s2underground_search · S2 guides
S2 guide GhostNet 1.5 Page 26 of 50 text: pdf

GhostNet 1.5, page 26

GhostNet Guide

S2 Underground field guide: GhostNet Guide

Version 1.5 — Stopgap Comms Solutions (CC BY-NC-SA 4.0)

Page 26 of GhostNet 1.5
Searchable page text (OCR / PDF)
26 Incident Response Monitoring Basic Monitoring Capabilities The capabilities listed below are intended to help concerned citizens track events in real time, without forgetting a particular capability or tool. Not every item listed will be necessary for every event, but this checklist can be helpful for setting up an ad hoc monitoring station, listening post, or TOC as needed. Signals Intelligence (SIGINT) ADS-B receiver - Aircraft Monitoring KrakenSDR Passive Radar - For limited Passive Radar capability, as well as Direction Finding capabilities. SDR w/ Scanner feature - For identifying signals of interest in a local area. Laptop, Tablet, or PC capable of running Windows or Linux OS - For processing signals with an SDR. Note: Several options exist for processing SDR signals on an Android smartphone, so this can be an option for limited work. However, for more substantial SIGINT processing tools, most smartphones do not have the processing (or CPU cooling capabilities) to get the job done, making a laptop or tablet the best overall choice. Communications Intelligence (COMINT) ACARS receiver (HF and VHF bands) - Configured to decode ACARS traffic from aircraft in the local area. L-Band Antenna for SDR - For intercepting commercial aviation SATCOM ACARS messages. General Purpose Scanner - Preferably with trunking capability. For monitoring unsecured local comms. SDR w/ Scanner feature - Additional tool for monitoring unsecured comms in a local area. HF Transceiver - Communication and information sharing/collection tool. Laptop, Tablet, or PC capable of running Windows or Linux OS - For interfacing with an SDR or Transceiver. Handheld Analog VHF/UHF Transceiver - Can be used for unsecured local comms, but also can be used to monitor local ham radio repeater networks in a time of crisis. These info networks are historically unreliable for HUMINT purposes, but worth monitoring to determine how widespread an incident is. Imagery Intelligence (IMINT) Satellite Imagery - Helpful to download before internet connections are lost. Also, basic SRTM elevation data would be helpful to have on hand to make maps with if needed. If internet connection is not available, intercepting weather imagery from orbiting satellites would be useful as well. Drone Imagery - For local imagery collection. Magnified Optics - A good pair of binoculars of a spotting scope is very helpful for local observation. Thermal Optics - Consumer grade thermal optics provide substantial force multiplication. Night Vision Optics - Mandatory for observation of the local area at night. Measurements and Signatures Intelligence (MASINT) CBRN detection networks - Though reliant on internet connections, various CBRN detection networks allow users around the world to be aware of increases in baseline HAZMAT activity. Weather Station/Kestrel Meter - Establishing WX sensors early on during a crisis is helpful for determin- ing weather patterns, which in turn aid weather forecasts. Human Intelligence (HUMINT) Local Sneakernet - Information shared by physical, face-to-face meetings with people in a local area. Text-Based Word-of-Mouth Information Exchange - Simply texting local contacts (or trusted/high-confi- dence sources) directly can provide real-time intelligence of the situation on the ground. Even if cellular networks are overwhelmed, text-based services (either standard SMS messages or satellite-based communications) can be very effective. Open Source Intelligence (OSINT) Social Media Feeds - If internet access permits, social media can be a valuable source for determining what’s going on around the world. Social media will be the only source of information that most people have, despite being heavily censored, surveilled, and increasingly unreliable. In a case of total devastation, internet access will be limited or nonexistent. Plan accordingly, and use OSINT tools as long as they are available, but always plan for that data link to be interrupted, censored, or subject to Information Operations.