The Quantus Intelligence Library: 52 Mission Domains, 52 Disciplines, 65 Data Points
The complete index to 169 field guides covering every mission domain we work, every intelligence discipline we practise, and every data point we pivot on.
This is the index to the Quantus Intelligence Library: 52 mission domains, 52 intelligence disciplines, and 65 data points — 169 field guides that together describe what we work on, how we work it, and what we work it with.
How the library is organised
Intelligence work has three axes, and confusing them is the source of most bad analysis. A mission domain is what you are working on — ransomware, sanctions evasion, human trafficking. An intelligence discipline is how you work it — the tradecraft of collection and analysis, such as FININT, GEOINT or CRYPTINT. A data point is what you work it with — the atomic artifact you pivot on, like an IP address, an IBAN, or a vessel IMO number.
Every article in this library is tagged on all three axes. A ransomware investigation is tagged with the disciplines it draws on and the data points it turns on; the CRYPTINT article is tagged back to ransomware, fraud and sanctions evasion. Follow any tag and you move sideways through the whole system rather than hitting a dead end.
The three top-level tags
mission_domain— all 52 mission domain guides.intel_discipline— all 52 intelligence discipline guides.data_point— all 65 data point guides.
Mission domains — what we work on
Fifty-two problem spaces, from nation-state operations and ransomware through financial crime, trafficking, environmental crime and conflict. Each guide covers the signals that matter, the authoritative sources, a working method, and the legal ground you must stand on.
- Nation State (8 disciplines, 8 data points)
- APT / Espionage (8 disciplines, 8 data points)
- Cyber Crime (7 disciplines, 8 data points)
- Ransomware (7 disciplines, 8 data points)
- Dark Web Intel (7 disciplines, 7 data points)
- Malware (6 disciplines, 8 data points)
- Threat Analysis (6 disciplines, 6 data points)
- Critical Infrastructure (7 disciplines, 7 data points)
- Operational Security (6 disciplines, 7 data points)
- Insider Threat (6 disciplines, 7 data points)
- Emerging Technology & AI Security (6 disciplines, 6 data points)
- Organized Crime (7 disciplines, 7 data points)
- Drug Trafficking (7 disciplines, 7 data points)
- Human Trafficking (7 disciplines, 7 data points)
- Weapons Trafficking (7 disciplines, 7 data points)
- Wildlife Trafficking (6 disciplines, 7 data points)
- Child Protection (6 disciplines, 7 data points)
- Gangs & Street Crime (6 disciplines, 7 data points)
- Kidnap, Hostage & Extortion (7 disciplines, 6 data points)
- Counterfeiting & IP Crime (6 disciplines, 7 data points)
- Art & Antiquities Trafficking (6 disciplines, 7 data points)
- Mining & Resource Crime (7 disciplines, 7 data points)
- Forced Labour & Modern Slavery (6 disciplines, 6 data points)
- Financial Crime (7 disciplines, 7 data points)
- Anti-Money Laundering (7 disciplines, 7 data points)
- Sanctions Evasion (7 disciplines, 7 data points)
- Fraud & Identity (7 disciplines, 8 data points)
- Economic Espionage (7 disciplines, 6 data points)
- Supply Chain Security (7 disciplines, 7 data points)
- Corruption & Governance (7 disciplines, 7 data points)
- Counter-Terrorism (7 disciplines, 7 data points)
- Extremism & Radicalization (6 disciplines, 7 data points)
- WMD / Proliferation (7 disciplines, 7 data points)
- Military & Defense (8 disciplines, 7 data points)
- Conflict & Humanitarian (7 disciplines, 7 data points)
- Transnational Repression (7 disciplines, 7 data points)
- Border Security & Migration (7 disciplines, 6 data points)
- Environmental Crime (6 disciplines, 7 data points)
- Climate Security (6 disciplines, 6 data points)
- Energy Security (7 disciplines, 7 data points)
- Water Security (6 disciplines, 5 data points)
- Food & Agricultural Security (6 disciplines, 6 data points)
- Maritime Security (7 disciplines, 7 data points)
- Maritime Piracy (6 disciplines, 6 data points)
- Biosecurity & Pandemic (6 disciplines, 6 data points)
- Healthcare & Drug Security (6 disciplines, 6 data points)
- Space & Satellite Intel (7 disciplines, 6 data points)
- RF & Signals Intel (7 disciplines, 6 data points)
- Aviation Security (6 disciplines, 6 data points)
- Election Security & PSYOP (6 disciplines, 7 data points)
- Disinformation / IO (6 disciplines, 7 data points)
- Risk Analysis (7 disciplines, 5 data points)
Intelligence disciplines — how we work it
Fifty-two collection and analysis methods. Disciplines are the tradecraft: each one answers questions no other discipline can, and each carries its own legal and ethical constraints.
Cyber & Threat
- ASMINT — Attack Surface Intelligence: Your Own Exposed Attack Surface
- BREACHINT — Breach Intelligence: Exposed Credentials and Compromised Data
- CERTINT — Certificate Intelligence: TLS Certificates and Certificate Transparency
- CYBINT — Cyber Intelligence: Adversary Activity in Networks and Systems
- DARKINT — Dark Web Intelligence: Hidden Services and Closed Criminal Venues
- DOMINT — Domain Intelligence: Domains, DNS, and Registration Intelligence
- MALINT — Malware Intelligence: Understanding Malicious Code
- NETINT — Network Intelligence: Networks, Routing, and Internet Infrastructure
- PASTINT — Paste Site Intelligence: Paste Sites and Leaked Text Dumps
- ACTORINT — Threat Actor Intelligence: Tracking Adversary Groups Over Time
- VULNINT — Vulnerability Intelligence: Weaknesses, Exploitation, and Prioritization
Environmental
- ENVINT — Environmental Intelligence: Environmental Conditions, Damage, and Crime
- METOCINT — Meteorological Intelligence: Weather, Ocean, and Atmospheric Conditions
Financial
- ACCTINT — Accounting Intelligence: Financial Statements and Accounting Analysis
- CORPINT — Corporate Intelligence: Understanding Companies, Structure, and Control
- CRYPTINT — Cryptocurrency Intelligence: Tracing Value on Public Ledgers
- ECONINT — Economic Intelligence: Economic Conditions, Trade, and Market Signals
- FININT — Financial Intelligence: Following Value Through the Financial System
- SANCINT — Sanctions Intelligence: Screening, Designations, and Evasion Detection
General
- OSINT — Open Source Intelligence: Publicly Available Information, Systematically Collected
- REFINT — Reference Intelligence: Authoritative Reference Data and Standards
- RISKINT — Risk Intelligence: Structured Assessment of Threat and Consequence
Geospatial
- GEOINT — Geospatial Intelligence: Intelligence Derived from Place
- IMINT — Imagery Intelligence: Interpretation of Visual Imagery
Governance
- ELECTINT — Election Intelligence: Electoral Processes, Integrity, and Threats
- GOVINT — Government Intelligence: Government Structures, Policy, and Officials
Health
- EPIINT — Epidemiological Intelligence: Disease Occurrence, Spread, and Public Health Threats
- MEDINT — Medical Intelligence: Health Systems, Capability, and Medical Threats
Human
- HUMINT — Human Intelligence: Information from People, Ethically Obtained
- SOCMINT — Social Media Intelligence: Intelligence from Social Platforms and Networks
Identity
- EMAILINT — Email Intelligence: Email Addresses, Headers, and Mail Infrastructure
- IDENT — Identity Intelligence: Resolving and Verifying Who Someone Is
- TELINT — Telephony Intelligence: Phone Numbers, Networks, and Telephony Data
Information
- DISINFOINT — Disinformation Intelligence: Detecting and Analyzing Information Manipulation
- NEWSINT — News Intelligence: Media Reporting as an Intelligence Source
Infrastructure
- ENERGYINT — Energy Intelligence: Energy Production, Transport, and Markets
Law Enforcement
- CRIMINT — Criminal Intelligence: Intelligence Supporting Criminal Investigation
- LEGINT — Legal Intelligence: Law, Litigation, and Regulatory Intelligence
Research & Technical
- ACADINT — Academic Intelligence: Research Output, Collaboration, and Expertise
- PATENTINT — Patent Intelligence: Patents, Filings, and Innovation Signals
- TECHINT — Technical Intelligence: Technology Capability, Design, and Exploitation
Technical
- MASINT — Measurement & Signature Intel: Signatures, Measurements, and Physical Phenomena
- RFINT — Radio Frequency Intelligence: The Electromagnetic Spectrum as an Intelligence Source
- SIGINT — Signals Intelligence: Intelligence from Intercepted Communications and Emissions
- SPACEINT — Space Intelligence: Orbital Activity, Space Assets, and Counterspace
Transportation
- AVINT — Aviation Intelligence: Aircraft, Flights, and the Aviation Domain
- LOGINT — Logistics Intelligence: Cargo, Freight, and Physical Movement
- MARINT — Maritime Intelligence: Vessels, Shipping, and the Maritime Domain
- SUPPLYINT — Supply Chain Intelligence: Supplier Networks, Dependencies, and Integrity
- VEHINT — Vehicle Intelligence: Vehicles, Registration, and Movement
WMD & Proliferation
- CBRNINT — CBRN Intelligence: Chemical, Biological, Radiological, and Nuclear Threats
- WEAPINT — Weapons Intelligence: Weapons Systems, Capability, and Trafficking
Data points — what we work it with
Sixty-five atomic artifacts. Each guide explains what the artifact is, what you can legitimately derive from it, how to enrich it, what it pivots to — and the ways it will mislead you if you take it at face value.
Analysis
- Keyword / Narrative: A search term, topic, hashtag, or narrative tracked across media and platforms.
- Event / Incident: A discrete real-world occurrence — protest, strike, breach, seizure — with time, place, and actors.
Aviation
- Flight Number / Route: A scheduled flight designator and its route — pivots to aircraft, operator, and movement history.
Code & Supply
- Code Repository: A source-code repository — leaks secrets, reveals developers, and anchors supply-chain risk.
- Software Package: A published dependency (npm, PyPI, Maven) — the vector for supply-chain compromise.
Communications
- Messaging Handle: An identity on a messaging platform (Telegram, Signal, Discord) used for coordination and sales.
- Email Header: Full message headers exposing routing, originating IP, authentication, and mailer artifacts.
Corporate
- Company / Organization: A legal entity — corporation, LLC, NGO, or business.
- Patent: An intellectual property filing granting invention rights.
- Legal Entity Identifier: A 20-character global identifier for a legal entity participating in financial transactions.
- Corporate Filing: A regulatory or corporate filing (SEC, Companies House, court).
- Tax ID / VAT Number: A jurisdiction-issued tax registration number for a person or entity.
Cyber
- File Hash: Cryptographic fingerprint of a file, used for malware identification.
- CVE / Vulnerability: Common Vulnerabilities and Exposures identifier for a known flaw.
- SSL/TLS Certificate: A digital certificate binding a public key to an identity.
- Malware Family: A named class of related malicious software.
- File / Document: A file or document artifact — malware sample, leaked document, image, or email attachment.
- Onion / Hidden Service: A Tor hidden service address on the dark web.
- Data Breach: A known data breach or leak incident with exposed records.
- Password / Credential: An exposed password or credential pair from leaks or dumps.
Dark & Leak
- Paste / Leak Post: Text posted to a paste site or leak forum — a frequent first appearance of stolen data.
Financial
- Cryptocurrency Address: Blockchain wallet address for receiving or sending crypto assets.
- Transaction Hash: A blockchain transaction identifier for tracing fund flows.
- Stock Ticker / Security: An exchange-listed security symbol, pivoting to filings, ownership, and market data.
- Sanction / Watchlist Entry: An entry on a sanctions list, watchlist, or PEP database.
- Bank Account / IBAN: A bank account identifier (IBAN, SWIFT/BIC, routing + account) central to financial tracing.
Geospatial
- Location / Coordinates: A geographic point, place, or region — the basis of GEOINT analysis.
- GPS Coordinates: Precise latitude/longitude coordinates identifying an exact point on Earth — the atomic unit of GEOINT analysi
- Facility / Site: A physical installation — plant, base, port, data centre — with a fixed footprint and function.
- Satellite Imagery: Overhead imagery of an area of interest, used for change detection and site analysis.
Identity
- Person / Name: A named individual — the subject of identity resolution and profiling.
- Email Address: Electronic mail address tied to an individual or organization.
- Username / Handle: Screen name or handle used across online platforms and services.
- Phone Number: Telephone number for voice, SMS, or messaging identification.
- Physical Address: A physical or mailing address tied to a person, company, or registered entity.
- Social Profile: A social media profile or online account page tied to a persona or identity.
- Device / Advertising ID: A mobile advertising or device identifier used in adtech data to track and locate devices.
- National ID Number: A government-issued personal identification number — highly sensitive PII.
- Biometric Identifier: Face, fingerprint, iris, gait, or voice templates used for identification — most sensitive PII class.
Legal
- Court Case / Docket: A filed legal proceeding — the authoritative record of disputes, judgments, and enforcement.
- Real Property / Parcel: A land or building record — deeds, title, valuation, and ownership history.
Media
- Image / Photograph: A still image — carries EXIF metadata and is the primary artifact for visual verification.
- Video: A video file or stream — the core artifact for incident verification and chronolocation.
Network
- Domain Name: Human-readable address that maps to IP infrastructure via DNS.
- IP Address: Internet Protocol address identifying a device or server on a network.
- URL: Uniform Resource Locator pointing to a web resource.
- ASN: Autonomous System Number identifying a network operator on the internet.
- Subdomain: A host under a parent domain — often reveals staging, admin, and forgotten infrastructure.
- IP Range / CIDR: A block of IP addresses expressed in CIDR notation — the unit of network ownership and allocation.
- MAC Address: Hardware address of a network interface; the OUI prefix identifies the manufacturer.
- Wi-Fi BSSID: The MAC address of a wireless access point — geolocatable via wardriving databases.
- DNS Record: An individual DNS resource record (A, MX, TXT, NS, CNAME) exposing hosting and mail posture.
- TLS / JA3 Fingerprint: A hash of TLS client-hello parameters used to fingerprint clients, malware, and C2 frameworks.
Signals
- Radio Callsign: A licensed radio identifier for a station, vessel, aircraft, or operator.
Telephony
- Cell Tower / Cell ID: A mobile network cell identifier (MCC/MNC/LAC/CID) usable for coarse device geolocation.
- IMEI / Device Identifier: A unique mobile-equipment identifier; the TAC prefix identifies make and model.
Threat
- Detection Signature: A YARA/Sigma/Snort rule encoding detection logic for a malware family or behavior.
- Credential / API Token: An exposed secret — API key, token, or JWT — granting access to systems and data.
Trade
- HS Commodity Code: The Harmonized System code classifying a traded good — the key to trade-flow analysis.
- Shipment / Bill of Lading: A consignment record linking shipper, consignee, goods, and route.
- Shipping Container: An ISO container identifier — trackable across ports, vessels, and customs events.
Transportation
- Vessel / Ship: A maritime vessel identified by IMO, MMSI, or call sign.
- Aircraft: An aircraft identified by tail number, ICAO hex, or registration.
Vehicle
- Vehicle Identification Number: A 17-character globally unique vehicle identifier encoding manufacturer, model, and year.
- License Plate: A jurisdiction-issued vehicle registration mark — the primary field identifier for a vehicle.
Using the library
Start from whichever axis matches your question. If you have been handed a problem — an extortion case, a sanctions query — start in the mission domain. If you have been handed an artifact — a wallet address, a container number — start in the data point. If you are building capability, start in the discipline and work outward to the domains that need it.
The platform behind the library
This taxonomy is not documentation written after the fact — it is the structure of the Quantus Intel threat intelligence platform itself. Every entry above has a live dashboard behind it.
- 204 application pages behind a 147-item sidebar, grouped into Command (24), Dashboards (15), Threat Theaters (14), Intelligence Domains (15), Investigate (34) and Administration (45).
- 18 indicator types — IP, CIDR, domain, subdomain, URL, ASN, five hash classes, CVE, email, phone, onion, and five cryptocurrency address families — each with its own profile page and enrichment path.
- 14 incident playbooks and 16 one-click AI skills, from sanctions screening and trafficking triage to ransomware, BEC, crypto tracing and insider review.
- A 30-step automation pipeline built from 25 seeders, 11 resolvers and 7 enrichment runners — all idempotent and cursor-based, so runs resume rather than restart.
- 18 export formats and 11 REST endpoints, plus a TAXII 2.1 server and MISP feed — so findings reach your SIEM, IDS and firewall without manual reformatting.
Data integrity: no fabrication, no drift, no hallucination
A library like this is only worth reading if the system behind it is honest about what it knows. Four rules govern every record.
Provenance on everything. Each indicator carries its source, first-seen and last-seen timestamps, and a sighting count. Multiple feeds reporting the same artifact are recorded separately rather than merged, so you can tell a finding backed by one source from one backed by twelve — and that attribution travels into every export.
Nothing invented to fill a gap. Where there is no data, the platform shows none. No placeholder rows, no illustrative samples, no plausible-looking filler. An empty dashboard is a true statement about collection coverage and is treated as a gap to close.
Deterministic scoring. Threat scores, reputation grades and risk tiers are computed from stated inputs with fixed weights. Same inputs, same output, every time. Cached aggregates carry an explicit lifetime, and a query that exceeds its time budget serves the last known-good value rather than fabricating a fresh one.
AI summarises; it never authors. No indicator, attribution or relationship in the platform originates from a language model. Every one is ingested from a named feed, resolved from a reference dataset, or entered by an analyst with a source recorded. Model output appears as narrative beside the underlying records, never instead of them.
The practical test: you should be able to put any finding from this platform in front of a regulator, a court, a board or a partner agency and show exactly where each element came from.