Analyst capability

Five OSINT capabilities, each with a method and published work behind it

Tools are not a capability. What matters is whether a judgement can be traced from public source to location, time, corroboration and a stated confidence level. These five capabilities carry the Africa research on this site.

Every capability here rests on public and open sources, applied by one analyst. Ratings are analyst judgements for planning, not official designations, and nothing on this site is continuous or real-time monitoring.

01

Conflict intelligence

What is happening, and how unusual is it against the historical baseline?

Event-level conflict and political-violence monitoring, tested against long-run data so a bad week is not mistaken for a structural shift.

Public sources used

  • ACLED
    Geolocated conflict, protest and actor-level events across all 54 states
  • UCDP
    Long-term conflict baselines for historical comparison
  • Insecurity Insight
    Incidents affecting aid and healthcare personnel
  • Local and national media
    First indication of localised events before wider pick-up

How the work is done

  1. Define the unit of analysis: country, admin area, corridor or single site.
  2. Pull current events, then compare frequency and actor mix against the multi-year baseline.
  3. Separate confirmed events from single-source claims before any rating moves.
  4. Translate the pattern into a threat statement with a UK-scale rating and a confidence word.

What this cannot settle

  • Event datasets carry reporting lag and are denser where media presence is stronger.
  • Absence of recorded events is not evidence of safety in low-coverage areas.
East Africa and Horn of Africa assessments

Threat, vulnerability, exposure, impact and mitigation with rated registers.

02

Humanitarian intelligence

Who is operating where, what are the needs, and where is access constrained?

Operational presence, displacement and needs data read as an access and duty-of-care picture, not as a headline total.

Public sources used

  • UN OCHA / HDX
    Operational presence, needs and administrative boundaries
  • ReliefWeb
    Situation reports and agency updates
  • IOM DTM
    Displacement tracking and population movement
  • UNHCR
    Refugee and returnee statistics
  • FEWS NET
    Food-security and drought indicators that precede displacement

How the work is done

  1. Ingest operational presence and needs records with their source and collection date attached.
  2. Read co-location as observation, never as proof of causation or of coverage quality.
  3. Avoid summing disaggregated needs figures; report them by sector and dataset instead.
  4. Convert the picture into access constraints, movement implications and staffing exposure.

What this cannot settle

  • Datasets describe reported activity, not verified delivery on the ground.
  • Coverage gaps concentrate exactly where access is hardest, so absence of records means little.
Africa Operations Map and humanitarian activity

Stored OCHA HDX and IATI records with per-country counts and provenance.

03

GEOINT and remote sensing

Can imagery corroborate, date or locate what open reporting claims?

Satellite and thermal data used for corroboration, before-and-after comparison and route orientation.

Public sources used

  • Copernicus Sentinel
    Optical and Sentinel-1 radar imagery, usable through cloud and at night
  • NASA FIRMS
    Fire and thermal anomaly detection for incident corroboration
  • USGS
    Earthquake and geophysical hazard data
  • Google Earth Pro
    Historical imagery, infrastructure and route analysis
  • GDACS
    Disaster alerting for rapid tasking of imagery checks

How the work is done

  1. Fix the location and the time window from the reporting before opening any imagery.
  2. Prefer radar where cloud, smoke or darkness would defeat optical scenes.
  3. State the acquisition date of every scene used, and what changed between scenes.
  4. Record what imagery cannot settle: intent, casualties, attribution.

What this cannot settle

  • A thermal detection is heat, not an attack; it needs a second, independent line of evidence.
  • Free imagery revisit rates and resolution limit what can be resolved at site level.
Situation Room layers

Geospatial and early-warning layers labelled by source and collection layer.

04

Verification and geolocation

Source, image, location, time, corroboration, confidence — can the chain be shown?

The discipline that decides whether a contested image or claim is allowed to influence a rating.

Public sources used

How the work is done

  1. Trace the earliest publication of the material before assessing its content.
  2. Reverse-search stills and keyframes to rule out recycled imagery.
  3. Match fixed features to imagery or mapping; confirm time with shadow and weather checks where possible.
  4. Record the chain and the residual doubt, then assign a confidence level.

What this cannot settle

  • Verification establishes place and time far more reliably than it establishes responsibility.
  • An unverifiable claim stays labelled reported, and does not move a rating on its own.
Method and source-reliability grading

A to D reliability with the fact, reported and assessed separation applied throughout.

05

Strategic and political risk

What is shifting in politics, narrative and counterparty exposure over the next 6 to 18 months?

Media-scale monitoring used as a tripwire, then tested against official, research-institute and due-diligence sources.

Public sources used

How the work is done

  1. Treat a media-volume spike as a prompt to look, never as a finding in itself.
  2. Test the signal against official advisories, primary documents and institute research.
  3. Screen counterparties and intermediaries before commitments, and record what was checked.
  4. Set out plausible 6 to 18 month pathways with explicit confidence, plus the indicators that would separate them.

What this cannot settle

  • Media attention measures coverage, not ground truth or severity.
  • Corporate and sanctions records are uneven across jurisdictions; a clean screen is not a clearance.
Source registry and OSINT Explorer

Tiered public-source register with reliability, cadence and coverage notes.

Worked examples — how a claim becomes a judgement

These walk-throughs use public reporting only and are written to show the reasoning, including the parts that stayed unresolved. Classification follows the desk convention: confirmed means independently established, reported means a source said it, assessed means analyst judgement from evidence, scenario means a planning construct that has not happened.

Conflict intelligenceReportedConfidence: Moderate

A social-media account states that a main supply route in south-central Somalia has been closed by an armed group, and that movement has stopped entirely.

The reasoning chain

  1. Step 1

    Fixed the claim in time and place before searching for anything else — which road, which segment, which day.

    The post named a district but not a segment. Two earlier posts from the same account described a different road. The claim was too loose to test as written.

  2. Step 2

    Checked event-level conflict data for the district over the preceding and following days.

    Two recorded incidents on the corridor in the same week, both consistent with harassment at a checkpoint rather than a closure.

  3. Step 3

    Looked for independent local-language reporting from outlets that cover the district routinely.

    One local outlet reported traffic being stopped and taxed at a checkpoint. None reported closure. No national outlet carried the story.

  4. Step 4

    Tested the practical signature a closure would leave — cancelled transport, market price movement, aid convoy notices.

    No corresponding notices or price signals in the public datasets for that week.

Left unresolved

  • Whether the taxation point was a new position or an established one operating more aggressively.
  • Conditions on the final stretch of the corridor, for which no public reporting exists.

Operational implication

The corridor should be treated as open but taxed and subject to interference, not closed. Movement planning changes — earlier departure, checkpoint money policy, a named decision point for turning back — but the route does not come off the map. Calling it a closure on this evidence would have stopped movement for a week without cause.

GEOINTConfirmedConfidence: Moderate

Photographs circulate showing a burned settlement, captioned as an attack that took place the previous night.

The reasoning chain

  1. Step 1

    Reverse image search on each frame before treating any of them as new.

    Two of the four images had been published eleven months earlier in a different country.

  2. Step 2

    Read the two remaining frames for internal evidence — vegetation, building style, vehicle types, signage, shadow direction.

    Consistent with the claimed region. Shadow angle placed the photograph in the morning, not at night as captioned.

  3. Step 3

    Checked thermal-anomaly detections over the claimed area for the claimed night and the two nights either side.

    Detections present on the claimed night, in the right area, consistent with structure fire rather than agricultural burning.

  4. Step 4

    Compared before-and-after optical imagery of the settlement at the coarsest resolution that would still show roof loss.

    Visible change across part of the settlement. Extent smaller than the caption implied.

Left unresolved

  • Who carried out the burning — imagery shows damage, never attribution.
  • Casualties, which no remote source can establish.
  • Whether the population had already displaced before the fire.

Operational implication

Burning of part of the settlement is confirmed and can be stated as fact with the date. Responsibility and human cost stay unresolved and must be written as such. Two of the four circulating images are recycled and should be named as recycled wherever they appear again.

Early warningAssessedConfidence: Moderate

A run of small, similar incidents in a border area is described in commentary as the beginning of a wider escalation.

The reasoning chain

  1. Step 1

    Counted the incidents against the same area's multi-year baseline for the same months.

    The run sat above the quiet-season average but inside the range seen in two previous years.

  2. Step 2

    Separated the incident types rather than totalling them.

    The increase was almost entirely one category. The categories that historically precede escalation in this area had not moved.

  3. Step 3

    Checked the non-violent indicators the desk watches for this border — market closures, school suspensions, movement restrictions, displacement registrations.

    Displacement registrations flat. One market reported disrupted trading.

  4. Step 4

    Set explicit thresholds that would change the judgement, with a date to review them.

    Two named indicators would move the assessment if they appeared; neither had. The judgement is falsifiable rather than open-ended.

Left unresolved

  • Intent, which public reporting cannot establish.
  • Reporting coverage in the least-accessible part of the border, where quiet may mean unobserved.

Operational implication

Not an escalation on current evidence — an elevated but recognisable pattern. The value of the work is the two named thresholds: if either appears, the assessment moves without argument. Declaring escalation from the raw count would have spent credibility on a normal seasonal rise.

The full source register

Each capability draws on the tiered public-source register, which records reliability, collection cadence and Africa coverage for every source named in an assessment.

For shipowners, insurers and risk teams

Need a decision-ready briefing on this risk?

Country, port and voyage briefings with named sources, stated confidence and clear evidence limits.