather than on the claims.
How should impact be measured?
Against a baseline, and with willingness to report failure. Compare engagement to typical performance for similar accounts and content on the same platform, check whether authentic communities picked the content up or whether it circulated only within the network, track whether it reached mainstream media, and look for any observable offline correlate such as attendance at an event. Most operations do not achieve meaningful reach. Reporting that honestly is more valuable than an impressive-sounding account count, and it protects the credibility of the cases where impact genuinely was significant.
What about synthetic media?
Treat detection claims cautiously in both directions. Automated detection of synthetic audio, image and video remains unreliable, with meaningful false positive and false negative rates, and detection results should never be the sole basis for a published claim. The stronger approach is provenance: where did the file first appear, what does its metadata and encoding history show, does the depicted event have independent corroboration, and do the accounts distributing it show coordination signatures. The existence of synthetic media also enables denial of authentic material, so verification of genuine content matters as much as detection of fakes.
What is manipulation-for-hire and why does it matter?
It is a commercial market in which public relations firms, marketing agencies and specialist providers sell amplification, fabricated engagement, persona networks and reputation attacks to clients including corporations, political actors and governments. It matters because it breaks the assumption that influence operations are state-run: the same infrastructure and personas may serve several unrelated clients, which complicates attribution considerably. It is also more tractable to investigate, since commercial operations leave corporate registrations, invoices, employment records and advertising material. Follow the corporate and payment layer, which is where these networks are most exposed.
Standards, frameworks and further reading
Work that references a recognised framework is easier to defend, easier to hand over, and easier for a partner to consume:
- Berkeley Protocol on Digital Open Source Investigations, which sets provenance, preservation and verification standards for online evidence.
- EU Code of Practice on Disinformation and the Digital Services Act, which set platform obligations on systemic risk and transparency.
- International Covenant on Civil and Political Rights Article 19, which protects expression and constrains what may lawfully be restricted.
- Santa Clara Principles on transparency and accountability in content moderation, which frame platform enforcement expectations.
- ABC framework distinguishing actors, behaviours and content, which structures analysis away from adjudicating truth claims.
- MITRE DISARM or equivalent influence operation frameworks, which provide shared vocabulary for tactics and countermeasures.
- Research ethics standards for internet research including institutional review requirements for scraped and platform data.
- ICD 203 analytic standards, which govern confidence expression and source characterisation in attribution products.
References
Primary sources and authoritative references for this entry. Publishers revise and retire material, so treat the retrieval date as part of the citation and re-check before relying on any of it in a formal product.
- EUvsDisinfo case database — EU East StratCom Task Force. Documented disinformation cases with narrative categorisation and sources
- Adversarial Threat Reports — Meta. Periodic disclosures of coordinated inauthentic behaviour enforcement
- Threat Analysis Group bulletins — Google. Reporting on coordinated influence operations and state-linked activity
- Digital Forensic Research Lab investigations — Atlantic Council. Open-source investigations into influence operations with methodology
- GDELT Project — GDELT. Global news monitoring and event coding used for narrative propagation analysis
- Media Cloud platform — Media Cloud. Open platform for studying media attention and coverage over time
- Certificate Transparency search — crt.sh. Public certificate logs used for domain infrastructure pivoting
- EU DisinfoLab research and methodology — EU DisinfoLab. Investigations and methodological guidance on influence operations
- Berkeley Protocol on Digital Open Source Investigations — UN Human Rights Office and UC Berkeley Human Rights Center. Standards for lawful, ethical and effective open-source investigation
Link integrity: every reference above was verified with a live request when this page was generated. Where a publisher had moved or withdrawn a document, the link was repointed at a preserved copy in the Internet Archive and marked as archived. Anything with no reachable copy anywhere had its link removed rather than left to rot — the source is still credited, it simply cannot be linked.
Put it into practice
The Quantus Intel threat intelligence platform operationalises this entry: behavioural coordination detection, infrastructure pivoting and laundering pathway reconstruction with archived, provenance-tracked evidence. Explore the platform, or browse the rest of the library by following any tag above.