August 7, 2026

Measurement & Signature Intel (MASINT): Intelligence Discipline Guide

0

Imagery shows you the object. Measurement and signature intelligence tells you what the object is doing, how hot it is running, what it is emitting, and whether it is the same object you saw last week.

measurement-and-signature-intel-intelligence-discipline-guide

Imagery shows you the object. Measurement and signature intelligence tells you what the object is doing, how hot it is running, what it is emitting, and whether it is the same object you saw last week.

What Measurement & Signature Intel is as a discipline

Measurement and signature intelligence derives conclusions from the measured physical characteristics of a target and its emissions rather than from a picture or a message. It works with quantities: radiant intensity, spectral reflectance, seismic waveform, acoustic spectrum, magnetic anomaly, radiation dose rate, effluent composition. The core method is signature comparison, matching an observed measurement against a library of characterised sources so an unknown event can be identified, located and quantified. Its authority comes from physics: a signature is a consequence of construction and process, and is much harder to disguise than an appearance.

Recognised sub-disciplines include geophysical, radar, radiofrequency, electro-optical, nuclear radiation and materials MASINT. In the intelligence cycle it functions as a measurement and validation layer: it converts phenomena into calibrated numbers that confirm, refute or quantify hypotheses raised by imagery, human reporting or open reporting, and it supports change detection where a signature shift precedes any visible change.

Why it matters

Only measurement intelligence answers how much, how hot, how deep and what material. It distinguishes a mine collapse from a small explosion from an earthquake using the same seismic network, quantifies flaring or methane release from an industrial site, detects thermal activity at a facility that appears idle in imagery, and identifies material composition at distance. It answers whether an event occurred at all when no one is reporting it, and it provides the calibrated evidence base that turns a suspicion into a defensible measurement.

What analysts actually look for

These are the concrete, observable signals that carry weight in this area of work:

  • Seismic waveform characteristics distinguishing natural earthquakes from mining events and surface or buried explosions
  • Infrasound arrivals from large atmospheric events, giving independent detection and rough source location over long ranges
  • Thermal anomaly detections indicating active furnaces, flaring, fires or facility operation invisible in daytime optical imagery
  • Multispectral and hyperspectral reflectance signatures indicating material type, vegetation stress, disturbed soil or water contamination
  • Atmospheric trace gas column measurements quantifying methane, sulphur dioxide or nitrogen dioxide plumes and their sources
  • Ambient gamma dose rate deviations from established baselines across public radiation monitoring networks
  • Radar backscatter and interferometric change indicating ground deformation, subsidence, construction or heavy vehicle activity
  • Acoustic and hydroacoustic spectra used to classify machinery and platform types by their characteristic tonal patterns

Where the data comes from

Authoritative and openly available collection points. Always confirm licensing and terms before operational or commercial use:

  • USGS Earthquake Hazards and IRIS or EarthScope — Free global seismic catalogues and raw waveform archives for event discrimination and independent location
  • CTBTO International Monitoring System and vDEC — Seismic, hydroacoustic, infrasound and radionuclide monitoring; virtual Data Exploitation Centre offers research access
  • NASA FIRMS — Near real time thermal anomaly and active fire detections from MODIS and VIIRS, free and globally gridded
  • Copernicus Sentinel Open Access Hub — Free Sentinel-1 radar, Sentinel-2 multispectral and Sentinel-5P trace gas products for change and plume analysis
  • EPA RadNet and EURDEP — Public ambient radiation monitoring networks providing baselines and deviation detection across the US and Europe
  • Safecast — Open crowd-sourced radiation measurement dataset useful for local baselines where official coverage is sparse
  • NOAA and Copernicus atmospheric services — Meteorological and atmospheric composition data needed to model transport and interpret any plume observation

A working method

A repeatable sequence beats ad-hoc searching. This is a practical starting workflow:

  1. Establish the baseline — Characterise normal conditions at the location and season before assessing any measurement, because anomaly only exists relative to a documented baseline.
  2. Select the right phenomenology — Match the question to the physics: thermal for activity, radar for deformation and all-weather coverage, spectral for material, seismic for subsurface events.
  3. Calibrate and correct — Apply sensor calibration, atmospheric correction and geolocation adjustment before comparison, since raw values across instruments are not directly comparable.
  4. Cross-phenomenology corroboration — Confirm any anomaly with an independent measurement type; a single-sensor anomaly is usually instrument or environmental artefact.
  5. Model the transport — For any emission or plume, run or obtain meteorological transport analysis to connect a downwind measurement to a plausible source location.
  6. Quantify with uncertainty — Report magnitudes with explicit error bounds and detection limits, distinguishing a non-detection from an absence of the phenomenon.
  7. Fuse with other disciplines — Anchor the measurement to imagery, open reporting and site records so the physical finding acquires operational meaning.

How this connects across the intelligence taxonomy

Intelligence work does not respect neat boundaries. The mission domain you are working, the disciplines you practise, and the data points you pivot on are one connected system. These are the direct relationships for this entry — every link is also a tag, so you can follow any thread across the whole library.

Applied in these mission domains

Operates on these data points

  • GPS Coordinates — Precise latitude/longitude coordinates identifying an exact point on Earth — the atomic unit of GEOINT analysi
  • Facility / Site — A physical installation — plant, base, port, data centre — with a fixed footprint and function.
  • Event / Incident — A discrete real-world occurrence — protest, strike, breach, seizure — with time, place, and actors.
  • Satellite Imagery — Overhead imagery of an area of interest, used for change detection and site analysis.
  • Radio Callsign — A licensed radio identifier for a station, vessel, aircraft, or operator.
  • Location / Coordinates — A geographic point, place, or region — the basis of GEOINT analysis.
  • Company / Organization — A legal entity — corporation, LLC, NGO, or business.

Related disciplines

Inside the platform: where Measurement & Signature Intel lives

The Quantus platform is 204 pages behind a 147-item sidebar organised into six working groups: Command (24 items), Dashboards (15), Threat Theaters (14), Intelligence Domains (15), Investigate (34), and Administration (45). This entry is not a page in isolation — it is a thread running through several of them.

The modules that matter most here:

Each dashboard is local-first: it renders from the platform’s own database rather than depending on a live third-party call, so it still works when an upstream API is unreachable or rate-limited. Heavy aggregates are cached with a hard query time cap and degrade to the last good value instead of hanging the page.

Automation, playbooks and AI skills

Analysis that only happens when someone remembers to run it is not a capability. The platform ships a 30-step automation pipeline (cron.php) that collects, ingests, resolves, enriches, correlates and scores on a schedule — 25 seeders, 11 resolvers and 7 enrichment runners, all idempotent and cursor-based so a run can be interrupted and resumed without duplicating or losing work.

AI skills that apply

The 16 one-click operations in ai-skills.php are deterministic jobs, not free-text generation. The ones that matter here:

  • Score Country Risk
  • Sync Intel Domains
  • Resolve Everything
  • Summarise (Copilot)
  • Generate Report

Alerting closes the loop: rules in alerts.php fire on new indicators matching a saved query, so a first sighting in this area raises a notification rather than waiting to be noticed at the next review.

Feeds, data sources and the API

The collection layer runs a feed registry of free, machine-readable sources — bulk blocklists and trackers (Maltrail, IPsum, FireHOL, the full abuse.ch corpora, phishing databases, Emerging Threats, Spamhaus, DigitalSide, ThreatView), authoritative government feeds (CISA KEV, OFAC, UN and EU sanctions lists), and reference datasets (RIR allocations, ip-to-ASN and geolocation tables, MITRE ATT&CK, EPSS). collect.php pulls them server-side on a schedule; feeds.php and source-catalog.php show what is registered, what it covers and when it last ran.

Anything the platform holds is reachable programmatically. The REST API in api.php exposes 11 endpoints — status, stats, search, lookup, recent, export, bulk_check, top_threats, by_category, categories, check — and export.php streams 18 formats in bounded chunks, so a million-row export neither exhausts memory nor times out:

STIX 2.1, MISP, OpenIOC 1.1, CEF (ArcSight), LEEF 2.0 (QRadar), Zeek/Bro intel, Snort/Suricata rules, Palo Alto EDL, BIND RPZ, hosts blackhole, iptables, CSV, JSON, NDJSON/JSONL, XML.

That covers the CTI standards (STIX 2.1, MISP, OpenIOC), SIEM ingestion (CEF, LEEF, Zeek), detection engines (Snort/Suricata), and direct enforcement (Palo Alto EDL, BIND RPZ, hosts, iptables) — so intelligence developed here can be actioned in the tools you already run, without a manual reformatting step. A TAXII 2.1 server and a MISP/RSS feed are also served for pull-based sharing.

Use cases

Three ways this entry earns its keep in day-to-day work:

  1. Triage under time pressure. An artifact or report lands and you need a defensible read in minutes, not days. Establish the baseline is the first move; the platform pre-computes the enrichment so the analyst spends the time on judgement rather than lookups.
  2. Building the picture. A single indicator is rarely the story. Calibrate and correct turns one artifact into a network — shared infrastructure, repeated selectors, the same operator behind different names — via the correlation graph and the cross-entity link engine.
  3. Producing something actionable. Analysis that ends in a document nobody can use is wasted. Fuse with other disciplines feeds the case file, the detection rule, the block list or the referral — with sourcing attached so the recipient can verify it.

Case management (cases.php), watchlists, saved searches and scheduled reports mean the work persists between sessions and survives an analyst leaving the team.

How each sector uses Measurement & Signature Intel

The same entry is worked very differently depending on who you are, what authority you hold, and what you are ultimately producing. A military analyst is supporting a commander’s decision; a journalist is meeting a publication standard; an NGO caseworker is protecting a person. The underlying artifacts are shared — the constraints, outputs and thresholds are not.

🎖 Military and defence

Measurement and signature intelligence supports battle damage assessment, target characterisation, camouflage and concealment defeat, and detection of activity at facilities that appear inert in imagery. Thermal, radar, acoustic and seismic signatures quantify what is happening rather than showing what is present. Products feed targeting support with calibrated confidence, force protection through detection of chemical or radiological hazard, and IPB by characterising the physical environment. Constraints include sensor tasking competition, the classification of national signature libraries, and the requirement to state error bounds honestly, because a measurement presented without uncertainty invites decisions the data cannot support.

🕵 National intelligence

National intelligence uses measurement data as the arbiter when imagery and human reporting disagree. Requirements typically ask whether an event occurred, how large it was, what material was involved and whether a facility is operating. Signature libraries and calibrated national sensors are usually classified, so the analytic challenge is producing releasable conclusions from open scientific and civil monitoring networks that can be shared with partners and, when necessary, with the public. Fusion is essential: a seismic or thermal anomaly acquires meaning only when tied to a site, an actor and a chronology from other disciplines.

👮 Law enforcement

Law enforcement encounters measurement intelligence in environmental crime, illegal mining and dumping, clandestine laboratory detection, and radiological source recovery. Public seismic, thermal and air quality data can establish that an event occurred and when, which supports search warrant applications. Evidentially, measurements need instrument calibration records, chain of custody for any physical sample, and an expert who can speak to the method, because a number without a documented calibration and detection limit is inadmissible in most proceedings. Placement of sensors on private land requires authority, and monitoring near sensitive sites can itself breach the law.

🔍 Private investigation and corporate security

Corporate and environmental consultants use open measurement data for site due diligence, emissions verification, insurance loss assessment and monitoring of counterparty facilities. Thermal anomalies indicate operating status, radar deformation indicates subsidence or construction, and atmospheric data supports plume claims. Private actors may not place sensors on land they do not control, fly instrumented aircraft into restricted airspace, or misrepresent measurements as regulatory findings. Detection instruments, especially radiation and specialised spectral equipment, may be licence-controlled to possess and export controlled to move across borders, which surprises many commercial teams.

📰 Journalism and OSINT media

Investigative journalists use measurement data to establish that an explosion, fire, flaring event or release occurred when authorities deny it. Verification standards require an independent second phenomenology, a stated baseline, and a specialist review before publication, because misread thermal or seismic data has produced high-profile errors. Publish the data source, acquisition time, processing steps and uncertainty so others can check the work. Where findings suggest a live radiological or chemical hazard, notify competent authorities before publication, and be careful not to present a modelled plume as an observed one.

🌍 NGO, humanitarian and human rights

Environmental, humanitarian and human rights organisations use measurement data to document burning of villages, destruction of infrastructure, illegal mining, flaring and industrial pollution affecting communities. Practice should be community-centred: measurements about a place affect the people living there, so findings should be shared with them and framed to support their claims rather than to extract a story. Duty of care applies to field staff placing sensors in contested areas. Accountability documentation needs baselines, calibration notes and preserved raw data, since adversarial review of NGO measurement work is now routine and usually attacks the baseline first.

🎓 University and research

Researchers in geophysics, remote sensing, atmospheric science and radiation monitoring produce most of the open data this discipline uses. Methodological requirements are the discipline's own: documented calibration, atmospheric correction, geolocation accuracy, detection limits and propagated uncertainty. Ethics review is rarely engaged unless work involves human exposure data or fieldwork risk, but data-sharing agreements and licence terms on satellite products can restrict redistribution. Reproducibility requires publishing processing chains, software versions and parameter choices, since apparently minor preprocessing decisions can create or erase an anomaly entirely.

Playbook: working Measurement & Signature Intel end to end

A repeatable sequence, from the moment the requirement lands to the moment a product is delivered and the case is closed out. Each phase states what you are trying to establish, not merely what to click — the point is a defensible chain of reasoning, not a checklist.

Phase 1 — Convert the question into a physical quantity

Restate the intelligence question as something measurable: temperature, displacement, spectral reflectance, ground velocity, dose rate, gas concentration. If it cannot be phrased as a quantity with units, measurement intelligence is the wrong discipline for it. A good output names the quantity, the required sensitivity and the acceptable uncertainty. Stop and return to the customer if the question implicitly asks for an identification that no available sensor can make at the required distance or revisit rate.

Phase 2 — Select the phenomenology deliberately

Match physics to question: thermal infrared for activity and combustion, synthetic aperture radar for deformation and all-weather coverage, multispectral and hyperspectral for material, seismic for subsurface and explosive events, infrasound for atmospheric explosions, hydroacoustic for underwater, radiation monitoring for release. A good output justifies the choice and names the phenomenology you rejected and why. Stop when the selected sensor's resolution, revisit and detection limit are documented as adequate for the required decision.

Phase 3 — Establish the baseline

Characterise normal conditions at the location for the relevant season, time of day and operating cycle, using the longest consistent record available. Anomaly exists only relative to a documented baseline, and most false findings are baseline failures rather than sensor failures. A good output is a baseline with its period, variance and known confounders such as agricultural burning or seasonal flooding. Stop when the baseline is long enough to contain at least one full cycle of the natural variation you must exclude.

Phase 4 — Acquire with metadata intact

Retrieve data with full acquisition metadata: sensor, band, acquisition time in UTC, viewing geometry, processing level, calibration version and geolocation accuracy. Preserve the original product alongside any derived layer. A good output is an acquisition register that lets someone else reproduce your retrieval exactly. Stop and record the limitation if only a processed or visualised product is available, because you cannot assess uncertainty on a picture.

Phase 5 — Calibrate and correct

Apply radiometric calibration, atmospheric correction, terrain correction and geolocation refinement before comparing anything. Raw digital numbers from different instruments, or from the same instrument under different conditions, are not comparable. A good output documents each correction applied with its algorithm and parameters. Stop when the residual error is characterised, and state it, rather than presenting corrected values as if they were exact.

Phase 6 — Detect and quantify the anomaly

Compare against the baseline using a stated threshold, and quantify magnitude with explicit error bounds. Distinguish clearly between a non-detection, which means the signal was below the instrument's detection limit, and an absence, which means the phenomenon did not occur. A good output gives a value, an uncertainty and a detection limit. Stop before converting a marginal exceedance into a finding; report it as inconclusive and specify what additional data would resolve it.

Phase 7 — Cross-phenomenology corroboration

Confirm any anomaly with an independent measurement type or an independent sensor. A single-sensor anomaly is more often an instrument artefact, a processing artefact or an environmental effect than a real event. A good output shows at least two physically independent observations pointing the same way, or states plainly that corroboration was unavailable. Stop and downgrade confidence rather than publishing a single-sensor detection as an established event.

Phase 8 — Model transport and propagation

For any emission, plume or wave, run or obtain the relevant transport model: atmospheric dispersion with real meteorology for gases and particulates, seismic travel time and magnitude estimation for ground motion, propagation modelling for acoustic and infrasound. This connects a downwind or distant measurement to a plausible source. A good output includes the meteorological or velocity model used and a source region rather than a point. Stop before asserting a single source location when the model yields an area.

Phase 9 — Discriminate between candidate causes

List the natural and mundane explanations first: earthquake, quarry blast, agricultural fire, industrial routine, solar heating, sensor drift. Identify the discriminating feature for each, such as waveform character for explosion versus earthquake, or diurnal pattern for solar heating versus process heat. A good output names the discriminator that ruled each alternative in or out. Stop when the remaining explanation is supported by a discriminating feature rather than merely being the analyst's preferred narrative.

Phase 10 — Fuse with other disciplines

Anchor the measurement to a place, an operator, a chronology and a purpose using imagery, corporate records, permits, shipping or open reporting. A calibrated number is not intelligence until someone can say whose facility it is and what it means. A good output ties the physical finding to an entity and a timeline with sources. Stop when the physical and contextual pictures are consistent, and report the disagreement explicitly if they are not.

Phase 11 — Apply the notification duty

Where findings indicate a radiological, chemical or biological hazard, an environmental emergency or a risk to life, notify the competent authority before doing anything else. This is a professional and often legal obligation and it takes precedence over publication or client delivery. A good output is a documented notification with time, recipient and content. Stop all dissemination planning until the notification decision is made and recorded.

Phase 12 — Report with uncertainty and reproducibility

Deliver the finding as a quantity with error bounds, the baseline it is measured against, the corroborating observation, the alternatives excluded and the processing chain used, including software versions and parameters. Provide the data identifiers so the work can be repeated. A good output can be reproduced by an independent scientist from the report alone. Stop before presenting a visualisation without the underlying numbers, because coloured imagery persuades far beyond what the data supports.

The platform ships this as a step-checked workflow in playbooks.php, so progress is recorded against a case rather than held in someone’s head.

Source register: what to collect from, and how

Sources are listed with their access model so you can plan around cost and licensing before you build a dependency on them. Open means no account required; registration means a free account or API key; licensed means paid or institutional access. Always confirm current terms — licensing changes, and a source that was free for research may not be free for commercial or evidential use.

Source Access What it gives you How it is used here
USGS Earthquake Hazards Program Open Global earthquake catalogue with locations, depths, magnitudes, waveform links and rapid automated solutions First check for any seismic event, and the baseline for distinguishing natural seismicity from blasts and collapses
EarthScope and IRIS seismic data services Registration Archive of global broadband seismic waveform data with station metadata, instrument responses and request tools Waveform-level analysis to discriminate explosion, collapse and earthquake sources at a specific site
CTBTO International Monitoring System and vDEC Registration Global seismic, hydroacoustic, infrasound and radionuclide monitoring network with data access for vetted researchers The reference network for detecting and characterising explosive events and radionuclide releases worldwide
NASA FIRMS active fire data Open Near real time thermal anomaly and active fire detections from MODIS and VIIRS with confidence values and timestamps Detects flaring, burning and combustion events including village burning and industrial thermal activity
Copernicus Data Space Ecosystem Registration Free access to Sentinel radar, optical and atmospheric data with processing tools and long archives Radar deformation and change detection plus multispectral analysis for material and activity assessment
NASA Earthdata Registration Portal to NASA earth observation collections including thermal, atmospheric composition, altimetry and land products Retrieval of calibrated science products with full metadata rather than pre-rendered visualisations
Copernicus Atmosphere Monitoring Service Registration Global atmospheric composition analyses and forecasts including aerosols, trace gases and dispersion products Supports plume transport reasoning and gives modelled background concentrations for comparison
EPA RadNet Open US environmental radiation monitoring network measuring air, precipitation and drinking water with historical records Baseline and anomaly detection for radiological release within the United States
European Radiological Data Exchange Platform Open Aggregated national gamma dose rate monitoring across European countries with near real time and historical series Cross-border radiological baseline and detection of elevated dose rates near facilities of interest
Safecast Open Volunteer-collected radiation measurements with device metadata, timestamps, geolocation and open licensing across many countries Fills geographic gaps left by official networks, with the caveat of uncalibrated consumer instruments
NOAA National Centers for Environmental Information Open Meteorological, oceanographic and geophysical archives including reanalysis products and station observations Supplies the meteorology needed for dispersion modelling and for excluding weather-driven anomalies
NOAA HYSPLIT modelling system Open Atmospheric trajectory and dispersion model with archived meteorological fields and a web interface Connects a downwind measurement to a candidate source region, forwards or backwards in time
Sentinel-5P and TROPOMI products Registration Daily global measurements of trace gases including nitrogen dioxide, sulphur dioxide, carbon monoxide and methane Detects industrial emissions, methane releases and facility activity that thermal sensors miss
USGS Landsat archive Open Five decades of calibrated multispectral and thermal imagery with consistent processing levels Long baselines for thermal and land change analysis where consistency matters more than resolution
IAEA radiation monitoring and safety resources Open International standards, guidance and reporting on radiation monitoring, source security and emergency response Defines the measurement and notification framework any radiological finding must be referred into
OpenAQ Open Aggregated global air quality measurements from government and research monitors with station metadata Ground-truth for particulate and gas anomalies detected from orbit, where stations exist

Prefer sources that publish a methodology and a revision history. A dataset that changes silently is a liability in any product that has to survive challenge.

Tooling

Tools commonly used against Measurement & Signature Intel. None of these replace judgement, and each carries its own failure modes — know what a tool infers versus what it observes.

  • ObsPy — Python framework for seismological data retrieval, instrument response removal and waveform analysis; powerful, and it assumes the user understands instrument responses.
  • SNAP, the Sentinel Application Platform — ESA toolbox for radar and optical processing including interferometry; capable and free, with heavy memory demands and a complex processing graph model.
  • QGIS with GDAL — Georeferencing, raster algebra and visualisation of measurement products; excellent general platform, though careless resampling can create artefacts.
  • HYSPLIT — Atmospheric trajectory and dispersion modelling with archived meteorology; widely accepted, but results depend heavily on the chosen meteorological field and release assumptions.
  • Google Earth Engine — Cloud processing over petabyte satellite archives for time series analysis; removes data handling burden, but the licence restricts some operational and commercial uses.
  • Python scientific stack with xarray and rasterio — Reproducible processing of gridded measurement data with metadata preserved; requires the analyst to implement calibration and uncertainty handling explicitly.
  • InSAR processing tools such as ISCE or MintPy — Produce deformation time series from radar stacks; sensitive to atmospheric phase delay and decorrelation over vegetated terrain.
  • Spectral libraries such as the USGS spectral library — Reference reflectance spectra for material identification; matching requires atmospheric correction and rarely resolves mixtures reliably.
  • Calibrated field instruments with logging — Radiation, gas and acoustic meters producing timestamped records; possession and export of some instruments is licence-controlled, and calibration certificates are mandatory for any evidential use.

AI skills and automation in detail

These are deterministic jobs with defined inputs and outputs, not open-ended prompting. Each is idempotent and cursor-based: interrupt one and it resumes where it stopped rather than duplicating work or losing progress.

  • Score Country Risk — Recomputes country risk from the weighted inputs and snapshots the result so movement over time is measurable.
  • Sync Intel Domains — Refreshes the reference and country-level intelligence datasets from their authorities.
  • Resolve Everything — Batch-resolves ASN, country, org and netblock for every IP from local reference datasets — no API calls, so it runs at millions of rows and works offline.
  • Summarise (Copilot) — Produces a narrative summary beside the underlying records. It explains; it never creates indicators or assigns attribution.
  • Generate Report — Assembles a sourced product from the current case or query, with provenance attached to each element.

A note on the boundary: the only skill that involves a language model is Summarise (Copilot), and it writes prose about records that already exist. Nothing else on this list involves generation of any kind. No indicator, relationship or attribution in the platform originates from a model. See the full skill list.

Tradecraft notes

The distinctions that separate a competent analyst from a fast one:

  • The baseline is the analysis. Almost every false measurement finding comes from an inadequate baseline rather than a bad sensor. Characterise seasonal, diurnal and operational normality before you look at the event, and document the period you used.
  • A non-detection is not an absence. Report the detection limit alongside every negative result, because saying nothing was detected without saying what could have been detected is meaningless and routinely misread as proof that nothing happened.
  • Single-sensor anomalies are usually artefacts. Cloud edges, sun glint, station drift, processing seams and atmospheric phase delay all produce convincing signals. Require an independent phenomenology before an anomaly becomes an event.
  • Colour scales lie. A visualisation with a stretched palette can turn noise into a dramatic plume. Work from numbers with uncertainties, and if you publish an image, publish the scale, the processing chain and the underlying values as well.
  • Meteorology decides plume conclusions more than the measurement does. Two dispersion runs with different meteorological fields can place a source tens of kilometres apart, so state the fields used and present a source region rather than a point.
  • Waveform character distinguishes explosion from earthquake far better than magnitude does. The ratio of body wave to surface wave energy, depth and first motion carry the discrimination, and a magnitude alone supports almost no conclusion about cause.
  • Hazard findings carry a duty to notify. If measurements suggest a radiological, chemical or biological release, the competent authority is told before the client and long before publication, and the notification is recorded.

Measuring whether it is working

Capability claims should be falsifiable. These are the measures that show whether work on Measurement & Signature Intel is producing anything, and they are worth baselining before you change process or tooling.

  • Proportion of reported anomalies confirmed by an independent phenomenology or an independent sensor before dissemination.
  • False positive rate measured against subsequently established ground truth, tracked by phenomenology to expose which sensor types are being over-read.
  • Share of products stating a detection limit and a quantified uncertainty rather than a bare value.
  • Median time from data availability to a delivered assessment, which determines whether the finding can still influence a response decision.
  • Reproducibility rate, measured by whether an independent analyst can recreate the result from the published processing chain and data identifiers.
  • Number of hazard findings notified to a competent authority within the target window, tracked as a safety compliance measure.
  • Baseline coverage, expressed as the proportion of monitored sites with a documented seasonal baseline rather than an ad hoc comparison scene.

Beware of measuring volume alone. Indicator counts and report counts rise easily and say little; time-to-attribution, proportion of findings that survive review, and how often a product changed a decision say a great deal.

Common pitfalls

  • Mistaking sensor artefacts, cloud edges or calibration drift for real anomalies, particularly in automated thermal and spectral products
  • Ignoring seasonal and diurnal baselines, so ordinary agricultural, weather or industrial cycles are reported as significant change
  • Attributing a measured plume to the nearest facility without transport modelling, when the real source may be far upwind
  • Confusing detection limit with absence: most sensors simply cannot see small or shielded sources, and a null result proves little
  • Over-precise reporting of derived quantities whose real uncertainty spans an order of magnitude
  • Treating a single overpass as continuous monitoring when revisit intervals leave large temporal gaps

Legal and ethical considerations

Work from openly published scientific and civil monitoring data, which is designed for public and research use, and honour each provider's licence and attribution terms. Sensor and detector hardware, particularly radiation and specialised spectral equipment, can be export controlled and in some jurisdictions requires possession licensing. Measurements near sensitive sites may be restricted by national security or trespass law; collect only from lawful vantage points. Findings that suggest a radiological or chemical hazard carry a duty to notify competent authorities rather than to publish first.

Data integrity: no fabrication, no drift, no hallucination

Intelligence that cannot be traced back to a source is not intelligence, it is assertion. Everything in this entry — and everything in the platform behind it — is built on a small number of non-negotiable rules.

Provenance on every record

Every indicator carries the source that supplied it, a first-seen and last-seen timestamp, and a sighting count. Where several feeds report the same artifact, each contribution is recorded separately rather than collapsed, so you can see whether a finding rests on one source or twelve. Source attribution travels with the data into every export, so a recipient can audit a claim without asking you for the working.

Nothing is invented to fill a gap

If the platform has no data for Measurement & Signature Intel, it says so. Empty is displayed as empty — never padded with plausible-looking placeholder values, sample records or illustrative examples that a reader might mistake for observations. A dashboard with no rows is a true statement about collection coverage, and it is treated as a gap to close, not a blemish to hide.

Scoring is deterministic and reproducible

Threat scores, reputation grades and risk tiers are computed from stated inputs with fixed weights, not estimated. The same inputs always produce the same output, and the formula is visible rather than a black box. Aggregates are cached with an explicit time-to-live so a figure on screen is never silently stale — and when a heavy query exceeds its time budget the platform serves the last known-good value and labels it, rather than inventing a fresh number or hanging.

Where AI is used, and where it is not

Language models summarise and explain. They do not create indicators, assign attribution or manufacture relationships. No IP address, wallet, hash or identity in the platform originates from a model — every one is ingested from a named feed, resolved from a reference dataset, or entered by an analyst with a source recorded. Copilot output is presented as narrative alongside the underlying records, never in place of them, so a reader can always check the summary against the evidence.

Guarding against drift

Enrichment is additive and timestamped rather than overwriting. Reference data — sanctions lists, allocations, taxonomies — is re-synchronised from the authority on a schedule instead of being edited in place, so local copies cannot quietly diverge from the source of truth. Attribution is recorded with a confidence level and the reporting it rests on, and inferred relationships are labelled as inferred. When a source retracts or corrects, the correction propagates rather than leaving a stale assertion behind.

What this means for you

You can put a finding from this platform in front of a regulator, a court, a board or a partner agency and show where each element came from. That is the standard the tooling is built to — because in this work, being confidently wrong is more damaging than being usefully uncertain.

By the numbers

The taxonomy this entry belongs to is not a marketing list — it is the actual structure of the platform: 52 mission domains, 52 intelligence disciplines and 65 data points, each with a live dashboard behind it. Supporting that: 18 indicator types, 14 playbooks, 16 AI skills, 18 export formats and a 30-step automated pipeline.

This particular entry connects directly to 7 data points, 5 mission domains, 3 closely related entries — every one of them a tag you can follow, and a dashboard you can open.

Questions analysts actually ask

Can I tell an explosion from an earthquake with public seismic data?

Frequently yes, using waveform character rather than magnitude. Explosions are shallow, compressive, rich in high frequency body waves and generate relatively weak surface waves, while tectonic earthquakes usually show deeper hypocentres and stronger surface wave energy. Depth estimates, first motion polarity and the ratio of body to surface wave amplitude are the practical discriminators. Mine collapses show a distinctive implosive signature. The analysis needs waveform data from multiple stations, not just a catalogue entry, and a seismologist should review any conclusion that will be published or used to support an accusation.

How reliable are thermal anomaly detections?

Reliable for detecting that something hot happened, much less reliable for saying what. Products such as VIIRS and MODIS active fire detections carry confidence values, have pixel footprints of hundreds of metres, and can miss small or short events between overpasses. Gas flares, agricultural burning, industrial furnaces and wildfires all produce similar detections. Use the confidence field, check the acquisition time against the claimed event, look for a repeating diurnal or seasonal pattern that indicates routine industry, and corroborate with imagery before attributing a detection to a specific incident.

What can radiation monitoring networks actually detect?

Public networks such as RadNet and the European exchange platform measure gamma dose rate and, at some stations, airborne particulate and specific isotopes. They reliably detect significant releases that reach a station, and they provide the historical baseline needed to say whether a reading is elevated. They will not detect a shielded source, a small localised release that disperses before reaching a monitor, or activity inside a facility. Isotopic identification, which is what distinguishes a reactor release from a medical source or from natural radon, requires spectrometry rather than dose rate alone.

Do I need to declare the uncertainty even when it is large?

Especially then. A measurement without an uncertainty is presented as exact and will be treated as exact by every downstream reader, which is how measurement findings survive into decisions they cannot support. State the value, the error bounds, the detection limit and the main sources of error, and if the uncertainty is wide enough that the finding cannot discriminate between the competing explanations, say so plainly and specify what additional data would narrow it. An honest inconclusive result is a usable product; a falsely precise one is a liability.

Is it lawful to take my own measurements near a facility?

It depends where you stand and what you carry. Measuring from a public road or from land you have permission to use is generally lawful, but trespass, national security site restrictions, airspace rules for drones and local prohibitions on monitoring near critical infrastructure all apply. Some instruments, particularly radiation detectors and specialised spectral equipment, require a possession licence in certain countries and are export controlled to move across borders. Check the local position before travelling with equipment, and never place a sensor on land you do not control.

How do I choose between radar and optical for change detection?

Radar sees through cloud and darkness and measures geometry and moisture, which makes it the right choice for persistent monitoring, deformation, and any region with frequent cloud. Optical and thermal give material and temperature information that radar cannot, and are easier to interpret visually. In practice use radar for reliable revisit and to trigger, then task or retrieve optical and thermal to characterise what the radar flagged. Interferometric radar requires stable scatterers, so it performs poorly over dense vegetation, snow and rapidly changing surfaces.

Who do I notify if I detect a possible hazardous release?

The competent national authority for the hazard type, immediately and before publication or client delivery. For radiological findings that means the national nuclear regulator and, where an international dimension exists, the IAEA incident and emergency system. For chemical events it means the national authority under the Chemical Weapons Convention and civil emergency services. For disease anomalies it means the national public health authority. Record the time, recipient and content of the notification. Publishing first can delay response, endanger people and expose you and your organisation to serious criticism or liability.

Standards, frameworks and further reading

Work that references a recognised framework is easier to defend, easier to hand over, and easier for a partner to consume:

  • Comprehensive Nuclear-Test-Ban Treaty verification regime, which defines the International Monitoring System's seismic, hydroacoustic, infrasound and radionuclide networks and their data policy.
  • IAEA safety standards on environmental radiation monitoring and emergency preparedness, which govern measurement, interpretation and notification of radiological findings.
  • ISO/IEC 17025 on the competence of testing and calibration laboratories, which underpins the admissibility of any measurement offered as evidence.
  • Guide to the Expression of Uncertainty in Measurement, the international reference for calculating and reporting measurement uncertainty.
  • CEOS and WMO calibration and validation practices for earth observation sensors, which define radiometric and geometric calibration expectations.
  • Berkeley Protocol on Digital Open Source Investigations, which sets standards for provenance, preservation and verification when open data supports accountability work.
  • Chemical Weapons Convention verification provisions administered by the OPCW, which frame sampling, analysis and reporting for chemical findings.
  • National environmental monitoring regulations such as EU ambient air quality directives, which define reference methods and data quality objectives for pollutant measurement.

References

Primary sources and authoritative references for this entry. Publishers revise and retire material, so treat the retrieval date as part of the citation and re-check before relying on any of it in a formal product.

  1. Earthquake Hazards Program catalogue and data — US Geological Survey. Authoritative global earthquake catalogue with waveform access and rapid event solutions
  2. International Monitoring System and verification regime — Comprehensive Nuclear-Test-Ban Treaty Organization. Global multi-phenomenology monitoring network for detecting and characterising explosive events
  3. Fire Information for Resource Management System — NASA. Near real time global active fire and thermal anomaly detections with confidence metadata
  4. Copernicus Data Space Ecosystem — European Space Agency and European Commission. Open access to Sentinel radar, optical and atmospheric composition data and processing services
  5. RadNet environmental radiation monitoring — US Environmental Protection Agency. National network measuring ambient radiation with long historical baselines
  6. HYSPLIT atmospheric transport and dispersion model — NOAA Air Resources Laboratory. Trajectory and dispersion modelling system used to link measurements to candidate sources
  7. IAEA safety standards series on radiation monitoring — International Atomic Energy Agency. International guidance on environmental monitoring, interpretation and emergency notification
  8. Berkeley Protocol on Digital Open Source Investigations — UN Office of the High Commissioner for Human Rights and UC Berkeley. Standards for provenance, preservation and analysis of open data used in accountability work
  9. Landsat archive and science products — US Geological Survey and NASA. Five decades of calibrated multispectral and thermal imagery supporting long baselines
  10. Copernicus Atmosphere Monitoring Service products — ECMWF for the European Commission. Global atmospheric composition analyses used for background concentrations and dispersion context

Link integrity: every reference above was verified with a live request when this page was generated. Where a publisher had moved or withdrawn a document, the link was repointed at a preserved copy in the Internet Archive and marked as archived. Anything with no reachable copy anywhere had its link removed rather than left to rot — the source is still credited, it simply cannot be linked.

Put it into practice

The Quantus Intel threat intelligence platform operationalises this entry: ingests public seismic, thermal, spectral and radiation feeds and alerts on baseline deviation at watched sites. Explore the platform, or browse the rest of the library by following any tag above.

Leave a Reply

Your email address will not be published. Required fields are marked *