Playbooks

PB00001 Game Mechanics: show examples of fake news and train the user to identify them on the basis of various types of indicators

Summary:


PB00002 Game mechanics: use a crowd-sourced mechanism so that the public can categorize newly spreading news sources or articles a la Re-Captcha

Summary:


PB00003 Develop a regulatory body like the CFPB to regulate and enforce regulation for digital organizations.

Summary:


PB00004 Government regulation

Summary:


PB00005 Government shutdown.

Summary:


PB00006 Use a media campaign to promote in-group to out-group in person communication / activities .

Summary:


PB00007 Spread Infographics & Training Material teaching ways to identify and counter divisive rhetorical techniques and content, by stimulating their sense of outrage at being manipulated. Show them how to address the rhetorical technique rather than the content

Summary:


PB00008 Twitter hashtags & paid advertising

Summary:


PB00009 Teach people to identify non-civil/unconstructive conversations and call them out

Summary:


PB00010 Popularize (via memes, infographics) and get the centrists demographic who are tired of polarization to identify such messaging, call it out and display their outrage on the basis of divisive rhetorical techniques rather than merely arguing about the content

Summary:


PB00011 Recruit respected thought leaders to model behavior

Summary:


PB00012 Feature established respected thought leaders to model behavior

Summary:


PB00013 Promote dialog from communities with disparate viewpoints

Summary:


PB00014 Establish facilitation guidelines for "civil" interaction.

Summary:


PB00015 Identify ignorant agents (ex: anti-vaxx people willing to pay money to advertise their cause)

Summary:


PB00016 Sell physical merchandise that has instructive counter-effect

Summary:


PB00017 Secondary Objective: Obtain real-life identity of ignorant agents, to further disrupt their influence activities

Summary:


PB00018 Create multiple versions of the narrative and amplify.

Summary:


PB00019 Dissect narrative, piecemeal the components and then amplify

Summary:


PB00020 Hijack hashtag and redirect conversation to truth based content.

Summary:


PB00021 Hijack (man in the middle) redirect from bad content to good content

Summary:


PB00022 -Discredit via backstopped blogs/websites showing their past activity and opinions as being opposite to their current ingroup

Summary:


PB00023 Create a trail of commentary about their idea of infiltrating the enemy (current in-group)

Summary:


PB00024 Publicize this by targeting their in-group competitors (ignorant agents)

Summary:


PB00025 Verify personal credentials

Summary:


PB00026 Syndicated reputation management (fact-checking syndication)

Summary:


PB00027 Academia ISAO

Summary:


PB00028 Rate restrict via regulation posting above a statistical threshold

Summary:


PB00029 Unless account is de-anonymized and advertised as automated messaging

Summary:


PB00030 Identify the accounts, the real person's name and shame them on social media.

Summary:


PB00031 Social media companies remove inactive accounts

Summary:


PB00032 Account holders remove accounts they're no longer using.

Summary:


PB00033 Influencers encourage people to remove their inactive accounts "Do you really need that old account" campaign, world-war-two poster-style.

Summary:


PB00034 Create alternative memorial websites for accounts of deceased people, so their accounts can't be reactivated on 'live' sites.

Summary:


PB00035 Educate/scare users on the risks of losing control over a dormant account (would their employer be forgiving if an account associated with the user suddenly starting posting extremist content?).

Summary:


PB00036 Platform adds a hash of the post to the post metadata and make it publicly available (content addressing). Scrape for duplicate content and deplatform the content/users across affected. In all cases some checks need to prevent deplatforming of highly correlated organic traffic such as a community group copy/pasting their bake sale advert.

Summary:


PB00037 Platform adds plagiarism score metadata to a post and makes it publicly available. Scrape for duplicate content and deplatform the content/users across affected platforms.

Summary:


PB00038 Use message hashing and fuzzy hashing to detect identical/similar content.

Summary:


PB00039 Use plagiarism algorithm to detect similar blog posts.

Summary:


PB00040 Use basic web scraping techniques, Google dorks, etc to identify similar head lines, uniques phrases, authorship, embedded links and any other correlating data point.

Summary:


PB00041 Affected person contacts platform for action

Summary:


PB00042 Work with platform to identify active target audiences through finanical data and messaging.

Summary:


PB00043 Use a platform's publicly available advertising/targeting capabilities to enumerate a list of possible microtargeted demographics. Compare these to known TAs of past/ongoing influence ops to identify the vulnerable demographics.

Summary:


PB00044 DDoS adversary link shorteners by spamming real links.

Summary:


PB00045 Compromise service and reroute links to benign content or counter messaging.

Summary:


PB00046 Degrade TA engagement using bots; direct the adversary to engage insular bot communities-within-communities rather than the authentic target audience.

Summary:


PB00047 Degrade MOEs/MOPs by faking inter-community sharing.

Summary:


PB00048 Distort TA demographics by posting irrelevant content, misleading demogaphic data, etc.

Summary:


PB00049 Work with the media platform to distort publicly available metrics. Can we work with Twitter to get crappy off-brand memes artificially bumped without needing to create fake accounts, etc.?

Summary:


PB00050 Use adtech to promote content inconsistent with TA demographics. If the adversary is reverse engineering a groups demographics by analyzing ads placed on the platform/group, by spamming ads for out-group stuff it may distort analysis of the group.

Summary:


PB00051 Distort Google Trends and other publicly available source of metrics using bots, cyborgs, adtech.

Summary:


PB00052 Distort TA emotional response to content/narratives.

Summary:


PB00053 Promote damp squibs. Within a known TA promote/inflate crappy off-brand memes which are unlikley to resonate.

Summary:


PB00054 Detect early trending/engagement and undermine the content by responding with 5Ds, toxic community behaviour, satirical responses, etc.

Summary:


PB00055 If adtech is used, fake clicks and engagements on the content.

Summary:


PB00056 Elected officials lead return to First Amendment norms that embrace free and fair media as central to democracy.

Summary:


PB00057 TechCamp bringing together local journalists, with a several-day training program that includes a sponsored yearlong investigative project

Summary:


PB00058 Create a standard reporting format and method for social platforms for reporting false accounts.

Summary:


PB00059 Determine whether account might be compromised

Summary: Questions: - Is the account compromised? - Is it known to be associated with threat actors - common/random name - Names violate terms of service - Dormant account - Change of country IP - Social network growth patterns (number of friends etc) - Evidence of linguistic artifacts (multiple fingerprints, terms/idiosyncrasies ) - Community vs. narrative vs. individuals


PB00060 Report suspected bots.

Summary:


PB00061 Report ToS violations. In all playbooks the platform must force user verification, credential reset and enable MFA. Suspend the account if it cannot be verified.

Summary:


PB00062 Use sites like https://haveibeenpwned.com to detect compromised and at risk user accounts.

Summary:


PB00063 Monitor for unusual account usage (use of VPN, new geographic location, unusual usage hours, etc).

Summary:


PB00064 Detect sudden deviation in user sentiment such as suddenly dropping hashtags linked to extremist content.

Summary:


PB00065 Purchase "likes", "retweets" and other vehicles which identify a bot and/or hijacked account. Ban the account.

Summary:


PB00066 Detect hijacked account and spam their posts. "OP is a known disinformation bot. http://link.to.proof[.]com"

Summary:


PB00067 Add date and source to images

Summary:


PB00068 Develop a baseline virality per platform, monitor trends, trigger alert for anomalies.

Summary:


PB00069 Destroy Desire to Work for Propaganda Businesses

Summary: -Identify non-committed actors (ie. IRA 2$/h employees) -Identify where they reside (ie. postal code level) -Send a viral message that clarifies the risk of working in influence ops.


PB00070 Hack personal accounts -Send inflammatory messages on their behalf

Summary:


PB00071 Identify target and entice individual to reveal insider information

Summary:


PB00072 -Model communities on the basis of behavior and identity, etc -Model different online behaviors in terms of how these groups interact with propaganda -Model how these group-based behaviors are affected by the tech platform they are using -This research can feed into later-stage playbooks to adapt them to communities/platforms

Summary:


PB00073 Model each major platform

Summary: Determine: a) Moderation Method (global, subcommunity level, none -ie. twitter, reddit, 8chan) b) Access Model (friend request, open, real-life identity) c) Communication Model (global, friends only, subcommunity, hybrid) Determine how the combination of the above (and other characteristics) allow different technical methods to communicate and influence various audiences This will allow to adapt playbooks to specific platforms


PB00074 - Trace money and financing - Trace connections to known operations

Summary:


PB00075 - Hashes - Data voids - User handles - Domains + link shortener - TinEye For video (visual artifact)

Summary:


PB00076 Create standard scoring for emptional content

Summary:


PB00077 Ad tech - De-platform funding sites - Blockchain transaction - Sell items - Identify manufacturers - Pay to play meetings

Summary:


PB00078 Identify ad tech on platforms - Selling merch? - Financial platform - Bitcoin etc.. .

Summary:


PB00079 Identify re-use of ads

Summary: Look at Ad trackers, Tracking ids, Tracking ads, Re-use of as features (language, name, themes, plug-in, re-use/versions)


PB00080 track funding sources

Summary:


PB00081 Build and update a model bot behaviour.

Summary:


PB00082 Build network of companies that model / rate bots. Build standards around data sharing and exchange

Summary:


PB00083 Build a reporting system for the public, so they can report disinformation artefacts and have them available to channels etc for action.

Summary: