Environmental Crime: Mission Domain Intelligence Guide
Illegal gold rarely travels as gold. It travels as scrap, as jewellery, as a refinery invoice in a third country. The crime is visible from orbit; the profit is visible in customs data.
Illegal gold rarely travels as gold. It travels as scrap, as jewellery, as a refinery invoice in a third country. The crime is visible from orbit; the profit is visible in customs data.
What Environmental Crime covers as a mission domain
Environmental crime intelligence covers the illicit exploitation of natural resources and the illegal handling of waste and pollutants. In practice this means illegal logging and timber laundering, unlicensed and artisanal mining, illegal unreported and unregulated fishing, hazardous waste dumping and export fraud, and the trade in ozone-depleting substances and refrigerants. The work is unusual because the predicate offence leaves a large physical footprint that remote sensing can detect, while the laundering happens in paperwork: falsified species declarations, mis-stated harvest concessions, mislabelled tariff codes and shell exporters in transhipment jurisdictions.
Sub-areas split between extraction-site investigation, supply chain and trade-data forensics, and corporate ownership work. Actors range from subsistence operators through organised syndicates running dredge fleets and haul-road logistics, to licensed companies laundering illegal volume through legitimate concessions. Corruption is structural: permits, transport documents and export certificates are the chokepoints that get bought, which is why analysts follow the paperwork and the beneficial ownership as hard as the imagery.
Why it matters
Environmental crime is one of the largest illicit economies on the planet and it converges directly with other portfolios. The same routes, brokers and cash-intensive businesses that move illegal timber move narcotics and launder proceeds. Mercury from unlicensed gold recovery poisons river basins used by hundreds of thousands of people, and armed groups in several regions fund themselves entirely from mining and logging rents. Prosecutions depend on evidence that ties a physical site to a specific consignment and a named beneficiary.
What analysts actually look for
These are the concrete, observable signals that carry weight in this area of work:
- GLAD or RADD deforestation alerts forming linear patterns consistent with haul roads rather than the mosaic pattern of smallholder clearing.
- New sediment plumes and turbidity changes downstream of a river reach, a common signature of dredge or hydraulic mining activity.
- Persistent night-time light detections in NASA VIIRS data at locations with no permitted industrial activity or grid connection.
- Export tonnage of a timber species exceeding the plausible harvest capacity of every concession within economic transport range.
- Mirror-trade mismatches in UN Comtrade where the importer records far more volume than the exporter declared for the same code.
- Repeated thermal anomalies at waste sites, indicating illegal burning of material that should have gone through licensed treatment.
- Fishing vessels with AIS gaps that resume transmission inside a protected area boundary or immediately after a transhipment window.
- Newly incorporated exporters with no operating history taking large consignments in a jurisdiction known for certificate fraud.
Where the data comes from
Authoritative and openly available collection points. Always confirm licensing and terms before operational or commercial use:
- Global Forest Watch (GLAD and RADD alerts) — Near-real-time forest loss alerts, concession boundaries and protected area layers for the whole tropics.
- Copernicus Sentinel-1 and Sentinel-2 — Free radar and optical imagery for pit expansion, road construction, tailings ponds and cloud-penetrating change detection.
- NASA FIRMS — Active fire and thermal anomaly detections useful for land clearing, waste burning and flaring at illegal sites.
- Global Fishing Watch — AIS-derived fishing effort, transhipment events, port visits and vessel identity history at no cost.
- CITES Trade Database — Reported trade in listed species by permit, party and purpose, for cross-checking declared legality.
- UN Comtrade — Bilateral trade flows by HS code, enabling mirror-trade analysis and detection of impossible export volumes.
- UNEP and INTERPOL environmental crime reporting — Typologies, seizure case studies and route analysis across waste, timber, minerals and wildlife.
- MAAP (Amazon Conservation) — Published imagery-based monitoring of illegal mining and deforestation hotspots in the Amazon basin.
A working method
A repeatable sequence beats ad-hoc searching. This is a practical starting workflow:
- Fix the commodity and chain — Choose one commodity and map its legal chain end to end: extraction, transport, first processing, export, refining or milling, and final buyer.
- Detect the physical footprint — Run change detection over the target area using alert products first, then confirm with higher-resolution optical or radar imagery.
- Overlay legal geography — Intersect detections with concession boundaries, protected areas, indigenous territories and permit registries to establish whether activity is licensed.
- Interrogate the trade data — Compare declared exports against physical capacity and against importer-side records, isolating codes and corridors that do not balance.
- Resolve the corporate layer — Pull registries, filings and beneficial ownership to link exporters, transporters and buyers, noting nominee directors and recycled addresses.
- Build the evidentiary package — Assemble a timeline tying site imagery to shipment documents and corporate records, preserving provenance and hashes for each artefact.
- Refer and monitor — Route findings to the competent authority or customs partner and keep monitoring the site, since operations typically relocate rather than stop.
How this connects across the intelligence taxonomy
Intelligence work does not respect neat boundaries. The mission domain you are working, the disciplines you practise, and the data points you pivot on are one connected system. These are the direct relationships for this entry — every link is also a tag, so you can follow any thread across the whole library.
Practised with these disciplines
- Environmental Intelligence — Environmental Conditions, Damage, and Crime
- Geospatial Intelligence — Intelligence Derived from Place
- Imagery Intelligence — Interpretation of Visual Imagery
- Meteorological Intelligence — Weather, Ocean, and Atmospheric Conditions
- Legal Intelligence — Law, Litigation, and Regulatory Intelligence
- Criminal Intelligence — Intelligence Supporting Criminal Investigation
Worked in these data points
- Location / Coordinates — A geographic point, place, or region — the basis of GEOINT analysis.
- Satellite Imagery — Overhead imagery of an area of interest, used for change detection and site analysis.
- Facility / Site — A physical installation — plant, base, port, data centre — with a fixed footprint and function.
- Company / Organization — A legal entity — corporation, LLC, NGO, or business.
- Event / Incident — A discrete real-world occurrence — protest, strike, breach, seizure — with time, place, and actors.
- GPS Coordinates — Precise latitude/longitude coordinates identifying an exact point on Earth — the atomic unit of GEOINT analysi
- Image / Photograph — A still image — carries EXIF metadata and is the primary artifact for visual verification.
Adjacent mission domains
- Wildlife Trafficking
- Mining & Resource Crime
- Climate Security
- Water Security
- Food & Agricultural Security
- Maritime Security
Inside the platform: where Environmental Crime lives
The Quantus platform is 204 pages behind a 147-item sidebar organised into six working groups: Command (24 items), Dashboards (15), Threat Theaters (14), Intelligence Domains (15), Investigate (34), and Administration (45). This entry is not a page in isolation — it is a thread running through several of them.
The modules that matter most here:
domain.php?d=env— Environmental Crime dashboardtheater.php?d=env— Threat theater viewsearch.php— Company / Organization profilecorrelate.php— Correlation graphcases.php— Case management
Each dashboard is local-first: it renders from the platform’s own database rather than depending on a live third-party call, so it still works when an upstream API is unreachable or rate-limited. Heavy aggregates are cached with a hard query time cap and degrade to the last good value instead of hanging the page.
Automation, playbooks and AI skills
Analysis that only happens when someone remembers to run it is not a capability. The platform ships a 30-step automation pipeline (cron.php) that collects, ingests, resolves, enriches, correlates and scores on a schedule — 25 seeders, 11 resolvers and 7 enrichment runners, all idempotent and cursor-based so a run can be interrupted and resumed without duplicating or losing work.
Relevant playbooks
Of the 14 incident playbooks in playbooks.php, these apply directly to Environmental Crime:
- Sanctions Screening & Escalation — a step-checked workflow with the pivots, sources and handling rules already wired in.
AI skills that apply
The 16 one-click operations in ai-skills.php are deterministic jobs, not free-text generation. The ones that matter here:
- Threat Hunt
- Correlate Infrastructure
- Run Alert Rules
- Summarise (Copilot)
- Generate Report
Alerting closes the loop: rules in alerts.php fire on new indicators matching a saved query, so a first sighting in this area raises a notification rather than waiting to be noticed at the next review.
Feeds, data sources and the API
The collection layer runs a feed registry of free, machine-readable sources — bulk blocklists and trackers (Maltrail, IPsum, FireHOL, the full abuse.ch corpora, phishing databases, Emerging Threats, Spamhaus, DigitalSide, ThreatView), authoritative government feeds (CISA KEV, OFAC, UN and EU sanctions lists), and reference datasets (RIR allocations, ip-to-ASN and geolocation tables, MITRE ATT&CK, EPSS). collect.php pulls them server-side on a schedule; feeds.php and source-catalog.php show what is registered, what it covers and when it last ran.
Anything the platform holds is reachable programmatically. The REST API in api.php exposes 11 endpoints — status, stats, search, lookup, recent, export, bulk_check, top_threats, by_category, categories, check — and export.php streams 18 formats in bounded chunks, so a million-row export neither exhausts memory nor times out:
STIX 2.1, MISP, OpenIOC 1.1, CEF (ArcSight), LEEF 2.0 (QRadar), Zeek/Bro intel, Snort/Suricata rules, Palo Alto EDL, BIND RPZ, hosts blackhole, iptables, CSV, JSON, NDJSON/JSONL, XML.
That covers the CTI standards (STIX 2.1, MISP, OpenIOC), SIEM ingestion (CEF, LEEF, Zeek), detection engines (Snort/Suricata), and direct enforcement (Palo Alto EDL, BIND RPZ, hosts, iptables) — so intelligence developed here can be actioned in the tools you already run, without a manual reformatting step. A TAXII 2.1 server and a MISP/RSS feed are also served for pull-based sharing.
Use cases
Three ways this entry earns its keep in day-to-day work:
- Triage under time pressure. An artifact or report lands and you need a defensible read in minutes, not days. Fix the commodity and chain is the first move; the platform pre-computes the enrichment so the analyst spends the time on judgement rather than lookups.
- Building the picture. A single indicator is rarely the story. Overlay legal geography turns one artifact into a network — shared infrastructure, repeated selectors, the same operator behind different names — via the correlation graph and the cross-entity link engine.
- Producing something actionable. Analysis that ends in a document nobody can use is wasted. Refer and monitor feeds the case file, the detection rule, the block list or the referral — with sourcing attached so the recipient can verify it.
Case management (cases.php), watchlists, saved searches and scheduled reports mean the work persists between sessions and survives an analyst leaving the team.
How each sector uses Environmental Crime
The same entry is worked very differently depending on who you are, what authority you hold, and what you are ultimately producing. A military analyst is supporting a commander’s decision; a journalist is meeting a publication standard; an NGO caseworker is protecting a person. The underlying artifacts are shared — the constraints, outputs and thresholds are not.
🎖 Military and defence
Defence interest in environmental crime is indirect but real: illegal mining and logging economies finance armed groups, dredge fleets and haul roads change trafficability, and resource sites generate the local grievance that shapes an operating environment. Analysts use site detection to map non-state revenue, to identify airstrips and river ports serving illicit extraction, and to support partner-nation capacity building and interdiction planning. Products feed the civil dimension of intelligence preparation of the environment and force protection assessments where units operate near contested extraction. The constraint is jurisdictional: environmental crime is a law enforcement matter in most contexts, so military analysis should hand off to civil authorities with evidence handled to their standard.
🕵 National intelligence
National intelligence treats environmental crime as a convergence problem: the same corridors, corrupt officials and financial channels carry timber, gold, wildlife, narcotics and sanctioned goods. Requirements typically focus on revenue reaching designated groups, corruption at permit and export chokepoints, and the third-country refineries and traders that launder volume. Fusion combines commercial and open imagery, trade statistics, corporate registries and liaison reporting. Because much of the evidence is open, maintain an unclassified tearline that can pass to customs, financial intelligence units and environmental regulators. Dissemination should identify the specific chokepoint a policy tool could act on rather than describing the scale of the problem.
👮 Law enforcement
Investigators build environmental crime cases around documents rather than around the pit or the stump. Imagery establishes that extraction occurred at a place and time; the offence is usually proved through falsified permits, transport documents, species declarations and export certificates. Lawful process is required for company records, customs entries and banking material, often across borders through mutual legal assistance. Preserve imagery with full acquisition metadata, capture registry pages with hashes and timestamps, and document analyst methodology so a change-detection finding survives challenge. Charging decisions frequently rest on documentary fraud, tax and money laundering offences, which carry heavier sentences than the environmental predicate.
🔍 Private investigation and corporate security
Corporate security and due diligence practitioners use this domain for supply chain integrity: verifying that timber, minerals, seafood or scrap entering a client supply chain came from a lawful source. Work centres on concession verification, chain of custody audit, beneficial ownership resolution of suppliers and intermediaries, and screening of transhipment jurisdictions. Private actors may not conduct covert surveillance of communities near extraction sites, may not access non-public government systems, and should never pay officials for information. Findings implicating criminality belong with client legal counsel and, where reporting duties apply, with regulators or financial intelligence units, not with private enforcement.
📰 Journalism and OSINT media
For journalists the strength of this domain is that the physical evidence is public. Verification requires independent geolocation of every site, dated imagery sequences rather than single frames, and corroboration of the trade layer through customs data or corporate records before any laundering claim. Local sources carry serious risk, because environmental defenders and whistleblowers are among the most frequently killed source categories, so protect identities aggressively and treat publication timing as a safety variable. Give named companies and officials a genuine right of reply, and be precise about the difference between a licensed operator with irregularities and an organised criminal enterprise.
🌍 NGO, humanitarian and human rights
Environmental and human rights organisations document harm to communities as well as ecosystems: displacement, mercury contamination, forced labour at remote sites and violence against defenders. Practice should be victim centred and consent based, with particular care around indigenous communities where free, prior and informed consent applies. Do-no-harm requires assessing whether publishing a site location exposes a community to reprisal or invasion. Documentation intended for accountability should follow open-source investigation standards so it can support litigation or treaty body submissions later. Duty of care to field monitors is critical, since defenders in this space face intimidation, criminalisation and lethal violence.
🎓 University and research
Research typically pairs remote sensing of extraction footprints with trade and corporate data, and the methodological risk is inference from footprint to legality, which imagery alone can never establish. Publish classification methods, validation samples and accuracy statistics, and treat concession boundary data as uncertain rather than authoritative. Ethics review applies whenever fieldwork touches communities or workers at sites, and increasingly to publication of precise site coordinates. Share code and derived layers under open licences where possible, respect the terms of licensed trade datasets, and cite the exact vintage of concession registers and trade statistics, which are revised frequently and quietly.
Playbook: working Environmental Crime end to end
A repeatable sequence, from the moment the requirement lands to the moment a product is delivered and the case is closed out. Each phase states what you are trying to establish, not merely what to click — the point is a defensible chain of reasoning, not a checklist.
Phase 1 — Frame the commodity chain
Write the chain from extraction to end market before touching data: site, primary transport, aggregation point, processing or refining, export documentation, transhipment jurisdiction, importer and final buyer. Mark which stages leave a physical footprint and which leave only paper. This determines where imagery is useful and where the case will actually be made. A good output is a chain diagram with the evidence type available at each node and the authority responsible for it. Stop when every node has an identified source or an explicit gap.
Phase 2 — Baseline the concession and permit picture
Assemble the legal layer: concession boundaries, mining and logging titles, protected area boundaries, indigenous territories, and the permits and quotas issued. Treat these registries as imperfect, since boundaries move, titles are backdated and digital registers lag paper decisions. Record the vintage of every layer. A good output is a legality basemap showing where extraction would be lawful, unlawful or ambiguous. Stop when you can state, for any point on the map, what the permit position is and how confident you are in it.
Phase 3 — Run automated site detection
Subscribe to forest disturbance alerts and set change-detection routines over mining basins, river reaches and coastal areas of interest. Radar alerts matter more than optical in cloudy tropics, where optical archives are effectively blind for months. Filter alerts against the legality basemap so effort concentrates on unlawful and ambiguous areas. A good output is a triaged alert queue with location, date range, area affected and legality status. Stop tuning sensitivity once false positives fall below the level your analysts can actually review.
Phase 4 — Confirm and characterise the site
For prioritised alerts, pull higher resolution imagery and characterise the operation: pit or dredge count, pond geometry indicating mercury or cyanide processing, haul road grade and destination, camp size, airstrip or river port presence, and equipment scale. Scale reveals actor type, since an excavator fleet and a graded haul road imply financing and logistics rather than subsistence activity. A good output is a site dossier with dated imagery, measurements and an actor-scale assessment. Stop when you can defend the characterisation to a non-specialist.
Phase 5 — Move to the trade layer
Take the commodity and look for the laundering signature in trade statistics: mirror discrepancies where the importer reports far more than the exporter, tariff code shifts that reclassify raw material as scrap or manufactured goods, and volumes exceeding plausible domestic production. Compare declared species and origin against biological and geological plausibility. A good output is a documented anomaly with both sides of the mirror and the alternative explanations tested. Stop when the anomaly persists across at least two years and survives valuation and reporting-lag checks.
Phase 6 — Resolve the corporate layer
Identify exporters, importers, traders and refiners from customs records and company registries, then resolve ownership and control through beneficial ownership filings, entity identifiers, litigation records and procurement databases. Watch for the standard pattern where a licensed company with a small legitimate concession exports volumes it could not possibly have produced. A good output is an entity graph with sourced ownership links and dates. Stop when the chain either reaches a natural person or hits an opaque jurisdiction you can document as a wall.
Phase 7 — Follow the paperwork chokepoints
Establish which documents were required at each border and which chokepoint was corrupted: harvest certificate, transport permit, phytosanitary or CITES certificate, certificate of origin, customs declaration. Identify the agents and brokers whose signature the chain depended on. Financial tracing normally requires lawful process, so for open work stop at the documented paper chain and refer. A good output is a chokepoint map showing where a control failed and who owned it. Stop before speculating about individual corruption without documentary support.
Phase 8 — Assess community and defender harm
Record the human consequences: displacement, contamination of water and fish, coerced or child labour at remote sites, and violence or criminalisation directed at defenders and journalists. This layer is often the most legally significant and the most dangerous to collect. Work through trusted local partners with informed consent, and assess whether publication of coordinates would expose the community. A good output is a documented harm annex with consent status recorded per source. Stop collecting the moment a source indicates elevated risk.
Phase 9 — Build the referral package
Assemble material an authority can act on: dated imagery with acquisition metadata, the legality basemap, trade anomaly tables with source citations, the entity graph, and a clear statement of methodology and its limits. Separate observation from inference explicitly. Identify the correct recipient, which may be a customs authority, an environmental regulator, a financial intelligence unit or a multilateral secretariat rather than a police force. A good output is a package a non-analyst prosecutor can read in twenty minutes. Stop when the package can be understood without the analyst present.
Phase 10 — Monitor for displacement and rebound
After enforcement, watch for the operation moving rather than stopping: new alerts in adjacent basins, a change in transhipment jurisdiction, a renamed exporter with the same address or directors, and a tariff code shift. Displacement is the normal outcome of a single successful action, so build the follow-on watch into the original tasking. A good output is a standing watch list of adjacent geographies and successor entities. Stop when the watch has run at least two full seasons without recurrence.
The platform ships this as a step-checked workflow in playbooks.php, so progress is recorded against a case rather than held in someone’s head.
Source register: what to collect from, and how
Sources are listed with their access model so you can plan around cost and licensing before you build a dependency on them. Open means no account required; registration means a free account or API key; licensed means paid or institutional access. Always confirm current terms — licensing changes, and a source that was free for research may not be free for commercial or evidential use.
| Source | Access | What it gives you | How it is used here |
|---|---|---|---|
| Global Forest Watch | Open | Forest loss and disturbance alerts including radar-based alerts that see through cloud, with concession and protected area overlays. | Primary trigger for illegal logging and mining detection in tropical basins where optical imagery is frequently obscured. |
| Copernicus Data Space Ecosystem | Registration | Sentinel-1 radar and Sentinel-2 optical archives, free, with revisit measured in days at ten metre resolution. | Confirms and dates alerts, measures pit and pond area, and tracks haul road extension over successive passes. |
| NASA FIRMS | Open | Near-real-time active fire and thermal anomaly detections from VIIRS and MODIS with location, time and confidence values. | Detects land clearing burns, charcoal production and flaring associated with illicit extraction and processing. |
| Global Fishing Watch | Registration | Vessel-reported positions processed into apparent fishing effort, encounters, loitering and port visits with vessel identity attributes. | Detects unreported fishing in closed areas, at-sea transhipment and vessels operating without visible authorisation. |
| CITES Trade Database | Open | Reported imports and exports of listed species by party, taxon, term, purpose and source code, spanning decades. | Reveals declaration mismatches between exporter and importer and implausible source codes on wildlife and timber trade. |
| UN Comtrade | Registration | Bilateral merchandise trade statistics by commodity code, reporter, partner, quantity and value, with known reporting lags. | Mirror analysis exposing volumes that exceed plausible domestic production or that appear only on the import side. |
| MAAP monitoring of the Andean Amazon | Open | Case-level imagery analysis of deforestation, illegal gold mining and road building across Amazonian countries. | Provides validated site examples and methodology benchmarks for mining and logging detection in the region. |
| UNEP environmental rule of law and crime reporting | Open | Assessments of environmental crime typologies, convergence with other crime types and enforcement capacity gaps. | Frames actor models and identifies which chokepoints enforcement has historically been able to act on. |
| OpenCorporates | Registration | Company registration, officer and filing data aggregated across many jurisdictions, with variable depth and update frequency. | Resolves exporters, importers and traders into entities and directors before beneficial ownership work begins. |
| Global Legal Entity Identifier Foundation | Open | Reference data linking legal entities to LEI codes with parent and child relationship records where reported. | Confirms corporate identity across jurisdictions and exposes group structures behind trading companies. |
| FAO forestry and fisheries statistics | Open | National production, trade and capacity statistics for forestry and fisheries with methodological documentation. | Establishes plausible production ceilings for a country against which suspicious export volumes and declared harvest figures are tested. |
| Basel Convention reporting and notifications | Open | National reporting and consent records on transboundary movement of hazardous and other wastes under prior informed consent. | Identifies waste export streams leaving a consenting jurisdiction with no matching consent at arrival. |
| INTERPOL environmental security reporting | Open | Operational reporting and assessments on wildlife, forestry, fisheries and pollution crime networks and international operations. | Supplies known typologies, network structures and enforcement precedent to test against your own entity graph. |
| OCCRP investigative archive | Open | Published cross-border investigations documenting front companies, laundering routes and corruption in resource supply chains. | Cross-references named intermediaries, front companies and jurisdictions already documented, saving weeks of duplicated corporate resolution work. |
Prefer sources that publish a methodology and a revision history. A dataset that changes silently is a liability in any product that has to survive challenge.
Tooling
Tools commonly used against Environmental Crime. None of these replace judgement, and each carries its own failure modes — know what a tool infers versus what it observes.
- QGIS with satellite plugins — Site measurement, concession overlay and change mapping. Free and flexible, though large radar stacks strain it and results depend on careful projection handling.
- Google Earth Pro — Historical imagery timeline for rapid site history and simple area measurement. Coverage and acquisition dates are uneven, especially in remote basins.
- ESA SNAP — Sentinel-1 radar processing including coherence change detection that works through cloud. Steep learning curve and heavy processing requirements.
- OpenRefine — Reconciles company names and commodity descriptions across customs and registry data. Good for entity clustering, no help with legal interpretation.
- Aleph — Cross-corpus search over registries, leaks and public filings for exporter and owner resolution. Coverage is biased toward already-investigated jurisdictions.
- Maltego — Visualises entity and ownership relationships from mixed sources. Persuasive graphs can outrun the sourcing, so every edge needs a citation attached.
- Python with pandas — Mirror trade analysis, unit reconciliation and anomaly detection at scale. Requires disciplined handling of commodity code revisions between years.
- Hunchly — Timestamped, hashed capture of registry and portal pages that change or disappear. Captures rendered pages only, so API data needs separate preservation.
AI skills and automation in detail
These are deterministic jobs with defined inputs and outputs, not open-ended prompting. Each is idempotent and cursor-based: interrupt one and it resumes where it stopped rather than duplicating work or losing progress.
- Threat Hunt — Runs saved hypotheses against the corpus and surfaces what matches, with the query preserved as a versioned artifact.
- Correlate Infrastructure — Builds the cross-entity link graph: shared hosting, reused certificates, overlapping registrants, repeated selectors.
- Run Alert Rules — Evaluates saved rules against new data so a first sighting raises a notification rather than waiting for review.
- Summarise (Copilot) — Produces a narrative summary beside the underlying records. It explains; it never creates indicators or assigns attribution.
- Generate Report — Assembles a sourced product from the current case or query, with provenance attached to each element.
A note on the boundary: the only skill that involves a language model is Summarise (Copilot), and it writes prose about records that already exist. Nothing else on this list involves generation of any kind. No indicator, relationship or attribution in the platform originates from a model. See the full skill list.
Tradecraft notes
The distinctions that separate a competent analyst from a fast one:
- Imagery proves disturbance, never illegality. The legal finding comes from the permit layer and the paperwork, so build the legality basemap before triaging alerts or you will generate confident nonsense at scale.
- In cloudy tropics, optical archives create a false sense of stability for months at a time. Radar-based alerting is the operative sensor, and any seasonal pattern in your detections should be checked against cloud statistics first.
- The most productive anomaly in trade data is a mirror discrepancy that persists across years and survives valuation and lag checks. One-year gaps are usually reporting artefacts and will embarrass you if published as laundering.
- Equipment scale is the cheapest actor discriminator available. Hand tools and small pits mean subsistence operators; excavator fleets, graded haul roads and processing ponds mean financed organisation with logistics and protection arrangements.
- Follow the certificate, not the commodity. Harvest permits, certificates of origin and species declarations are the chokepoints that get bought, and they are where the documentary fraud case actually lives.
- Expect displacement rather than cessation after enforcement. Build the adjacent-basin watch and the successor-entity check into the original tasking, because the same directors reappear at the same address under a new name within months.
- Site coordinates are dual use. Publishing them can trigger invasion of an indigenous territory or reprisals against the community that reported the activity, so treat precise location as a controlled field.
Measuring whether it is working
Capability claims should be falsifiable. These are the measures that show whether work on Environmental Crime is producing anything, and they are worth baselining before you change process or tooling.
- Proportion of triaged alerts that survive confirmation imagery and legality checks, showing the queue is getting more precise rather than merely larger.
- Median time from first disturbance alert to a referral-ready site dossier, measured in days across the reporting period.
- Number of referrals accepted by customs, regulators or prosecutors, and the proportion that progress to formal action.
- Share of trade anomalies that survive valuation, lag and code-revision checks, as a direct measure of analytic discipline.
- Recurrence rate at previously actioned sites after twelve months, which measures whether enforcement displaced or stopped the operation.
- Percentage of published site findings carrying complete acquisition metadata and documented methodology sufficient for evidential use.
- Count of successor entities identified after a named exporter was actioned, showing whether the corporate watch is functioning.
Beware of measuring volume alone. Indicator counts and report counts rise easily and say little; time-to-attribution, proportion of findings that survive review, and how often a product changed a decision say a great deal.
Common pitfalls
- Cloud cover and canopy regrowth make optical-only monitoring unreliable in the tropics; pair every optical read with radar.
- Alert products flag change, not legality. Licensed clearing and legitimate mining generate identical pixels to criminal operations.
- Trade mismatches often reflect valuation, timing lags or code differences between customs regimes rather than laundering.
- Attribution to a company from imagery alone is weak. Sites change hands informally and contractors operate under several names.
- Artisanal operators are frequently the visible layer above a financing and buying network that never appears near the site.
- Publishing precise coordinates of an active site can endanger local monitors, rangers and communities before enforcement arrives.
Legal and ethical considerations
Chain of custody governs whether your work survives court. Preserve imagery provenance, acquisition dates and processing steps, and record where each trade or registry record came from. Naming companies invites defamation exposure in several jurisdictions, so distinguish carefully between what the data shows and what you infer. Coordinates of active sites, informant identities and ranger positions must be handled as protected information. Where indigenous or community land is involved, consent and local partner safety should govern publication timing.
Data integrity: no fabrication, no drift, no hallucination
Intelligence that cannot be traced back to a source is not intelligence, it is assertion. Everything in this entry — and everything in the platform behind it — is built on a small number of non-negotiable rules.
Provenance on every record
Every indicator carries the source that supplied it, a first-seen and last-seen timestamp, and a sighting count. Where several feeds report the same artifact, each contribution is recorded separately rather than collapsed, so you can see whether a finding rests on one source or twelve. Source attribution travels with the data into every export, so a recipient can audit a claim without asking you for the working.
Nothing is invented to fill a gap
If the platform has no data for Environmental Crime, it says so. Empty is displayed as empty — never padded with plausible-looking placeholder values, sample records or illustrative examples that a reader might mistake for observations. A dashboard with no rows is a true statement about collection coverage, and it is treated as a gap to close, not a blemish to hide.
Scoring is deterministic and reproducible
Threat scores, reputation grades and risk tiers are computed from stated inputs with fixed weights, not estimated. The same inputs always produce the same output, and the formula is visible rather than a black box. Aggregates are cached with an explicit time-to-live so a figure on screen is never silently stale — and when a heavy query exceeds its time budget the platform serves the last known-good value and labels it, rather than inventing a fresh number or hanging.
Where AI is used, and where it is not
Language models summarise and explain. They do not create indicators, assign attribution or manufacture relationships. No IP address, wallet, hash or identity in the platform originates from a model — every one is ingested from a named feed, resolved from a reference dataset, or entered by an analyst with a source recorded. Copilot output is presented as narrative alongside the underlying records, never in place of them, so a reader can always check the summary against the evidence.
Guarding against drift
Enrichment is additive and timestamped rather than overwriting. Reference data — sanctions lists, allocations, taxonomies — is re-synchronised from the authority on a schedule instead of being edited in place, so local copies cannot quietly diverge from the source of truth. Attribution is recorded with a confidence level and the reporting it rests on, and inferred relationships are labelled as inferred. When a source retracts or corrects, the correction propagates rather than leaving a stale assertion behind.
What this means for you
You can put a finding from this platform in front of a regulator, a court, a board or a partner agency and show where each element came from. That is the standard the tooling is built to — because in this work, being confidently wrong is more damaging than being usefully uncertain.
By the numbers
The taxonomy this entry belongs to is not a marketing list — it is the actual structure of the platform: 52 mission domains, 52 intelligence disciplines and 65 data points, each with a live dashboard behind it. Supporting that: 18 indicator types, 14 playbooks, 16 AI skills, 18 export formats and a 30-step automated pipeline.
This particular entry connects directly to 6 intelligence disciplines, 7 data points, 6 closely related entries — every one of them a tag you can follow, and a dashboard you can open.
Questions analysts actually ask
Can satellite imagery prove illegal logging or mining?
It proves that a physical change happened at a location within a date range, and it can measure area, equipment scale and transport infrastructure. It cannot prove legality, because that depends on permits, concession boundaries, quota limits and dates that exist only on paper. The defensible workflow is to establish the legal layer first, then use imagery to show disturbance inside an area where extraction is prohibited or beyond a permitted volume. Present imagery findings with sensor, resolution, acquisition dates and cloud conditions, and state clearly which part of the conclusion is observation and which is inference.
What is a mirror discrepancy and when is it meaningful?
A mirror discrepancy is a gap between what an exporting country reports shipping and what importing countries report receiving of the same commodity. It becomes meaningful when it persists across multiple years, exceeds plausible valuation and timing differences, and cannot be explained by transhipment recorded elsewhere, commodity code revisions or reporting lags. Single-year gaps are usually artefacts. When the discrepancy survives those checks and coincides with detected extraction beyond permitted volumes, you have a documented laundering indicator worth referring. Always publish both sides of the mirror and name the checks you performed.
Why does the case usually end up being about documents rather than the environment?
Because documentary and financial offences are easier to prove and carry heavier penalties. Environmental predicates often attract modest fines and require technical proof of harm, while falsified certificates of origin, false customs declarations, tax evasion and money laundering are well-established offences with clear evidential paths. Investigators therefore build outward from the paperwork chokepoints: who signed the harvest permit, who certified the species, who declared the tariff code. Analysts should collect with that end in mind, preserving registry and customs records properly rather than assuming imagery will carry the case.
How do I handle risk to local sources and defenders?
Treat it as the dominant constraint, not a footnote. Environmental defenders and community whistleblowers are killed at high rates, and criminalisation through spurious litigation is routine. Work through established local organisations rather than direct outreach, obtain informed consent that explains publication consequences, use secure communications, and hold identifying material separately with strict access control. Consider publication timing and site-level detail as safety variables, since precise coordinates can trigger invasion or reprisal. If a source signals elevated risk, stop collecting and prioritise their protection over the investigation.
How do I tell an organised operation from artisanal activity?
Look at capital and logistics rather than at the pit. Artisanal activity shows hand tools, small dispersed workings, footpaths and camps that appear and vanish seasonally. Organised operations show excavator or dredge fleets, graded haul roads engineered for loaded trucks, fuel storage, processing ponds with regular geometry, permanent camp structures, and often an airstrip or river port. Persistence through the wet season is another discriminator because it implies financing. State the indicators you relied on, since actor characterisation determines whether the response is livelihoods policy or organised crime enforcement.
Which authority should receive a referral?
Rarely the police first. Map the chokepoint you documented to the body that owns it: customs and border agencies for declaration fraud and tariff misclassification, environmental regulators for permit and concession breaches, fisheries authorities and flag or port states for illegal fishing, financial intelligence units for laundering indicators, and CITES management authorities for listed species. Multilateral secretariats can act where national authorities are compromised. Send a package a non-specialist can read quickly, with observation separated from inference and full provenance for every image and document.
Standards, frameworks and further reading
Work that references a recognised framework is easier to defend, easier to hand over, and easier for a partner to consume:
- Convention on International Trade in Endangered Species, which governs permits and certificates for listed species and defines the declaration data used in trade analysis.
- Basel Convention on transboundary movement of hazardous wastes, which sets the prior informed consent requirements that waste export fraud circumvents.
- UN Convention against Transnational Organized Crime and its protocols, which supply the organised crime, laundering and mutual legal assistance framework for these cases.
- UN Convention against Corruption, which governs bribery of permit and customs officials sitting at the centre of most laundering chains.
- FATF standards and typologies on environmental crime proceeds, which shape financial intelligence reporting expectations for banks and traders.
- EU Deforestation Regulation and equivalent timber legality regimes, which impose due diligence and geolocation evidence duties on importers.
- OECD Due Diligence Guidance for Responsible Supply Chains of Minerals from Conflict-Affected and High-Risk Areas, which defines the corporate standard of care.
- Berkeley Protocol on Digital Open Source Investigations, which sets preservation and verification standards for imagery and web evidence in accountability work.
References
Primary sources and authoritative references for this entry. Publishers revise and retire material, so treat the retrieval date as part of the citation and re-check before relying on any of it in a formal product.
- Global Forest Watch — World Resources Institute. Forest disturbance alerting platform with concession and protected area layers
- CITES Trade Database — CITES Secretariat and UNEP-WCMC. Reported trade in listed species used for declaration mismatch analysis
- UN Comtrade database — United Nations Statistics Division. Bilateral merchandise trade statistics used for mirror analysis
- Global Fishing Watch platform — Global Fishing Watch. Vessel behaviour analytics used for illegal fishing detection
- World Wildlife Crime Report — UN Office on Drugs and Crime. Assessment of wildlife and forest crime markets and trafficking routes
- Environmental security programme reporting — INTERPOL. Operational reporting on environmental crime networks and international operations
- Environmental rule of law and crime assessments — UN Environment Programme. Assessments of environmental crime scale, convergence and enforcement gaps
- MAAP project reports — Amazon Conservation. Imagery-based case studies of illegal mining, logging and road building
- Legal Entity Identifier reference data — Global Legal Entity Identifier Foundation. Open corporate identity and parent relationship data for supply chain resolution
Link integrity: every reference above was verified with a live request when this page was generated. Where a publisher had moved or withdrawn a document, the link was repointed at a preserved copy in the Internet Archive and marked as archived. Anything with no reachable copy anywhere had its link removed rather than left to rot — the source is still credited, it simply cannot be linked.
Put it into practice
The Quantus Intel threat intelligence platform operationalises this entry: alert-driven site monitoring fused with trade-data forensics and corporate resolution into referral-ready evidence packages. Explore the platform, or browse the rest of the library by following any tag above.