Nation State: Mission Domain Intelligence Guide
State activity rarely arrives labelled. It surfaces as a procurement order routed through a third-country freight forwarder, a research institute hiring for a capability its published work does not need, or a fleet of tankers that goes dark on the same stretch of water every month.
State activity rarely arrives labelled. It surfaces as a procurement order routed through a third-country freight forwarder, a research institute hiring for a capability its published work does not need, or a fleet of tankers that goes dark on the same stretch of water every month.
What Nation State covers as a mission domain
Nation state intelligence covers activity directed, funded, tasked or knowingly tolerated by a sovereign government in pursuit of strategic objectives. In practice that means intelligence collection against foreign governments and industry, sanctions and export-control evasion, strategic corruption, covert procurement of restricted technology, support to proxy forces, and information operations. The analytic job is to connect observable behaviour to institutional structure and doctrine: which service, which directorate, which requirement. Assessments deal in intent and capability, and must survive the question of whether a criminal or commercial explanation fits the same evidence.
The domain divides roughly into services (civilian intelligence, military intelligence, internal security), the contractor and front-company layer that gives states deniability, the procurement networks that move restricted goods, and the media and influence apparatus. Actor types range from career case officers to universities, shipping brokers, chemical distributors and diaspora business figures who may not know whose requirement they are servicing.
Why it matters
The consequences are strategic rather than transactional. Diverted dual-use technology shortens an adversary weapons programme by years. Sanctions evasion funds a war. Covert influence changes the terms of a domestic political debate. Targets include defence primes and their tier-three suppliers, universities, law firms, dissidents and journalists in exile, and the compliance functions of banks and freight companies who become unwitting facilitators and then liable parties.
What analysts actually look for
These are the concrete, observable signals that carry weight in this area of work:
- Dual-use goods ordered by a newly incorporated intermediary in a permissive jurisdiction, with quantities far exceeding the stated civilian end use
- Shell companies sharing a registered address, nominee director or company secretary with entities already designated on sanctions lists
- Vessels showing repeated AIS gaps in the same corridor, followed by draught changes inconsistent with the declared voyage
- Research institutes recruiting for materials, propulsion or cryptography skills unconnected to any published civilian programme
- Synchronised narrative pushes across state broadcasters, diplomatic accounts and low-credibility syndication sites within a short window
- Diplomatic expulsions, visa refusals or accreditation withdrawals clustering around a specific mission or trade office
- Bills of lading showing a commodity code inconsistent with the declared weight, container type or insured value
- Procurement agents reusing the same freight forwarder, bank correspondent and end-user certificate template across unrelated buyers
- Sudden change in a state's declared exercise notifications, airspace reservations or maritime warnings ahead of a policy deadline
Where the data comes from
Authoritative and openly available collection points. Always confirm licensing and terms before operational or commercial use:
- OFAC SDN and Consolidated Sanctions Lists — Designated persons, vessels, aircraft and entities with identifiers, aliases and designation rationale
- EU Sanctions Map and UK OFSI consolidated list — European and UK designations, legal bases and sectoral restrictions for cross-checking counterparties
- UN Security Council Panel of Experts reports — Detailed, sourced case studies on sanctions evasion by DPRK, Libya, Yemen and others
- OpenSanctions — Aggregated, deduplicated sanctions, PEP and watchlist data with entity resolution across jurisdictions
- UN Comtrade and national customs statistics — Bilateral trade flows for spotting mirror-statistic gaps and implausible transhipment volumes
- Equasis and IMO GISIS — Ship ownership, management, classification and port state control history for maritime evasion work
- ODNI Annual Threat Assessment and equivalent national assessments — Baseline government judgements on state intent, priorities and capability trajectories
- National company registries such as Companies House — Directors, beneficial owners, filings and address reuse that anchor entity resolution
A working method
A repeatable sequence beats ad-hoc searching. This is a practical starting workflow:
- Fix the requirement — Write the priority intelligence requirement in falsifiable terms. Vague questions about a country produce vague answers; ask what decision the assessment supports.
- Map the institutional terrain — Document the state's declared doctrine, service structure, procurement law and tasking chain, so observed behaviour can be tied to a plausible owner.
- Resolve entities — Reconcile names across registries, sanctions lists, trade records and court filings, accounting for transliteration variants and nominee layers.
- Corroborate across collection types — Require at least two independent streams before promoting a hypothesis, for instance registry data plus trade records plus reporting.
- Test alternatives — Run analysis of competing hypotheses against commercial and criminal explanations. State what evidence would falsify each.
- Assign confidence and caveat — Use consistent estimative language, record source reliability, and separate what is observed from what is inferred.
- Disseminate with handling rules — Release under a defined marking, note sanctions and legal exposure for recipients, and log feedback for the next collection cycle.
How this connects across the intelligence taxonomy
Intelligence work does not respect neat boundaries. The mission domain you are working, the disciplines you practise, and the data points you pivot on are one connected system. These are the direct relationships for this entry — every link is also a tag, so you can follow any thread across the whole library.
Practised with these disciplines
- Cyber Intelligence — Adversary Activity in Networks and Systems
- Threat Actor Intelligence — Tracking Adversary Groups Over Time
- Government Intelligence — Government Structures, Policy, and Officials
- Signals Intelligence — Intelligence from Intercepted Communications and Emissions
- Geospatial Intelligence — Intelligence Derived from Place
- Disinformation Intelligence — Detecting and Analyzing Information Manipulation
- Technical Intelligence — Technology Capability, Design, and Exploitation
- Open Source Intelligence — Publicly Available Information, Systematically Collected
Worked in these data points
- IP Address — Internet Protocol address identifying a device or server on a network.
- Domain Name — Human-readable address that maps to IP infrastructure via DNS.
- Malware Family — A named class of related malicious software.
- File Hash — Cryptographic fingerprint of a file, used for malware identification.
- CVE / Vulnerability — Common Vulnerabilities and Exposures identifier for a known flaw.
- TLS / JA3 Fingerprint — A hash of TLS client-hello parameters used to fingerprint clients, malware, and C2 frameworks.
- SSL/TLS Certificate — A digital certificate binding a public key to an identity.
- Event / Incident — A discrete real-world occurrence — protest, strike, breach, seizure — with time, place, and actors.
Adjacent mission domains
- APT / Espionage
- Military & Defense
- Economic Espionage
- Disinformation / IO
- Election Security & PSYOP
- WMD / Proliferation
Inside the platform: where Nation State lives
The Quantus platform is 204 pages behind a 147-item sidebar organised into six working groups: Command (24 items), Dashboards (15), Threat Theaters (14), Intelligence Domains (15), Investigate (34), and Administration (45). This entry is not a page in isolation — it is a thread running through several of them.
The modules that matter most here:
threat-dashboard.php?theme=nation_state— Nation State dashboarddomain.php?d=ns— Mission domain hubtheater.php?d=ns— Threat theater viewip-profile.php— IP Address profileurl-profile.php— Domain Name profilehash-profile.php— Malware Family profiledetection-rules.php— CVE / Vulnerability profilesearch.php— Advanced search, filter and pivotcorrelate.php— Correlation graphcases.php— Case management
Each dashboard is local-first: it renders from the platform’s own database rather than depending on a live third-party call, so it still works when an upstream API is unreachable or rate-limited. Heavy aggregates are cached with a hard query time cap and degrade to the last good value instead of hanging the page.
Automation, playbooks and AI skills
Analysis that only happens when someone remembers to run it is not a capability. The platform ships a 30-step automation pipeline (cron.php) that collects, ingests, resolves, enriches, correlates and scores on a schedule — 25 seeders, 11 resolvers and 7 enrichment runners, all idempotent and cursor-based so a run can be interrupted and resumed without duplicating or losing work.
Relevant playbooks
Of the 14 incident playbooks in playbooks.php, these apply directly to Nation State:
- APT Intrusion Analysis — a step-checked workflow with the pivots, sources and handling rules already wired in.
- Infrastructure Pivoting — a step-checked workflow with the pivots, sources and handling rules already wired in.
- Malware Triage — a step-checked workflow with the pivots, sources and handling rules already wired in.
AI skills that apply
The 16 one-click operations in ai-skills.php are deterministic jobs, not free-text generation. The ones that matter here:
- Threat Hunt
- Correlate Infrastructure
- Run Alert Rules
- Detection Rules
- Summarise (Copilot)
- Generate Report
Alerting closes the loop: rules in alerts.php fire on new indicators matching a saved query, so a first sighting in this area raises a notification rather than waiting to be noticed at the next review.
Feeds, data sources and the API
The collection layer runs a feed registry of free, machine-readable sources — bulk blocklists and trackers (Maltrail, IPsum, FireHOL, the full abuse.ch corpora, phishing databases, Emerging Threats, Spamhaus, DigitalSide, ThreatView), authoritative government feeds (CISA KEV, OFAC, UN and EU sanctions lists), and reference datasets (RIR allocations, ip-to-ASN and geolocation tables, MITRE ATT&CK, EPSS). collect.php pulls them server-side on a schedule; feeds.php and source-catalog.php show what is registered, what it covers and when it last ran.
Anything the platform holds is reachable programmatically. The REST API in api.php exposes 11 endpoints — status, stats, search, lookup, recent, export, bulk_check, top_threats, by_category, categories, check — and export.php streams 18 formats in bounded chunks, so a million-row export neither exhausts memory nor times out:
STIX 2.1, MISP, OpenIOC 1.1, CEF (ArcSight), LEEF 2.0 (QRadar), Zeek/Bro intel, Snort/Suricata rules, Palo Alto EDL, BIND RPZ, hosts blackhole, iptables, CSV, JSON, NDJSON/JSONL, XML.
That covers the CTI standards (STIX 2.1, MISP, OpenIOC), SIEM ingestion (CEF, LEEF, Zeek), detection engines (Snort/Suricata), and direct enforcement (Palo Alto EDL, BIND RPZ, hosts, iptables) — so intelligence developed here can be actioned in the tools you already run, without a manual reformatting step. A TAXII 2.1 server and a MISP/RSS feed are also served for pull-based sharing.
Use cases
Three ways this entry earns its keep in day-to-day work:
- Triage under time pressure. An artifact or report lands and you need a defensible read in minutes, not days. Fix the requirement is the first move; the platform pre-computes the enrichment so the analyst spends the time on judgement rather than lookups.
- Building the picture. A single indicator is rarely the story. Resolve entities turns one artifact into a network — shared infrastructure, repeated selectors, the same operator behind different names — via the correlation graph and the cross-entity link engine.
- Producing something actionable. Analysis that ends in a document nobody can use is wasted. Disseminate with handling rules feeds the case file, the detection rule, the block list or the referral — with sourcing attached so the recipient can verify it.
Case management (cases.php), watchlists, saved searches and scheduled reports mean the work persists between sessions and survives an analyst leaving the team.
How each sector uses Nation State
The same entry is worked very differently depending on who you are, what authority you hold, and what you are ultimately producing. A military analyst is supporting a commander’s decision; a journalist is meeting a publication standard; an NGO caseworker is protecting a person. The underlying artifacts are shared — the constraints, outputs and thresholds are not.
🎖 Military and defence
Nation state activity defines the operating environment before any force is committed. A defence analyst uses this domain to populate intelligence preparation of the battlespace with adversary intent, proxy relationships and grey zone instruments that sit below the threshold of armed attack: procurement fronts, sanctioned suppliers, influence infrastructure and dual use technology flows. It supports indications and warning on mobilisation or pre-positioning, informs force protection for deployed units and partner bases, and shapes security cooperation planning. Constraints are firm. Collection authorities, status of forces arrangements and rules on handling partner nation material all bound what may be gathered, and anything feeding a targeting recommendation must carry explicit sourcing and stated confidence.
🕵 National intelligence
For a national service this is core requirements driven work. Standing requirements on a priority state generate collection tasking across signals, human, imagery, open source and financial channels, and the value added is fusion rather than any single stream. Analysts reconcile a procurement record against a designated entity list, a corporate registry filing against a diplomatic reporting cable, and a shipping manifest against a satellite pass. Handling matters as much as content: compartmented material cannot be mixed into a releasable product without a tearline, and originator control governs onward passage to partners. Dissemination is judged on whether a policy customer changed a decision, not on volume produced.
👮 Law enforcement
Law enforcement encounters nation state activity as sanctions evasion, export control breaches, foreign agent registration offences, procurement fraud and transnational repression against people living in the jurisdiction. The evidential bar is different from an intelligence judgement: each element must be provable from admissible material with an unbroken chain of custody. Corporate records, customs declarations, bank records and communications obtained under production orders or mutual legal assistance carry the case, while intelligence reporting typically cannot. Investigators plan early for the intelligence to evidence conversion, seek parallel construction lawfully through independent collection, and coordinate with prosecutors on whether a designation, a criminal charge or a disruption gives the better outcome.
🔍 Private investigation and corporate security
Corporate security uses this domain for counterparty due diligence, sanctions and export control compliance, joint venture risk and screening of investors or acquirers. The practical questions are beneficial ownership, state linkage, control by a designated person and whether goods or technology could be diverted to a restricted end use. A private actor may not conduct intrusive surveillance, deceive a subject into disclosing information, obtain government or telecoms data by pretext, or intercept communications. Work stays with registries, filings, litigation records, trade data, licensed screening databases and disciplined open source. Findings should be written to survive disclosure in litigation and to be defensible to a regulator.
📰 Journalism and OSINT media
Reporting on state activity requires more corroboration than most beats because denial is automatic and the cost of error is high. Verification means documents whose provenance can be described, at least two independent lines of evidence for any attribution claim, and named or well characterised sources for the central assertion. Leaked material needs authentication and a public interest assessment before use. Source protection is operational, not aspirational: secure contact, minimal metadata, and awareness that a state adversary may attempt to identify the source through the story itself. Right of reply to governments, companies and named individuals is standard, and refusal to comment should be reported precisely.
🌍 NGO, humanitarian and human rights
Human rights and humanitarian organisations meet this domain as transnational repression, surveillance of exiles, sanctions effects on aid delivery and export of surveillance technology. Practice is victim centred: consent for any use of a person's account, control by the individual over identification, and an honest explanation of the risk that documentation creates for relatives who remain in country. Documentation aimed at accountability should follow recognised investigation standards so it can survive later scrutiny. Duty of care extends to staff, who may themselves become targets, and to fixers and interpreters. Do no harm means accepting that some findings cannot be published in the form that would be most persuasive.
🎓 University and research
Academic work in this area lives or dies on transparent method. State a research question, define the population of entities or events, document how cases entered the sample, and publish the coding frame so another researcher can reproduce the classification. Ethics approval is required whenever human subjects, exiles or activists are involved, and risk assessment should cover the participants and the researcher. Data sharing is constrained by personal data law and by protection of participants, so plan for controlled access archives rather than open dumps. Cite primary instruments and datasets directly, distinguish clearly between evidence and inference, and archive sources that may be removed.
Playbook: working Nation State end to end
A repeatable sequence, from the moment the requirement lands to the moment a product is delivered and the case is closed out. Each phase states what you are trying to establish, not merely what to click — the point is a defensible chain of reasoning, not a checklist.
Phase 1 — Set the requirement
Start from the decision that needs support: an investment approval, a designation recommendation, a force protection assessment. Write the question as a specific, falsifiable statement with a deadline and a named customer. Break it into information requirements and identify which are answerable from open sources and which need privileged access or legal process. A good output is a one page requirement that a collector can act on without asking what you meant, and that tells you when the question is answered.
Phase 2 — Model the state apparatus
Map the relevant part of the state: ministries, services, state owned enterprises, sovereign funds, defence industrial base and the party or ruling network sitting above them. Record legal control, effective control and personal relationships separately, because they diverge. Note which functions are routinely outsourced to contractors, brokers or diaspora businesses. The output is a structural baseline you can hang entities on, so that a newly discovered company can be placed in context rather than treated as a novelty.
Phase 3 — Build the entity graph
Resolve names, registration numbers, addresses, directors and shareholders across corporate registries, beneficial ownership registers, sanctions lists and litigation records. Use legal entity identifiers where they exist and record every alias and transliteration variant. Attach a source and a date to each edge. A good graph is one where every relationship can be traced to a document, and where you can state which links are documented, which are inferred and which are asserted by a third party you have not verified.
Phase 4 — Trace the material flow
Where the question concerns procurement or evasion, follow the goods and the money separately. Trade and customs data, bills of lading, freight forwarder records, vessel and aircraft movement, and financial messaging each give a partial view. Look for the transhipment jurisdictions, the intermediary that appears in unrelated cases and the mismatch between declared end user and plausible end use. The output is a chain with named handoffs, not a claim that goods somehow reached a destination.
Phase 5 — Test alternative explanations
Before concluding state direction, force yourself through the competing hypotheses: commercial opportunism, criminal activity with no sponsor, a contractor exceeding its brief, or deliberate misdirection. Score the evidence against each hypothesis rather than accumulating support for the favoured one. Record which single piece of evidence would most change your view. This step is what separates an assessment from an accusation, and it is the part that survives hostile review.
Phase 6 — Grade sources and confidence
Apply a consistent source reliability and information credibility scale, and keep the confidence in the judgement separate from the reliability of the underlying reporting. State confidence in words with defined meanings and avoid numerical false precision. Where a judgement rests on a single source, say so in the text and not only in a footnote. A good output lets a reader see exactly which sentence would fail if one source were withdrawn.
Phase 7 — Assess intent and capability separately
Capability is generally observable and slow to change; intent is inferred and can shift quickly. Assess them in different paragraphs with different evidence, then state the conditions under which capability would be applied. This structure prevents the common failure of reading hostile intent from an inventory, and it gives the customer something actionable: the indicators that would show intent hardening.
Phase 8 — Write for the decision
Lead with the judgement and its confidence, then the so what for the customer, then the evidence. Keep estimative language consistent and never bury a caveat in a subordinate clause. Include what you do not know and what would change the assessment. Length is set by the decision, not by the volume of collection. A good product can be briefed in ninety seconds and defended for an hour.
Phase 9 — Handle, mark and disseminate
Apply classification and handling caveats at the paragraph level so a releasable version can be produced without a rewrite. Check originator control before passing anything to a partner, and record every dissemination. Where the product supports a sanctions or prosecution route, ensure the underlying evidence package is preserved separately to an evidential standard, because an assessment is not evidence. Record the marking decisions themselves, because they are frequently queried later.
Phase 10 — Monitor and revisit
Set named indicators with thresholds and an owner, and schedule a review date rather than waiting for an event to force one. Track your own judgements over time and record when they were wrong, because calibration only improves if outcomes are logged. Retire the requirement explicitly when the decision has passed, so collection is not spent on a question nobody is still asking.
The platform ships this as a step-checked workflow in playbooks.php, so progress is recorded against a case rather than held in someone’s head.
Source register: what to collect from, and how
Sources are listed with their access model so you can plan around cost and licensing before you build a dependency on them. Open means no account required; registration means a free account or API key; licensed means paid or institutional access. Always confirm current terms — licensing changes, and a source that was free for research may not be free for commercial or evidential use.
| Source | Access | What it gives you | How it is used here |
|---|---|---|---|
| OFAC Specially Designated Nationals list | Open | United States sanctions designations with aliases, addresses, identifiers and programme tags, updated continuously. | Screening entities and vessels found in procurement chains, and pivoting on shared addresses and identifiers. |
| EU Consolidated Sanctions List | Open | European Union restrictive measures covering persons, entities and bodies, with legal basis references for each listing. | Establishing whether a counterparty or its owner is restricted under EU measures and on what grounds. |
| OpenSanctions | Open | Aggregated sanctions, politically exposed person and watchlist data reconciled into a single entity model. | Fast cross jurisdictional screening and alias resolution when a name appears in multiple transliterations. |
| Global Legal Entity Identifier Foundation | Open | Reference data on legal entities including registered address, legal form and direct and ultimate parents. | Anchoring corporate identities and verifying claimed parentage in cross border ownership chains. |
| OpenCorporates | Registration | Company records aggregated from official registers across many jurisdictions with officer and filing history. | Finding front companies through shared directors, addresses and incorporation agents. Coverage varies by jurisdiction and filings are often stale. |
| OCCRP Aleph | Registration | Searchable archive of leaks, registries, court records and public documents assembled for investigative use. | Locating a named intermediary across document sets that no single registry search would reach. |
| UN Comtrade | Open | Reported international merchandise trade statistics by reporter, partner, commodity code and year. | Detecting anomalous flows of controlled commodity codes through transhipment jurisdictions. Compare mirrored reporting from both partners for discrepancies. |
| Bureau of Industry and Security Entity List | Open | United States export control listings identifying parties subject to licence requirements and the reason for listing. | Assessing whether a technology transfer or investment triggers export control exposure. Listing reasons matter as much as the listing itself. |
| UN Security Council Consolidated List and panel reports | Open | Multilateral designations plus expert panel documentation of evasion methods and named intermediaries. | Corroborating evasion typologies and identifying facilitators already documented by UN experts. Panel annexes frequently name companies and vessels directly. |
| Equasis | Registration | Ship particulars, registered owner, manager, classification and inspection history for the global merchant fleet. | Resolving beneficial ownership and management behind vessels in sanctioned trade. Management company changes are often the earliest signal. |
| C4ADS publications | Open | Open source investigations into illicit networks, procurement, sanctions evasion and maritime activity. | Methodological reference and named network baselines to build on rather than duplicate. |
| Citizen Lab research | Open | Technical documentation of state linked surveillance, spyware deployment and targeting of civil society. | Evidence base for transnational repression and surveillance technology export questions. Reports include indicators that can be checked independently. |
| National CERT and security agency advisories | Open | Government assessments of state linked cyber activity, including technical indicators and attribution statements. | Anchoring cyber elements of a state assessment to official, citable positions. Useful where an assessment must be defensible in public. |
| ACLED conflict event data | Registration | Coded political violence and protest events with actor, location, date and source notes. | Establishing baselines and detecting shifts in proxy or militia activity attributed to a sponsor. |
Prefer sources that publish a methodology and a revision history. A dataset that changes silently is a liability in any product that has to survive challenge.
Tooling
Tools commonly used against Nation State. None of these replace judgement, and each carries its own failure modes — know what a tool infers versus what it observes.
- Maltego — Graph based link analysis with connectors to registry, infrastructure and sanctions data. Limitation: transform quality varies and the graph flatters weak links visually.
- Neo4j or comparable graph database — Stores entity relationships at scale with query over paths and communities. Limitation: requires disciplined entity resolution upstream or the graph merges distinct people.
- Sayari or similar commercial network data — Licensed corporate and trade data with ownership inference across difficult jurisdictions. Limitation: inferred ownership is a model output and needs document verification before publication.
- Panjiva or ImportGenius trade records — Bill of lading level shipment records for some jurisdictions. Limitation: coverage is uneven and absence of a record proves nothing.
- MarineTraffic and vessel tracking — AIS derived position and port call history for merchant shipping. Limitation: AIS can be switched off, spoofed or manipulated, so gaps are the signal.
- Hunchly — Captures and hashes web pages during research with a full audit trail. Limitation: local to the researcher, so it supports but does not replace formal evidence handling.
- Structured analytic technique templates — Analysis of competing hypotheses, key assumptions check and indicator matrices in a shared workbook. Limitation: only useful if completed honestly before the judgement is written.
- Machine translation with human review — Rapid triage of foreign language filings and press. Limitation: legal and corporate terminology is frequently mistranslated in ways that reverse meaning.
AI skills and automation in detail
These are deterministic jobs with defined inputs and outputs, not open-ended prompting. Each is idempotent and cursor-based: interrupt one and it resumes where it stopped rather than duplicating work or losing progress.
- Threat Hunt — Runs saved hypotheses against the corpus and surfaces what matches, with the query preserved as a versioned artifact.
- Correlate Infrastructure — Builds the cross-entity link graph: shared hosting, reused certificates, overlapping registrants, repeated selectors.
- Run Alert Rules — Evaluates saved rules against new data so a first sighting raises a notification rather than waiting for review.
- Detection Rules — Generates YARA, Sigma and Snort/Suricata logic from the selected indicators, ready to deploy.
- Summarise (Copilot) — Produces a narrative summary beside the underlying records. It explains; it never creates indicators or assigns attribution.
- Generate Report — Assembles a sourced product from the current case or query, with provenance attached to each element.
A note on the boundary: the only skill that involves a language model is Summarise (Copilot), and it writes prose about records that already exist. Nothing else on this list involves generation of any kind. No indicator, relationship or attribution in the platform originates from a model. See the full skill list.
Tradecraft notes
The distinctions that separate a competent analyst from a fast one:
- Legal ownership, effective control and personal loyalty are three different graphs. A company can be privately owned, controlled through a supply contract and directed through a family relationship, and only the third explains its behaviour.
- Absence of a designation is not absence of risk. Sanctions lists lag reality by months or years, so treat a listing as confirmation of what analysis should already have flagged rather than as the trigger for looking.
- Transliteration is where entity resolution fails. Build variant tables for every name in the languages that matter, and search registries in the local script, because the English spelling in your report may never appear in the source data.
- The intermediary that appears in two unrelated cases is worth more analytic time than the principal. Principals change; the freight forwarder, incorporation agent and correspondent bank persist and are the durable chokepoints.
- Separate the question of who benefits from the question of who acted. Beneficiary reasoning is the weakest attribution input and the easiest for an adversary to manipulate through deliberate misdirection.
- Write the confidence statement before the narrative. If you cannot state confidence and the reason for it in one sentence, the judgement is not yet formed and the prose will conceal that.
- Track your withdrawn judgements. Services that keep a calibration log improve; those that only archive published products repeat the same failure modes for a decade.
Measuring whether it is working
Capability claims should be falsifiable. These are the measures that show whether work on Nation State is producing anything, and they are worth baselining before you change process or tooling.
- Proportion of assessments where the customer records that a decision was taken or changed, rather than raw dissemination counts.
- Time from first indication of a new procurement front to a documented entity record with sourced ownership and a screening recommendation.
- Calibration score of stated confidence against outcomes reviewed annually, including judgements later withdrawn or reversed.
- Share of network graph edges that can be traced to a dated primary document rather than to secondary reporting or inference.
- Number of independent lines of evidence supporting each published attribution claim, tracked as a distribution rather than an average.
- Reduction in repeat exposure after screening changes, measured as counterparties onboarded that later required unwinding.
- Analyst time spent on requirements formally retired as answered, as a share of total collection tasking.
Beware of measuring volume alone. Indicator counts and report counts rise easily and say little; time-to-attribution, proportion of findings that survive review, and how often a product changed a decision say a great deal.
Common pitfalls
- Mirror-imaging: assuming a foreign service weighs risk, cost and escalation the way your own institutions would
- Assuming central direction over proxies and contractors that in practice operate with wide discretion and their own commercial motives
- Reading state media output as a statement of intent rather than as a message aimed at a domestic or third-party audience
- Treating infrastructure nationality, hosting location or keyboard layout as evidence of state sponsorship
- Relying on stale sanctions data: designations change, and delisted or renamed entities reappear behind new registrations
- Letting a single defector, exile or vendor account anchor an assessment that later reporting is then read to confirm
Legal and ethical considerations
Work in this domain sits close to sanctions and export-control law, so screening counterparties and documenting the basis for any designation claim matters as much as the analysis itself. Avoid collection against protected persons without authority, keep classified and open-source material in separate systems, and be precise about the difference between a designated entity and an unproven allegation. Naming individuals engages data protection and defamation exposure in most jurisdictions, and disclosure to commercial clients may itself carry licensing implications.
Data integrity: no fabrication, no drift, no hallucination
Intelligence that cannot be traced back to a source is not intelligence, it is assertion. Everything in this entry — and everything in the platform behind it — is built on a small number of non-negotiable rules.
Provenance on every record
Every indicator carries the source that supplied it, a first-seen and last-seen timestamp, and a sighting count. Where several feeds report the same artifact, each contribution is recorded separately rather than collapsed, so you can see whether a finding rests on one source or twelve. Source attribution travels with the data into every export, so a recipient can audit a claim without asking you for the working.
Nothing is invented to fill a gap
If the platform has no data for Nation State, it says so. Empty is displayed as empty — never padded with plausible-looking placeholder values, sample records or illustrative examples that a reader might mistake for observations. A dashboard with no rows is a true statement about collection coverage, and it is treated as a gap to close, not a blemish to hide.
Scoring is deterministic and reproducible
Threat scores, reputation grades and risk tiers are computed from stated inputs with fixed weights, not estimated. The same inputs always produce the same output, and the formula is visible rather than a black box. Aggregates are cached with an explicit time-to-live so a figure on screen is never silently stale — and when a heavy query exceeds its time budget the platform serves the last known-good value and labels it, rather than inventing a fresh number or hanging.
Where AI is used, and where it is not
Language models summarise and explain. They do not create indicators, assign attribution or manufacture relationships. No IP address, wallet, hash or identity in the platform originates from a model — every one is ingested from a named feed, resolved from a reference dataset, or entered by an analyst with a source recorded. Copilot output is presented as narrative alongside the underlying records, never in place of them, so a reader can always check the summary against the evidence.
Guarding against drift
Enrichment is additive and timestamped rather than overwriting. Reference data — sanctions lists, allocations, taxonomies — is re-synchronised from the authority on a schedule instead of being edited in place, so local copies cannot quietly diverge from the source of truth. Attribution is recorded with a confidence level and the reporting it rests on, and inferred relationships are labelled as inferred. When a source retracts or corrects, the correction propagates rather than leaving a stale assertion behind.
What this means for you
You can put a finding from this platform in front of a regulator, a court, a board or a partner agency and show where each element came from. That is the standard the tooling is built to — because in this work, being confidently wrong is more damaging than being usefully uncertain.
By the numbers
The taxonomy this entry belongs to is not a marketing list — it is the actual structure of the platform: 52 mission domains, 52 intelligence disciplines and 65 data points, each with a live dashboard behind it. Supporting that: 18 indicator types, 14 playbooks, 16 AI skills, 18 export formats and a 30-step automated pipeline.
This particular entry connects directly to 8 intelligence disciplines, 8 data points, 6 closely related entries — every one of them a tag you can follow, and a dashboard you can open.
Questions analysts actually ask
When is attribution to a state defensible rather than speculative?
When you can separate four judgements and evidence each: who built the capability, who operated the infrastructure, who tasked the operation and who benefits. A defensible attribution names the confidence for each layer and identifies the evidence that carries the most weight. Circumstantial patterns such as working hours, language artefacts and target selection support a judgement but cannot found one alone, because all three are cheap to fake. If your case rests entirely on beneficiary reasoning, you have a hypothesis rather than an attribution, and the honest product says so in the first paragraph.
How do we handle a private client asking us to investigate a foreign government?
Scope it to what a private actor may lawfully do: public registries, filings, litigation records, trade data, licensed screening tools and open source research. You may not intercept communications, obtain telecoms or government data by pretext, deploy intrusive surveillance against individuals, or run agents. Consider foreign agent registration exposure if the work is directed by or benefits a foreign principal, and take advice on that early. Write the report expecting disclosure in litigation or to a regulator, which means sourcing every claim and separating fact from inference throughout.
Can intelligence reporting be used to support a prosecution?
Rarely in the form it was written. Intelligence reporting is usually inadmissible, protected by public interest immunity or subject to originator control, and its sourcing cannot be disclosed. The standard route is to use it as a lead and then collect the same facts through evidential means: production orders, mutual legal assistance, search, or open sources that can be exhibited. Plan that conversion at the start of the case rather than at charging stage, and keep the intelligence and evidence chains documented separately so the boundary is never unclear.
What distinguishes state directed activity from state tolerated activity?
Direction implies tasking, resourcing and accountability inside a state structure; toleration means the state declines to act against activity that serves its interests. The practical indicators differ. Direction shows up as consistent targeting aligned to a policy calendar, resource levels no criminal group would sustain and deconfliction between actors. Toleration shows up as impunity: known individuals operating openly, no prosecutions despite evidence, and travel or banking access that a genuinely pursued suspect would not have. The distinction matters because it changes which levers, diplomatic or law enforcement, actually work.
How should we treat leaked documents about a foreign state?
Authenticate before you rely on them. Establish provenance as far as you can describe it publicly, check internal consistency, verify names, dates, formats and identifiers against independent records, and look for the small errors that forgeries contain. Assume some leaks are seeded with altered material to discredit reporting or to expose the recipient. Assess public interest against harm to named individuals, and redact where publication would endanger someone. Where documents cannot be authenticated, either do not use them or describe precisely what you could and could not verify.
What is the most common analytic failure in this domain?
Treating the state as a single rational actor. Real governments contain competing services, ministries with commercial interests, contractors billing per result and factions pursuing personal enrichment under a policy banner. Assessments that assume a unified intent explain too much and predict too little. The corrective is structural: map who inside the state actually gains from the observed activity, ask whether an outcome is more consistent with coordination or with two agencies working at cross purposes, and say so explicitly when the evidence supports internal contradiction.
Standards, frameworks and further reading
Work that references a recognised framework is easier to defend, easier to hand over, and easier for a partner to consume:
- ICD 203 Analytic Standards, which sets objectivity, sourcing, alternative analysis and estimative language requirements for United States intelligence products.
- ICD 206 Sourcing Requirements, governing how source descriptions and reliability statements appear in finished intelligence.
- Admiralty or NATO source reliability and information credibility grading, used to score source and content independently.
- Traffic Light Protocol version 2.0 from FIRST, which governs onward sharing of sensitive material between organisations.
- OECD Due Diligence Guidance for Responsible Business Conduct, which frames counterparty and supply chain risk expectations for private actors.
- Wassenaar Arrangement control lists and national export control regimes, which define what technology transfer requires a licence.
- UN Charter Chapter VII sanctions regimes and the national implementing legislation that makes breaches criminal offences.
- Berkeley Protocol on Digital Open Source Investigations, which sets method and preservation standards for open source evidence intended for accountability use.
References
Primary sources and authoritative references for this entry. Publishers revise and retire material, so treat the retrieval date as part of the citation and re-check before relying on any of it in a formal product.
- Specially Designated Nationals and Blocked Persons List — US Department of the Treasury, Office of Foreign Assets Control. Authoritative United States designation list and programme documentation.
- EU Sanctions Map — European Union. Reference tool describing each EU restrictive measures regime and its legal basis.
- Global LEI Index — Global Legal Entity Identifier Foundation. Open reference data on legal entities and their ownership relationships.
- OpenSanctions dataset — OpenSanctions. Open aggregation of sanctions and watchlist data with entity reconciliation.
- Analytic Standards and tradecraft guidance — Office of the Director of National Intelligence. Published standards governing analytic rigour and estimative language.
- Berkeley Protocol on Digital Open Source Investigations — UN Office of the High Commissioner for Human Rights. Methodological standard for open source investigation intended for legal accountability.
- Investigations into illicit networks and procurement — C4ADS. Open source research reports documenting sanctions evasion and network structures.
- Export administration regulations and Entity List — Bureau of Industry and Security, US Department of Commerce. United States export control framework and restricted party listings.
Link integrity: every reference above was verified with a live request when this page was generated. Where a publisher had moved or withdrawn a document, the link was repointed at a preserved copy in the Internet Archive and marked as archived. Anything with no reachable copy anywhere had its link removed rather than left to rot — the source is still credited, it simply cannot be linked.
Put it into practice
The Quantus Intel threat intelligence platform operationalises this entry: maps state-linked entities, front companies and sanctioned intermediaries across registries, trade records and designation feeds. Explore the platform, or browse the rest of the library by following any tag above.