Research shelf / Defence & security / Threat assessments

Defence & security

Three open-source threat briefs, written in intelligence register

A threat assessment is a specific document genre: an executive summary, a capability characterisation, an attribution discussion, and a countermeasure section, written so an analyst can act on it. These three are exercises in that genre, built from open sources and banner-marked UNCLASSIFIED — open-source research, not classified material.

Speculative AGPL-3.0+ / commercial
Evidence level

Theory or design only. No in-house measurement.

FolderThreat Asessments
FieldDefence & security
StatusSpeculative open-source briefs. Genre exercise, no institutional standing.
What it is

Hypothetical intelligence briefs on identity-replacement tradecraft, neurological interference and an explosive mixture — written from open sources in the register such documents actually use.

The physical identity replacement brief characterises the capability tier at which biometric, visual and voice identification can be defeated by physical modification, and the infrastructure a capability at that tier requires — which is the analytically useful part, because it bounds who can plausibly do it. Its central distinction is between reversible short-duration kit and permanent modification for long-term cover, since the two imply very different preparation footprints.

The neurological interference brief covers reported directed-energy and acoustic health-incident claims, and the 2NT/TNT mixture brief covers an explosive characterisation. Both are written in the same structure: what the capability is, what evidence exists in open sources, what the attribution picture looks like, and what detection or countermeasure options follow.

The register is deliberate. Genre fidelity — classification banners, versioned documents, executive summary first — is the point of the exercise, in the same way the defence portfolio’s traceability discipline is the point there. These are unclassified open-source syntheses and are marked as such at the top of each document.

What these are for. A threat assessment is useful when it tells a defender what to look for and what a capability costs an adversary to field. These three are written at that level — capability tier, required infrastructure, detection options — and not at the level of instructions. That is the correct altitude for the genre and it is where they stay.
Claims ledger

Every number, and what stands behind it

A claim is only worth the evidence attached to it. Each row below carries its basis: measured on the author’s own hardware, derived from the construction, measured on synthetic data, projected from literature, or simply cited.

Breakdown of this page’s claims by what stands behind each one
scroll to see the whole chart →
Every claim, weighted by its evidence. The table below is the same data row by row.
ClaimFigureBasisContext
Briefs in the folder3DerivedIdentity replacement, neurological interference, explosive mixture
Source basisopen-source onlyDerivedUNCLASSIFIED banner on each document
Document structureexec summary → capability → attribution → countermeasuresDerivedConsistent across all three
Central analytical distinctionreversible kit vs permanent modificationDerivedBounds the preparation footprint a capability implies
Capability tier assessedstate-level infrastructure requiredCitedFrom the open-source record

Measured — author-run experiment on the stated setup. Synthetic — measured, but on synthetic rather than real data. Derived — follows from the stated construction or proof. Projected — paper-stated projection, not an author-run benchmark. Cited — taken from external literature.

Methods

How it works

  • Capability-tier characterisation. Assessing what infrastructure a capability implies, which is what actually narrows attribution.
  • Open-source synthesis. Reported cases and published material only, with the sourcing basis stated on the document.
  • Genre-faithful structure. Executive summary, capability, attribution, countermeasures — the structure an analyst expects.
  • Countermeasure orientation. Each brief closes on detection and mitigation rather than on capability description.
Stated limitations

What it does not do

Taken from the folder’s own README. Nothing here has been softened.

  • Hypothetical briefs written as an exercise in the genre. No classified sourcing, no intelligence access, no institutional standing.
  • Open-source characterisation of state tradecraft is inherently partial and dated.
  • Attribution discussion in all three is inference from published reporting, not evidence.
  • The neurological-interference material addresses a set of claims that remain contested in the public record.
  • These are analytical documents about defeating identification and detection. They are written at the level of capability characterisation and countermeasures — deliberately not at the level of procedure.
Use it

Free under AGPL-3.0+ for almost everyone

Personal use, charities, education and organisations under AUD 50,000 a year pay nothing. A tiered commercial licence covers everyone else.