Geospatial Intelligence (GEOINT) is intelligence derived from location and the visual or spatial representation of activity on the earth. It combines imagery, maps, and geographic data to describe where things are and how they relate in space. In cyber threat intelligence, GEOINT adds a geographic dimension to analysis: mapping infrastructure, placing adversary operations in a physical context, and associating activity with regions, facilities, or routes.
As a collection discipline, GEOINT is defined by its spatial nature. Analysts use it to visualize the distribution of infrastructure, to understand the physical context around a target, and to enrich other intelligence with location detail. It can connect digital observations to real-world geography, for example by relating network infrastructure to hosting regions or by situating events within a map of operations. In practice it is most often used to support and contextualize findings rather than to stand alone.
GEOINT matters because geography shapes risk, attribution context, and operational reach. It helps analysts communicate complex relationships visually and spot patterns that are hard to see in tabular data. Its typical inputs include commercial satellite and aerial imagery, mapping and geographic datasets, and location metadata. Its limits include imagery resolution and timeliness, the ambiguity of inferred locations, and privacy considerations that constrain how location data may be used.
References#
- SANS Cyber Threat Intelligence program materials
- The Diamond Model of Intrusion Analysis