September 1, 2026

GNET (Global Network on Extremism & Tech): Intelligence Source Guide

0

GNET is the academic research arm of the Global Internet Forum to Counter Terrorism, led by ICSR at King’s College London. It publishes short analytical Insights and longer reports on how violent extremists exploit online platforms – and it is funded by the industry it studies, which you should k…

gnet-global-network-on-extremism-and-tech-intelligence-source-guide

GNET is the academic research arm of the Global Internet Forum to Counter Terrorism, led by ICSR at King's College London. It publishes short analytical Insights and longer reports on how violent extremists exploit online platforms – and it is funded by the industry it studies, which you should know before you cite it.

At a glance

Source GNET (Global Network on Extremism & Tech)
Category Conflict, Crime & Human Security › Terrorism & Violent Extremism
Homepage https://gnet-research.org/
Format HTML
Access Open — no account required
Disciplines Social Media Intelligence, Disinformation Intelligence
Mission domains Extremism & Radicalization, Disinformation / IO

Online extremism research hub. — as catalogued in the platform’s own source registry.

The Global Network on Extremism and Technology is a research initiative launched in 2020 as the academic research arm of GIFCT, the industry body founded by major technology companies to counter terrorist and violent extremist exploitation of their services. It is led by the International Centre for the Study of Radicalisation at King's College London, working with a consortium of partner research institutions across several regions; the current partner list is on the site and has changed over time. Its output is publishing rather than data. The main product is a stream of Insights – short, analytically dense pieces, typically by a named academic or practitioner, published very frequently and covering a specific platform, actor, technique or policy question. Alongside these sit longer research reports, a podcast, and an annual conference. There is no dataset, no indicator feed and no API. What an intelligence platform extracts from GNET is the analytical content: which services are being exploited and how, which movements and subcultures are active where, what terminology is in use, what the regulatory picture looks like, and which research methods are producing results. It is a literature, and it should be treated as one.

The analytical job it does is to keep your model of the online extremism landscape current, which is a job that indicator feeds cannot do at all. Threat feeds tell you about known bad infrastructure; GNET tells you that a category of service you were not monitoring has become significant, that a movement has changed its recruitment surface, that a technique for evading content moderation has diffused, or that a regulatory change is about to shift where activity happens. For a SOCMINT or counter-disinformation function, that is target-set maintenance: the difference between monitoring the platforms that mattered two years ago and monitoring the ones that matter now. It also does a second, less obvious job. Because it is written largely by academics, it exposes the evidentiary basis for claims that circulate elsewhere without one – how a sample was drawn, what the coding scheme was, what the authors could not establish. In a field crowded with confident assertions about online radicalisation, a source that publishes its uncertainty is disproportionately valuable, and it is a useful corrective for analysts who have absorbed the consultancy version of this subject.

Who publishes it, and why that matters

The funding relationship is the first thing to understand and the thing most citations omit. GIFCT was established by major technology platforms and is funded by them; GNET is its research arm; the research is therefore paid for, at one remove, by the companies whose services are the subject of the research. GNET and its academic lead assert editorial independence, the output does contain criticism of platforms and of GIFCT itself, and the authors are largely external academics with their own institutional standing – so this is not a captured publication. But the structural incentive exists and it is legitimate to weigh it. In practice the effects to watch for are agenda effects rather than falsification: which questions get sustained attention, whether the framing tends towards technical and content-moderation solutions rather than towards platform business models, and whether the harms most expensive for industry to address receive proportionate coverage. State the funding relationship when you cite GNET in a product that matters. It costs one clause, it pre-empts the obvious challenge, and it is the kind of transparency that makes the rest of your assessment more credible rather than less.

Provenance is the first question to ask of any dataset and the one most often skipped. Who collects it, what their incentive is, whether they publish a methodology, and whether they correct the record when they get something wrong all bear directly on how much weight a finding drawn from it can carry.

What a record actually contains

The fields you will be working with, what each one means, and whether it is something you can pivot on. Read the meanings carefully — more analysis is wrecked by misreading a field than by failing to find one, and a field that looks like an observation is often an inference.

Field Type What it means Pivot value
title and standfirst string The piece's headline and summary line, which usually name the platform, movement or phenomenon under study. This is the field your monitoring should filter on. Keyword monitoring against your watch topics; triage into an analyst's reading queue.
author and affiliation string Named author with institutional affiliation, which is the primary signal of what evidentiary tradition the piece comes from – computational social science, ethnography, legal analysis or practitioner experience. Researcher and institution entities; tracking a specialist's body of work across outlets is often more efficient than tracking a topic.
publication date timestamp When the piece was published. In this field currency matters enormously: platform affordances, moderation policies and movement structures change within months, and a two-year-old technical claim is frequently obsolete. Timeline placement; decay weighting for any claim about platform behaviour or moderation practice.
platform and service references array Named online services discussed: mainstream social platforms, messaging applications, gaming and gaming-adjacent services, file hosting, alternative video and social platforms, decentralised and federated networks. This is the highest-value structured extraction from the corpus. Your SOCMINT target set; the collection coverage question of whether you monitor the services that are actually being used.
movement and ideology references array The extremist milieus under discussion – jihadist organisations and their media apparatus, violent far-right and accelerationist networks, gender-based violent extremism, and single-issue violent movements. Framing and terminology vary by author and by region. Actor and movement entities; reconciliation to proscription and designation lists where a named organisation is involved.
technique and behaviour descriptions string How exploitation of a service manifests analytically – migration between platforms after enforcement, use of a service's affordances for coordination, adaptation to moderation. Written for researchers and policymakers, not as operational instruction. Detection and monitoring design at the level of behaviour and platform selection, not at the level of replicating any activity.
terminology and lexicon string The vocabulary a milieu uses about itself, including coded terms and in-group references, as documented for research purposes. The most operationally useful field for anyone building keyword monitoring, and the fastest to become obsolete. Search and alerting vocabularies for SOCMINT work, with a short review cycle because lexicons shift once they become widely known.
regulatory and policy references string Named legislation, regulatory regimes and multi-stakeholder initiatives governing online content, and analysis of their practical effects. A durable and under-used part of the corpus. Compliance and jurisdiction analysis; predicting where activity will move when a regime takes effect.
methodology description string How the research was done: sample construction, data sources, coding scheme, limitations and ethics approval. Present in the longer reports and often in the Insights, and it is what distinguishes a finding from an assertion. Confidence weighting; also a template for designing your own defensible collection and analysis.
external citations array References to underlying academic literature, primary documents, court records and platform transparency reporting. The route from a summary claim to its evidentiary base. Primary source acquisition; frequently the citation is more useful to you than the article.
geographic focus string The region or country a piece addresses. Coverage is genuinely international but unevenly distributed, and the pattern reflects the partner network's composition. Regional coverage gap analysis; identifying where you need non-English and locally produced research instead.
content type enum Insight, research report, podcast episode or conference material. These carry different depth, different review and different citability, and conflating them in a bibliography is a small but visible error. Weighting in a literature review; a peer-reviewed report and a short commentary should not be cited identically.

Coverage — and what is not in it

Thematically, the exploitation of online technology by violent extremists and terrorists, across ideological categories: jihadist movements and their media production, violent far-right and accelerationist networks, gender-motivated violent extremism, and emerging or hybrid milieus that resist established categories. Technologically, the range has widened steadily from mainstream social media to encrypted messaging, alternative and decentralised platforms, gaming and gaming-adjacent services, file hosting and archiving, cryptocurrency and fundraising, and generative artificial intelligence. Policy coverage runs alongside: content moderation practice, transparency reporting, hash-sharing and cross-platform initiatives, and the online safety regulation now in force in several jurisdictions. Geographically it aims to be global and partly succeeds – there is meaningful coverage of South and Southeast Asia, Africa, the Middle East and Europe alongside the North American and Western European default – but the distribution follows the partner network and the available researchers rather than the distribution of the problem. Publication cadence is high, with new Insights appearing several times a week and longer reports periodically. The corpus is now several years deep, which is enough to trace how the field's attention has moved, and that trajectory is itself informative about which concerns proved durable and which did not.

Known blind spots

Absence of evidence here is not evidence of absence. These are the conditions under which GNET (Global Network on Extremism & Tech) will not show you something that is nevertheless real:

  • It is a research publication, not a data source. There are no indicators, no accounts, no channels and no infrastructure you can operationalise directly, and any platform treating it as a feed has misunderstood what it is.
  • Publication lag is the lag of research. A piece describing a platform dynamic reflects fieldwork conducted months earlier, and in an environment where enforcement actions and platform changes reshape activity within weeks, the technical specifics may already be historical.
  • The funding relationship shapes the agenda rather than the findings. Questions that are expensive or existential for the funding industry – business model, recommendation systems, the economics of engagement – are structurally less likely to receive sustained attention than questions about content and moderation technique.
  • Coverage follows researchers, not harm. Milieus and regions without an engaged academic community are under-covered regardless of significance, and the absence of a topic in the corpus says more about the field's staffing than about the world.
  • Non-English and non-Western milieus are under-represented relative to their real weight, despite genuine effort, because the research capacity and the language skills are unevenly distributed.
  • Platform access constrains what can be studied. Research concentrates where data can lawfully and practically be obtained, so services with restrictive terms, closed architectures or genuinely private communication are studied less – and those are frequently the services that matter most.
  • Individual-level attribution is out of scope. This literature describes movements, platforms and dynamics; it will not tell you who runs an account or who is behind a network, and it should never be cited as though it did.
  • The corpus deliberately does not describe how to locate or obtain extremist material, which is correct and which means it cannot serve any collection purpose beyond telling you what categories of service to think about.
  • Terminological lexicons decay fast and asymmetrically. Once a coded term is documented publicly, its use shifts, so a keyword list built from published research is always describing the previous vocabulary.

Write the blind spot into the product. A statement that something “was not observed in GNET (Global Network on Extremism & Tech)” is defensible; a statement that it “did not happen” is not, and the difference is what survives cross-examination.

Access, licensing and what you may do with it

Access model: Open — no account required

The site is open, free and requires no registration. Insights, reports and podcast episodes are published as web pages and documents, and there is no API or bulk export. Realistic collection is monitoring plus reading: follow the publication stream, filter on your platforms and milieus of interest, and route matches to an analyst. Attempting to treat this as a pipeline input misses the point, because the value is in the argument and the methodology rather than in extractable strings. For an intelligence function the sensible arrangement is a standing assignment – one analyst reads the stream weekly, extracts changes to your platform target set and your terminology, and files anything that alters a standing assumption. That costs an hour a week and is one of the higher-return hours in an online extremism programme. For access to the underlying research data behind a specific report, contact the authors directly; academics working in this space are generally willing to discuss method and limitations with practitioners, and that conversation is usually more valuable than the paper.

Licence

Assume the content is copyrighted by GNET or by the individual authors and their institutions, with terms stated on the site. Standard academic and analytical practice is safe: read it, quote briefly with attribution, cite the piece by author, title and date, and link to it. Building on the analysis in your own work is exactly what it is published for. What is not safe is reproducing whole pieces in a commercial product, mirroring the corpus, or presenting the analysis as your own. Where a piece is co-published or produced under a specific arrangement with a partner institution, the terms may differ from the site default, so check the individual item rather than assuming a blanket position. If you want to reproduce substantial material – in training content, in a client deliverable, in a public report – ask; academic publishers in this space are generally accommodating about reuse that credits properly, and the request is cheaper than the alternative.

Rate limits and fair use

No API and no published limits. Poll any syndication feed at a normal reader's cadence, no more than hourly, and do not crawl the archive. If you want the corpus at scale for research, write to them rather than scraping it – a network whose entire purpose is disseminating research to practitioners is a poor target for a crawler and a good candidate for a direct request. Cache what you fetch, identify your collector with a contact address, and back off on any error rather than retrying harder.

Licensing changes, and it changes without warning. A dataset that was free for research this year may not be free for commercial or evidential use next year. Confirm the current terms before you build a dependency on it, and record the terms you relied on alongside the data — the licence in force at the time of collection is part of the provenance.

Collecting it

How GNET (Global Network on Extremism & Tech) is actually pulled, in the order you would set it up. Prefer the bulk or export interface over per-item lookups wherever one exists: it is kinder to the publisher, faster for you, and gives a reproducible snapshot rather than a series of point-in-time answers you cannot reconstruct later.

Method Format Cadence Notes
Publication stream monitoring HTML weekly Follow new Insights and filter on your platforms, milieus and regions of interest. This is the primary collection mode and it is a reading task rather than a pipeline task.
Research reports HTML as published Longer studies with stated methodology and fuller evidence. These are the citable products and warrant full reading rather than skimming, particularly the limitations sections.
Podcast and conference material HTML periodic Practitioner and researcher discussion that frequently surfaces emerging concerns before they appear in writing. Useful for horizon scanning and for identifying who is working on what.
Citation harvesting HTML per piece of interest Extract the references from pieces relevant to you. The underlying primary sources – transparency reports, court documents, platform policy statements – are often what you actually need, and the article is the finding aid.
Analyst extraction to target set CSV monthly Maintain a structured list of services, milieus and terminology mentioned in the corpus, with the date and the citing piece. This is the durable artefact from reading the stream and it is what feeds your SOCMINT collection planning.

Ingesting it into the platform

Every step below is idempotent and cursor-based: interrupt one and it resumes from where it stopped rather than duplicating rows or losing progress. Collection is recorded per source, so a feed that quietly stops publishing shows up as a stale timestamp instead of silently thinning your coverage.

  1. Register as an analytic literature source — Record it in sources.php explicitly as research publication, not as a feed. Nothing from here should ever carry indicator-level confidence, and the source definition is where that distinction is enforced.
  2. Ingest as dated documents — Load pieces through import.php with title, author, affiliation, date, URL and full text. The author and date are load-bearing metadata for this source in a way they are not for most – claims here are attributable to a named researcher at a moment in time.
  3. Extract platform and terminology mentions — Derive named services and documented terminology into dp_keyword and dp_url data points with the citing piece and date attached. These populate the collection-planning view rather than any detection rule, and each entry carries an explicit review date because both decay quickly.
  4. Never derive indicators — URLs appearing in this corpus are research references and citations, not indicators of compromise, and must not be promoted into blocklists, detection rules or watchlists. The ingest must enforce this separation, because a URL field looks identical to a pipeline regardless of what it means.
  5. Link to movement and policy entities — Map movement references to actor entities and regulatory references to policy entities, with the piece as the citation. Where a named proscribed organisation is discussed, reconcile it to the relevant designation lists rather than creating a parallel identity.
  6. Summarise with Copilot, attribute to the author — Copilot summarisation over a set of ingested pieces is appropriate for orientation. The summary is prose about documents that exist; every substantive claim in your product must trace to a named author and a dated piece, and no assertion may originate from the model.
  7. Feed the collection plan, not the detection stack — Route the extracted service list into your SOCMINT coverage assessment so that gaps between what the literature says is being used and what you actually monitor become visible in coverage.php. This is the operational payoff from the source.
  8. Set review dates on everything derived — Any target-set or terminology entry derived from this corpus expires. Attach a review date at ingest – a few months is usually right – so that stale platform assumptions surface for revalidation instead of persisting silently in a collection plan.

Registered sources and their last-collected state are listed in sources.php, and the scheduled chain that keeps them current is in automation.php.

How it is wrong, and how to tell

Every dataset is wrong in characteristic ways. Knowing which ways is the difference between using a source and being used by one, and it is the part of source evaluation most often skipped because it is the part that takes work.

As academic and practitioner analysis, it is generally good and occasionally excellent, with the variance you would expect from a high-cadence platform publishing many authors. The longer reports carry stated methodology and are the most reliable; the short Insights range from careful empirical summaries to informed commentary, and the difference is usually visible within a paragraph if you look for the evidentiary basis. Judge quality piece by piece rather than by the imprint. The specific tests worth applying: does the author state how the sample was constructed and what it excludes; is the claim about a platform's behaviour based on observation or on the platform's own statements; does the piece distinguish what was found from what is inferred; and does it acknowledge that the situation may already have changed. The corpus scores well on the last of these more often than most sources in this field, which is a genuine strength. What you should not expect is operational precision. This literature is right about direction and category – which kinds of service, which movements, which dynamics – and it is not the place to look for specific, current, verified detail about any particular network.

Characteristic false positives

  • Currency decay presented as current. A piece describing a platform's moderation behaviour or a movement's preferred service was accurate at the time of fieldwork, and platform changes and enforcement actions can invalidate the specifics within months while the article reads as present-tense.
  • Single-study findings generalised. An analysis of one platform, one language community or one sample gets cited as a general claim about online radicalisation, and the qualifications in the original are stripped in the retelling.
  • Framing effects from the funding relationship. Not falsified findings, but a distribution of attention that under-weights the questions most costly to the funding industry. This shows up as an absence rather than as an error, which makes it easy to miss.
  • Platform naming without prevalence. Reporting that a milieu uses a service does not establish how much, or that it matters relative to other services, and target-set decisions made on mention alone will misallocate your collection.
  • Terminology treated as stable. Documented coded language shifts precisely because it is documented, so a keyword list built from published research will drift out of usefulness and will generate false positives from mainstream use of the same terms.
  • Category boundaries treated as real. The ideological taxonomies used across the corpus are contested and vary by author, and treating one piece's categorisation as an authoritative classification of a movement will put you at odds with another equally reasonable piece.
  • Research references mistaken for indicators. URLs and identifiers appear in this literature as citations. Promoting them into a blocklist or a detection rule is a category error with real consequences, including blocking legitimate research and archival material.
  • Absence of coverage read as absence of a problem. A milieu or region missing from the corpus reflects the distribution of researchers and access, not the distribution of harm, and this is a systematic rather than a random gap.

None of these make the source unusable. They make it a source that requires corroboration before an assertion built on it goes into a product, which is true of every source and admitted by few.

Ageing

This corpus ages unevenly by claim type, and knowing which type you are reading is the whole skill. Technical and platform-specific claims age fastest – a description of how a service's affordances are being used, or of what its moderation does, may be superseded by a product change or an enforcement wave within a quarter. Movement structure and terminology claims age at the pace of the milieu, which is months rather than years. Regulatory analysis ages predictably with the legislative calendar and is often the most durable content in the corpus. Conceptual and methodological contributions age slowest and remain useful for years. A stale GNET-derived assumption looks like a monitoring plan that covers the services that mattered when the plan was written, with no mechanism to notice that activity moved – which is the single most common failure in online extremism collection. Build review dates into everything you derive, re-read your standing assumptions against the recent stream at least twice a year, and treat any claim about a specific platform's current behaviour as requiring independent confirmation before it drives a decision.

What this source feeds

A source is only worth what it lets you conclude. These are the disciplines that collect through it, the mission domains it serves and the data points it yields — every one is a tag, so you can follow any thread from here into the rest of the library.

Collected by these intelligence disciplines

Serves these mission domains

Yields these data points

How each sector uses GNET (Global Network on Extremism & Tech)

The same dataset is worked very differently depending on who you are, what authority you hold, and what you are ultimately producing. A military analyst is supporting a commander’s decision; a journalist is meeting a publication standard; an NGO caseworker is protecting a person. The records are shared — the constraints, thresholds and outputs are not.

🎖 Military and defence

For information operations, psychological operations and force protection staff, the relevant contribution is understanding of the online environment in which recruitment, incitement and coordination now occur, including the gaming and messaging surfaces that fall outside conventional social media monitoring. It supports environment characterisation and target-audience analysis at a conceptual level, and it will tell you when a category of service has become significant in a theatre you care about. It contains no targeting information, no attributable networks and no infrastructure, and it should never be presented as intelligence on a specific adversary. Its practical use is to keep the assumptions in your collection plan from going quietly out of date.

🕵 National intelligence

For counter-terrorism analysts, this is literature maintenance: the mechanism by which your understanding of the online dimension stays current between formal assessments. Read it for shifts in platform ecology, for the diffusion of techniques between movements, and for the emergence of milieus that do not fit existing categories – the last of which is where this corpus is most consistently ahead of official reporting. It also provides methodological grounding for your own collection design, which matters when your methods will be scrutinised. Weigh the funding relationship when a finding touches on platform responsibility, and always attribute to the named author rather than to the imprint.

👮 Law enforcement

For investigators and specialist online units, the value is contextual and preparatory rather than evidential. It explains the platforms and behaviours you will encounter, the terminology you will see, and the regulatory levers available for removal and preservation requests in different jurisdictions. It is not evidence, it names no suspects, and it cannot support an attribution. Where an investigation touches material that is illegal to possess or distribute, the handling constraints are governed by your own legal framework and by the established reporting routes, and nothing in a research article changes that. Use the literature to brief a team before an operation, not to conduct one.

🔍 Private investigation and corporate security

For corporate security, trust and safety functions and platform integrity teams, this is among the better open sources for anticipating where a problem will migrate after an enforcement action, and for understanding how smaller services become significant once large ones tighten. It supports policy design, risk assessment for a product launch, and the argument you need to make internally about resourcing. Be careful about the funding relationship if you are advising on platform accountability, disclose it, and pair the analysis with independent civil society research so that your recommendation does not rest entirely on industry-funded work.

📰 Journalism and OSINT media

For journalists covering extremism and platform accountability, GNET is a route to named academic experts and to careful summaries of what is actually known, which is a useful antidote to the confident and evidence-free claims that dominate this beat. Two obligations. Disclose the funding relationship when you cite it in a story about platform responsibility – it is material context and a reader deserves it. And do not treat a single Insight as an established finding; check whether the piece presents new research or informed commentary, and read the limitations before you build a headline on it.

🌍 NGO, humanitarian and human rights

For civil society organisations working on online harms, hate speech and the protection of targeted communities, the corpus provides evidence for advocacy and a map of where harm is occurring beyond the platforms that get regulatory attention. It is particularly useful for understanding what platform policy actually does in practice as opposed to what it says. Approach the funding relationship as a fact to be handled rather than a reason for dismissal: cite the work, note the funder, and triangulate with independent research when the question concerns platform accountability. Where your work touches material that harms children or identifiable victims, the route is always the established reporting mechanism, never independent investigation.

🎓 University and research

For researchers, this is a fast-publication venue and a current bibliography of the field, useful for literature reviews and for identifying active researchers and unresolved questions. Cite Insights as what they are – short analytical commentary, not peer-reviewed research – and cite the longer reports separately. The funding relationship belongs in your methods or acknowledgements discussion when you rely on the corpus substantially. It is also a good source of research design examples for a field where ethics, platform terms of service and researcher safety constrain method heavily, and where seeing how others navigated those constraints is genuinely instructive.

Playbook: working GNET (Global Network on Extremism & Tech) end to end

A repeatable sequence from first pull to finished product. Each phase states what you are trying to establish, not merely what to click — the objective is a defensible chain of reasoning, not a completed checklist.

Phase 1 — Decide what you are using it for

Establish up front that this is a literature for maintaining your understanding, not a source of indicators or attribution. Teams that skip this end up trying to build detection from research citations, which produces false positives and, worse, blocks legitimate archival and research resources.

Phase 2 — Build a standing reading assignment

Assign one analyst to read the stream weekly with a fixed extraction template: services named, milieus discussed, terminology documented, regulatory developments, and anything that contradicts a standing assumption in your collection plan. Consistency of reading matters more than volume, because the value is in noticing change.

Phase 3 — Separate finding from commentary as you read

For each piece, identify whether it presents original research with a stated method, summarises other people's research, or offers informed opinion. Record which. All three are useful and they carry entirely different weight, and the distinction disappears the moment a claim enters a downstream product without it.

Phase 4 — Maintain a dated platform target set

Keep a structured list of the services the literature says are being exploited, each with the date and the citing piece. This is the artefact that justifies your collection plan and exposes where it has fallen behind. Review it at a fixed interval rather than when someone happens to notice a gap.

Phase 5 — Audit your coverage against it

Compare the service list against what you actually monitor. The gap is the finding. In most organisations the gap is systematic – collection concentrates on the platforms that are easiest to collect, which are not the platforms where the activity has moved – and making that visible in coverage.php is the highest-value output of this source.

Phase 6 — Handle terminology as perishable

Where the corpus documents in-group language, add it to your search vocabulary with an explicit expiry. Also test each term against mainstream usage before deploying it, because a large share of coded extremist vocabulary consists of ordinary words and will otherwise flood your queue with irrelevant results.

Phase 7 — Follow the citations to primary sources

For any claim that will carry weight, go to the references: the transparency report, the court document, the platform policy statement, the underlying dataset. Frequently the primary source is what you actually needed and the article was the finding aid. This step also reveals when several pieces rest on the same single study.

Phase 8 — Track the regulatory thread deliberately

Follow the policy and regulation coverage as its own line of work. Online safety regimes in several jurisdictions now change where activity happens and what platforms will preserve or disclose, which has direct consequences for both your collection and your requests. This content ages more predictably than anything else in the corpus.

Phase 9 — Weigh the funder when the finding touches industry

When a piece bears on platform responsibility, moderation effectiveness or regulatory design, read it alongside independent civil society and academic work funded elsewhere. You are not looking for falsification, you are looking for questions that are not being asked, and the comparison is the only way to see an absence.

Phase 10 — Convert insight into a testable question, not a conclusion

When the literature says a milieu has moved to a category of service, turn that into something you can check in your own environment rather than adopting it as fact. Research describes a sample at a time; your operating environment may differ, and the verification is usually quick.

Phase 11 — Keep the safety boundaries explicit

Nothing derived from this corpus should describe how material is located, obtained or distributed, and no derived product should identify a private individual. If your work touches child sexual abuse material or trafficking, stop and route it through the statutory reporting mechanism – the research literature is not a handling framework and must never be used as one.

Phase 12 — Feed conclusions back into the collection plan

Close the loop: every reading cycle should end with a concrete change or a recorded decision not to change – a service added to monitoring, a term retired, an assumption revalidated. A literature source that never alters your behaviour is a subscription rather than an intelligence input.

The platform ships this as a step-checked workflow in playbooks.php, so progress is recorded against a case rather than held in someone’s head.

What to pair it with

No single source carries a finding. These are the datasets that corroborate, extend or contradict this one — and a source that contradicts is worth more than one that agrees, because it is the only thing that will tell you when you are wrong.

Source Relationship What it adds
GIFCT prerequisite The parent industry body: its membership, funding, working groups and transparency reporting. Read it to understand the institutional context in which the research is produced.
ICSR prerequisite The academic lead at King's College London, with its own longer-standing publication record on radicalisation that provides the intellectual lineage behind much of the output.
VOX-Pol corroborates An independently funded research network on violent online political extremism, covering similar ground without the industry funding relationship. The natural triangulation partner.
Tech Against Terrorism extends Practitioner-facing work supporting smaller platforms on counter-terrorism obligations, closer to the operational and compliance end than the research end.
Institute for Strategic Dialogue corroborates Independent research on extremism, disinformation and online harms, frequently addressing the platform accountability questions that industry-funded research is structurally less likely to pursue.
RUSI extends Security and defence research including terrorism and technology, providing a policy and national security frame alongside the platform-centred analysis.
European Commission digital policy extends The official source on EU online content regulation, which is the regulatory environment much of this literature analyses and which determines what platforms must actually do.
Ofcom extends The UK online safety regulator, whose guidance and enforcement decisions are the practical implementation of one of the regimes the corpus discusses.
Global Terrorism Database contradicts Offline attack event data with no online dimension at all. Useful precisely because it grounds online-focused analysis against the record of what violence actually occurred.

Legal, ethical and operational constraints

This source is analysis about extremism rather than extremist material, so reading and citing it carries no unusual legal exposure in most jurisdictions. The exposure arises in what you do next. In several countries, possessing, storing or transmitting terrorist publications and certain extremist material is a criminal offence with narrow research and journalism defences that depend on documented purpose, controlled handling and, frequently, institutional authorisation. If reading this literature leads you towards collecting primary material, stop and establish your legal basis, your handling regime and your authorisation before you collect anything – not afterwards. Monitoring individuals or communities online engages data protection law and, in most jurisdictions, requires a lawful basis, a documented necessity and proportionality assessment, and limits on retention, particularly where political or religious opinion is inferred. Assume you may be operating across jurisdictions with different thresholds. And there is an absolute boundary: if any line of work touches child sexual abuse material, the only lawful and ethical course is to stop and route it to the statutory reporting mechanism in your jurisdiction – NCMEC's CyberTipline, the IWF, an INHOPE member hotline or the national police channel – and never to view, collect, preserve or forward the material yourself.

Operational security

Reading a public research site is low-exposure and reveals only an interest in the subject. The risk sits in what a naive reading of the literature invites you to do next. Visiting the services and communities the research describes, from attributable infrastructure, exposes your organisation's interest to platform operators, to the communities themselves, and to anyone with access to your network traffic – and some of the milieus discussed here actively hunt for researchers and investigators and have doxed them. If your work extends from reading about these environments to observing them, that requires managed infrastructure, a documented legal basis and an operational security plan approved before first contact, not improvised afterwards. Consider also that sustained targeted reading of research about a specific movement produces a pattern at your egress point. For sensitive work, separate the reading environment from the operating environment, and never let curiosity from an article turn into an unplanned visit from a corporate address.

Two rules that hold regardless of jurisdiction. Collection that is lawful is not automatically proportionate, and a dataset assembled for one purpose does not carry consent for another. Where the records concern identifiable people, the question is not only whether you may hold the data but whether holding it serves the purpose you are accountable for.

Is it earning its place?

Sources accumulate. Feeds get added during an incident and are never reviewed again, and a decade later the pipeline is carrying dead weight that nobody dares remove. These are the measures that show whether GNET (Global Network on Extremism & Tech) is contributing anything, and they are worth baselining now so the answer is available later.

  • Number of changes to your platform target set per quarter that originated in this corpus, which is the direct measure of whether reading it is altering your collection or merely informing it.
  • Coverage gap: services named in the recent literature that you do not monitor, tracked as a count and reviewed rather than accumulated.
  • Age distribution of the platform assumptions currently underpinning your collection plan, exposing how much of your monitoring rests on claims nobody has revalidated.
  • Proportion of terminology entries in your search vocabulary that are past their review date, since expired coded language is a leading cause of false positives in SOCMINT queues.
  • Ratio of claims you use that trace to original research with a stated method versus to commentary, tracked as a discipline measure on your own citation practice.
  • Frequency with which following a citation led you to a primary source you then used directly, which tells you whether the corpus is functioning as a finding aid as well as a literature.
  • Share of products citing this source that disclosed the funding relationship, as a straightforward transparency count.

Beware of volume. Indicator counts rise easily and say almost nothing. Unique contribution — findings this source produced that no other source in your stack would have — is the measure that matters, and it is usually far lower than anyone expects.

Tradecraft notes

The distinctions that separate a competent analyst from a fast one:

  • This is a literature, not a feed. The moment someone builds a parser to extract indicators from it, the source is being misused and the output will be wrong in ways that are hard to detect.
  • Attribute to the author and the date, never to the imprint. Pieces vary enormously in evidentiary weight, and a citation to the network rather than to a named researcher conceals exactly the information a reader needs.
  • Read the methodology and the limitations before the findings. In this field the constraints on how research can be done are severe, and what a study could not establish is frequently more informative than what it did.
  • Platform mention is not platform prevalence. Knowing a service is used tells you nothing about scale relative to alternatives, and collection plans built on mentions will over-invest in the exotic and under-invest in the obvious.
  • Treat documented coded terminology as perishable and test it against mainstream usage before deployment. Publication accelerates the shift in vocabulary that made the term worth documenting.
  • State the funding relationship when you cite this in anything touching platform accountability. It costs a clause, it pre-empts the obvious attack, and omitting it is the kind of thing that discredits an otherwise sound product.
  • Use the corpus to find the primary sources. Transparency reports, court records and platform policy statements are more citable and more durable than any summary of them.
  • Watch for absence as well as content. What this literature does not cover – by region, by milieu, by platform, by question – is a structured gap driven by researcher availability, access and funding, and reading it as a picture of the world will mislead you.
  • Keep the boundary between reading about an environment and entering it explicit and governed. That transition needs legal basis, infrastructure and authorisation, and the fact that a research article described something is not authorisation to go and look.

Questions analysts actually ask

Does GNET publish indicators, accounts or channels I can monitor?

No. It publishes research and analysis. There is no feed, no dataset and no indicator content, and URLs appearing in the text are citations rather than indicators. Treating them as detection input is a category error that will block legitimate research and archival resources.

Is the research independent given who funds it?

GNET asserts editorial independence, its authors are largely external academics, and the output does criticise platforms and GIFCT. The funding relationship nonetheless exists and is worth weighing, mainly for its effect on which questions receive sustained attention rather than on whether findings are accurate. Disclose it when you cite the work in anything about platform responsibility.

How current is it?

Fast for research and slow for operations. Publication cadence is high, but pieces reflect fieldwork conducted earlier, and platform-specific claims can be overtaken within a quarter by product changes or enforcement waves. Verify anything platform-specific independently before it drives a decision.

Can I use it to build a keyword list for social media monitoring?

Partially, and with an expiry date. Documented in-group terminology is useful, but publication accelerates its replacement, and much coded vocabulary consists of ordinary words that will flood your queue. Test each term against mainstream usage, set a review date, and expect to retire terms regularly.

Can I cite it in an intelligence assessment?

Yes, attributed to the named author, the piece title and the date, and labelled as external research rather than as your own collection. Distinguish research reports from short commentary pieces in your citations, because they carry different weight and a reader will notice if you conflate them.

Does it cover regions outside Europe and North America?

Yes, genuinely, but unevenly. Coverage follows the partner network and available researchers rather than the distribution of the problem, so for many regions you will need locally produced and non-English research alongside it. Read thin coverage as a fact about research capacity, not about the region.

What should I do if research leads me towards actual extremist material?

Stop and establish your legal basis, handling regime and authorisation before collecting anything. Several jurisdictions criminalise possession of terrorist publications with narrow research defences that depend on documented purpose and controlled handling. If the material involves children, do not view or collect it – route it immediately to the statutory reporting mechanism in your jurisdiction.

How does this fit with an indicator-driven platform?

As collection planning rather than detection. It tells you which services and milieus deserve monitoring attention and when your assumptions have gone stale, and the output belongs in your coverage assessment. Nothing from it should ever reach a detection rule or a watchlist.

Is one Insight enough to support a claim in a client report?

Usually not on its own. Check whether the piece presents original research with a stated method or informed commentary, read the limitations, and where the claim matters, follow the citations to the primary evidence and cite that instead.

Standards, formats and interoperability

What this source speaks natively, and what it has to be translated into before a partner can consume it. Work that arrives in a recognised format is easier to defend, easier to hand over and easier to automate against:

  • Academic publication conventions: named authorship, institutional affiliation, dated pieces and reference lists, which is the citation standard any downstream use must preserve.
  • Maps to the counter-terrorism and countering violent extremism policy frame rather than to any cyber threat taxonomy; do not attempt to force it into ATT&CK-style structures, which do not describe this phenomenon.
  • Regulatory analysis references named online safety and content regulation regimes in several jurisdictions, which are the compliance standards that determine what platforms preserve and disclose.
  • Ideological and movement taxonomies vary by author and are contested; record which taxonomy a piece used rather than normalising silently to your own.
  • Where proscribed organisations are discussed, reconcile to national and international designation lists, which are the authoritative identity standard for those entities.
  • Derived terminology and platform lists should carry an explicit review date, because unlike an indicator these have no natural expiry mechanism and will otherwise persist indefinitely in a collection plan.
  • Handling of any primary material encountered downstream is governed by national terrorism and child protection law and by the established reporting mechanisms, not by any research convention.

References

Primary documentation and authoritative references for this source. Publishers revise and retire material, so treat the retrieval date as part of the citation and re-check before relying on any of it in a formal product.

  1. GNET — Global Network on Extremism and Technology. The source itself: Insights, research reports, podcast and the current partner institution list.
  2. GIFCT — Global Internet Forum to Counter Terrorism. The parent industry body – membership, funding model, working groups and transparency reporting. Essential context for weighing the research.
  3. ICSR — King's College London. The academic lead, with its own long-standing publication record on radicalisation and terrorism.
  4. VOX-Pol — VOX-Pol Network. An independently funded research network covering violent online political extremism – the natural triangulation partner on questions of platform responsibility.
  5. Tech Against Terrorism — Tech Against Terrorism. Practitioner-facing support for smaller platforms on counter-terrorism obligations, closer to the compliance and operational end of the field.
  6. Institute for Strategic Dialogue — ISD. Independent research on extremism, disinformation and online harms, useful for the questions industry-funded work is less likely to pursue.
  7. RUSI — Royal United Services Institute. Security and defence research including terrorism and technology, providing a national security frame around the platform analysis.
  8. European Commission digital strategy — European Commission. The authoritative source on EU online content regulation, which is the legal environment much of this literature analyses.
  9. Europol — European Union Agency for Law Enforcement Cooperation. Operational European work on terrorist content online, including referral activity and the enforcement side of the regulatory regimes this literature analyses.
  10. INHOPE — INHOPE. The network of national hotlines for reporting child sexual abuse material. The correct route if any line of work touches material involving children.

Link integrity: every reference above was verified with a live request when this page was generated. Where a publisher had moved or withdrawn a document, the link was repointed at a preserved copy in the Internet Archive and marked as archived. Anything with no reachable copy anywhere had its link removed rather than left to rot — the source is still credited, it simply cannot be linked.

Put it into practice

The Quantus Intel threat intelligence platform operationalises this source: it ingests the corpus as dated, attributed research documents, converts named services and terminology into a reviewable SOCMINT target set with expiry dates, and enforces the separation between research citations and indicators so nothing from a literature ever reaches a detection rule.. Browse the full source catalogue, or follow any tag above into the rest of the library.

Leave a Reply