Investigative Frameworks & Methodologies

    Structured approaches to intelligence gathering, analysis, and investigations.

    The Intelligence Cycle (Expanded Operational Model)

    Intelligence Operations
    Ongoing / Cyclical
    Complexity:
    National SecurityMilitaryLaw EnforcementCorporate Intelligence

    The Intelligence Cycle is the foundational process model for producing actionable intelligence from raw information. While traditionally depicted as a five-phase linear cycle, modern operational reality treats it as a dynamic, iterative process with continuous feedback loops. This expanded model breaks the cycle into six operational phases with detailed sub-steps, quality gates, and feedback mechanisms that reflect how intelligence is actually produced in practice. Understanding this framework is prerequisite to all other intelligence methodologies.

    OSINT Investigation Methodology

    OSINT & Digital Investigation
    Hours to weeks depending on scope
    Complexity:
    OSINTLaw EnforcementCybersecurityCorporate IntelligenceJournalism

    A systematic framework for conducting open source intelligence investigations from initial requirement through final reporting. This methodology emphasizes investigative tradecraft, operational security, source evaluation, and the disciplined pivot-based approach that distinguishes professional OSINT from casual internet searching. The framework is designed to be applied whether investigating an individual, organization, domain, event, or network.

    Cyber Threat Intelligence (CTI) Lifecycle

    Cybersecurity & Incident Response
    Ongoing / Cyclical with event-driven surges
    Complexity:
    CybersecurityCyber Threat IntelligenceIncident ResponseNational Security

    The Cyber Threat Intelligence Lifecycle adapts the traditional intelligence cycle specifically for the cybersecurity domain. It provides a structured approach to identifying, collecting, analyzing, and disseminating intelligence about cyber threats, threat actors, and adversary tactics, techniques, and procedures (TTPs). This framework integrates the MITRE ATT&CK framework, Diamond Model, and Cyber Kill Chain as analytical lenses within a unified operational process.

    F3EAD Targeting Cycle

    Intelligence Operations
    Hours to months per cycle iteration
    Complexity:
    Military IntelligenceCounterterrorismLaw EnforcementCybersecurity

    F3EAD (Find, Fix, Finish, Exploit, Analyze, Disseminate) is an operations-intelligence integration methodology that synchronizes intelligence activities with operational actions in a continuous targeting cycle. Originally developed for military counterterrorism and counterinsurgency operations, F3EAD has been adapted for law enforcement targeting of criminal networks, cybersecurity threat operations, and counterintelligence. The framework's power lies in its tight integration of operations and intelligence — each operation generates intelligence that feeds the next iteration.

    Financial Crime Investigation Framework (Follow the Money)

    Financial Crime Investigation
    Months to years
    Complexity:
    Financial CrimesLaw EnforcementForensic AccountingComplianceAnti-Money Laundering

    The Financial Crime Investigation Framework provides a structured methodology for investigating the full spectrum of financial crimes — money laundering, fraud, embezzlement, bribery, corruption, sanctions evasion, terrorist financing, and tax evasion. Built on the foundational principle of "follow the money," this framework traces financial flows from origin through layering to integration, combining forensic accounting with traditional investigative techniques. The framework addresses the unique challenges of financial investigations: complex corporate structures, international jurisdictions, digital currencies, and the adversary's use of sophisticated schemes to obscure the money trail.

    Digital Forensics Investigation Framework

    Cybersecurity & Incident Response
    Days to months
    Complexity:
    Digital ForensicsLaw EnforcementCybersecurityIncident Response

    A systematic methodology for identifying, preserving, collecting, examining, analyzing, and presenting digital evidence from electronic devices and digital systems. Based on NIST SP 800-86, ISO/IEC 27037, and ACPO guidelines, this framework ensures that digital evidence is handled in a forensically sound manner that maintains its integrity, authenticity, and admissibility. The framework applies to computer forensics, mobile forensics, network forensics, cloud forensics, and IoT forensics.

    We use cookies to analyze traffic and personalize content. You can opt out at any time. See our Cookie Policy.