Official Threat Source Collection Tracker
The official-source lane should expand through dated source packets, not a single sprawling enemies document. This tracker identifies which agency source families are already usable, which need dedicated packets, and which safety boundaries must be preserved before the corpus makes stronger judgments.
Classification: UNCLASSIFIED//OPEN SOURCE
Tracker ID: WI-TRACKER-US-THREAT-SOURCES-2026-0001
Prepared UTC: 2026-06-18T11:54:34Z
Information cutoff UTC: 2026-06-18T11:54:34Z
Source base: U.S. intelligence and law-enforcement source register; ODNI, CIA, FBI, NCTC, DHS, CISA, NSA, State, Treasury, DEA, ATF, CBP, Coast Guard, DOJ, and NGA public source families; existing WARLOCK-INDEX source registers and assessments; Salt Typhoon and telecommunications defensive source note; PRC APT/Typhoon label crosswalk and advisory refresh source packet. The tracker now also includes the U.S. law-enforcement threat source capture packet and assessment plus the cyber nation-state actor/APT source tracker.
Analytic confidence: High for collection architecture. Moderate for source recency because dynamic agency pages and annual reports require dated refreshes.
Purpose: Track the collection status of official U.S. threat-source families for future WARLOCK-INDEX expansion.
Boundary: This tracker does not provide recommendations, targeting, investigative direction, collection tasking, operational guidance, route selection, technical exploitation, domestic political profiling, or tactical instructions.
Bottom Line
The official-source lane should expand through dated source packets, not a single sprawling enemies document. This tracker identifies which agency source families are already usable, which need dedicated packets, and which safety boundaries must be preserved before the corpus makes stronger judgments.
Collection Matrix
| Source family | Current status | Next product | Confidence | Boundary |
|---|---|---|---|---|
| ODNI Annual Threat Assessment | Active in repo; used in Russia, DPRK, and Iran strategic-weapons packets | Keep annual comparison packet current | High | No classified inference |
| DoD/DIA/PRC issuer China military-source lane | DoD 2025 PRC report, DoD 2024 comparator, DIA 2019 China baseline, China/PLA source baseline, PRC official doctrine/issuer-language packet, DoD/DIA China military-power extraction map, China/PLA source tracker, PRC cyber defensive packet, Salt Typhoon telecommunications source note, and PRC APT/Typhoon label crosswalk added | PRC MND/PLA dated capture, PLA services/arms, Taiwan pressure, South China Sea, PRC cyber advisory page-level refresh, space, defense-industrial, DoD-to-PRC-issuer crosswalk, and PRC-Russia support packets | High for source identity; moderate for public completeness and current implementation evidence | No operational detail, targeting, live tracking, contingency planning, cyber exploitation, telecom network diagrams, lawful-intercept detail, issuer-claim laundering, or export-control evasion |
| CIA World Leaders | Registered | Foreign government reference packet | High | No personal dossiers or targeting |
| CIA Factbook / CIA maps legacy | Replacement note added; maps split into map/geospatial register; theater map index added | Map-heavy theater source packets as needed | High for sunset status; moderate for archived access | No current claims without refresh |
| FBI terrorism | Law-enforcement source capture packet and assessment added; FBI page verified | FBI/DHS terrorism and targeted-violence source packet with current DHS HTA and State designation refresh | High for FBI source-family framing; moderate pending DHS/State annual refresh | No political profiling, tactics, recruitment, attack-method detail, or protected-speech labeling |
| FBI cyber / IC3 | Law-enforcement source capture packet and assessment added; IC3 2024 report verified; Salt Typhoon telecommunications source note, PRC APT/Typhoon label crosswalk, cyber nation-state actor/APT tracker, Russia state-cyber packet, and weekly current source sweep tracker added | Iran cyber source packet, DPRK cyber-finance/IT-worker packet, IC3 data extraction map, PRC/Russia advisory page-level refresh, and allied cyber-center crosswalk | High for FBI/IC3 source identity; moderate for current advisory page-level extraction | No exploit or evasion detail, indicators-for-misuse, provider vulnerability mapping, telecom network diagrams, APT alias laundering, or sanctions/finance procedure |
| FBI counterintelligence | Law-enforcement source capture packet and assessment added; FBI page verified | FBI/DOJ counterintelligence and national-security legal-action source packet | High for FBI source-family framing; moderate for case-specific current state | No identification of private persons absent official legal source |
| FBI WMD | Law-enforcement source capture packet and assessment added; WMD/biosecurity source packet already added | Maintain WMD public-source packet and add FBI/FSAP/DTRA/State BWC refresh as needed | Moderate to high by source family | No materials, methods, device, facility, site-map, or vulnerability detail |
| ODNI global biolab disclosure | Source-treatment note, WMD/biosecurity source packet, and Ukraine claim-reconciliation note added | Declassification and information-resilience source note | High for ODNI release; moderate to low for uncorroborated underlying claims | No biological methods, facility table, site mapping, or vulnerability detail |
| DTRA / Cooperative Threat Reduction | DTRA mission, fact sheet, and DoD BTRP Ukraine fact sheet registered; document-level CTR work still needed | DoD Cooperative Threat Reduction source packet | Moderate | No foreign facility inference from general mission pages |
| Federal Select Agent Program | Registered; WMD/biosecurity source packet added | Select Agent oversight source packet | High for source family | No controlled lists, quantities, facility-sensitive detail, or compliance workarounds |
| State / UNODA BWC sources | Source families registered with access caveats | BWC treaty and compliance source packet | Moderate pending access refresh | No legal conclusion without current text/status verification |
| NCTC groups | Registered as historical | Terrorism group source refresh | Moderate to low for current status | Do not reproduce tactics |
| DHS Homeland Threat Assessment | Registered and routed through law-enforcement source capture packet | DHS HTA packet with dated URL verification | Moderate | No domestic political enemies framing |
| CISA KEV/advisories | Registered; cyber nation-state actor/APT tracker added as the advisory-control surface; PRC APT/Typhoon label crosswalk added | PRC advisory page-level refresh and Russia/Iran/DPRK source packets | High | No offensive cyber instruction, IOCs-for-misuse, or exploit chains |
| NSA cyber advisories | Registered; cyber nation-state actor/APT tracker added as the advisory-control surface; PRC APT/Typhoon label crosswalk added | PRC advisory page-level refresh and Russia/Iran/DPRK source packets | High | No exploit chains, commands, malware procedures, or operational guidance |
| State FTO and terrorism reports | Registered | Terrorism designation packet | High | Designation status only; no targeting |
| Treasury OFAC and risk assessments | Active in repo | Sanctions and illicit finance source packet | High | No evasion guidance |
| DEA threat sources | Registered and routed through law-enforcement source capture packet | TCO and narcotics source packet | Moderate | No trafficking methods |
| ATF data/statistics | Registered and routed through law-enforcement source capture packet | Firearms commerce, tracing, trafficking, and explosives statistics source packet | Moderate | No procurement or explosives guidance |
| CBP statistics | Registered and routed through law-enforcement source capture packet | Border and port-of-entry statistics source packet | Moderate | No route or evasion guidance |
| Coast Guard sources | Registered and routed through law-enforcement source capture packet | Maritime homeland source packet | Moderate | No patrol or interdiction detail |
| DOJ NSD | Registered and routed through law-enforcement source capture packet | National security legal-action tracker | Moderate | Case-specific evidence only |
| NGA public sources | Map/geospatial register, theater map index, Indo-Pacific/Taiwan map packet, Philippines/South China Sea map packet, and Europe/NATO/Ukraine map packet added | Additional map-heavy theater packets as needed | Moderate | No targeting or vulnerability maps |
Update Triggers
- ODNI releases a new Annual Threat Assessment.
- DoD releases a new PRC military power report, DIA refreshes China military power material, or major China/PLA official-source collections change.
- ODNI releases new declassified WMD, biosecurity, foreign-laboratory, or threat-reduction material requiring claim-treatment controls.
- DHS releases a new Homeland Threat Assessment.
- FBI releases a new IC3 annual report or strategic terrorism/cyber/WMD assessment.
- CISA or NSA publishes a major joint cyber advisory series affecting tracked state actors, APT labels, ransomware, or critical infrastructure.
- State updates FTO, State Sponsors of Terrorism, or Country Reports on Terrorism material.
- Treasury updates national risk assessments, sanctions programs, or OFAC designation source pages.
- DEA, ATF, CBP, or Coast Guard releases annual statistical or threat reports.
- CIA, State, or NGA changes public map/country/foreign leadership source availability.
Information Gaps
- Current DHS HTA and some agency product URLs need manual date capture.
- The NCTC public group guide is historically useful but stale for current group status.
- Public law-enforcement statistics require definition discipline before use in trend claims.
- Law-enforcement source treatment now has an assessment baseline, but dated page-level extraction remains incomplete for DHS, DEA, ATF, CBP, Coast Guard, Treasury/State status records, and DOJ legal-action lanes.
- Cyber advisories can include technical detail that must be summarized safely.
- APT labels can be unstable across official, allied, and private research sources; source-class labels are required before broader use.
- Domestic threat products require explicit civil liberties boundary review.
- The Ukraine biolab claim-reconciliation note reduces the immediate issuer-layering gap, but DoD Cooperative Threat Reduction, State Department arms-control/BWC, congressional, Ukrainian, treaty-organization, technical biosecurity, and independent oversight sources still need document-level collection before stronger judgments are made.
- State and UNODA BWC source pages need successful access refresh before carrying exact treaty-status or current U.S. diplomatic claims.
- DTRA Cooperative Threat Reduction needs document-level source collection; the current packet only registers the public mission/fact-sheet source family.
Cross References
- U.S. Official Threat Source Operating Picture
- U.S. Law Enforcement Threat Source Assessment
- Official U.S. Threat Source Baseline Packet
- U.S. Law Enforcement Threat Source Capture Packet
- Official U.S. Threat Source Assimilation Matrix
- Official U.S. Intelligence And Law Enforcement Source Register
- Legacy Factbook Replacement Note
- ODNI Global Biolab Disclosure Source-Treatment Note
- Ukraine Biolab Claim-Reconciliation Source Note
- WMD/Biosecurity Public Source Baseline Packet
- China/PLA Official Military And Security Source Baseline Packet
- PRC Official Doctrine And Issuer-Language Source Packet
- DoD/DIA China Military Power Extraction Map
- Salt Typhoon And Telecommunications Defensive Source Note
- PRC APT/Typhoon Label Crosswalk And Advisory Refresh Source Packet
- Cyber Nation-State Actor And APT Source Tracker
- Weekly Current Source Sweep Tracker
- Russia State Cyber Source Packet Weekly Sweep Continuation
- China/PLA Source Collection Tracker
- Theater Map Index
- Indo-Pacific And Taiwan Map Reference Source Packet
- Philippines And South China Sea Map Reference Source Packet
- Europe, NATO, And Ukraine Map Reference Source Packet
- Russia Strategic Weapons And Nuclear Signaling Source Packet
- DPRK Strategic Weapons Source Packet
- Iran WMD And Missile-Relevance Source Packet