2C – Large-Scale Intelligence¶
2C is research-grade institutional work. The cells here are where coalitions, civil-society research labs, and platform-policy teams operate – the analytical layer that sits above day-to-day fact-checking and feeds the policy briefs, the coalition reports, the cross-organisational threat assessments. The intended reader is on the institutional analysis side of the room – Sinar Project's network-measurement team, MAFINDO's research desk during an election cycle, a Watchdog OSINT lead working with LIRNEasia, a coalition partner preparing a DISARM-coded report for inter-org sharing. This section walks the three 2C cells, carries forward the access-barrier honesty discipline from 1C, operationalises the ABCDE / DISARM split that Foundational Decision 2 codifies, integrates the coordinated-operation pattern analysis material into the cross-lingual narrative tracking work in 2C.3, and lands the operational link sideways into the country-page case studies and the methodology layer.
When this tier applies¶
A claim about an alleged Indonesian-government policy starts appearing as variations across WhatsApp Groups, Telegram channels, Facebook Groups, and TikTok comment sections in the same forty-eight-hour window. The variations rhyme on phrasing and imagery but cycle through enough surface variation to defeat per-platform debunk efforts. That is 2C.1 work: cross-platform claim correlation through Information Tracer, supplementary news-side monitoring through Media Cloud, SEA-network and censorship monitoring through Sinar Project iMAP, and Telegram-specific channel-pattern work through FactFlow AI.
A 1C.1 CIB pass at MAFINDO has surfaced a cluster of fifty accounts pushing aligned content, and the research team wants to visualise the network for an internal briefing and a potential coalition report. 2C.2 is the mapping layer: Maltego for the OSINT gold-standard graph environment, Gephi for the publication-grade open-source visualisation, Meta Content Library as the IFCN-signatory escalation route to historical Facebook data.
A coalition report needs to describe a coordinated operation in language other organisations will understand and re-use. ABCDE for the public-facing prose; DISARM for the institutional annex; the Online Operations Kill Chain for the disruption-mapping section; DISARM Navigator with STIX2 if a partner CSIRT is integrating the operation into shared threat infrastructure. 2C.3 is the codification layer that turns analytical work into shareable institutional output.
How techniques in this tier connect¶
The 2C cells run sequentially across an institutional case: monitoring (2C.1) surfaces the pattern; network analysis (2C.2) maps it; cross-lingual narrative tracking and DISARM (2C.3) codifies it. They also run in parallel during major events. A coalition operation during an Indonesian election cycle might run monitoring through Information Tracer continuously, do iterative network-mapping passes through Gephi as new accounts surface, and codify weekly reports against the ABCDE vocabulary for public briefings while keeping a DISARM-coded annex for inter-org sharing.
The editorial honesty about access barriers that surfaced in 1C carries forward with sharper teeth at 2C. Meta Content Library is IFCN-signatory-gated – MAFINDO, Rappler, and VERA Files have access; Watchdog Sri Lanka does not currently, and Laos has no IFCN signatory at all, which is named directly in the Meta Content Library card and in the Laos country page structural-gap close. DISARM Navigator with STIX2 is institutional-CSIRT infrastructure that very few SEA newsrooms operate against directly; the Quickstart redirect on the card explains how to cite Navigator-coded output without planning a deployment that probably is not realistic for the reader. Maltego's Community Edition is free but its full-tier OSINT capabilities sit at paid-tier pricing.
The ABCDE / DISARM split is what Foundational Decision 2 codifies and what 2C.3 operationalises. ABCDE is the public-facing surface vocabulary – Actor, Behaviour, Content, Distribution, Effect. DISARM is the institutional annex – the structured taxonomy of tactics, techniques, and countermeasures that inter-org sharing and CSIRT integration use. Both go in the toolkit, but in clearly distinct contexts: ABCDE for the press release and the public-facing brief; DISARM for the threat-intel exchange and the academic case study. The Online Operations Kill Chain sits adjacent – the Meta / Carnegie ten-link framing that walks an operation from setup through dissemination to platform response, useful when the analytical question shifts from description to disruption.
The coordinated-operation pattern analysis material — including the source-handling cross to T6 — lives in 2C.3. Pattern recognition across multilingual narrative-tracking work is the operational layer that turns ABCDE description into DISARM-coded analysis, and the toolkit's regional re-angle here is non-trivial: DISARM and the Online Operations Kill Chain were built around European FIMI cases, and the SEA information environment is mostly domestic – buzzer networks in Indonesia, cybertroop infrastructure in the Philippines, scam-fraud-hybrid economies across the region. The toolkit re-angles the European frameworks for SEA's domestic operations and does not pretend the regional context is just a smaller version of the European one.
What this tier produces¶
Coalition-grade analytical output. The artefacts that 2C produces tend to be: a cross-platform pattern report identifying the same claim's variations across messaging apps and platforms; a network map describing the actor pool driving the pattern; an ABCDE-coded brief for public release; a DISARM-coded annex for institutional sharing; and the operational record that informs the country-page case studies and the policy-brief recommendations downstream of the toolkit.
When to escalate, when to stop¶
Stop when the institutional record is complete – this is the Pillar 2 ceiling and there is no higher tier inside the pillar. The operational link is sideways, into the cross-cutting Regional Case Studies layer the country pages document. A 2C analytical record on Indonesia feeds the Indonesia country page and the broader CekFakta-coalition reporting cycle; a record on Sri Lanka feeds the Sri Lanka country page and the Hashtag / Watchdog / Fact Crescendo / FactSeeker / FactCheck.lk record set.
The T5 escalation tree handles the rare backward move from 2C into 1C when network analysis surfaces an artefact that needs institutional-grade deepfake or explainable-AI work the coalition has not yet done. Most 2C work routes sideways into reporting and policy, not back down into Pillar 1.
The cells in detail¶
2C.1 – Automated claim monitoring¶
When monitoring a claim moves from per-tipline-message work into cross-platform pattern work, the operational unit shifts. The cell ships four tools that cover the practical surface of cross-platform monitoring at SEA institutional scale.
Information Tracer is the primary cross-platform claim tracer – the operational option for tracking a claim's variations across messaging-app and platform boundaries. Media Cloud is the news-side alternative – 60,000-plus news sources, 20-plus languages, free at the basic tier, with the honest gap that SEA news-source coverage is uneven. Sinar Project iMAP is the SEA-network-monitoring option – ten-country OONI infrastructure with documented MalaysiaNow and Malaysia-Today MCMC-blocking case data, the practical alternative to Meta Content Library's gated access for SEA partners. FactFlow AI is the Telegram-specific channel-pattern option, anchored in the Animal Político ten-million-message processing reference.
Organisations select by platform and language. Cross-platform claim correlation routes through Information Tracer. News-side monitoring routes through Media Cloud with the SEA coverage caveat. SEA-specific network and censorship measurement routes through Sinar Project iMAP – the practical route around Meta Content Library's gating for partners not on the IFCN list. Telegram-specific channel monitoring routes through FactFlow AI. All four are non-detector behaviour-pillar signal generators under Architectural Anchor 1. Under Anchor 2 a single platform-pattern hit is one signal class and combines with claim-extraction (2B.2) or CIB (1C.1) before any institutional finding gets published. The bridge in is from 2B.* tipline-and-extraction operations when the case scales; the bridges sideways are to 2C.2 visualisation and forward to 2C.3 codification.
2C.2 – Network analysis¶
When CIB analysis at 1C.1 or claim monitoring at 2C.1 surfaces a network of related accounts, posts, or domains, mapping the network is the next step. Three tools cover the cell at three different access tiers.
Maltego is the OSINT gold standard – Community Edition is free, full-tier pricing applies for production-grade institutional work. The interface is the most documented in OSINT training and the default starting point for analysts who already work in the Maltego graph environment. Gephi is the free open-source visualisation alternative – the right choice when the analysis benefits from publication-grade network graphics for coalition reports or academic case studies. Meta Content Library is the IFCN-signatory escalation route to historical Facebook data, with the gating policy named directly on the card: IFCN-signatory researchers at MAFINDO, Rappler, and VERA Files have access; journalists are excluded under the current policy; Laos has no IFCN signatory at all.
In workflow terms, organisations start with Maltego because Community Edition is free and the training curve is well-documented. Gephi is the reach when the analysis benefits from publication-grade graphics. Meta Content Library is the only path to historical Meta data for institutional partners and is gated to IFCN signatories – the same Graphika-style redirect pattern that 1C surfaced applies here. The toolkit names the gating, gives the operational alternative (Sinar Project iMAP for live network monitoring as a partial workaround on platform-related questions), and does not pretend Meta Content Library is reachable for readers it is not actually reachable for. All three are non-detector tools under Anchor 1; under Anchor 2 a network map is a single visualisation of an existing CIB signal, not a new signal class. The bridge in is from 1C.1 CIB or 2C.1 monitoring; the bridge forward is to 2C.3 for codification.
2C.3 – Cross-lingual narrative tracking + DISARM¶
When an operation has been detected, mapped, and characterised, this cell provides the shared vocabulary for describing it across organisations. The pattern-analysis work that turns multilingual narrative tracking into a codified record lives here, and the cell carries the Decision 2 ABCDE / DISARM split as embedded operational logic.
ABCDE Framework is primary – the public-facing surface vocabulary the toolkit defaults to for any externally-shared analytical work. The five elements (Actor, Behaviour, Content, Distribution, Effect) read cleanly in a press release and in a coalition brief; the framework is the vocabulary that civil-society organisations across the region already share. DISARM Framework is the institutional alternative – the structured taxonomy of tactics, techniques, and countermeasures for inter-org reporting and researcher use, with the European-FIMI provenance named on the card and the SEA re-angle codified in the toolkit's prose. Online Operations Kill Chain is the Meta and Carnegie ten-link framing for operational response planning – useful when the analytical question is "how do we disrupt this" instead of "how do we describe it." DISARM Navigator with STIX2 is the escalation option for institutional CSIRTs and government partners – tooling that integrates DISARM-coded operations into shared threat-intel infrastructure, with the same access-barrier redirect pattern the 1C and 2C.2 access-gated tools use.
The operational logic across the cell: public-facing analysis defaults to ABCDE. Institutional reporting and inter-org sharing route to DISARM. Operational-response planning uses the Kill Chain. CSIRT-level integration with threat-intel infrastructure uses Navigator with STIX2. None of these are detection signals – they are taxonomies and process frameworks under the framework-not-tool declaration that Anchor 1 carries forward. The pattern-analysis material the toolkit integrates here is the work of recognising operation shapes across regions, languages, and platforms: the same domestic-buzzer pattern in Indonesia repeating with surface variation in Filipino cybertroop work and Thai network-coordinated content; the cross-language narrative coherence that classifies multiple linguistic surface forms as one coordinated operation. The honest gap is that the European-FIMI origins of DISARM and the Online Operations Kill Chain need explicit re-angling for SEA's domestic-operation reality; the toolkit names this and applies the re-angle in the framework-card prose. Bridges: from any of 1C.1, 2C.1, or 2C.2 when the analytical work needs codification – this cell is the codification step. The operational link onward is to the cross-cutting Regional Case Studies theme on the country pages, which is where 2C analytical output lands as published case material.
Cross-references¶
- T5 escalation – tier-pivot logic between 2C and Pillar 1 when network analysis surfaces an artefact that needs 1C work
- T6 source-protection – binding alongside any 2C work that handles source-identifying intake (Maltego transforms in particular)
- 1C Institutional Analysis – the institutional Pillar 1 partner to 2C work
- 2B Collaborative Verification – the scaling entry into 2C
- Country pages: Indonesia, Malaysia, Philippines, Thailand, Sri Lanka, Laos – where 2C analytical output lands as documented case material
- Methodology: architectural anchors – Anchor 1's framework-not-tool declaration as operationalised in 2C.3
- Methodology editorial-patterns – the access-barrier redirect pattern (Meta Content Library, DISARM Navigator)
Sources¶
- Sinar Project. iMAP Internet Monitoring Action Project. Sinar Project, 2025. sinarproject.org. (Sinar Project iMAP MCMC-blocking case data; Malaysia coordinated-operation tracking at 2C.1.)
- VERA Files / #FactsFirstPH. About VERA Files and #FactsFirstPH. VERA Files, 2025. verafiles.org. (Philippines coalition-grade analytical work at 2C.1; #FactsFirstPH CIB pipeline cross-reference.)
- DISARM Foundation. DISARM Framework Navigator. DISARM Foundation, 2025. disarmframework.org. (ABCDE / DISARM split operationalised at 2C.3; institutional-tier framework reference.)
- Stanford Internet Observatory / EU DisinfoLab. FIMI Frameworks: European and Southeast Asian Applications. 2025. (SEA domestic-operation framing against European FIMI methodologies for 2C.3 narrative.)
- change-log — Foundational Decision 2 (ABCDE / DISARM split).
- Architectural Anchors — Anchor 1 (framework-not-tool declaration) as operationalised at 2C.3.