Imagery Intelligence (IMINT): Intelligence Discipline Guide
An image is a measurement, not a picture. Imagery intelligence extracts what can be measured, then defends out loud the difference between what is visible and what is inferred.
An image is a measurement, not a picture. Imagery intelligence extracts what can be measured, then defends out loud the difference between what is visible and what is inferred.
What Imagery Intelligence is as a discipline
Imagery intelligence is the exploitation of visual and non-visual imagery: optical satellite, synthetic aperture radar, thermal and multispectral, aerial and drone survey, and ground-level photography and video. Analysts identify and measure objects, assess activity and status, compare against previous coverage, and grade confidence against resolution and collection geometry. The craft is disciplined description first, recording what is measurably present, then interpretation of what the pattern means, with the two kept visibly separate so a reviewer can dispute one without discarding the other.
Sub-methods include change detection between passes, shadow-based measurement, spectral indices for vegetation, water, burn scars and thermal anomalies, radar amplitude and coherence for structural change under cloud, video frame analysis, and manipulation detection on user-generated imagery. Within the cycle it is a processing and analysis discipline that feeds geospatial products and, just as importantly, cues collection by other means when it finds something it cannot resolve alone.
Why it matters
Imagery answers what is physically present at a place at a moment, with no need for access or cooperation. It corroborates or contradicts claims about damage, construction, stockpiles, deployment and activity, and it provides a consistent time series no witness can offer. It is also the discipline that most often disproves a confident narrative, because a site either shows the claimed activity in the pixels or it does not.
What analysts actually look for
These are the concrete, observable signals that carry weight in this area of work:
- Object dimensions derived from measured shadow length combined with known solar geometry for that date and location.
- Presence, count and dispersal pattern of vehicles, aircraft, rolling stock or containers between successive passes.
- Ground scarring, spoil heaps and track development indicating recent works or repeated heavy movement.
- Thermal anomalies indicating flaring, furnace operation, active fires or newly started industrial processes.
- Radar amplitude and coherence changes revealing structural damage or new construction beneath persistent cloud.
- Compression artefacts, resampling traces and inconsistent lighting suggesting an image has been edited or recycled.
- Seasonal and vegetative context that confirms or contradicts a claimed capture date.
- Construction sequence and progress rates that constrain how long a facility has been in development.
Where the data comes from
Authoritative and openly available collection points. Always confirm licensing and terms before operational or commercial use:
- Copernicus Data Space Ecosystem — Free Sentinel-2 optical and Sentinel-1 radar imagery with frequent revisit and full archive access
- USGS EarthExplorer — Landsat archive plus declassified historic satellite imagery for multi-decade baselines
- NASA Worldview and FIRMS — Daily browse imagery and near real-time thermal anomaly detections at coarse resolution
- Copernicus Emergency Management Service — Rapid mapping products and damage assessments published after disasters and major incidents
- Planet NICFI basemaps — Free high-cadence basemaps over tropical regions for monitoring land change
- Mapillary — Crowd-sourced street-level imagery useful for ground truth and feature confirmation
- SunCalc — Solar azimuth and elevation for any place and time, underpinning shadow-based chronolocation
- Google Earth Pro historic imagery — Time-slider archive of high-resolution commercial imagery for rapid visual change comparison over years
A working method
A repeatable sequence beats ad-hoc searching. This is a practical starting workflow:
- Define the essential elements — Write what must be observable for the question to be answered, so exploitation targets specific features instead of browsing a scene.
- Select the sensor — Match resolution, spectrum and revisit to the question, choosing radar where cloud, smoke or darkness defeats optical collection.
- Establish a baseline — Pull earlier coverage of the same site so change is measured against a known normal rather than assumed from one frame.
- Exploit systematically — Describe and measure before interpreting, annotating each observation with its pixel evidence and recording what could not be resolved.
- Corroborate — Confirm the observation with a second sensor, a different date or an independent ground source before it becomes a finding.
- Grade confidence — Assign confidence per observation against resolution, viewing geometry and atmospheric conditions rather than to the report as a whole.
- Produce the annotated product — Publish with sensor, capture date and time, ground sample distance, licence, and a clear separation of observation from assessment.
How this connects across the intelligence taxonomy
Intelligence work does not respect neat boundaries. The mission domain you are working, the disciplines you practise, and the data points you pivot on are one connected system. These are the direct relationships for this entry — every link is also a tag, so you can follow any thread across the whole library.
Applied in these mission domains
- Mining & Resource Crime
- WMD / Proliferation
- Military & Defense
- Conflict & Humanitarian
- Border Security & Migration
- Environmental Crime
- Climate Security
- Energy Security
- Water Security
- Maritime Security
Operates on these data points
- GPS Coordinates — Precise latitude/longitude coordinates identifying an exact point on Earth — the atomic unit of GEOINT analysi
- Facility / Site — A physical installation — plant, base, port, data centre — with a fixed footprint and function.
- Location / Coordinates — A geographic point, place, or region — the basis of GEOINT analysis.
- Satellite Imagery — Overhead imagery of an area of interest, used for change detection and site analysis.
- Event / Incident — A discrete real-world occurrence — protest, strike, breach, seizure — with time, place, and actors.
- Company / Organization — A legal entity — corporation, LLC, NGO, or business.
- Shipment / Bill of Lading — A consignment record linking shipper, consignee, goods, and route.
- HS Commodity Code — The Harmonized System code classifying a traded good — the key to trade-flow analysis.
- Vessel / Ship — A maritime vessel identified by IMO, MMSI, or call sign.
- Radio Callsign — A licensed radio identifier for a station, vessel, aircraft, or operator.
Related disciplines
- Geospatial Intelligence — Intelligence Derived from Place
Inside the platform: where Imagery Intelligence lives
The Quantus platform is 204 pages behind a 147-item sidebar organised into six working groups: Command (24 items), Dashboards (15), Threat Theaters (14), Intelligence Domains (15), Investigate (34), and Administration (45). This entry is not a page in isolation — it is a thread running through several of them.
The modules that matter most here:
discipline.php?d=IMINT— Discipline hubsource-catalog.php?disc=IMINT— Source catalogue filtered to this disciplinesearch.php— Advanced search, filter and pivotcorrelate.php— Correlation graphcases.php— Case management
Each dashboard is local-first: it renders from the platform’s own database rather than depending on a live third-party call, so it still works when an upstream API is unreachable or rate-limited. Heavy aggregates are cached with a hard query time cap and degrade to the last good value instead of hanging the page.
Automation, playbooks and AI skills
Analysis that only happens when someone remembers to run it is not a capability. The platform ships a 30-step automation pipeline (cron.php) that collects, ingests, resolves, enriches, correlates and scores on a schedule — 25 seeders, 11 resolvers and 7 enrichment runners, all idempotent and cursor-based so a run can be interrupted and resumed without duplicating or losing work.
AI skills that apply
The 16 one-click operations in ai-skills.php are deterministic jobs, not free-text generation. The ones that matter here:
- Score Country Risk
- Sync Intel Domains
- Resolve Everything
- Summarise (Copilot)
- Generate Report
Alerting closes the loop: rules in alerts.php fire on new indicators matching a saved query, so a first sighting in this area raises a notification rather than waiting to be noticed at the next review.
Feeds, data sources and the API
The collection layer runs a feed registry of free, machine-readable sources — bulk blocklists and trackers (Maltrail, IPsum, FireHOL, the full abuse.ch corpora, phishing databases, Emerging Threats, Spamhaus, DigitalSide, ThreatView), authoritative government feeds (CISA KEV, OFAC, UN and EU sanctions lists), and reference datasets (RIR allocations, ip-to-ASN and geolocation tables, MITRE ATT&CK, EPSS). collect.php pulls them server-side on a schedule; feeds.php and source-catalog.php show what is registered, what it covers and when it last ran.
Anything the platform holds is reachable programmatically. The REST API in api.php exposes 11 endpoints — status, stats, search, lookup, recent, export, bulk_check, top_threats, by_category, categories, check — and export.php streams 18 formats in bounded chunks, so a million-row export neither exhausts memory nor times out:
STIX 2.1, MISP, OpenIOC 1.1, CEF (ArcSight), LEEF 2.0 (QRadar), Zeek/Bro intel, Snort/Suricata rules, Palo Alto EDL, BIND RPZ, hosts blackhole, iptables, CSV, JSON, NDJSON/JSONL, XML.
That covers the CTI standards (STIX 2.1, MISP, OpenIOC), SIEM ingestion (CEF, LEEF, Zeek), detection engines (Snort/Suricata), and direct enforcement (Palo Alto EDL, BIND RPZ, hosts, iptables) — so intelligence developed here can be actioned in the tools you already run, without a manual reformatting step. A TAXII 2.1 server and a MISP/RSS feed are also served for pull-based sharing.
Use cases
Three ways this entry earns its keep in day-to-day work:
- Triage under time pressure. An artifact or report lands and you need a defensible read in minutes, not days. Define the essential elements is the first move; the platform pre-computes the enrichment so the analyst spends the time on judgement rather than lookups.
- Building the picture. A single indicator is rarely the story. Establish a baseline turns one artifact into a network — shared infrastructure, repeated selectors, the same operator behind different names — via the correlation graph and the cross-entity link engine.
- Producing something actionable. Analysis that ends in a document nobody can use is wasted. Produce the annotated product feeds the case file, the detection rule, the block list or the referral — with sourcing attached so the recipient can verify it.
Case management (cases.php), watchlists, saved searches and scheduled reports mean the work persists between sessions and survives an analyst leaving the team.
How each sector uses Imagery Intelligence
The same entry is worked very differently depending on who you are, what authority you hold, and what you are ultimately producing. A military analyst is supporting a commander’s decision; a journalist is meeting a publication standard; an NGO caseworker is protecting a person. The underlying artifacts are shared — the constraints, outputs and thresholds are not.
🎖 Military and defence
Imagery exploitation supports order of battle, facility and installation assessment, battle damage assessment and indications and warning. Analysts measure and count what is present, grade it against national imagery interpretability standards, compare it with previous coverage, and pass what they cannot resolve back as a collection requirement for another sensor. It feeds target folders, force protection assessments and the intelligence estimate. Constraints include the collection geometry and resolution limits that bound what can honestly be claimed, the requirement to keep measured description separate from interpretation so a reviewer can dispute one without discarding the other, and the legal protections attaching to medical, cultural and civilian objects visible in the scene.
🕵 National intelligence
National agencies exploit imagery against standing requirements on strategic facilities, proliferation-relevant activity, infrastructure and force disposition. The discipline is comparison over time: a single scene rarely establishes anything, whereas a coverage series establishes tempo, construction sequence and pattern of life at facility level. Sourcing and classification usually follow the sensor rather than the finding, so unclassified derivable products from commercial or open imagery are prepared deliberately for partner and public release. Analytic standards require stated confidence tied to resolution and geometry, and explicit acknowledgement of what alternative explanations the imagery cannot exclude.
👮 Law enforcement
Investigators use imagery in scene reconstruction, vehicle and object identification, and authentication of photographs and video offered as evidence. Evidential standards are demanding: preserve the original file with metadata and hash, document every enhancement or processing step, and be able to explain why a measurement is reliable given the camera geometry. Manipulation detection findings must be expressed as what is inconsistent rather than as a bare conclusion of fabrication. Aerial and satellite imagery of private property may require authorisation depending on the jurisdiction, and imagery obtained from a platform generally requires legal process rather than a screenshot.
🔍 Private investigation and corporate security
Corporate investigators use imagery to verify asset existence and condition, monitor construction progress at counterparty sites, assess environmental compliance, and support insurance and litigation questions such as whether a facility operated on a date. Open and licensed satellite imagery supports this well. What a private actor may not do is conduct aerial or drone surveillance of individuals or private residences, image restricted sites, or redistribute licensed imagery beyond the terms purchased. Covert photography of people in private settings breaches privacy law in most jurisdictions and can convert an investigation into an offence.
📰 Journalism and OSINT media
Newsrooms use imagery both as evidence and as the object of verification. The standard is provenance first: obtain the highest-quality original available, examine metadata where it survives, reverse-search for earlier appearances, and check internal consistency of shadows, weather, vegetation and visible detail. Manipulation and synthetic media claims require caution in both directions, since detection tools produce false positives and compression destroys the signals they rely on. Publish the verification method. Ethics require care with graphic imagery, avoiding identification of victims and bystanders, and offering right of reply where imagery underpins an allegation against a named party.
🌍 NGO, humanitarian and human rights
Human rights and humanitarian organisations use imagery for damage assessment, documentation of attacks on protected objects, displacement and settlement monitoring, and corroboration of witness accounts where access is impossible. Practice must be preservation-grade if the material may support future accountability: original files, hashes, documented processing, and a chain of custody. Do-no-harm governs publication of imagery that identifies individuals, shelters or grave sites. Duty of care applies to staff reviewing graphic material, with exposure limits and support. Imagery of the deceased and of survivors requires dignity considerations and, where possible, consent from families or communities.
🎓 University and research
Researchers use imagery for environmental change, urbanisation, conflict damage and methodological work on detection and manipulation. Reproducibility requires publishing scene identifiers, acquisition dates, processing chains and code, since results depend heavily on preprocessing choices that are rarely reported in enough detail. Ethics review is engaged where imagery could identify individuals or locate vulnerable populations. Licensing constrains sharing: open Sentinel and Landsat data can be redistributed, commercial scenes usually cannot, so publish derived measurements and identifiers rather than the imagery itself, with an explicit data availability statement.
Playbook: working Imagery Intelligence end to end
A repeatable sequence, from the moment the requirement lands to the moment a product is delivered and the case is closed out. Each phase states what you are trying to establish, not merely what to click — the point is a defensible chain of reasoning, not a checklist.
Phase 1 — Define the exploitation task
State what must be determined from imagery: presence or absence of a specific object, a count, a measurement, a change between dates, or the authenticity of a supplied file. Attach the required confidence and the decision it supports. Different tasks have different minimum resolutions, and agreeing this first prevents expensive collection against a question imagery cannot answer. A good output is a task statement naming the object, the accuracy needed and the deadline. Stop when the task is specific enough to select a sensor.
Phase 2 — Establish the baseline
Before looking for change, characterise normal. Pull the longest available coverage series for the site and describe its usual state across seasons: vehicle presence, vegetation, water level, activity rhythm, construction that has been static for years. Without a baseline, every observation looks like an anomaly. A good output is a documented normal-state description with representative dated scenes. Stop when you can state what an ordinary day at this site looks like in imagery, including seasonal variation.
Phase 3 — Select sensors deliberately
Match sensor to question. Optical for identification and counting where cloud and light permit; radar for all-weather and night coverage and for structural change through coherence; thermal for activity, flaring and heat signatures; multispectral indices for vegetation, water, burn scars and disturbed soil. Note revisit intervals, because the tightness of a change window is a function of revisit rather than resolution. A good output is a sensor plan with justification. Stop when the plan bounds the change in time as well as space.
Phase 4 — Assess collection geometry
Record off-nadir angle, sun azimuth and elevation, ground sample distance and any resampling applied, because these bound what can honestly be claimed. Oblique geometry distorts measurement and hides objects behind structures; low sun exaggerates relief and lengthens shadows usefully but obscures shaded detail. A good output is a geometry note attached to each scene, stating the practical limits of interpretation. Stop when the limits are written down before interpretation begins, not defended afterwards.
Phase 5 — Describe before interpreting
Write what is measurably present: dimensions, counts, shapes, surface materials, orientations, spatial relationships. Use measurements with stated error rather than adjectives. Keep this description physically separate from the interpretation section so a reviewer can accept the observation and challenge the meaning. This separation is the single most valuable habit in imagery work. A good output is an annotated description a sceptical reader could verify against the same scene. Stop when the description stands alone without the conclusion.
Phase 6 — Measure with method
Derive dimensions using shadow length against solar geometry, known reference objects in the scene, and ground sample distance, and state the uncertainty of each measurement. Cross-check with a second method where the number matters. Recognise that resampled or pan-sharpened imagery can display detail finer than the true resolution supports. A good output is a measurement table with method and error bounds. Stop when the measurement's uncertainty is small enough for the decision, or the shortfall is stated.
Phase 7 — Detect change rigorously
Compare co-registered scenes and rule out non-substantive causes first: seasonal vegetation, illumination and shadow differences, sensor and processing changes, snow, moisture and atmospheric effects. Where optical comparison is ambiguous, test with radar amplitude and coherence. Record both the date pair bounding the change and the confidence. A good output is a change record naming the scenes, the observed difference, the excluded alternatives and the residual uncertainty. Stop when the alternative explanations have been actively tested rather than merely acknowledged.
Phase 8 — Verify supplied imagery
For user-generated material, obtain the highest quality original available rather than a re-shared copy, examine surviving metadata, reverse-search across multiple engines for earlier appearances, and check internal consistency of shadows, weather, vegetation, signage and visible technology. Test whether the claimed location and time survive independent geolocation and chronolocation. A good output is a verification note listing checks performed, findings and unresolved questions. Stop when further checks stop moving confidence in either direction.
Phase 9 — Assess manipulation carefully
Look for inconsistencies rather than for artefacts alone: impossible lighting or shadow geometry, perspective that does not close, repeated texture, edges inconsistent with the surrounding compression, and content inconsistent with independently verifiable context. Treat automated detector outputs as one weak input, since compression, resizing and re-encoding destroy the signals they use and generate false positives. A good output states what is inconsistent and what that does and does not support. Stop short of asserting fabrication where you can only show inconsistency.
Phase 10 — Cue other collection
Where imagery reveals something it cannot resolve, convert it into a specific requirement for another discipline: a named facility for open source registry work, a vessel for maritime tracking, a construction pattern for procurement analysis, a location for ground reporting. This is where imagery earns most of its value in fused work. A good output is a written collection request naming the question and the acceptable answer. Stop when the requirement is specific enough to be tasked.
Phase 11 — Grade and express confidence
State confidence explicitly and tie it to resolution, geometry, coverage frequency and the strength of alternative explanations. Use consistent language across products. Avoid identifying specific equipment types where the ground sample distance cannot support that level of discrimination, which is the most common overreach in imagery reporting. A good output is a judgement sentence naming the confidence and the limiting factor. Stop when a reader can tell what the imagery could not exclude.
Phase 12 — Preserve and document
Retain the original files with metadata and hashes, record every processing step including enhancement, contrast stretch, pan-sharpening and reprojection, and store scene identifiers so the source can be reacquired. Record licences and redistribution rights. Where the material may become evidence, apply a preservation hold and chain of custody. A good output is a package that reproduces the finding after the provider catalogue changes. Stop when reproduction has been tested by a second analyst.
The platform ships this as a step-checked workflow in playbooks.php, so progress is recorded against a case rather than held in someone’s head.
Source register: what to collect from, and how
Sources are listed with their access model so you can plan around cost and licensing before you build a dependency on them. Open means no account required; registration means a free account or API key; licensed means paid or institutional access. Always confirm current terms — licensing changes, and a source that was free for research may not be free for commercial or evidential use.
| Source | Access | What it gives you | How it is used here |
|---|---|---|---|
| Copernicus Data Space Ecosystem | Registration | Sentinel-1 radar and Sentinel-2 optical imagery with browsing, processing and download at no cost. | Core open imagery for change detection, all-weather radar coverage and coherence analysis of structural change. |
| USGS EarthExplorer | Registration | Landsat series, aerial photography, declassified historic satellite imagery and elevation products. | Establishes decades-long baselines and supplies historic coverage that commercial archives do not reach. |
| NASA Worldview | Open | Browse interface for near real time global imagery from MODIS, VIIRS and other instruments with layer overlays. | Rapid situational confirmation of large-scale events such as smoke plumes, floods and dust at daily cadence. |
| NASA FIRMS active fire data | Open | Thermal anomaly and active fire detections with location, timestamp, confidence and satellite of origin. | Timestamps fires, flaring and large thermal events to bound an incident when optical imagery is unavailable. |
| Sentinel Hub | Licensed | Commercial service providing streamlined access, processing and visualisation of open and commercial satellite archives. | Fast comparison of dated scenes and custom index rendering without local processing infrastructure. |
| Planet | Licensed | Commercial constellation offering high revisit medium resolution and tasked high resolution optical imagery. | Daily revisit narrows change windows to a day where open archives can only bracket a week or more. |
| Maxar | Licensed | Commercial provider of sub-metre optical satellite imagery with archive search and tasking services. | Object-level identification and damage assessment where open imagery resolution is insufficient. |
| Airbus Intelligence imagery services | Licensed | Commercial optical and radar satellite imagery including Pleiades and TerraSAR-X archives and tasking. | Alternative high resolution and radar tasking source, useful where a second independent sensor is required. |
| Copernicus Emergency Management Service | Open | Validated rapid mapping products including damage grading, flood delineation and reference maps for activated events. | Independent damage assessment to a documented method that can be cited rather than reproduced from scratch. |
| UNOSAT | Open | Satellite image analysis for humanitarian and human rights purposes with published methodology and dated products. | Citable independent imagery analysis for accountability work, including damage and displacement assessment. |
| Google Earth historic imagery | Open | Time slider access to archived high resolution imagery across many years for much of the populated world. | Quick historic comparison and identification of when a structure first appeared, subject to approximate dating. |
| Mapillary | Registration | Crowd-contributed street-level imagery with positions, capture dates and derived map features. | Ground-level corroboration of features identified from above during geolocation and site characterisation. |
| InVID-WeVerify verification plugin | Open | Toolkit for keyframe extraction, reverse image search across engines, metadata inspection and image forensics filters. | First-pass verification of supplied photographs and video, including detection of earlier online appearances. |
| Content provenance and authenticity specifications | Open | Open technical standards for cryptographically signed capture and edit provenance embedded in media files. | Where present, provides verifiable capture and editing history; absence proves nothing but presence is strong evidence. |
Prefer sources that publish a methodology and a revision history. A dataset that changes silently is a liability in any product that has to survive challenge.
Tooling
Tools commonly used against Imagery Intelligence. None of these replace judgement, and each carries its own failure modes — know what a tool infers versus what it observes.
- QGIS with raster analysis plugins — Displays, co-registers and analyses multi-date imagery with band maths and index calculation. Limitation: interactive performance degrades on very large scenes without pre-processing.
- SNAP Sentinel toolbox — Processes Sentinel-1 radar including calibration, speckle filtering, amplitude change and interferometric coherence. Limitation: radar outputs are easily over-interpreted without training in what coherence loss actually indicates.
- Sentinel Hub EO Browser — Rapid browsing and comparison of dated scenes with configurable spectral index rendering in a browser. Limitation: convenience rendering can mask preprocessing choices that affect what is visible.
- InVID-WeVerify plugin — Extracts video keyframes, runs multi-engine reverse search and applies forensic filters to still images. Limitation: forensic filters produce suggestive artefacts on compressed media that are frequently misread as manipulation.
- ExifTool — Reads, writes and reports metadata from a very wide range of image and video formats. Limitation: platforms strip metadata on upload, so absence is normal and presence can be forged.
- Solar position calculators — Compute sun azimuth and elevation for shadow-based measurement and date consistency checks. Limitation: shadow geometry repeats across the year, so results constrain rather than determine the date.
- Photogrammetry and structure from motion software — Reconstructs three-dimensional geometry from overlapping images for measurement and scene reconstruction. Limitation: requires sufficient overlap and known scale, which user-generated material rarely provides.
- Synthetic media detection services — Score media for likelihood of generative or manipulative processing. Limitation: accuracy falls sharply on recompressed, resized or screen-captured files, and both false positives and false negatives are common.
- Image hashing and duplicate detection — Perceptual hashes find re-uploads and near-duplicates of an image across collections. Limitation: crops, overlays and heavy re-encoding defeat many hash schemes, so negative results are weak.
AI skills and automation in detail
These are deterministic jobs with defined inputs and outputs, not open-ended prompting. Each is idempotent and cursor-based: interrupt one and it resumes where it stopped rather than duplicating work or losing progress.
- Score Country Risk — Recomputes country risk from the weighted inputs and snapshots the result so movement over time is measurable.
- Sync Intel Domains — Refreshes the reference and country-level intelligence datasets from their authorities.
- Resolve Everything — Batch-resolves ASN, country, org and netblock for every IP from local reference datasets — no API calls, so it runs at millions of rows and works offline.
- Summarise (Copilot) — Produces a narrative summary beside the underlying records. It explains; it never creates indicators or assigns attribution.
- Generate Report — Assembles a sourced product from the current case or query, with provenance attached to each element.
A note on the boundary: the only skill that involves a language model is Summarise (Copilot), and it writes prose about records that already exist. Nothing else on this list involves generation of any kind. No indicator, relationship or attribution in the platform originates from a model. See the full skill list.
Tradecraft notes
The distinctions that separate a competent analyst from a fast one:
- Separate description from interpretation on the page. A reviewer who can accept the measurement and reject the meaning will improve the product; one who is forced to accept or reject the whole thing will simply defer to the author.
- Resolution bounds honesty. Pan-sharpened and resampled imagery displays detail finer than the sensor supports, and identifying a specific equipment type below the true ground sample distance is the most common overreach in the discipline.
- Revisit interval, not resolution, determines how tightly you can date a change. A weekly ten-metre series often answers a timing question better than a single sub-metre scene taken afterwards.
- Establish the baseline before hunting anomalies. Without a documented normal state across seasons, ordinary variation reads as significant activity, and the resulting reporting is confidently wrong in a way that is hard to unwind.
- Actively exclude the mundane explanation. Seasonal vegetation, moisture, illumination change and a different processing pipeline account for most apparent change, and testing them is what separates an assessment from an observation.
- Coherence loss in radar indicates that something about the surface changed, not necessarily damage. Corroborate with optical or ground reporting before characterising it, because agricultural work and weather produce the same signal.
- Absent metadata is normal, not suspicious. Platforms strip it on upload, so its absence carries almost no information, while its presence must be treated as assertable rather than authoritative because it is trivially editable.
- Manipulation findings should be phrased as inconsistencies. Stating that the shadow geometry cannot be reconciled with the claimed time is defensible; stating that an image is fake usually is not, and the difference matters legally.
- Imagery is at its most valuable when it cues other collection. The unresolved detail that generates a specific question for registry, maritime or ground reporting is often worth more than the scene you could fully interpret.
Measuring whether it is working
Capability claims should be falsifiable. These are the measures that show whether work on Imagery Intelligence is producing anything, and they are worth baselining before you change process or tooling.
- Proportion of imagery reports where description and interpretation are separately stated and the confidence is explicitly tied to resolution and collection geometry.
- Rate at which change detections are corroborated by an independent sensor or source, and the rate of withdrawn detections traced to seasonal or processing artefacts.
- Median width of the change window achieved per site, reflecting whether sensor selection and revisit planning are actually bounding events in time.
- Number of specific, taskable collection requirements generated from imagery findings and the proportion that were subsequently answered.
- Reproduction rate: share of archived exploitation packages that a second analyst can rerun to the same result from recorded scene identifiers and processing steps.
- Verification outcomes on supplied media, tracking how often provenance was established, refuted or left unresolved, rather than counting items reviewed.
- Adherence to exposure limits and support uptake for analysts reviewing graphic imagery, treated as a capability indicator rather than a welfare statistic.
Beware of measuring volume alone. Indicator counts and report counts rise easily and say little; time-to-attribution, proportion of findings that survive review, and how often a product changed a decision say a great deal.
Common pitfalls
- Interpreting beyond the ground sample distance, describing detail the pixels cannot support.
- Reading cloud shadow, haze or off-nadir lean as physical change on the ground.
- Assuming the imagery timestamp is the event timestamp when the nearest pass may be days away.
- Anchoring on the first interpretation and then fitting every subsequent frame to it.
- Recycled or mirrored imagery from an earlier event presented as current, especially in user-generated material.
- Mistaking seasonal vegetation, flooding or snow cover for activity, construction or damage.
Legal and ethical considerations
Licensing governs what you may publish: Copernicus and Landsat are open, while commercial imagery usually restricts redistribution and derivative products. Aerial and drone collection is bound by aviation and privacy law, and several jurisdictions restrict imaging of designated sensitive sites. Weigh harm before publishing imagery that identifies individuals, exposes shelters or reveals protected locations. Where imagery may become evidence, retain the original file with its metadata and hash, and record every processing step applied to it.
Data integrity: no fabrication, no drift, no hallucination
Intelligence that cannot be traced back to a source is not intelligence, it is assertion. Everything in this entry — and everything in the platform behind it — is built on a small number of non-negotiable rules.
Provenance on every record
Every indicator carries the source that supplied it, a first-seen and last-seen timestamp, and a sighting count. Where several feeds report the same artifact, each contribution is recorded separately rather than collapsed, so you can see whether a finding rests on one source or twelve. Source attribution travels with the data into every export, so a recipient can audit a claim without asking you for the working.
Nothing is invented to fill a gap
If the platform has no data for Imagery Intelligence, it says so. Empty is displayed as empty — never padded with plausible-looking placeholder values, sample records or illustrative examples that a reader might mistake for observations. A dashboard with no rows is a true statement about collection coverage, and it is treated as a gap to close, not a blemish to hide.
Scoring is deterministic and reproducible
Threat scores, reputation grades and risk tiers are computed from stated inputs with fixed weights, not estimated. The same inputs always produce the same output, and the formula is visible rather than a black box. Aggregates are cached with an explicit time-to-live so a figure on screen is never silently stale — and when a heavy query exceeds its time budget the platform serves the last known-good value and labels it, rather than inventing a fresh number or hanging.
Where AI is used, and where it is not
Language models summarise and explain. They do not create indicators, assign attribution or manufacture relationships. No IP address, wallet, hash or identity in the platform originates from a model — every one is ingested from a named feed, resolved from a reference dataset, or entered by an analyst with a source recorded. Copilot output is presented as narrative alongside the underlying records, never in place of them, so a reader can always check the summary against the evidence.
Guarding against drift
Enrichment is additive and timestamped rather than overwriting. Reference data — sanctions lists, allocations, taxonomies — is re-synchronised from the authority on a schedule instead of being edited in place, so local copies cannot quietly diverge from the source of truth. Attribution is recorded with a confidence level and the reporting it rests on, and inferred relationships are labelled as inferred. When a source retracts or corrects, the correction propagates rather than leaving a stale assertion behind.
What this means for you
You can put a finding from this platform in front of a regulator, a court, a board or a partner agency and show where each element came from. That is the standard the tooling is built to — because in this work, being confidently wrong is more damaging than being usefully uncertain.
By the numbers
The taxonomy this entry belongs to is not a marketing list — it is the actual structure of the platform: 52 mission domains, 52 intelligence disciplines and 65 data points, each with a live dashboard behind it. Supporting that: 18 indicator types, 14 playbooks, 16 AI skills, 18 export formats and a 30-step automated pipeline.
This particular entry connects directly to 10 data points, 10 mission domains, 1 closely related entries — every one of them a tag you can follow, and a dashboard you can open.
Questions analysts actually ask
Can imagery alone identify a specific weapon or vehicle type?
Only when the ground sample distance genuinely supports the discriminating features, and often not even then. Silhouette, dimensions and configuration can narrow a class reliably at moderate resolution; distinguishing variants within a class usually requires sub-metre imagery, favourable geometry and corroborating context such as known unit locations or associated equipment. Report the class you can support and state what you cannot exclude, rather than naming a specific model to satisfy the reader. Pan-sharpening and display zoom create an impression of resolution that the underlying data does not carry, and this is where most misidentification originates.
How do you tell real change from seasonal variation?
By having a baseline and by testing the mundane explanations first. Pull the multi-year coverage series and check what the site looks like in the same month in previous years, then compare illumination and sun angle, check precipitation and snow records, and look at whether surrounding untouched areas show the same apparent difference. If the whole scene shifted, it is illumination or processing; if only the area of interest changed, it is more likely substantive. Radar amplitude and coherence provide an independent check because they respond to structure rather than to colour and light.
Are metadata timestamps reliable?
No, treat them as claims. Camera clocks are frequently wrong or set to the wrong timezone, metadata is trivially editable, and platforms usually strip it entirely on upload, so its absence tells you almost nothing. Where metadata survives, it is useful as a hypothesis to test against physical evidence: shadow geometry against solar position for the claimed date and place, weather records, vegetation state and visible dated features. Independent chronolocation that agrees with metadata is strong; metadata alone is weak. Always preserve the original file so the metadata question can be reopened.
How should synthetic media claims be handled?
With symmetric scepticism. Detection tools produce false positives on recompressed, resized or screen-captured files and false negatives on high-quality generations, so a detector score is one weak input rather than a finding. Work the provenance instead: find the earliest appearance, obtain the highest quality original, check internal physical consistency, and test whether the depicted location and time survive independent verification. Where content provenance signatures are present, they carry real weight, but their absence is uninformative. Report what is inconsistent and what remains unresolved rather than declaring authenticity or fabrication.
What does open imagery genuinely support, and where must you pay?
Sentinel-2 at ten metres and Landsat at thirty support extent, land cover change, large construction, flooding, burn scars and long historic baselines extremely well. Sentinel-1 radar supports all-weather monitoring and structural change detection through coherence. Together they answer a large share of real questions at no cost. Commercial sub-metre imagery becomes necessary for counting vehicles, assessing damage to individual buildings, and identifying equipment. Daily-revisit commercial constellations become necessary when the requirement is to date a change to within a day. Use the open archive first to bound the window, then task.
How is imagery preserved so it holds up later?
Keep the original file exactly as received, hashed at the point of receipt, with the acquisition metadata and scene identifier recorded. Log every subsequent operation including contrast stretch, pan-sharpening, reprojection, cropping and annotation, and keep derived products separate from originals. Record the licence and redistribution rights. For evidential material apply a preservation hold with access control and a chain of custody log. The test is whether an independent analyst, years later and after the provider catalogue has changed, could reacquire or verify the source and reproduce your processing from the record.
What confidence language should imagery reporting use?
Language tied to what the sensor could actually support. State the observation, the resolution and geometry limiting it, the alternative explanations considered and excluded, and the residual confidence in consistent terms used across the organisation. Avoid confidence that comes from the plausibility of the conclusion rather than the strength of the imagery. A useful discipline is to write the sentence describing what the imagery cannot exclude before writing the judgement, because that sentence usually determines the honest confidence level and is the first thing a competent reviewer will ask for.
Standards, frameworks and further reading
Work that references a recognised framework is easier to defend, easier to hand over, and easier for a partner to consume:
- National Imagery Interpretability Rating Scale, providing a common vocabulary for what interpretation tasks a given image quality can support.
- ISO 19115 geographic metadata, governing recording of source, lineage, acquisition date, accuracy and licensing for imagery-derived products.
- Berkeley Protocol on Digital Open Source Investigations, setting collection, preservation and verification standards for imagery used in accountability work.
- ISO/IEC 27037, governing identification, collection, acquisition and preservation of digital evidence including image and video files.
- C2PA content provenance and authenticity specification, defining cryptographically signed capture and edit history for media files.
- International humanitarian law protections for medical units, cultural property and civilian objects, which govern what may be published about identifiable protected sites.
- Copernicus and Landsat open data policies versus commercial imagery licences, which determine redistribution rights of source scenes and of derived products.
- DART Center guidance on working with traumatic imagery, governing exposure management for analysts and dignity considerations for those depicted.
References
Primary sources and authoritative references for this entry. Publishers revise and retire material, so treat the retrieval date as part of the citation and re-check before relying on any of it in a formal product.
- Copernicus Data Space Ecosystem — European Space Agency and European Commission. Open Sentinel radar and optical imagery archive and processing services
- EarthExplorer — US Geological Survey. Landsat, aerial and declassified historic imagery archive
- Fire Information for Resource Management System — NASA. Active fire and thermal anomaly detections with timestamps and confidence
- Copernicus Emergency Management Service — European Commission. Validated rapid mapping and damage grading products
- UNOSAT — UNITAR. Satellite imagery analysis for humanitarian and human rights purposes
- C2PA specification — Coalition for Content Provenance and Authenticity. Open standard for signed media capture and edit provenance
- InVID-WeVerify verification tools — WeVerify project consortium. Toolkit for video keyframe extraction, reverse search and image forensics
- Berkeley Protocol on Digital Open Source Investigations — UN Human Rights Office and Human Rights Center, UC Berkeley. Standards for collection, preservation and verification of digital open source material
- Dart Center resources on traumatic imagery — Columbia Journalism School. Guidance on managing exposure to graphic visual material
- Worldview imagery browser — NASA Earthdata. Near real time global satellite imagery browsing across many instruments
Link integrity: every reference above was verified with a live request when this page was generated. Where a publisher had moved or withdrawn a document, the link was repointed at a preserved copy in the Internet Archive and marked as archived. Anything with no reachable copy anywhere had its link removed rather than left to rot — the source is still credited, it simply cannot be linked.
Put it into practice
The Quantus Intel threat intelligence platform operationalises this entry: tasked imagery baselines, change alerting and annotated exploitation products with sourcing intact. Explore the platform, or browse the rest of the library by following any tag above.