TrackerCollectionsTrackersOfficial Source

Official Threat Source Collection Tracker

The official-source lane should expand through dated source packets, not a single sprawling enemies document. This tracker identifies which agency source families are already usable, which need dedicated packets, and which safety boundaries must be preserved before the corpus makes stronger judgments.

Review Queue Full Index

Classification: UNCLASSIFIED//OPEN SOURCE

Tracker ID: WI-TRACKER-US-THREAT-SOURCES-2026-0001

Prepared UTC: 2026-06-18T11:54:34Z

Information cutoff UTC: 2026-06-18T11:54:34Z

Source base: U.S. intelligence and law-enforcement source register; ODNI, CIA, FBI, NCTC, DHS, CISA, NSA, State, Treasury, DEA, ATF, CBP, Coast Guard, DOJ, and NGA public source families; existing WARLOCK-INDEX source registers and assessments; Salt Typhoon and telecommunications defensive source note; PRC APT/Typhoon label crosswalk and advisory refresh source packet. The tracker now also includes the U.S. law-enforcement threat source capture packet and assessment plus the cyber nation-state actor/APT source tracker.

Analytic confidence: High for collection architecture. Moderate for source recency because dynamic agency pages and annual reports require dated refreshes.

Purpose: Track the collection status of official U.S. threat-source families for future WARLOCK-INDEX expansion.

Boundary: This tracker does not provide recommendations, targeting, investigative direction, collection tasking, operational guidance, route selection, technical exploitation, domestic political profiling, or tactical instructions.

Bottom Line

The official-source lane should expand through dated source packets, not a single sprawling enemies document. This tracker identifies which agency source families are already usable, which need dedicated packets, and which safety boundaries must be preserved before the corpus makes stronger judgments.

Collection Matrix

Source familyCurrent statusNext productConfidenceBoundary
ODNI Annual Threat AssessmentActive in repo; used in Russia, DPRK, and Iran strategic-weapons packetsKeep annual comparison packet currentHighNo classified inference
DoD/DIA/PRC issuer China military-source laneDoD 2025 PRC report, DoD 2024 comparator, DIA 2019 China baseline, China/PLA source baseline, PRC official doctrine/issuer-language packet, DoD/DIA China military-power extraction map, China/PLA source tracker, PRC cyber defensive packet, Salt Typhoon telecommunications source note, and PRC APT/Typhoon label crosswalk addedPRC MND/PLA dated capture, PLA services/arms, Taiwan pressure, South China Sea, PRC cyber advisory page-level refresh, space, defense-industrial, DoD-to-PRC-issuer crosswalk, and PRC-Russia support packetsHigh for source identity; moderate for public completeness and current implementation evidenceNo operational detail, targeting, live tracking, contingency planning, cyber exploitation, telecom network diagrams, lawful-intercept detail, issuer-claim laundering, or export-control evasion
CIA World LeadersRegisteredForeign government reference packetHighNo personal dossiers or targeting
CIA Factbook / CIA maps legacyReplacement note added; maps split into map/geospatial register; theater map index addedMap-heavy theater source packets as neededHigh for sunset status; moderate for archived accessNo current claims without refresh
FBI terrorismLaw-enforcement source capture packet and assessment added; FBI page verifiedFBI/DHS terrorism and targeted-violence source packet with current DHS HTA and State designation refreshHigh for FBI source-family framing; moderate pending DHS/State annual refreshNo political profiling, tactics, recruitment, attack-method detail, or protected-speech labeling
FBI cyber / IC3Law-enforcement source capture packet and assessment added; IC3 2024 report verified; Salt Typhoon telecommunications source note, PRC APT/Typhoon label crosswalk, cyber nation-state actor/APT tracker, Russia state-cyber packet, and weekly current source sweep tracker addedIran cyber source packet, DPRK cyber-finance/IT-worker packet, IC3 data extraction map, PRC/Russia advisory page-level refresh, and allied cyber-center crosswalkHigh for FBI/IC3 source identity; moderate for current advisory page-level extractionNo exploit or evasion detail, indicators-for-misuse, provider vulnerability mapping, telecom network diagrams, APT alias laundering, or sanctions/finance procedure
FBI counterintelligenceLaw-enforcement source capture packet and assessment added; FBI page verifiedFBI/DOJ counterintelligence and national-security legal-action source packetHigh for FBI source-family framing; moderate for case-specific current stateNo identification of private persons absent official legal source
FBI WMDLaw-enforcement source capture packet and assessment added; WMD/biosecurity source packet already addedMaintain WMD public-source packet and add FBI/FSAP/DTRA/State BWC refresh as neededModerate to high by source familyNo materials, methods, device, facility, site-map, or vulnerability detail
ODNI global biolab disclosureSource-treatment note, WMD/biosecurity source packet, and Ukraine claim-reconciliation note addedDeclassification and information-resilience source noteHigh for ODNI release; moderate to low for uncorroborated underlying claimsNo biological methods, facility table, site mapping, or vulnerability detail
DTRA / Cooperative Threat ReductionDTRA mission, fact sheet, and DoD BTRP Ukraine fact sheet registered; document-level CTR work still neededDoD Cooperative Threat Reduction source packetModerateNo foreign facility inference from general mission pages
Federal Select Agent ProgramRegistered; WMD/biosecurity source packet addedSelect Agent oversight source packetHigh for source familyNo controlled lists, quantities, facility-sensitive detail, or compliance workarounds
State / UNODA BWC sourcesSource families registered with access caveatsBWC treaty and compliance source packetModerate pending access refreshNo legal conclusion without current text/status verification
NCTC groupsRegistered as historicalTerrorism group source refreshModerate to low for current statusDo not reproduce tactics
DHS Homeland Threat AssessmentRegistered and routed through law-enforcement source capture packetDHS HTA packet with dated URL verificationModerateNo domestic political enemies framing
CISA KEV/advisoriesRegistered; cyber nation-state actor/APT tracker added as the advisory-control surface; PRC APT/Typhoon label crosswalk addedPRC advisory page-level refresh and Russia/Iran/DPRK source packetsHighNo offensive cyber instruction, IOCs-for-misuse, or exploit chains
NSA cyber advisoriesRegistered; cyber nation-state actor/APT tracker added as the advisory-control surface; PRC APT/Typhoon label crosswalk addedPRC advisory page-level refresh and Russia/Iran/DPRK source packetsHighNo exploit chains, commands, malware procedures, or operational guidance
State FTO and terrorism reportsRegisteredTerrorism designation packetHighDesignation status only; no targeting
Treasury OFAC and risk assessmentsActive in repoSanctions and illicit finance source packetHighNo evasion guidance
DEA threat sourcesRegistered and routed through law-enforcement source capture packetTCO and narcotics source packetModerateNo trafficking methods
ATF data/statisticsRegistered and routed through law-enforcement source capture packetFirearms commerce, tracing, trafficking, and explosives statistics source packetModerateNo procurement or explosives guidance
CBP statisticsRegistered and routed through law-enforcement source capture packetBorder and port-of-entry statistics source packetModerateNo route or evasion guidance
Coast Guard sourcesRegistered and routed through law-enforcement source capture packetMaritime homeland source packetModerateNo patrol or interdiction detail
DOJ NSDRegistered and routed through law-enforcement source capture packetNational security legal-action trackerModerateCase-specific evidence only
NGA public sourcesMap/geospatial register, theater map index, Indo-Pacific/Taiwan map packet, Philippines/South China Sea map packet, and Europe/NATO/Ukraine map packet addedAdditional map-heavy theater packets as neededModerateNo targeting or vulnerability maps

Update Triggers

  • ODNI releases a new Annual Threat Assessment.
  • DoD releases a new PRC military power report, DIA refreshes China military power material, or major China/PLA official-source collections change.
  • ODNI releases new declassified WMD, biosecurity, foreign-laboratory, or threat-reduction material requiring claim-treatment controls.
  • DHS releases a new Homeland Threat Assessment.
  • FBI releases a new IC3 annual report or strategic terrorism/cyber/WMD assessment.
  • CISA or NSA publishes a major joint cyber advisory series affecting tracked state actors, APT labels, ransomware, or critical infrastructure.
  • State updates FTO, State Sponsors of Terrorism, or Country Reports on Terrorism material.
  • Treasury updates national risk assessments, sanctions programs, or OFAC designation source pages.
  • DEA, ATF, CBP, or Coast Guard releases annual statistical or threat reports.
  • CIA, State, or NGA changes public map/country/foreign leadership source availability.

Information Gaps

  • Current DHS HTA and some agency product URLs need manual date capture.
  • The NCTC public group guide is historically useful but stale for current group status.
  • Public law-enforcement statistics require definition discipline before use in trend claims.
  • Law-enforcement source treatment now has an assessment baseline, but dated page-level extraction remains incomplete for DHS, DEA, ATF, CBP, Coast Guard, Treasury/State status records, and DOJ legal-action lanes.
  • Cyber advisories can include technical detail that must be summarized safely.
  • APT labels can be unstable across official, allied, and private research sources; source-class labels are required before broader use.
  • Domestic threat products require explicit civil liberties boundary review.
  • The Ukraine biolab claim-reconciliation note reduces the immediate issuer-layering gap, but DoD Cooperative Threat Reduction, State Department arms-control/BWC, congressional, Ukrainian, treaty-organization, technical biosecurity, and independent oversight sources still need document-level collection before stronger judgments are made.
  • State and UNODA BWC source pages need successful access refresh before carrying exact treaty-status or current U.S. diplomatic claims.
  • DTRA Cooperative Threat Reduction needs document-level source collection; the current packet only registers the public mission/fact-sheet source family.

Cross References