August 7, 2026

Military & Defense: Mission Domain Intelligence Guide

0

Order of battle used to be a classified product. Now a unit’s deployment is visible from insignia in a soldier’s photograph, a lorry column on commercial imagery, and a procurement notice for cold-weather boots.

military-and-defense-mission-domain-guide

Order of battle used to be a classified product. Now a unit's deployment is visible from insignia in a soldier's photograph, a lorry column on commercial imagery, and a procurement notice for cold-weather boots.

What Military & Defense covers as a mission domain

Military and defence intelligence covers the capabilities, posture, procurement and activity of state armed forces and organised armed groups, assessed from open and commercial sources for analytical, protective and accountability purposes. It includes order-of-battle and unit tracking, equipment inventories and attrition, defence-industrial capacity and supply chains, arms transfers and export licensing, exercise and readiness patterns, base and infrastructure development, and defence budget analysis. In a civilian intelligence context the aim is understanding risk to people, operations and assets, and supporting accountability for how force is used.

The tradecraft draws on satellite and aerial imagery, transponder data from vessels and aircraft, commercial trade and customs records, procurement portals, official budget documents, state media and geolocated user-generated content. Analysts work at three levels: strategic, covering doctrine, budgets and industrial base; operational, covering formations, logistics and readiness; and technical, covering specific platforms, munitions and the physical features that identify them in imagery and debris.

Why it matters

Accurate open-source military analysis underpins early warning of conflict, protects humanitarian and commercial operations in contested areas, and supplies the evidentiary base for arms-transfer accountability and international humanitarian law investigations. Poor analysis carries real cost: overstated capability drives escalation and misallocated resources, while understated capability leaves populations and organisations unprepared. Documenting which weapon systems were used in specific strikes has become central to modern accountability work.

What analysts actually look for

These are the concrete, observable signals that carry weight in this area of work:

  • Sustained increase in rail and road movement of armoured vehicles toward a border region, visible in imagery and corroborated by local reporting.
  • Field hospital, fuel bladder and ammunition storage construction near a staging area, which precedes movement more reliably than vehicles do.
  • Procurement notices for blood products, body bags, ration packs or winter kit at volumes inconsistent with routine replenishment cycles.
  • Transport aircraft flying with transponders off on repeated routes between a supplier state and a specific recipient airfield.
  • Unit insignia, tactical markings and vehicle serial numbers in imagery that place a named formation at a new location.
  • Weapon fragment markings, including lot numbers, factory codes and fuze types, that tie munitions used to a manufacturer and transfer chain.
  • Changes in exercise tempo, cancellation of leave, or reserve call-up notices published in official gazettes and regional orders.
  • New hardened shelters, revetments or runway extensions at an airbase, with dispersal patterns implying an anticipated threat.

Where the data comes from

Authoritative and openly available collection points. Always confirm licensing and terms before operational or commercial use:

  • SIPRI Arms Transfers Database — Quantified international transfers of major conventional weapons by supplier, recipient and year.
  • UN Register of Conventional Arms — State-declared imports and exports across the major categories of conventional weapons.
  • IISS Military Balance — Reference inventories, personnel figures and defence economics compiled by country and service.
  • ACLED and UCDP — Georeferenced conflict event data with actor coding, supporting activity and intensity analysis.
  • Conflict Armament Research — Field documentation of weapons and components recovered in conflict zones, with transfer-chain tracing.
  • Copernicus Sentinel and commercial satellite imagery — Free and paid Earth observation supporting facility, movement and damage analysis over time.
  • National arms export reports and the EU annual report — Licence approvals, denials and values by destination and equipment category.
  • Government procurement portals and defence budget documents — Contract awards, quantities and delivery schedules revealing actual programme progress.

A working method

A repeatable sequence beats ad-hoc searching. This is a practical starting workflow:

  1. Define the intelligence question — State what decision the assessment supports, whether evacuation, insurance, forecasting or accountability, because that sets the evidentiary standard.
  2. Build the baseline order of battle — Compile known formations, equipment and garrisons from reference sources before attempting to detect any change.
  3. Collect and geolocate — Gather imagery, transponder data and user-generated content, geolocating and chronolocating each item independently of its caption.
  4. Verify before integrating — Check for recycled, mislabelled or synthetic media, confirming shadows, terrain, signage and metadata consistency.
  5. Separate capability from intent — Distinguish what a force can do from what indicators suggest it will do, and state confidence separately for each.
  6. Track logistics as the leading indicator — Prioritise fuel, ammunition, medical and transport signals, which change earlier and more reliably than combat formations.
  7. Publish with source discipline — Document every geolocation and identification so the assessment can be independently reproduced and challenged.

How this connects across the intelligence taxonomy

Intelligence work does not respect neat boundaries. The mission domain you are working, the disciplines you practise, and the data points you pivot on are one connected system. These are the direct relationships for this entry — every link is also a tag, so you can follow any thread across the whole library.

Practised with these disciplines

Worked in these data points

  • Facility / Site — A physical installation — plant, base, port, data centre — with a fixed footprint and function.
  • Aircraft — An aircraft identified by tail number, ICAO hex, or registration.
  • Vessel / Ship — A maritime vessel identified by IMO, MMSI, or call sign.
  • Satellite Imagery — Overhead imagery of an area of interest, used for change detection and site analysis.
  • GPS Coordinates — Precise latitude/longitude coordinates identifying an exact point on Earth — the atomic unit of GEOINT analysi
  • Radio Callsign — A licensed radio identifier for a station, vessel, aircraft, or operator.
  • Event / Incident — A discrete real-world occurrence — protest, strike, breach, seizure — with time, place, and actors.

Adjacent mission domains

Inside the platform: where Military & Defense lives

The Quantus platform is 204 pages behind a 147-item sidebar organised into six working groups: Command (24 items), Dashboards (15), Threat Theaters (14), Intelligence Domains (15), Investigate (34), and Administration (45). This entry is not a page in isolation — it is a thread running through several of them.

The modules that matter most here:

Each dashboard is local-first: it renders from the platform’s own database rather than depending on a live third-party call, so it still works when an upstream API is unreachable or rate-limited. Heavy aggregates are cached with a hard query time cap and degrade to the last good value instead of hanging the page.

Automation, playbooks and AI skills

Analysis that only happens when someone remembers to run it is not a capability. The platform ships a 30-step automation pipeline (cron.php) that collects, ingests, resolves, enriches, correlates and scores on a schedule — 25 seeders, 11 resolvers and 7 enrichment runners, all idempotent and cursor-based so a run can be interrupted and resumed without duplicating or losing work.

Relevant playbooks

Of the 14 incident playbooks in playbooks.php, these apply directly to Military & Defense:

  • APT Intrusion Analysis — a step-checked workflow with the pivots, sources and handling rules already wired in.
  • Infrastructure Pivoting — a step-checked workflow with the pivots, sources and handling rules already wired in.

AI skills that apply

The 16 one-click operations in ai-skills.php are deterministic jobs, not free-text generation. The ones that matter here:

  • Threat Hunt
  • Correlate Infrastructure
  • Run Alert Rules
  • Summarise (Copilot)
  • Generate Report

Alerting closes the loop: rules in alerts.php fire on new indicators matching a saved query, so a first sighting in this area raises a notification rather than waiting to be noticed at the next review.

Feeds, data sources and the API

The collection layer runs a feed registry of free, machine-readable sources — bulk blocklists and trackers (Maltrail, IPsum, FireHOL, the full abuse.ch corpora, phishing databases, Emerging Threats, Spamhaus, DigitalSide, ThreatView), authoritative government feeds (CISA KEV, OFAC, UN and EU sanctions lists), and reference datasets (RIR allocations, ip-to-ASN and geolocation tables, MITRE ATT&CK, EPSS). collect.php pulls them server-side on a schedule; feeds.php and source-catalog.php show what is registered, what it covers and when it last ran.

Anything the platform holds is reachable programmatically. The REST API in api.php exposes 11 endpoints — status, stats, search, lookup, recent, export, bulk_check, top_threats, by_category, categories, check — and export.php streams 18 formats in bounded chunks, so a million-row export neither exhausts memory nor times out:

STIX 2.1, MISP, OpenIOC 1.1, CEF (ArcSight), LEEF 2.0 (QRadar), Zeek/Bro intel, Snort/Suricata rules, Palo Alto EDL, BIND RPZ, hosts blackhole, iptables, CSV, JSON, NDJSON/JSONL, XML.

That covers the CTI standards (STIX 2.1, MISP, OpenIOC), SIEM ingestion (CEF, LEEF, Zeek), detection engines (Snort/Suricata), and direct enforcement (Palo Alto EDL, BIND RPZ, hosts, iptables) — so intelligence developed here can be actioned in the tools you already run, without a manual reformatting step. A TAXII 2.1 server and a MISP/RSS feed are also served for pull-based sharing.

Use cases

Three ways this entry earns its keep in day-to-day work:

  1. Triage under time pressure. An artifact or report lands and you need a defensible read in minutes, not days. Define the intelligence question is the first move; the platform pre-computes the enrichment so the analyst spends the time on judgement rather than lookups.
  2. Building the picture. A single indicator is rarely the story. Collect and geolocate turns one artifact into a network — shared infrastructure, repeated selectors, the same operator behind different names — via the correlation graph and the cross-entity link engine.
  3. Producing something actionable. Analysis that ends in a document nobody can use is wasted. Publish with source discipline feeds the case file, the detection rule, the block list or the referral — with sourcing attached so the recipient can verify it.

Case management (cases.php), watchlists, saved searches and scheduled reports mean the work persists between sessions and survives an analyst leaving the team.

How each sector uses Military & Defense

The same entry is worked very differently depending on who you are, what authority you hold, and what you are ultimately producing. A military analyst is supporting a commander’s decision; a journalist is meeting a publication standard; an NGO caseworker is protecting a person. The underlying artifacts are shared — the constraints, outputs and thresholds are not.

🎖 Military and defence

For defence analysts this is the core discipline: order of battle, capability assessment, readiness indicators and industrial base analysis feeding IPB, force development and operational planning. Open and commercial sources now carry much of the load formerly reserved to national collection, particularly for unit tracking, equipment inventories and attrition accounting, and they can be shared with partners and released publicly in a way classified reporting cannot. Constraints include operational security around one's own force, since the same techniques apply symmetrically, and the requirement that assessments feeding targeting meet law of armed conflict standards on distinction and precaution with sourcing to match.

🕵 National intelligence

National services use this to assess capability, intent indicators and industrial sustainment, and increasingly to build releasable products that support diplomacy and public attribution. Fusion joins imagery, signals, human and open sources, with commercial imagery and transponder data now supplying the backbone of many unclassified assessments. Handling questions centre on whether an open-source finding independently corroborates a classified one or merely reflects the same underlying reality. Dissemination priorities include policy customers, partner services, and the growing requirement to produce assessments at a classification that allows sharing with coalition partners and the public.

👮 Law enforcement

Law enforcement relevance is mainly arms trafficking, export control violations and war crimes investigation. Evidence includes weapon serial numbers and lot markings, transfer documentation, end-user certificates, shipping records and imagery establishing the presence of specific systems at specific times. Weapons tracing through manufacturer records and national authorities is a formal process with defined channels. War crimes cases additionally require establishing which unit was present, under whose command, which turns on order of battle work. Chain of custody for recovered materiel and for digital evidence is the practical constraint, and it is frequently broken in conflict conditions.

🔍 Private investigation and corporate security

Corporate applications include country risk for operations near conflict, aviation and maritime route risk, defence sector due diligence and export compliance for suppliers. The deliverable translates military activity into consequences for people, assets and continuity. A private actor may not conduct collection against military installations in ways that breach local law, fly drones in restricted airspace, or handle controlled technical data without authorisation. Analysts should also be conscious that publishing granular defence analysis about a host state can create legal exposure for local staff, and that espionage statutes in many countries are broad and applied to open-source work.

📰 Journalism and OSINT media

Open-source military reporting has become central to conflict journalism, and its standards are now well developed: geolocation, chronolocation, equipment identification by visible features, and corroboration across independent sources. Verify claimed losses against visual evidence rather than official statements from either side, and be explicit about what a single image can and cannot establish. Protect sources, including local contributors whose imagery can identify them. Avoid publishing material that provides current targeting value, particularly precise locations of active positions or air defence, and apply a delay where the information advantage is live.

🌍 NGO, humanitarian and human rights

Human rights and humanitarian organisations use military analysis for accountability: establishing which forces were present, what weapons were used, and whether the effects were consistent with lawful targeting. Documentation must meet the standards used by investigative mechanisms, with imagery provenance, timestamps and analytical reasoning shown. Do-no-harm requires care that published analysis does not identify witnesses or contributors, and that unit identification does not expose civilians to reprisal. Duty of care applies to field documenters, who face detention and violence, and to staff handling graphic material continuously without adequate support.

🎓 University and research

Research spans security studies, defence economics, remote sensing and conflict analysis. Open-source military data has made much of this reproducible: imagery, transponder records, procurement notices and equipment loss datasets can be independently verified. Methodology should address survivorship and visibility bias, since documented losses reflect what was photographed rather than what occurred. Ethics review is needed for work involving contributors in conflict zones. Researchers should consider dual-use publication questions and export control rules on technical data, and should be careful that quantitative loss datasets built from social media are described accurately as minimum documented counts.

Playbook: working Military & Defense end to end

A repeatable sequence, from the moment the requirement lands to the moment a product is delivered and the case is closed out. Each phase states what you are trying to establish, not merely what to click — the point is a defensible chain of reasoning, not a checklist.

Phase 1 — Define the intelligence requirement

Fix what decision the assessment supports: force protection for a specific site, an assessment of sustainment capacity, an accountability question about a specific incident, or a capability judgement. This determines the level of resolution needed and what counts as sufficient evidence. Output is a requirement statement with a deadline and a customer. Stop when you can state what would answer the question, because open-source military work expands without limit otherwise.

Phase 2 — Establish the order of battle baseline

Assemble known formations, their subordination, garrisons, equipment establishment and recent deployment history from reference publications, official sources and prior reporting. This baseline is what makes any new observation meaningful, since a vehicle photograph means nothing without knowing which unit uses that pattern. Stop when you can place a new indicator against an existing structure rather than treating it as an isolated data point.

Phase 3 — Build the collection plan around observables

Identify what is actually observable for each question: imagery-visible infrastructure, transponder-visible movement, procurement notices, budget documents, unit insignia in user-generated content, and personnel social media. Match each requirement to a source that can answer it and note where nothing observable exists. Output is a collection plan with named sources and expected revisit intervals.

Phase 4 — Verify every item before it enters the picture

Apply the standard discipline to each piece of user-generated content: geolocate against terrain and structures, chronolocate using shadows, weather, vegetation and known events, check for prior appearance to exclude recycled material, and identify equipment from visible features rather than from the caption. Output is a verified item record with the reasoning. Stop when an independent analyst could reproduce the verification from your notes.

Phase 5 — Track units rather than equipment sightings

Aggregate verified observations into unit-level assessments: insignia, vehicle tactical markings, licence plate series, personnel accounts and repeated appearances in the same area. Unit tracking is what turns a stream of sightings into an order of battle picture and supports both capability assessment and accountability work. Stop when you can state a unit's assessed location with a confidence level and the observations supporting it.

Phase 6 — Account for equipment and attrition honestly

Maintain visually confirmed loss records with the type, date, location and source, and state explicitly that the count is a documented minimum rather than a total. Compare against known inventories and production or refurbishment capacity to assess sustainability. The analytical error to avoid is treating documented losses as complete, since documentation depends on who was present with a camera.

Phase 7 — Assess the industrial and logistics base

Examine production facilities through imagery, procurement notices, component import data, workforce indicators and budget documents. Sustainment capacity frequently constrains operations more than force size does, and it is more observable than most operational activity. Output is a production and sustainment assessment with the assumptions and the uncertainty stated.

Phase 8 — Analyse movement and readiness indicators

Track logistics movement, rail and road transport, transport aircraft and vessel activity, field hospital construction, ammunition storage changes and exercise patterns. Readiness assessment rests on the accumulation of mundane logistics signatures rather than on any single dramatic indicator. Stop when you can distinguish routine cyclical activity from a genuine change in posture.

Phase 9 — Test alternative explanations explicitly

For every significant judgement, construct the alternative: an exercise rather than a deployment, a refurbishment rather than a new build, a signalling move rather than a preparation. Record why each alternative was rejected. This is what separates assessment from pattern-matching and is the step most often skipped under time pressure.

Phase 10 — Handle publication with an operational security test

Before publishing, assess whether the information provides current targeting value: precise locations of active positions, air defence, logistics nodes or leadership. Apply delay, aggregation or omission where it does. Analysts producing public work in an active conflict carry real responsibility for the consequences of precision, and this test should be a documented step rather than an instinct.

Phase 11 — Package for the customer's standard

Accountability mechanisms want provenance and reasoning for every item. Force protection customers want the threat and the mitigation. Policy customers want the judgement and the confidence. Write separately for each rather than issuing one product and expecting the reader to adapt. Include a clear statement of what is observed, inferred and assessed.

Phase 12 — Maintain and archive the picture

Keep the order of battle, loss records and verified item archive as living assets with version history, since sources disappear and content is deleted. An archived, provenance-preserved record is what allows an assessment to be defended or a war crimes case to be built years later, and rebuilding it retrospectively is impossible.

The platform ships this as a step-checked workflow in playbooks.php, so progress is recorded against a case rather than held in someone’s head.

Source register: what to collect from, and how

Sources are listed with their access model so you can plan around cost and licensing before you build a dependency on them. Open means no account required; registration means a free account or API key; licensed means paid or institutional access. Always confirm current terms — licensing changes, and a source that was free for research may not be free for commercial or evidential use.

Source Access What it gives you How it is used here
SIPRI databases Open Arms transfers, military expenditure, arms industry and nuclear forces datasets with documented methodology. Provides authoritative baselines for transfers, spending and industrial capacity in capability assessments.
IISS Military Balance Licensed Annual reference on national armed forces, formations, equipment holdings and defence economics by country. Supplies the standard order of battle and inventory baseline against which observations are assessed.
Janes defence intelligence Licensed Reference and analysis on equipment, units, defence industry and procurement programmes worldwide. Provides equipment identification detail and programme history for platform and unit assessment.
Conflict Armament Research Open Field documentation of weapons and components recovered in conflict, traced through manufacturer and transfer records. Establishes supply chains for weapons in a theatre and evidences transfers in breach of controls.
UN Register of Conventional Arms Open Voluntary state reporting of imports and exports across seven categories of major conventional weapons. Provides declared transfer data for comparison against observed holdings and independent transfer estimates.
Small Arms Survey Open Research on small arms holdings, transfers, ammunition and armed group weaponry with country studies. Supplies the evidence base for small arms and light weapons holdings and their movement in a conflict.
Copernicus Data Space Ecosystem Registration Free Sentinel optical and radar imagery with frequent revisit and full archive access. Provides no-cost change detection over bases, airfields and industrial sites with a consistent time series.
Planet and commercial imagery providers Licensed High-resolution and daily revisit optical imagery suitable for counting platforms and identifying activity. Confirms aircraft, vehicle and vessel counts and detects construction at installations under observation.
OpenSky Network Registration Community-operated ADS-B receiver network providing historical flight tracking data for research use. Reconstructs transport and surveillance aircraft activity patterns with a citable and reproducible dataset.
ADS-B Exchange and flight tracking services Registration Unfiltered aggregated aircraft transponder data including military aircraft not filtered from public feeds. Tracks strategic lift, tanker and surveillance activity indicating deployment and readiness changes.
MarineTraffic and AIS providers Licensed Historical and current vessel position data from terrestrial and satellite AIS reception. Tracks naval auxiliary and sealift movement and port activity supporting deployment assessment.
TED and national defence procurement portals Open Published tender and award notices including defence support contracts, construction and materiel purchases. Reveals sustainment priorities, base development and equipment programmes through contracting activity.
Bellingcat methodology and investigations Open Open-source verification methodology including geolocation, chronolocation and equipment identification technique. Provides the reference standard for verifying user-generated content used in order of battle work.
ACLED and UCDP conflict event data Registration Georeferenced organised violence event datasets with actor coding and long time series. Establishes activity patterns and geographic distribution of engagements for operational assessment.
Airwars Open Documentation of civilian harm from airstrikes and artillery with incident-level sourcing and assessment. Supports accountability work by correlating strike events with civilian harm and responsible actors.
NATO and national defence ministry publications Open Official statements, exercise announcements, force structure documents and defence budget submissions. Supplies authoritative declared positions and budget detail for comparison against observed activity.

Prefer sources that publish a methodology and a revision history. A dataset that changes silently is a liability in any product that has to survive challenge.

Tooling

Tools commonly used against Military & Defense. None of these replace judgement, and each carries its own failure modes — know what a tool infers versus what it observes.

  • QGIS and geospatial analysis suites — Geolocation, terrain analysis and mapping of unit locations and infrastructure. Limitation: base map currency varies widely, and rural areas are frequently poorly mapped.
  • Google Earth and historical imagery — Provides free historical imagery for geolocation and change detection. Limitation: update frequency is inconsistent and dates can be misleading.
  • SunCalc and shadow analysis tools — Establishes time of day and date range from shadow geometry in imagery. Limitation: requires clear shadows and known object heights to be precise.
  • Reverse image and video search — Detects recycled or misattributed footage before it enters an assessment. Limitation: coverage is poor for video and for content from closed platforms.
  • Flight and vessel tracking platforms — Reconstruct movement patterns of transport and surveillance assets. Limitation: military transponders are frequently off, and filtering varies by service.
  • Structured loss and order of battle databases — Maintain verified records with sourcing to support quantitative assessment. Limitation: represents documented minimums, and treating totals as complete is a persistent misuse.
  • Satellite tasking and archive platforms — Acquire imagery of specific sites on demand or from archive. Limitation: cost, tasking latency and cloud cover routinely defeat time-sensitive questions.
  • Content archiving tools — Preserve user-generated content with metadata before deletion. Limitation: platform compression strips much of the metadata analysts would want.
  • Equipment identification reference libraries — Support identification of platforms and variants from visible features. Limitation: local modifications and captured equipment defeat reference matching frequently.

AI skills and automation in detail

These are deterministic jobs with defined inputs and outputs, not open-ended prompting. Each is idempotent and cursor-based: interrupt one and it resumes where it stopped rather than duplicating work or losing progress.

  • Threat Hunt — Runs saved hypotheses against the corpus and surfaces what matches, with the query preserved as a versioned artifact.
  • Correlate Infrastructure — Builds the cross-entity link graph: shared hosting, reused certificates, overlapping registrants, repeated selectors.
  • Run Alert Rules — Evaluates saved rules against new data so a first sighting raises a notification rather than waiting for review.
  • Summarise (Copilot) — Produces a narrative summary beside the underlying records. It explains; it never creates indicators or assigns attribution.
  • Generate Report — Assembles a sourced product from the current case or query, with provenance attached to each element.

A note on the boundary: the only skill that involves a language model is Summarise (Copilot), and it writes prose about records that already exist. Nothing else on this list involves generation of any kind. No indicator, relationship or attribution in the platform originates from a model. See the full skill list.

Tradecraft notes

The distinctions that separate a competent analyst from a fast one:

  • Verify before you aggregate. A single unverified item entering an order of battle contaminates every judgement built on it, and because these pictures are cumulative the error propagates silently for months, so geolocation and chronolocation are not optional steps for interesting items.
  • Documented losses are a minimum, never a total. Visual loss counts reflect where cameras were present and which side had an interest in publishing, so any product using them must state the bias explicitly rather than presenting a documented count as an attrition figure.
  • Track units, not vehicles. A photograph of a tank tells you little; the same tactical marking appearing in three locations over two weeks tells you about a formation's movement, and unit-level tracking is what converts observations into assessment.
  • Sustainment constrains more than order of battle suggests. Production capacity, refurbishment throughput, ammunition stocks and transport availability determine what a force can actually do, and all of them are more observable than operational intent.
  • Absence of transponder data is expected, not informative. Military aircraft and vessels routinely operate without transmitting, so tracking data reveals the deliberately visible portion of activity, which is a biased sample and should be described as one.
  • Publication in an active conflict is an operational act. Precise locations of active positions, air defence and logistics nodes carry targeting value, so apply a documented delay-or-omit test and accept that some verified findings should not be published now.
  • Insignia, plates and markings are the cheapest high-value indicators available. They are visible in ordinary photographs, they are systematically catalogued in open reference work, and they identify formations far more reliably than equipment type does.
  • Distinguish exercise from deployment carefully. Both produce logistics movement, field infrastructure and increased transport activity, and the difference usually lies in what is not present, such as ammunition handling, medical build-out or family notification patterns.

Measuring whether it is working

Capability claims should be falsifiable. These are the measures that show whether work on Military & Defense is producing anything, and they are worth baselining before you change process or tooling.

  • Proportion of items entering the order of battle picture with complete verification records that an independent analyst could reproduce.
  • Accuracy of unit location assessments when subsequently confirmed by other sources, tracked as a calibration measure.
  • Time from a significant observable change to a delivered assessment for the customer who needs it.
  • Proportion of assessments containing explicit alternative explanations and confidence statements, audited by peer review.
  • Coverage of the sustainment picture, measured as the share of key production and logistics nodes under active monitoring.
  • Number of publication decisions where the operational security test led to delay, aggregation or omission, as evidence the control functions.
  • Contribution rate to accountability mechanisms, measured by material accepted by investigative bodies with provenance intact.

Beware of measuring volume alone. Indicator counts and report counts rise easily and say little; time-to-attribution, proportion of findings that survive review, and how often a product changed a decision say a great deal.

Common pitfalls

  • Counting equipment visible in imagery as operational, when storage yards, hulks and decoys inflate apparent inventories substantially.
  • Accepting circulating conflict footage without independent geolocation, since recycled and misattributed video is the norm rather than the exception.
  • Mirror-imaging doctrine by assuming a foreign force will fight the way your reference military would.
  • Reading movement as intent, when exercises, rotations and deliberate deception produce identical observable signatures.
  • Publishing precise real-time locations of units or individuals, which can directly enable targeting and endanger civilians nearby.

Legal and ethical considerations

Open-source military analysis is generally lawful, but publication can have lethal consequences, so apply a targeting-harm test before releasing precise coordinates, timings or personnel identities. Commercial imagery licences frequently restrict redistribution. Where analysis supports accountability work, evidence handling must meet the receiving mechanism's standards for provenance, hashing and chain of custody. Be alert to national security and official secrets legislation, which in some jurisdictions criminalises collection or publication even of openly available material.

Data integrity: no fabrication, no drift, no hallucination

Intelligence that cannot be traced back to a source is not intelligence, it is assertion. Everything in this entry — and everything in the platform behind it — is built on a small number of non-negotiable rules.

Provenance on every record

Every indicator carries the source that supplied it, a first-seen and last-seen timestamp, and a sighting count. Where several feeds report the same artifact, each contribution is recorded separately rather than collapsed, so you can see whether a finding rests on one source or twelve. Source attribution travels with the data into every export, so a recipient can audit a claim without asking you for the working.

Nothing is invented to fill a gap

If the platform has no data for Military & Defense, it says so. Empty is displayed as empty — never padded with plausible-looking placeholder values, sample records or illustrative examples that a reader might mistake for observations. A dashboard with no rows is a true statement about collection coverage, and it is treated as a gap to close, not a blemish to hide.

Scoring is deterministic and reproducible

Threat scores, reputation grades and risk tiers are computed from stated inputs with fixed weights, not estimated. The same inputs always produce the same output, and the formula is visible rather than a black box. Aggregates are cached with an explicit time-to-live so a figure on screen is never silently stale — and when a heavy query exceeds its time budget the platform serves the last known-good value and labels it, rather than inventing a fresh number or hanging.

Where AI is used, and where it is not

Language models summarise and explain. They do not create indicators, assign attribution or manufacture relationships. No IP address, wallet, hash or identity in the platform originates from a model — every one is ingested from a named feed, resolved from a reference dataset, or entered by an analyst with a source recorded. Copilot output is presented as narrative alongside the underlying records, never in place of them, so a reader can always check the summary against the evidence.

Guarding against drift

Enrichment is additive and timestamped rather than overwriting. Reference data — sanctions lists, allocations, taxonomies — is re-synchronised from the authority on a schedule instead of being edited in place, so local copies cannot quietly diverge from the source of truth. Attribution is recorded with a confidence level and the reporting it rests on, and inferred relationships are labelled as inferred. When a source retracts or corrects, the correction propagates rather than leaving a stale assertion behind.

What this means for you

You can put a finding from this platform in front of a regulator, a court, a board or a partner agency and show where each element came from. That is the standard the tooling is built to — because in this work, being confidently wrong is more damaging than being usefully uncertain.

By the numbers

The taxonomy this entry belongs to is not a marketing list — it is the actual structure of the platform: 52 mission domains, 52 intelligence disciplines and 65 data points, each with a live dashboard behind it. Supporting that: 18 indicator types, 14 playbooks, 16 AI skills, 18 export formats and a 30-step automated pipeline.

This particular entry connects directly to 8 intelligence disciplines, 7 data points, 7 closely related entries — every one of them a tag you can follow, and a dashboard you can open.

Questions analysts actually ask

How reliable are visually confirmed loss counts?

They are reliable as minimums and unreliable as totals. Each entry rests on an image of an identifiable vehicle at an identifiable place and time, which is a high evidential standard. What they cannot capture is anything not photographed, and photography depends on which side controlled the ground, whether personnel had phones and connectivity, and whether publishing served a purpose. This produces systematic bias, usually undercounting the side that retained the battlefield and recovered its equipment. Used as a floor and as a comparative trend over time they are genuinely valuable; used as a casualty figure they are simply wrong.

What is the single most useful open indicator of a coming deployment?

Logistics movement, particularly rail. Formations move on rail in most large armies, and rail loading, flat wagon accumulation, and unusual freight patterns are visible in imagery and often in commercial rail data. Supporting indicators include field hospital construction, ammunition storage changes, transport aircraft and sealift activity, and procurement of consumables. No single indicator is decisive, and each has an exercise explanation, which is precisely why the assessment rests on the accumulation of mundane logistics signatures rather than on any dramatic single observation.

How do you identify a unit from a photograph?

Layered features rather than any one marking. Formation insignia and patches, vehicle tactical numbers and their series conventions, licence plate ranges, radio call sign conventions, distinctive local modifications, and personnel visible in the frame whose social media presence can be matched. Each is individually weak and jointly strong. Reference libraries and prior verified observations do most of the work, which is why the baseline order of battle picture is the actual analytical asset and any single photograph is only a data point tested against it.

Is open-source analysis a substitute for classified collection?

No, but it now carries much of the load for certain questions, and it has one decisive advantage: it can be shared. Open-source assessments can go to coalition partners, humanitarian organisations, accountability mechanisms and the public without any release process, which is why national services increasingly build unclassified products deliberately. What it does not provide is intent, internal decision making, or anything happening indoors. The strongest practice is treating them as complementary and being rigorous about whether an open finding independently corroborates a classified one or simply reflects the same underlying event.

When should analysis be withheld from publication?

When it provides current targeting value. Precise locations of active positions, air defence systems, logistics nodes, command posts and named individuals in a live conflict all fall into this category, and publishing them shifts an analyst from observer to participant. The practical approach is a documented test applied before publication, with options of delay, geographic aggregation, or omission of the precise detail while publishing the analytical point. Historical analysis, accountability documentation and capability assessment can almost always be published; current locational detail frequently cannot.

How does this work support war crimes accountability?

By establishing presence, capability and command. Accountability mechanisms need to know which unit was in a location at a time, what weapons it held, who commanded it and what the effects of a specific engagement were. That is order of battle work applied to a legal question, combined with weapons identification from remnants and imagery-based damage assessment. The requirements are stricter than for military assessment: provenance for every item, preserved originals, documented chain of custody, and analytical reasoning shown rather than asserted, since the material must survive adversarial testing years later.

Standards, frameworks and further reading

Work that references a recognised framework is easier to defend, easier to hand over, and easier for a partner to consume:

  • Geneva Conventions and Additional Protocols, establishing the law of armed conflict principles of distinction, proportionality and precaution.
  • Rome Statute of the International Criminal Court, defining the crimes and evidentiary context for accountability work.
  • Berkeley Protocol on Digital Open Source Investigations, the recognised standard for open-source evidence in international investigations.
  • Arms Trade Treaty, governing state obligations on transfer authorisation and diversion prevention for conventional arms.
  • UN Register of Conventional Arms reporting framework, providing the declared transparency mechanism for major weapons transfers.
  • Wassenaar Arrangement munitions and dual-use lists, defining controlled conventional arms and related technology.
  • International Traffic in Arms Regulations and equivalent national controls on defence articles and technical data.
  • NATO standardisation agreements on order of battle terminology and symbology, which structure how military information is recorded and exchanged.

References

Primary sources and authoritative references for this entry. Publishers revise and retire material, so treat the retrieval date as part of the citation and re-check before relying on any of it in a formal product.

  1. Arms transfers and military expenditure databases — SIPRI. Documented methodology datasets on transfers, spending and arms industry.
  2. The Military Balance — International Institute for Strategic Studies. Annual reference on force structures and equipment holdings by country.
  3. Weapons tracing field reports — Conflict Armament Research. Documentation linking recovered weapons to manufacturers and transfer chains.
  4. Berkeley Protocol on Digital Open Source Investigations — UN Human Rights Office and UC Berkeley. Standard for collecting and preserving open-source evidence for accountability.
  5. UN Register of Conventional Arms — UN Office for Disarmament Affairs. Declared state reporting of major conventional weapons transfers.
  6. Small arms holdings and transfer research — Small Arms Survey. Evidence base on small arms and light weapons in conflict settings.
  7. Open-source investigation methodology — Bellingcat. Published technique for geolocation, chronolocation and verification.
  8. Civilian harm documentation from air and artillery strikes — Airwars. Incident-level records correlating strikes with civilian casualties.
  9. Flight tracking research dataset — OpenSky Network. Historical ADS-B data available for reproducible research use.

Link integrity: every reference above was verified with a live request when this page was generated. Where a publisher had moved or withdrawn a document, the link was repointed at a preserved copy in the Internet Archive and marked as archived. Anything with no reachable copy anywhere had its link removed rather than left to rot — the source is still credited, it simply cannot be linked.

Put it into practice

The Quantus Intel threat intelligence platform operationalises this entry: fuses imagery, transponder, procurement and open reporting into a verifiable order-of-battle picture. Explore the platform, or browse the rest of the library by following any tag above.

Leave a Reply

Your email address will not be published. Required fields are marked *