Conflict monitoring
Watching an active conflict through public feeds — news, social channels, transponder and sensor networks, official alert systems — and assembling them into a current picture of a place. The subject is an event in a territory, not a person and not a machine.
That makes it a third value on the object axis this spoke uses to sort tools (synthesis):
- person — llm-osint, kallisto-osinter, gitsint, username-reconnaissance
- machine / attack surface — swaggerspy, ip-reconnaissance, cloakquest3r
- place and event — conflict monitoring, entered with ironsight
What is different about it
The subject cannot be enumerated. Person- and infrastructure-recon both work by querying an index: a handle against hundreds of profile URLs, an address against WHOIS and ASN data. A conflict has no index. The practice is instead aggregation over time — many partial, contradictory streams, sampled continuously, with the analyst doing the correlation. ironsight makes this literal: it polls each feed on its own clock and draws them on one map.
The sources are institutional, not incidental. Air-raid sirens, ADS-B transponders and satellite thermal data exist because someone built them for another purpose entirely — public warning, air traffic safety, wildfire detection. Conflict monitoring is a repurposing discipline, and its capability tracks whatever public sensor networks happen to exist, which is why the two theatres in ironsight have different instruments (Ukraine has a drone-track feed; Israel has a national siren API).
Contamination is the primary risk, not privacy. The dual-use hazard elsewhere in this spoke is aggregation harm to an individual. Here the target is public and the harm runs the other way: every belligerent has a motive to poison the feed, and state media on both sides is in the source list by design. osint-overview-wikipedia names deliberate poisoning as OSINT’s structural weakness; conflict monitoring is where that weakness is at its worst, because the fast feeds — sirens, Telegram channels, community trackers — are the least verified and the most trusted in the moment.
Verification has an owner. The berkeley-protocol was written for exactly this material — digital open source investigation of atrocity and armed conflict, with methodology and preservation requirements. So unlike most of this spoke’s corpus, the practice has a professional standard to be measured against. Tools that skip it are choosing to.
Open
- Nothing in the corpus yet measures a conflict-monitoring feed against ground truth, the way llm-osint-reliability-study does for LLM analysis.
- The archival half of the discipline — preserving evidence for later accountability, which is the Berkeley Protocol’s centre of gravity — is unsourced here. ironsight is a live view that keeps nothing.