August 7, 2026

The Quantus Intelligence Library: 52 Mission Domains, 52 Disciplines, 65 Data Points

0

The complete index to 169 field guides covering every mission domain we work, every intelligence discipline we practise, and every data point we pivot on.

quantus-intelligence-library

This is the index to the Quantus Intelligence Library: 52 mission domains, 52 intelligence disciplines, and 65 data points — 169 field guides that together describe what we work on, how we work it, and what we work it with.

How the library is organised

Intelligence work has three axes, and confusing them is the source of most bad analysis. A mission domain is what you are working on — ransomware, sanctions evasion, human trafficking. An intelligence discipline is how you work it — the tradecraft of collection and analysis, such as FININT, GEOINT or CRYPTINT. A data point is what you work it with — the atomic artifact you pivot on, like an IP address, an IBAN, or a vessel IMO number.

Every article in this library is tagged on all three axes. A ransomware investigation is tagged with the disciplines it draws on and the data points it turns on; the CRYPTINT article is tagged back to ransomware, fraud and sanctions evasion. Follow any tag and you move sideways through the whole system rather than hitting a dead end.

The three top-level tags

Mission domains — what we work on

Fifty-two problem spaces, from nation-state operations and ransomware through financial crime, trafficking, environmental crime and conflict. Each guide covers the signals that matter, the authoritative sources, a working method, and the legal ground you must stand on.

Intelligence disciplines — how we work it

Fifty-two collection and analysis methods. Disciplines are the tradecraft: each one answers questions no other discipline can, and each carries its own legal and ethical constraints.

Cyber & Threat

Environmental

Financial

General

Geospatial

Governance

Health

Human

Identity

Information

Infrastructure

Law Enforcement

Research & Technical

Technical

Transportation

WMD & Proliferation

Data points — what we work it with

Sixty-five atomic artifacts. Each guide explains what the artifact is, what you can legitimately derive from it, how to enrich it, what it pivots to — and the ways it will mislead you if you take it at face value.

Analysis

  • Keyword / Narrative: A search term, topic, hashtag, or narrative tracked across media and platforms.
  • Event / Incident: A discrete real-world occurrence — protest, strike, breach, seizure — with time, place, and actors.

Aviation

  • Flight Number / Route: A scheduled flight designator and its route — pivots to aircraft, operator, and movement history.

Code & Supply

  • Code Repository: A source-code repository — leaks secrets, reveals developers, and anchors supply-chain risk.
  • Software Package: A published dependency (npm, PyPI, Maven) — the vector for supply-chain compromise.

Communications

  • Messaging Handle: An identity on a messaging platform (Telegram, Signal, Discord) used for coordination and sales.
  • Email Header: Full message headers exposing routing, originating IP, authentication, and mailer artifacts.

Corporate

  • Company / Organization: A legal entity — corporation, LLC, NGO, or business.
  • Patent: An intellectual property filing granting invention rights.
  • Legal Entity Identifier: A 20-character global identifier for a legal entity participating in financial transactions.
  • Corporate Filing: A regulatory or corporate filing (SEC, Companies House, court).
  • Tax ID / VAT Number: A jurisdiction-issued tax registration number for a person or entity.

Cyber

Dark & Leak

  • Paste / Leak Post: Text posted to a paste site or leak forum — a frequent first appearance of stolen data.

Financial

Geospatial

  • Location / Coordinates: A geographic point, place, or region — the basis of GEOINT analysis.
  • GPS Coordinates: Precise latitude/longitude coordinates identifying an exact point on Earth — the atomic unit of GEOINT analysi
  • Facility / Site: A physical installation — plant, base, port, data centre — with a fixed footprint and function.
  • Satellite Imagery: Overhead imagery of an area of interest, used for change detection and site analysis.

Identity

  • Person / Name: A named individual — the subject of identity resolution and profiling.
  • Email Address: Electronic mail address tied to an individual or organization.
  • Username / Handle: Screen name or handle used across online platforms and services.
  • Phone Number: Telephone number for voice, SMS, or messaging identification.
  • Physical Address: A physical or mailing address tied to a person, company, or registered entity.
  • Social Profile: A social media profile or online account page tied to a persona or identity.
  • Device / Advertising ID: A mobile advertising or device identifier used in adtech data to track and locate devices.
  • National ID Number: A government-issued personal identification number — highly sensitive PII.
  • Biometric Identifier: Face, fingerprint, iris, gait, or voice templates used for identification — most sensitive PII class.

Legal

  • Court Case / Docket: A filed legal proceeding — the authoritative record of disputes, judgments, and enforcement.
  • Real Property / Parcel: A land or building record — deeds, title, valuation, and ownership history.

Media

  • Image / Photograph: A still image — carries EXIF metadata and is the primary artifact for visual verification.
  • Video: A video file or stream — the core artifact for incident verification and chronolocation.

Network

  • Domain Name: Human-readable address that maps to IP infrastructure via DNS.
  • IP Address: Internet Protocol address identifying a device or server on a network.
  • URL: Uniform Resource Locator pointing to a web resource.
  • ASN: Autonomous System Number identifying a network operator on the internet.
  • Subdomain: A host under a parent domain — often reveals staging, admin, and forgotten infrastructure.
  • IP Range / CIDR: A block of IP addresses expressed in CIDR notation — the unit of network ownership and allocation.
  • MAC Address: Hardware address of a network interface; the OUI prefix identifies the manufacturer.
  • Wi-Fi BSSID: The MAC address of a wireless access point — geolocatable via wardriving databases.
  • DNS Record: An individual DNS resource record (A, MX, TXT, NS, CNAME) exposing hosting and mail posture.
  • TLS / JA3 Fingerprint: A hash of TLS client-hello parameters used to fingerprint clients, malware, and C2 frameworks.

Signals

  • Radio Callsign: A licensed radio identifier for a station, vessel, aircraft, or operator.

Telephony

Threat

  • Detection Signature: A YARA/Sigma/Snort rule encoding detection logic for a malware family or behavior.
  • Credential / API Token: An exposed secret — API key, token, or JWT — granting access to systems and data.

Trade

  • HS Commodity Code: The Harmonized System code classifying a traded good — the key to trade-flow analysis.
  • Shipment / Bill of Lading: A consignment record linking shipper, consignee, goods, and route.
  • Shipping Container: An ISO container identifier — trackable across ports, vessels, and customs events.

Transportation

  • Vessel / Ship: A maritime vessel identified by IMO, MMSI, or call sign.
  • Aircraft: An aircraft identified by tail number, ICAO hex, or registration.

Vehicle

  • Vehicle Identification Number: A 17-character globally unique vehicle identifier encoding manufacturer, model, and year.
  • License Plate: A jurisdiction-issued vehicle registration mark — the primary field identifier for a vehicle.

Using the library

Start from whichever axis matches your question. If you have been handed a problem — an extortion case, a sanctions query — start in the mission domain. If you have been handed an artifact — a wallet address, a container number — start in the data point. If you are building capability, start in the discipline and work outward to the domains that need it.

The platform behind the library

This taxonomy is not documentation written after the fact — it is the structure of the Quantus Intel threat intelligence platform itself. Every entry above has a live dashboard behind it.

  • 204 application pages behind a 147-item sidebar, grouped into Command (24), Dashboards (15), Threat Theaters (14), Intelligence Domains (15), Investigate (34) and Administration (45).
  • 18 indicator types — IP, CIDR, domain, subdomain, URL, ASN, five hash classes, CVE, email, phone, onion, and five cryptocurrency address families — each with its own profile page and enrichment path.
  • 14 incident playbooks and 16 one-click AI skills, from sanctions screening and trafficking triage to ransomware, BEC, crypto tracing and insider review.
  • A 30-step automation pipeline built from 25 seeders, 11 resolvers and 7 enrichment runners — all idempotent and cursor-based, so runs resume rather than restart.
  • 18 export formats and 11 REST endpoints, plus a TAXII 2.1 server and MISP feed — so findings reach your SIEM, IDS and firewall without manual reformatting.

Data integrity: no fabrication, no drift, no hallucination

A library like this is only worth reading if the system behind it is honest about what it knows. Four rules govern every record.

Provenance on everything. Each indicator carries its source, first-seen and last-seen timestamps, and a sighting count. Multiple feeds reporting the same artifact are recorded separately rather than merged, so you can tell a finding backed by one source from one backed by twelve — and that attribution travels into every export.

Nothing invented to fill a gap. Where there is no data, the platform shows none. No placeholder rows, no illustrative samples, no plausible-looking filler. An empty dashboard is a true statement about collection coverage and is treated as a gap to close.

Deterministic scoring. Threat scores, reputation grades and risk tiers are computed from stated inputs with fixed weights. Same inputs, same output, every time. Cached aggregates carry an explicit lifetime, and a query that exceeds its time budget serves the last known-good value rather than fabricating a fresh one.

AI summarises; it never authors. No indicator, attribution or relationship in the platform originates from a language model. Every one is ingested from a named feed, resolved from a reference dataset, or entered by an analyst with a source recorded. Model output appears as narrative beside the underlying records, never instead of them.

The practical test: you should be able to put any finding from this platform in front of a regulator, a court, a board or a partner agency and show exactly where each element came from.

Leave a Reply

Your email address will not be published. Required fields are marked *