Showing posts with label intelligence. Show all posts
Showing posts with label intelligence. Show all posts

Friday, January 16, 2026

An Intelligence Training Tool - and a fun game!

Did you know that the Central Intelligence Agency (CIA) uses games to train its analysts? Let's talk about that!

Today, I'm continuing to discuss intelligence techniques, but I'm doing so by looking at a card game called "Collect It All". This game was developed by a CIA intelligence analyst named David Clopper, and was used to teach new recruits at the agency about collection techniques. Originally it was classified "Top Secret", but (after some redactions) it was released into the public domain.

The game can be played in one of two ways - cooperational or confrontational. In confrontational play, the players are different intelligence teams or groups competing with each other, while in coop play they are all on the same team.

There are several kinds of cards in the game, divided into two decks: the crisis deck and the collection deck.

The crisis deck includes a number of possible crises that the players have to avert by gathering enough intelligence based on the difficulty of the card representing that crisis. Every crisis card has a difficulty rating between 1 and 9, as well as symbols indicating which of the intelligence aspects (political, military, economic, and/or weapons) the crisis involves. Each crisis also has a point value between 1 and 3, indicated by dots in the top-right corner of the card - these are used in confrontational play, as the first play to resolve ten points of crises wins.

The crisis deck with a few of its cards.

The collection deck has three kinds of cards: technique cards (divided into HUMINT, GEOINT, MASINT, SIGINT, and OSINT), "Reality Check" cards which can help or block a technique card, and "Resolution/Manager Challenge" cards - the resolution aspect of these cards is used in cooperative play to determine if a crisis was resolved successfully, and the manager challenge aspect can be used in an advanced form of confrontational play to force the player to explain how the technique actually applies. (These latter cards are removed for a simpler confrontational-play game.)

Reality Check cards can help or block a technique

Resolution/Manager Challenge cards

Basically, you use technique cards to gather information about a crisis, provided that a) the range of the technique is at least as high as the difficulty of the challenge, and b) the technique card matches at least one of the intelligence aspects of the crisis (political, military, economic, and/or weapons, as stated before). The difficulty of the crisis determines how many successful techniques are needed to defuse that crisis, so for a three-point crisis card you'll need to play three techniques that aren't countered by Reality Checks. If you play a technique on a crisis successfully, but it's not enough to defuse the crisis, then it stays "in play" until additional techniques are played to reach the challenge's difficulty. This means that, during confrontational play, another player could steal the crisis that you'd only partially solved on your turn.

A selection of technique cards

You can download the original (heavily-redacted) materials released by the CIA here (PDF, 104 pages), or there are vendors online that sell games based on it, such as my version which came from Techdirt and Diagetic Games. And if you want a peek at some of the other games the CIA has developed and used as teaching tools, this article is pretty interesting.

Friday, January 9, 2026

How about another intelligence post? Let's talk about red teaming!

 Hey, it's been a hot minute since we've talked about intelligence (i.e. spy stuff). As a reminder, micronations generally DON'T need an intelligence service, but it's fun to talk about, so here we are.

Today I want to talk about "red teaming". Red teams mean different things in different contexts, but it's all ultimately the same thing - having a team on your side whose job is to "think like the other guys" in order to be able to anticipate what "the other guys" might do. (The name comes from military exercises, where the friendly force is deemed "blue" and the other side is "red".)

For example, the United States Air Force uses "aggressor squadrons" (the Navy and USMC call them "adversary squadrons") which use the tactics, techniques, and procedures of the enemy, in order for their own pilots to be familiar with them, which can give an edge in a fight.

Over in the cybersecurity world, "red teaming" is a form of security testing that's one big step beyond "ethical hacking". Red teams can use almost any tactic to try to gain access to facilities and information, within reason. This can include lock-picking, "seeding" the parking lot with USB drives that have malware on them, launching their own phishing campaigns, and other tactics a real attacker might use.

Back in Spook Country, red teaming can help you to avoid two separate but related pitfalls, either of which could result in intelligence failures. First, done properly, it can help you to understand that your adversary doesn't think like you. They have different values, goals, and priorities, and may even come from different cultures, and red teaming can help identify those and prevent the "mirror image problem" (meaning that you assume the other side thinks just like you do, with the same motives, values, and understandings). Second, it can help you escape the mental trap of "They're the bad guys" because once you start to believe that, you can start to believe all of the tropes that modern media assigns to "bad guys". It's important to remember that they're doing their job, just like you're doing yours.

In order to successfully use red teaming, you need to understand the other side's culture, history, organizations, and overall objectives from a real perspective. This is why, for example, the CIA used to hire a lot of people who studied Russian literature in university, because Russian literature shaped the national psyche, and thus informed their culture to a large degree.

The big risk of red teaming (in intelligence or in cybersecurity) is overconfidence - assuming you've got THE answer. I.e., in cybersecurity, you might assume your red team found all of the ways in and you've blocked them. Well, no - your red team found all of the ways in that they looked for, but there's no guarantee that they looked for everything. The reverse of that is also true - you can go nuts trying to figure out what might have been missed, and you can always run another test, and another, and another - basically, you can never finish, if you're so inclined. After all, the organization you tested today isn't the same organization that'll be there next week - new servers, new software vulnerabilities, new people joining the company, it all means that there's always another potential way in. Since red teams can be sneaky and under-handed (as can the other side!), their methods can also lead to resentment among the people they've come in contact with, and even mistrust of management.

On the other hand, there are definite benefits to "thinking like the other guys", and to be honest, it can be quite fun sometimes. Just make sure you can take their shoes back off, when you're done wearing them...

If you want to know more about red teaming, you can check out the CIA's Tradecraft Primer (which devotes a page or two to red teaming, among other techniques) here, or the US Army's Red Team Manual  (which is devoted to the subject) here.

Picture is unrelated.
(Probably...)


Friday, December 19, 2025

So, what's counter-intelligence?

 If you're hanging around the intelligence community, or watching too many spy movies, then sooner or later you're going to hear the term "counter-intelligence". But what is it, and why would you need it?

Simply put, if intelligence is how you find stuff out, then counter-intelligence is how you prevent the other guys from finding out stuff. How do you do that? There are two basic techniques: obfuscation, and increasing the "noise" (if you've ever heard the term "signal-to-noise ratio"). As an aside, and broadly speaking, those are the same two basic techniques used in cryptography.

Obfuscation means hiding what your opponent wants to see. This includes things like fences and barriers to keep prying eyes away from your facilities (blocking HUMINT), covered or underground facilities to foil GEOINT, and encrypting communications to block SIGINT. Classification and control of information also falls under obfuscation, by (hopefully) making it harder for the other people to get the information. By extension, vetting your people before providing them access to that information would also fall here, although it's now stretching the definition of "obfuscate" beyond all reasonable use...

Adding noise means creating additional false data points to force your opponent to spend more time on analysis, and hopefully to draw incorrect conclusions. For example, this might include creating fake military sites or vehicles to fool air reconnaissance. There was a famous (alleged) instance in WWII where the Germans built a fake air field with ersatz planes and equipment manufactured of wood to fool the British, or so they thought. The British waited until the fake facility was completed, then sent over a single plane that dropped a single wooden bomb. (I will note that Snopes rates the anecdote as "unproven".)

Another even more famous example from the same conflict was Operation Mincemeat, in which the British used a deceased homeless man (dressed in a military uniform) to feed false plans to the German intelligence machine. Incredibly, the plan for Operation Mincemeat was conceptualized by none other than Ian Fleming, who would later go on to write the James Bond books.

Picture from Microsoft Word ClipArt


Friday, December 12, 2025

Intelligence Analysis Techniques: Analysis of Competing Hypotheses

 This wasn't supposed to be an intelligence blog, but here we are... 

Today, I want to talk about a very powerful technique of intelligence analysis called "Analysis of Competing Hypotheses" (ACH). And, crucially, this isn't something that needs to stay in the halls of Langley, VA (home of the CIA) - it's something you can probably use.

Previously I talked about "all-source intelligence" - where you take intelligence from a bunch of different sources to form a more holistic picture of what's happening. We also mentioned the possibility of contradictory evidence, i.e. your HUMINT source was saying that the Hostilian (we were still calling it XYZ then) fleet was undergoing retrofit, but your GEOINT was showing that the naval yards were empty.

The point of ACH is to prevent intelligence analysts from developing "tunnel vision" - from being so focused on "proving" some presupposed "fact" that they ignore any other evidence. One famous example of this confirmation bias is how the US intelligence community handled information about the Iraqi chemical weapons program - they decided that there were two possibilities, that either Iraq had a large chemical weapons program, or they had a small one, and all of their evidence was forced to fit into one of those two possibilities. They completely ignored the third possibility, that Iraq had actually done what they had committed to and shut down those programs, with tragic results.

So, how is ACH done?

It starts with identifying your competing hypotheses. Remember that these are competing hypotheses, meaning that they should be very distinct, almost opposites from each other. ACH isn't so useful in identifying degrees of difference in two similar options.

Next, you want to gather all relevant information - your all-source intelligence.

Draw up a matrix with all of your hypotheses along the top, and all of your information items along the side. For each intelligence item, assess whether it supports (S), refutes (R), or is neutral for each hypothesis. If you have intelligence that doesn't provide any value for any of the items (it's neutral all the way across), discard it.

Assess each hypothesis on the basis of the evidence you have. Possibly counter-intuitively, you want to disprove hypotheses, not prove them. This can help you identify a "tentative conclusion" - the one with the least amount of disproving data associated with it.

See whether there's any key pieces of evidence that are crucial - this is a measure of the "sensitivity" of the conclusion. If, for example, your conclusion depends completely on a single piece of intelligence, and that item turns out to be wrong, then so are your conclusions.

Finally, report your conclusions. This doesn't just mean you present the most likely hypothesis - it means you present all of your hypotheses (that haven't been completely discounted), along with any additional lines of questioning that should be pursued to solidify your conclusions.

So let's see what this looks like in practice. Returning to our example about the Hostilian fleet, our government wants to know if they're poised to attack us. We start with two hypotheses here that are (at least for now) pretty contradictory: that either they are on their way to attack us (we'll call this hypothesis 1, or H1 for short), or that they are undergoing refit (H2). Next, we gather as much information as we can: we've already talked about the HUMINT and GEOINT, but we also have MASINT (which doesn't show unusual levels of communication or activity at their Naval headquarters) and an OSINT report from the Hostilian newspaper about their government signing a big contract with a private shipyard earlier this year. So we put all of that together into a matrix as below:

ACH Matrix example

Looking at the available data, it seems that H2 is more likely (and suggests that we need to get some GEOINT coverage of that private company's shipyards to confirm). So, based on the above, we can report to the government that it's unlikely that we will be attacked by the Hostilian Navy any time soon (although, once they're done with the refits, the situation could change).

So, how could you use this in your own life? If you've got a decision to make, you can use ACH to assess the pros and cons of each decision (and if any factors are key - remember what I said before about "sensitivity" to key data). 

Tuesday, December 9, 2025

Hey, look, more about micronational intelligence services!

 Apparently I'm not done speaking about micronational intelligence services - you know, that thing I said you probably didn't need, and then wouldn't shut up about?

Today I want to talk about sources, which are part of "sources and methods". First, I'll throw this out there: while we previously talked about intelligence classification schemes as part of this post, it's important to remember that most information is classified to protect the source, not because of the information itself. For example, if you've got a source inside the naval strategic planning office of your main opponent (let's call them the Hostilians), you don't want to accidentally "burn" that source, so you want to protect everything that comes from them (i.e. "need to know", "eyes only", "NOFORN" - that last one meaning basically "No foreigners"), and filter it carefully before disseminating it. As another example, if your information is coming from SIGINT (see below) because you've cracked the Hostilian codes and you're reading their emails before they do, you certainly don't want them finding out and changing those codes!

Broadly speaking, intelligence sources are described in terms of where they came from, and usually they are abbreviated. For example, OSINT is "open-source intelligence", which means intelligence that is gathered or derived from freely-accessible sources. Despite the free availability, it's frequently a very valuable source of information, with some estimates saying that up to 80% of intelligence being derived from OSINT. For example, if the Hostilian press is suddenly full of editorials slagging on your country, and their leader is at the podium saying what a horrible place your country is and that your government is full of crooks, well, it's pretty obvious that they don't have the best of intentions for you.

HUMINT, or "human intelligence", is derived from human sources - like the aforementioned mole in the Hostilians' naval strategic planning office. This can also be intelligence you gather from prisoners you've taken from the other side, from refugees running from the Hostilian regime, from your border security patrols, from debriefing travelers that have returned from visiting Hostilia, and so on. This is probably the oldest form of intelligence gathering.

GEOINT is "geospatial intelligence" - this can be Google Earth imagery or your own drone reconnaissance footage, for example. Aerial reconnaissance actually predates powered flight, with the use of tethered hot air balloons for spotting troop movement as well as directing artillery fire.

Signals Intelligence (SIGINT) often works closely with cryptanalysis. SIGINT will capture the transmissions, and then the cryptanalysis team will try to break the codes and determine what is actually being said (assuming your enemy isn't just transmitting in the clear!).

Measurement and Signature Intelligence (MASINT), which is distinct from SIGINT, can tell you a lot about what's happening even without being able to understand the enemy's transmissions. For example, if you can triangulate the position of a transmitter, you know where it is (and thus, over time, if it is moving). You may also be able detect what kind of equipment they're using to transmit, and this can yield additional information. Suppose, for example, that the Hostilian Navy has suddenly started using X-band radar. This is useful to know, because X-band radar is shorter range, but higher resolution, and it suffers in poor weather. This, in turn, could help form a battle strategy if it becomes necessary to engage the Hostilian fleet - use the weather to your advantage.

Finally, Technical Intelligence, or TECHINT, is information about the equipment and weapons being used by your opponent. For example, if you've discovered that the Hostilian Navy just bought a bunch of Motorola Talkabout T210 radios for their people, TECHINT will tell you that the maximum range for those radios under optimal conditions is about 32km (20 miles, for the metrically-declined), as well as which frequency ranges that family of radios operates in. The previous insight about X-band radar would also be TECHINT - MASINT identifies the use of the radar, and then TECHINT tells you its limitations, basically.

There's also FININT, or financial intelligence, which looks at financial transactions and the flow of money, but this is generally more useful in law enforcement contexts.

All of the above are ideally combined using something called "all-source intelligence" to create a holistic view of what your opponents are doing/planning.

All-source Intelligence

The point of all-source intelligence is to make sure that you're forming as full a picture of possible, and not disregarding information that might contradict what you think you know. (If you remember, in a previous post I mentioned the possibility that your HUMINT source was saying that the Hostilian (we were still calling it XYZ then) fleet was undergoing retrofit, but your GEOINT was showing that the naval yards were empty.)

By the way, I've been mostly focusing on "state security" intelligence in these blog posts. For a quick view on military intelligence (which overlaps significantly, but not 100%), I can recommend this video by Daniella Mestyanek Young (author of Uncultured, a frankly shocking and disturbing book about growing up in a cult).


Tuesday, November 18, 2025

Micronational spy games - still not done!

 First, apparently I missed my posting on Tuesday last week - I was in a cybersecurity competition all weekend and forgot to make sure I had postings queued up here, as well as on Instagram (MEDALS Monday and Travel Thursday posts) and on Tumblr (Wednesday Slabovian factoid) and Facebook (Wednesday meme post). Oops. Let's see if we can get back on track this week!

So, let's keep talking about micronational spy agencies, because it's fun. Today, I want to talk about cryptography, because what good's a spy if they don't have their codes, right?

Let's start with some terminology.

First the obligatory etymology: the word "cryptography" comes to us from the Greek words kryptos (hidden or secret) and graphein (to write), so it literally translates to "secret writing".

Basically, cryptography is the technique of making unreadable gibberish out of a message, but in a way that can be undone later so the original message can be read. (This is unlike a "hashing function" like MD5, which is a one-way function; there's no easy way to determine the original message from the hash.)

The method or algorithm we use to encrypt and decrypt the message is called the cipher. The unencrypted message is usually referred to as plaintext, while the encrypted message is called ciphertext.

The encryption/decryption flow

What's missing from the above diagram is the key (or "cryptovariable", according to the NSA), an additional piece of information that guides the encryption/decryption processes so that you don't always get the same results. If you use the same key for encryption and decryption, this is called "symmetric encryption" - it's quicker, but if someone else compromises the key then they can read all of your messages. Systems that use different keys for encryption and decryption are "asymmetric" - they tend to be slower than symmetric encryption, in part because the keys are much larger (and thus the math is more computationally intensive), but you can allow part of the key to be publicly disclosed without fear of compromising the system. Public key encryption, which is how your web browser talks to a web server over Transport Layer Security (TLS), works this way, and we'll talk about that a bit more later on.

Historically, cryptographic systems were either substitution ciphers or transposition ciphers. A substitution cipher literally just substitutes a letter for a different letter (or a symbol) in a known way. Morse code is a substitution cipher of sorts, as is ASCII encoding. One of the first known substitution ciphers in history was the Caesar cipher, invented by Julius Caesar himself. He just shifted each letter by three positions in the alphabet, and the last three letters "wrapped around" to the front. So A would become D, B would become E, and so on, and when you got to X, Y, and Z, they would become A, B, and C respectively. A more modern version of the Caesar cipher is "ROT-13", which rotates each letter by 13 places in the alphabet.

As an aside, a lot of "alien languages" in science fiction movies and television shows tend to just be substitution ciphers - basically they write the message in English and then change the font to the galactic equivalent of "Wingdings". Aurebesh (the language used in the Star Wars films) is a bit better, as it uses 34 symbols rather than 26, adding specific symbols for sounds such as "Ch", "Sh", and "Th".

All substitution ciphers suffer from the same basic problem: predictability. We know that, for instance, E is a much more common letter in the English language than, say, X, so a "frequency analysis" of symbols will quickly help us determine which letter is probably an E. Also, short words such as "the" occur very frequently in English, so if we already suspect that H is the ciphertext for E, and we see WKH several times in our ciphertext, then WKH is probably the encoded THE, and now we have a couple more letters. By proceeding in this way, given enough ciphertexts you can always crack a substitution cipher.

Transposition ciphers, on the other hand, try to "scramble" the plaintext (albeit in a predictable way, so the scrambling can be undone) to generate the ciphertext as a permutation. For example, you could just write all of your text backward. Historically, these might have been tough to crack without knowing the key, but not impossible - if you have some idea of which words should appear in the plaintext, and you can identify the corresponding letters in the ciphertext, that can help you determine how the scrambling occurred (and how to reverse it). Modern computers can generally apply brute-force solving methods to quickly crack such ciphers. (When I run across such ciphers during cybersecurity competitions, I usually go to dcode.fr as my first stop - it can often identify the cipher AND solve it in a matter of seconds, by trying various permutations and combinations and looking for English-language words in the results.)

Based on the above, you can probably determine that more effective cipher systems will combine substitution and transposition...

Next time we'll continue talking about cryptography, including more modern systems.

Friday, November 7, 2025

Micronational Intelligence (Spy) Services

 I'll preface today's blog posting with this: while I do not claim to have worked for any intelligence agencies, I've taken multiple courses in intelligence analysis, and I've been both a producer and consumer of intelligence in my "day job" in cybersecurity, so this is all coming from a place of some experience.

Some micronations establish spy agencies. They probably don't need them.

First, why do spy agencies exist? Simply put, the way it's supposed to work is that intelligence informs policy. Policy-makers rely on intelligence to make decisions, support or change policies, and gain a knowledge advantage.

Thus, since micronations for the most part don't have policies beyond who they are friends with, they don't need intelligence agencies.

However, if you decide that your micronation really MUST have a spy agency, at least learn the basics. For starters, there's something called the Intelligence Cycle.

The Intelligence Cycle

Requirements come from the policy makers - they come to the intelligence group with questions which could include military (i.e., what is the strength of the navy of country XYZ?), economic (How is XYZ's economy faring?), political (Who is favoured to be the next leader of XYZ?), social (How do XYZ's citizens feel about their leadership?), and so on.

Next is gathering - this starts with a plan based on the requirements. For example, given the question, "what is the strength of the navy of country XYZ?", you might rely on satellite imagery, human intelligence (maybe you have someone on the inside?), open-source intelligence (maybe they publish the information on their website!) and so on.

Then you have to process the information - this may include translation from other languages as well as assessing the reliability and accuracy of the information and its sources. Do you trust your person working for the navy of XYZ, or have they been compromised and used to feed you false information? Often, this assessment is done using the Admiralty Code, which assigns values to both the source reliability (A = completely reliable, F = completely unreliable) and the reliability of the information itself (1 = verified accurate, 6 = known to be false), and plots the results on a table similar to the below.

Admiralty Code for assessing information reliability

Here, anything that lands "in the green" should be considered reliable unless you have reason to suspect otherwise, anything "in the red" should be discarded or discounted, and anything landing in the yellow zone would require further investigation or collaboration.

Analysis involves taking all of the disparate pieces of information you've gathered and determining the "big picture". If your source in the XYZ navy is saying their fleet is in the harbour for refit, but the satellite imagery shows the docks are empty, that's a mismatch that needs to be taken into account.

Finally, dissemination is the act of reporting your findings back to the policy makers - answering their original questions. This almost invariably leads to more questions, which is why the whole thing is a cycle.

Classification is about assigning a level of secrecy to intelligence. Often, this is more about protecting the source, rather than the information itself. For example, if you've got a mole in XYZ's navy, you want to keep that fact protected, both to protect the mole and to ensure the information keeps coming, so information coming from that source would be highly classified.

Typically there are several levels of classification:

  • Public - Can be published on the external website, etc.
  • Classified / Internal - Information should be kept within the organization
  • Secret - Information is only to be viewed by those with a specific "need to know", and generally means that individuals must pass a reliability assessment and sign some sort of non-disclosure agreement to view it.
  • Top Secret - May require additional clearance or special restrictions to view - this can include modifiers such as "Eyes Only" (meaning you can't make copies or take notes) or "NOFORN" (meaning no foreigners should be allowed to view this information).

If you want to know more, there are various online sources to pursue. For example, here is a US Army Intelligence Analysis field manual, and here is a manual from the United Nations Office on Drugs and Crime (UNODC) on criminal intelligence (which focuses on what criminal groups are doing, rather than nation states, but the basic techniques are similar). You can also find reprints of both modern and historical intelligence manuals on sites like Amazon, although a lot of that tends to be stuff that you could find online anyway, if you looked for it.

Oh, and you can take a look at West Who's spy agency - they're having fun with it anyway.