Official Threat Source Collection Tracker

The official-source lane should expand through dated source packets, not a single sprawling enemies document. This tracker identifies which agency source families are already usable, whic...

Full Index

Classification: UNCLASSIFIED//OPEN SOURCE

Tracker ID: WI-TRACKER-US-THREAT-SOURCES-2026-0001

Prepared UTC: 2026-06-13T06:00:00Z

Information cutoff UTC: 2026-06-13T06:00:00Z

Source base: U.S. intelligence and law-enforcement source register; ODNI, CIA, FBI, NCTC, DHS, CISA, NSA, State, Treasury, DEA, ATF, CBP, Coast Guard, DOJ, and NGA public source families; existing WARLOCK-INDEX source registers and assessments.

Analytic confidence: High for collection architecture. Moderate for source recency because dynamic agency pages and annual reports require dated refreshes.

Purpose: Track the collection status of official U.S. threat-source families for future WARLOCK-INDEX expansion.

Boundary: This tracker does not provide recommendations, targeting, investigative direction, collection tasking, operational guidance, route selection, technical exploitation, domestic political profiling, or tactical instructions.

Bottom Line

The official-source lane should expand through dated source packets, not a single sprawling enemies document. This tracker identifies which agency source families are already usable, which need dedicated packets, and which safety boundaries must be preserved before the corpus makes stronger judgments.

Collection Matrix

Source familyCurrent statusNext productConfidenceBoundary
ODNI Annual Threat AssessmentActive in repo; used in Russia, DPRK, and Iran strategic-weapons packetsKeep annual comparison packet currentHighNo classified inference
CIA World LeadersRegisteredForeign government reference packetHighNo personal dossiers or targeting
CIA Factbook / CIA maps legacyReplacement note added; maps split into map/geospatial register; theater map index addedMap-heavy theater source packets as neededHigh for sunset status; moderate for archived accessNo current claims without refresh
FBI terrorismRegisteredFBI/DHS terrorism source packetHighNo political profiling or tactics
FBI cyber / IC3RegisteredCISA/NSA/FBI cyber source packetHighNo exploit or evasion detail
FBI counterintelligenceRegisteredForeign intelligence source packetModerateNo identification of private persons absent official legal source
FBI WMDRegisteredWMD public-source packetModerateNo materials, methods, or vulnerability detail
NCTC groupsRegistered as historicalTerrorism group source refreshModerate to low for current statusDo not reproduce tactics
DHS Homeland Threat AssessmentRegistered as product familyDHS HTA packet with dated URL verificationModerateNo domestic political enemies framing
CISA KEV/advisoriesRegisteredDefensive cyber advisory packetHighNo offensive cyber instruction
NSA cyber advisoriesRegisteredDefensive cyber advisory packetHighNo exploit chains
State FTO and terrorism reportsRegisteredTerrorism designation packetHighDesignation status only; no targeting
Treasury OFAC and risk assessmentsActive in repoSanctions and illicit finance source packetHighNo evasion guidance
DEA threat sourcesRegisteredTCO and narcotics source packetModerateNo trafficking methods
ATF data/statisticsRegisteredFirearms trafficking source packetModerateNo procurement or explosives guidance
CBP statisticsRegisteredBorder threat vector source packetModerateNo route or evasion guidance
Coast Guard sourcesRegisteredMaritime homeland source packetModerateNo patrol or interdiction detail
DOJ NSDRegisteredNational security legal-action trackerModerateCase-specific evidence only
NGA public sourcesMap/geospatial register, theater map index, Indo-Pacific/Taiwan map packet, Philippines/South China Sea map packet, and Europe/NATO/Ukraine map packet addedAdditional map-heavy theater packets as neededModerateNo targeting or vulnerability maps

Update Triggers

  • ODNI releases a new Annual Threat Assessment.
  • DHS releases a new Homeland Threat Assessment.
  • FBI releases a new IC3 annual report or strategic terrorism/cyber/WMD assessment.
  • CISA or NSA publishes a major joint cyber advisory series affecting tracked state actors, ransomware, or critical infrastructure.
  • State updates FTO, State Sponsors of Terrorism, or Country Reports on Terrorism material.
  • Treasury updates national risk assessments, sanctions programs, or OFAC designation source pages.
  • DEA, ATF, CBP, or Coast Guard releases annual statistical or threat reports.
  • CIA, State, or NGA changes public map/country/foreign leadership source availability.

Information Gaps

  • Current DHS HTA and some agency product URLs need manual date capture.
  • The NCTC public group guide is historically useful but stale for current group status.
  • Public law-enforcement statistics require definition discipline before use in trend claims.
  • Cyber advisories can include technical detail that must be summarized safely.
  • Domestic threat products require explicit civil liberties boundary review.

Cross References