·73 min read·Empyrean 7

Ubiquitous Technical Surveillance Will Get You Killed on the Streets

ubiquitous technical surveillancedigital force protectionoperations securitysignature managementcommercial location datadata fusioncounterintelligencepattern of lifeco-traveler analysisIndo-PacificEABOStand-In Forces

Introduction

On 14 April 2026, U.S. Central Command told Congress that it had received multiple threat reports concerning adversary exploitation of commercial location data to target or surveil U.S. personnel in theater. The disclosure became public on May 28th, 2026, through a bipartisan congressional letter and marked the first official confirmation that commercially available location data had reportedly been used against American service members in an active war zone.

CENTCOM did not identify the adversary or explain how the data was acquired. Because the reports arose during the conflict with Iran, analysts have reasonably identified Iran as the most likely actor, but that attribution remains unconfirmed. What is confirmed is troubling enough: the data was apparently not obtained through a conventional compromise of the service members’ devices. It was part of a commercial surveillance ecosystem through which movement histories are routinely collected, packaged, transferred, and sold.

This piece is long. It covers the doctrine, the plumbing, the body count, and the countermeasures, in that order, because I have found that people do not take the countermeasures seriously until they understand the plumbing, and they do not care about the plumbing until they have seen the body count.

If you build software in this space, as we do, you have an obligation to explain the mechanism rather than gesture at it. If you are an operator, a site security manager, an intelligence officer, a port director, a federal agent, or a person who is uncomfortable with how much of your life is legible to strangers, this is written for you.

The Pentagon Stopped Calling This Hypothetical in April 2026

The confirmation arrived through a letter from fourteen members of Congress, led by Senator Ron Wyden and Representative Pat Harrigan, addressed to the Department's Chief Information Officer. CENTCOM's unclassified written response, first reported by Reuters, acknowledged the threat reports without further specifics, which is what an unclassified response looks like when the specifics are ugly.

The lawmakers framed the exposure plainly: commercial location data reveals where troops congregate and what their pattern of life looks like, which supports targeting for missiles, drones, or improvised explosive devices, and supports counterintelligence work besides. Wyden's line was that it is time to start treating the AdTech industry as a national security threat. Whatever you think of the politics surrounding that decision, the operational claim is not in dispute.

What makes the disclosure damning is not the threat report, but the timeline attached to it. According to the lawmakers, in 2016 a government contractor briefed senior officers at Joint Special Operations Command on exactly this problem, and during the demonstration tracked phones from U.S. bases associated with special operations units to an abandoned cement factory in Syria that was, at the time, reportedly a staging area for American and allied special operations forces. While that was over ten years ago, it was already a viable attack vector against our most lethal Special Missions Units and special operations forces; it has only gotten more precise.

The response has been slower than the threat. CENTCOM told Congress it had only recently rolled out the ability to administratively disable location sharing on smartphones, and that the Department has still not taken steps to deactivate the advertising identifiers that brokers use to follow devices across apps and across years. The Department is simultaneously moving toward broader bring-your-own-device policies, phasing out managed handsets in at least one branch in favor of personal phones.

There is no policy that categorically prevents personal devices in operational areas, saves full unit shakedowns and confiscation while stateside. So, while the threat is confirmed and the attack vector is understood, the mitigation is a checkbox that has not been checked.

I am not writing this to score points against the Department, which is a bureaucracy about the size of a mid-sized nation and moves accordingly. I am writing it because the same exposure applies to a port authority, a police department, a pipeline operator, a stadium security team, and a defense software company with a few people in it. Nobody is going to disable your advertising ID for you either.

Ubiquitous Technical Surveillance Is Not Espionage, It Is Exhaust

The U.S. Government coined the term Ubiquitous Technical Surveillance (UTS) around 2017 to describe a condition rather than an actor.

Ubiquitous technical surveillance is the collection and indefinite retention of data that allows an adversary to connect a person to other people, places, activities, and organizations, forensically, long after the fact.

UTS is neither a wiretap nor a surveillance team, but rather the accumulated residue of ordinary life in an instrumented world, which turns out to be sufficient for reconstruction, and is also for sale. The Central Intelligence Agency has reportedly described the threat as existential, a word intelligence services do not use casually, and one that the Center for Internet Security repeated in its 2025 assessment for American law enforcement.

Doctrine organizes UTS into five threat vectors, and the taxonomy is worth committing to because it is how the problem is being staffed inside the interagency.

  • Online: covers browsing history, search, and social media. I would also argue it should cover LLM chats and LLM memories, too.
  • Electronic: covers the emissions and identifiers of the devices you carry. Whether that is your cellphone connecting to towers, Bluetooth and NFC devices, Wi-Fi, or other wearables and devices with their own signatures (VR/AR glasses, drones, etc.)
  • Visual-physical: covers cameras, license plate readers, and the biometric surface you present to the world.
  • Financial: covers transaction records and the unique identifiers that ride along with them.
  • Travel: covers the bookings, reservations, border crossings, and loyalty programs that pin you to a time and a place with documentary certainty.

Any one of these pillars is a nuisance from a Digital Force Protection (DFP) perspective, because DFP runs counter to UTS. Overlaid, they are targeting products.

The Small Wars Journal has argued, correctly in my view, that UTS is the operationalized form of unrestricted warfare, the doctrine Qiao Liang and Wang Xiangsui described when they wrote that the battlefield would be everywhere and the boundary between war and non-war would be destroyed.

The strategic consequence is that the assumptions underneath a great deal of American practice, meaning access, attribution, and initiative, no longer hold by default. You cannot assume you arrived unobserved. You cannot assume the observation cannot be attributed to you. And you cannot assume that the initiative belongs to the side that moves first, because the side that moves first is the side that leaves a track.

The main thing that differs from UTS from previous generations of the counterintelligence problem is not the sensors, but retroactivity.

A surveillance team must decide to follow you before you go somewhere, which has its own resourcing and mission planning contraindications. UTS does not require that decision, because the data was collected on everyone, stored indefinitely, and can be queried after the fact.

The adversary does not need to know you as a person of interest today, let alone specifically target you at the onset. He needs only to find you interesting eventually and then reach back through two years of coordinates to reconstruct where you slept, who slept near you, and which building you entered in the morning you thought nobody was watching.

Every Automated License Plate Reader (ALPR) you pass by, every time you stay at a hotel or Airbnb, every car you rent, every time you have your phone on you, every time you drive your car, every query you have submitted to Claude or ChatGPT, and dozens of other mundane activities can and will be tracked. Our own globalization is being leveraged against us every second of every day.

Signature Management: OPSEC Is a Process, PERSEC Is a Consequence

This is likely overly pedantic of me, but there is enough sloppy usage of the term OPSEC (let alone PERSEC), that it is worth some definition.

Operations Security (OPSEC) is a five-step analytical process: identify critical information, analyze the threat, analyze vulnerabilities, assess risk, and apply countermeasures. It is a discipline aimed at an operation, and its unit of analysis is the indicator, meaning the observable that an adversary can assemble into knowledge of your intentions or capabilities.

OPSEC was not meant to be a WWII-style poster in a hallway, nor was it meant to be an annual training module, though it has been reduced to both. OPSEC is a repeatable process for finding the things you are unintentionally telling people.

Personal Security (PERSEC) is what happens to a human being when operations security fails. PERSEC is your home address, your spouse's employer, your children's school, the gym you use for your morning lift, the route you run, the plate on your truck.

In an era where a unit's operational indicators can be reconstructed from the aggregate PERSEC failures of its members, the distinction between the two collapses in practice. The DPR soldiers at Makiivka were not conducting an operation when they called home on New Year's Eve. They were simply being human; the reconstruction and subsequent targeting did not care.

Above both sits the thing that actually gets managed, which is signature. Your signature is the total set of observables you emit across all five vectors, whether or not you intended to emit them, and whether or not you know they exist.

Signature reduction is the doctrine of deliberately shaping that emission, and it is being advanced in the professional literature as a counteroffensive concept rather than a defensive one, because a force that can control what it emits regains the freedom of maneuver that UTS collection took away. Hiding is a posture and can be observed as a signature unto itself. Controlling your emissions is a capability.

OPSEC as commonly practiced asks what you should not say or write, and it is not something that we should ignore either. Taking selfies for “the ‘Gram” in an active combat zone or even at your unit’s training location is dangerous and stupid. The stupidity curve only increases when you get into live videos, bragging about combat or deployments, and other autobiographical documenting that so many folks are keen to do. Social media is not the end of it, even the wrong word to the guy at your bodega, a bank teller, your contractor, a longshoreman - by you or your family members - can spell disaster.

Signature management asks what you are emitting, whether or not you speak. That encompasses a much larger set of signals, including some that no policy document has ever contemplated because the underlying technology did not exist when the policy was written. Nobody wrote rules governing advertising identifiers in 1995. Nevertheless, the identifier followed the soldier into the bunker.

DFP demands that we take a more proactive approach to countering UTS while also doubling down on what we should already be doing regarding OPSEC and PERSEC. In a world where we are all subject to persistent surveillance, we must be nearly perfect at managing every other signature.

In Season 1 of HBO’s The Wire, Avon Barksdale, one of the series’ main antagonists, summed up our predicament perfectly: “Thing is, you only got to fuck up once. Be a little slow, be a little late, just once. And how you ain’t gonna never be slow, never be late? You can’t plan for no shit like this, man. It’s life. Yeah, it scares me.” That is the problem we all face now. Let us resolve to never be slow, nor late.

Every Device is a Beacon

The physics of technological modernization for convenience (or otherwise) is that of an unstoppable force versus an immoveable object. UTS was not so much of a concept in regard to OPSEC and PERSEC even three decades ago because we were still using office phones and pagers. Now? We all carry surveillance devices with us or ride them.

A cellular handset that is powered on is in a continuous conversation with the network about where it is. It must be, as that is how a call reaches you. Your cellular device registers with towers, it performs location area updates as it moves, and it does this when idle, when the screen is dark, when you have not opened an app in four hours. The same thing goes for other cellular connected devices. Your Counter UAS scanner that uses an LTE or 5G backhaul? Your brand-new Escalade or S-class Mercedes equipped with onboard internet? That quad-band radio your department issued you with cellular backhaul? It all works the same.

The carrier knows, at minimum, which cell sector you are in, and in practice knows a good deal more than that through timing advance and multilateration. This is not a bug, and there is no setting to turn it off short of powering down or pulling the radio. In theory, “airplane mode” will stop this by disabling the cellular radios. That said, if you just decided to pull the SIM card, your phone may still connect to towers to maintain location and 911 service usage. In Empyrean Defense's own testing, using LineageOS on Samsung devices, these SIM-less phones connected to towers on 2G!

Layer the rest of the stack on top. Wi-Fi radios probe for known networks, broadcasting the names of the access points you have previously joined, which is to say a partial history of where you have been, offered voluntarily to anyone with Kismet or a Wi-Fi Pineapple. Again, your phone is not the only thing with Wi-Fi. Think of all the “smart home” and connected devices you have.

Bluetooth and Bluetooth Low Energy beacon continuously for peripherals, and the retail analytics industry has spent a decade building infrastructure to catch those beacons and correlate them into foot traffic. While stuffing a Wi-Fi radio into devices may not always be possible, everything that is wireless has this signature. Your Beats by Dre or AirPods, your fitness watch, your children’s tablets and toys likely all have Bluetooth as well.

GNSS receivers are passive, so your phone's GPS chip does not emit, but the applications that read it do, and they emit over the cellular link you cannot turn off. Beyond that, your tire pressure monitoring sensors emit, on an unlicensed band, with a static identifier per wheel, at every intersection with a receiver.

MAC address randomization helped, but it did not totally solve the problem, because randomization is implemented inconsistently. Hell, randomization is often abandoned once a device associates with a network and does nothing about the higher-layer identifiers that persist across randomizations. Sure, modern Android and iPhones that profess a certain amount of heightened privacy do better, but other signatures from up the stack will stake you to the device; such as the connection list of Wi-Fi access points.

The identifiers that matter are rarely the ones on the radio layer. It is the one at the application layer, which is stable, commercially valuable, and specifically designed to survive exactly the kind of hygiene most people practice. You can randomize your MAC address every ninety seconds and still be the same advertising ID to four hundred data brokers.

The point of enumerating this is not to induce paralysis. It is to establish a baseline that most security programs do not have, which is an honest inventory of emissions inside a fence line. In Empyrean Defense’s own work on Digital Force Protection, the first thing any deployment does is build a device census, meaning a fused picture of what is emitting inside a defined volume of space, correlated across radio types and over time.

The number is always higher than the site expected. It is always higher than the badge count. It usually includes devices nobody can account for, and a handful of devices that have been there for months.

The Advertising Industry Built the Best Targeting Database on Earth

When an application on your phone has ad space to fill, it does not simply request an advertisement. It triggers an auction. The ad exchange broadcasts a bid request to many potential buyers, and that bid request contains, depending on the software development kit involved, your mobile advertising identifier, your coordinates, a timestamp, your device model, your operating system, the app you are using, and a good deal more.

Buyers have roughly a hundred milliseconds to decide whether to bid. The auction is resolved and ultimately one buyer wins. However, everyone who received the bid request keeps the data.

The Electronic Frontier Foundation has stated it about as plainly as it can be stated: only one advertiser wins the auction, but every participant receives data about the person who would have seen the ad. There is neither a bidding requirement nor a requirement for a relationship with the app. Anyone who can present themselves as a plausible ad buyer receives a firehose of location data about billions of devices per day, whether they ever purchase a single advertisement. The FTC found that one location broker had collected data on more than a billion people, with the majority of it sourced from real-time bidding auctions.

Just like MAC address randomization, some more privacy focused cellphone providers do rotate or allow you to straight up delete your advertising ID. There is probably a deeper argument here whether that matters beyond ad personalization, let alone if your ISP sends a subscriber ID or IMEI. However, there is another collection mechanism that renders this rotation (or deletion) moot.

The second collection path is more direct and, for our purposes, more dangerous. Data brokers pay application developers to embed software development kits inside apps, on a revenue-sharing basis, and those SDKs report location continuously and directly. Weather apps, navigation apps, dating apps, fitness apps, and family-safety apps all have defensible reasons to request location permission. Regardless of whether you are attaching a MAC address or advertising ID to it, this is the purest form of pattern of life analysis that someone can get, short of hitching a piggyback ride on your person.

Once granted, that permission is a pipe, and the developer may not always know where the other end of the pipe terminates. The user certainly does not. The consent, such as it is, was obtained in a modal dialog that the user dismissed to see whether it would rain. Or even more commonly, it may have been enumerated in an End-User License Agreement (EULA) that you opted into by merely downloading the app. Hey, who cares, you wanted to find hot singles in your area anyway right?

Neither path is a data breach or a cyber-attack. Further, neither of these paths are illegal in most of the world. There is no incident, no notification, no CVE, no patch. The entire architecture is functioning exactly as designed, and its design output is a real-time global movement database of unprecedented resolution, offered for sale by companies whose names you have never heard. This is what people mean when they say the surveillance economy has become a national security problem.

It is not a metaphor for privacy. Our digitization is a semi-complex supply chain, and our adversaries are customers on it.

Your Advertising ID Is a Selector

An advertising identifier is a unique string assigned by the operating system to your device, called the IDFA on iOS and the Google Advertising ID on Android, and its stated purpose is to let advertisers measure whether their ads worked. As I mentioned, is user resettable.

Your advertising ID is also, in the language of signals intelligence, a selector: a durable, unique handle that lets a collector pull every record associated with one device out of an ocean of records. The California Privacy Protection Agency's own guidance notes that because a phone is used by one person, brokers use these identifiers to track habits and location and then monetize the result. That is the entire business model, described by the regulator, without euphemism.

The identifier is pseudonymous, which is a word that does a lot of unearned work. It is pseudonymous in the sense that the string itself is not your name. It is not pseudonymous in any sense that survives in contact with an adversary, because an entire industry exists to resolve advertising identifiers to real identities for a fee. Reporting on the identity-resolution sector has documented companies that will accept a Mobile Advertising ID (MAID) and return names, email addresses, and physical addresses, marketed as a routine marketing service, and has noted the significant risks this poses to military, law enforcement, and other high-risk individuals when brokers ingest bid-stream data. The de-anonymization step is merely another product service.

It gets worse when you consider that you do not need the resolution service at all if you have enough coordinates. A device that sleeps at one address every night and spends every weekday inside a fenced military installation has told you who it belongs to in the aggregate, without ever telling you its name. German journalists working with the location dataset described later in this piece identified an officer of the BND by matching where a device slept against where it worked. There is no sophistication about this, merely a SQL join on large CSVs with DuckDB or another database engine. Hell, your favorite LLM will gladly build this for you along with a custom UI and visualization library with a small prompt.

For any organization with people worth protecting, this reframes the mitigation. Resetting or deleting an advertising ID is worth doing and is not sufficient, because the historical data is already sold, and the pattern of life is already legible. The durable countermeasure is to prevent the emission at the source, meaning disabling the identifier entirely at the operating system level, removing the applications whose only purpose is to monetize telemetry, and enforcing that at the device management layer rather than through a policy memo nobody reads.

Congress has asked the Department to do exactly this. It has not been done, because this is a much harder problem to solve in the grand scheme of things. Save outright confiscating devices or developing a mobile OS that strips out every single bit of Adware and Bloatware; we won’t get around this issue. In fact, developing a custom Android OS is probably to only way that this will get solved, because even military and law enforcement using End-User Devices (EUDs) for ATAK are part of the advertiser network the second they side-load an app or search for something online.

While not widespread, this already clashes with military forces such as the Armed Forces of Ukraine instrumenting every device with acoustic Counter-UAS software. While it has not happened yet, I could even see a use case where militaries need to power their growing AI/ML needs via parasitic usage of mobile devices, borrowing compute cycles to crunch ever-increasing volumes of data. All that data needs a pipe, and every pipe needs a connection. In the words of every single person who ever considered themselves a hacker or red teamer: “Connected Equals Pwned”.

SOCMINT Means You Are the Collection Platform

Social media intelligence (SOCMINT), if you even consider it a standalone intelligence discipline, is the most democratized collection discipline in existence. Within SOCMINT, the collection platform is the target, and the target is uploading willingly.

The online vector in the UTS taxonomy encompasses browsing and searching, but the operationally significant portion is what people publish about themselves and each other, timestamped, geotagged, and cross-linked into a social graph they built by hand. An adversary does not need a warrant to read your unit's tagged photographs after all, just an email address.

The data volume problem that used to somewhat protect people has been solved. It was once true that nobody could read all of it, and that truth was load bearing for a lot of casual OPSEC. Cheap language models and cheap image classification (and plentiful cloud compute) removed the constraint, and the constraint is not coming back. Every open post is now indexed, entity-extracted, and correlated at machine speed against every other open post, which means the protection you used to get from obscurity has been reduced to zero. Ukraine's use of facial recognition against imagery of Russian personnel demonstrated, at national scale, how quickly a face in a photograph becomes a name in a database.

The specific failure mode that gets people hurt is not merely disclosure, though it can be, but the aggregation across people. You may be screaming at me through your screen that you do not even have social media, but that does not matter.

Your spouse or kids can post a photograph of your homecoming with the unit patch visible, let alone any other easily geolocated infrastructure. A colleague leaves a public Google review of a restaurant to get $10 off their Maryland blue crab or pit beef. Another one may have a fitness app that publishes a run. A vendor's press release names the contract and includes your name in the release or a team photograph.

None of those are a violation of anything, and none of them individually reveals a critical indicator. Assembled, they establish who you are, where you work, when you deploy, when you return, and what you do for a living, which is the entire targeting package.

Our own Narrative Intelligence Workspace creates social media graphs by topical graphs, and that is a UTS vector as well. When you layer in topical clustering, subject matters, Named Entity Recognition (NER), geolocation data, and other extraction from multimedia posts, this graph provides an even richer targeting package. You combine this data with other collected signatures via UTS, and now your adversary not only has pinned you down in the electromagnetic domain, but the information domain as well. This makes UTS a Joint All-Domain Operations (JADO), or multi-domain operations (MDO), vector writ large. The only difference, as I stated several times already, is that you need not be an active participant.

I have watched security programs spend enormous energy on the individual's posting behavior and none whatsoever on the aggregate. From a Digital Force Protection perspective, this is backwards. The correct unit of analysis for SOCMINT exposure is the organization, not the person, because the adversary is running the organizational query, and you are running the individual audit.

Seriously, go ahead and do this right now using LLMs (ChatGPT, Claude, Grok, Gemini, Qwen, Mistral) and search engines, and see how much you uncover:

  • Find your own name, or the name of your commanders or leaders
  • Find Press Releases or Public Affairs posting about your organization and look for pictures
  • Find yourself and others on LinkedIn, Yelp Reviews, or Google Reviews and then check for any dates or photos
  • Attempt to find your own social media
  • Use one of the free people search tools to see how much corroboration is returned
  • Look on social media for mention of your specific unit or organization, such as on Bluesky, Threads, X, or Reddit

If you do not periodically collect your own open-source footprint the way an adversary would collect it, and look at what falls out of the join, you do not know what you look like. I am not arguing that social media discipline at the individual-level and family unit level is a wasted effort, but even our own Public Affairs or marketing teams can offer vectors to UTS.

UTS is building the entire surveillance apparatus from the ground up, piece by piece, and every single piece matters. Stop leaving your damn pieces on the board.

Co-Traveler Analysis Can Unmask the People Who Move with You

If you hold a large body of timestamped location records, you can identify entities that repeatedly appear near a known device. This can be gathered from advertising data, from UTS collected by common wardriving software such as WiGLE, Kismet, Network Survey, or otherwise. Heck, you could do this with TPMS data gathered by rtl_433, labeled Computer Vision (CV) data such as license plates, or even facial recognition.

Bin the observations in space and time, measure their overlaps, apply thresholds for distance, duration, and recurrence, and discount likely coincidences created by airports, barracks, traffic corridors, public events, and dense urban environments. What remains is not automatic proof of identity or intent. It is a ranked set of devices whose movements are unusually correlated with the target.

This is not an exotic intelligence technique. Esri’s current ArcGIS AllSource documentation includes a Find Cotravelers tool with configurable thresholds for search distance, time difference, and minimum co-traveling duration. Even relatively coarse traces can be an identifying selector. In a 2013 Scientific Reports study of 1.5 million people, four approximate spatiotemporal points were enough to uniquely identify 95 percent of the mobility traces in the studied dataset. Human movement is often distinctive enough to function as a fingerprint, and not merely as an observable.

The Washington Post’s 2013 reporting on the National Security Agency’s bulk location collection described a family of analytic tools known collectively as CO-TRAVELER. Their purpose was to discover unknown associates of known targets by identifying people whose movements repeatedly intersected. The NSA was reportedly ingesting nearly five billion location records per day into a repository called FASCIA, covering at least hundreds of millions of devices. Five billion records did not mean five billion people: a single device could generate tens of thousands of records as it registered with networks or moved between cellular towers.

That report already showed the transition from traditional telecommunications collection toward the commercial data environment. A program called HAPPYFOOT intercepted mobile-app traffic that transmitted smartphone locations to advertising networks. Nearly thirteen years later, the commercial ecosystem has industrialized the same underlying primitive: a persistent device identifier attached to coordinates and a timestamp.

The scale is no longer confined to intelligence collection, or at least; it is not solely in the purview of national intelligence organizations. In a 2024 complaint against Gravy Analytics and Venntel, the Federal Trade Commission alleged that the companies claimed to process more than 17 billion signals from approximately one billion mobile devices each day. According to the complaint, their products offered customers access to years of historical information, the ability to geofence locations, and tools to “continuously” track individual devices. Venntel reportedly marketed location data as a means of identifying patterns of life, bed-down locations, workplaces, visits to U.S. government buildings, and known associates.

The analysis also runs in both directions, and this is the part that matters for defense. If you can identify devices that travel with a target, you can also identify devices that appear to be following one. The NSA capability called FAST FOLLOWER was designed to determine who might have been assigned to tail American case officers overseas by correlating the officers’ cellphone signals with those of other people moving in tandem through the same city.

That is surveillance detection expressed as a spatiotemporal correlation problem. It answers the oldest countersurveillance question “am I being followed?” with arithmetic rather than a surveillance-detection route.

Consider what this does to a small team. Four people who are individually careful, who practice good tradecraft, who never post, and who maintain disciplined accounts and devices can still be resolved as a cohort if their devices repeatedly occupy the same places at similar times. A single member’s attribution failure can contaminate the group because identity can propagate outward through the co-traveler graph from whichever node is easiest to resolve. Your compartment is only as tight as the sloppiest phone (or other entity) inside it.

This is why unit-level signature management cannot be delegated entirely to individual discipline. An organization that trains individuals but never measures the aggregate has left its most consequential collective signature unmanaged. This also needs to balance against the necessity to support these forward-deployed, low visibility mission requirements. Whether it is a Foreign Internal Defense (FID) or Counter Terrorism (CT) mission that requires embedding into the local population, as enough time passes, adversarial UTS can theoretically find this group. That goes back to not having any devices, or relying on partners who can provide devices that are already “burnt in” instead of popping up with an American cellular device, regardless of what MDM or encryption passes it off as “compliant”.

Co-traveler analysis is also a capability we build. Our Digital Force Protection work computes co-travel relationships across fused RF detections, cellular telemetry, and commercial location data to answer two operational questions: Which unknown devices are shadowing a protected person or asset, and which of our own devices are correlating in ways they should not? This is useful for red cells as well as anyone who is worried about UTS, one of our US Air Force customers uses our DFP module for exactly this purpose.

We do not publish our scoring model, and we will not. The underlying mechanism has been a matter of public records and research for more than a decade. The implementation is what remains worth protecting: our methods and your signatures.

Data Fusion Wins the Ubiquitous Technical Surveillance Battle

So far one vector has been described at a time, which is mostly a teaching convenience, but obviously competent adversaries do not work on one vector at a time. The power of UTS is not in any single feed, but in data fusion products. On its own, almost every feed across the five UTS pillars is partial, noisy, and/or a deniable observation. Phone names can change as can Wi-Fi Access Point (AP) names and SSIDs.

Heck, certain SSIDs can be geographically prevalent, think of how many APs are named “Linksys” or “Verizon” in an average American subdivision. TPMS data can come from rental cars, Ubers, or the target’s mother’s vehicle they borrowed. Some of the data such as financial transactions, internet search history, and other data that would violate several laws to access is much more attributable; but that already exists across other adversarial intelligence collection.

Joined, these signals and observables collapse into an identity with a schedule, and the collapse is not additive but multiplicative, because each feed resolves the ambiguity in the others. While “data fusion” may be an attractive buzzword, this is just the product of the intelligence cycle. As intelligence professionals, whatever domain(s) we are involved in, we set Priority Intelligence Requirements (PIRs), we collect the raw data, we analyze it into useful information, furnish it into intelligence products, disseminate it and start again. UTS is just multi-intelligence fusion across Measures & Signature Intelligence (MASINT), Financial Intelligence (FININT), Signals Intelligence (SIGINT), and perhaps Human Intelligence (HUMINT) along with OSINT and SOCMINT.

Run the exercise from the perspective of a mid-sized American police department, but it could easily be a seaport security team, or a small military unit. Public safety organizations already field automated license plate readers, whether Flock or another vendor, blanketing their jurisdiction and logging every plate against a time and a place. Their officers' personal vehicles emit tire-pressure-monitoring identifiers, static per wheel, readable by a cheap receiver at every chokepoint. Their officers carry phones with advertising IDs and Wi-Fi radios that probe for known networks, and those probe requests are catalogued in public wardriving databases, meaning WiGLE, Kismet captures, or a commercial network-survey feed, that map access-point identifiers to coordinates. A Wi-Fi Positioning Service or any reverse-geocoding lookup turns a captured access point back into a location. There are photographs of their officers, in uniform, on the department's own social media. And there is each officer's personal social footprint, tagged, timestamped, and cross-linked to family.

Now join them. The ALPR log puts a specific plate at the station at shift change. The TPMS identifiers confirm the vehicle independently of the plate, defeating a plate swap. The advertising ID and wardriven access points resolve the officer's home. The WPS lookup confirms it with a reverse geocode lookup on Google Maps. The department's own photograph puts a face to the name. The personal social profile confirms the family, the spouse's workplace, and the child's school.

Outside of requiring access to ALPRs, not even one of those observables is a secret, and it’s not hard to run CV algorithms over publicly accessible livestreams or traffic cameras either way. Not to mention State actors are not going to respect cybersecurity and privacy laws, while there has not been a verified occurrence, Flock Security and other ALPRs have had their fair share of negative vulnerability attention. Each bit of signal was collected for a mundane commercial or administrative reason. Assembled, they are a targeting package on a named law enforcement officer and everyone that officer loves, and they were assembled from feeds that are, individually, legal to buy and trivial to collect.

You are, in the vernacular of my kids, “mega cooked”.

This is the entire argument for treating signature as a fusion problem rather than a hygiene problem. The officer who resets his advertising ID has closed one column in a table with six columns, and the other five still resolved him. The defender who audits one vector at a time is playing a game the adversary is not playing. The adversary is running the join. The only adequate response is to run the same join against yourself first, which is the whole reason a fusion engine exists in this space, and the reason a stack of single-purpose privacy tools does not add up to a defense no matter how many of them you buy.

Like I said, our enemy does not play fairly to begin with. Within their arsenal, supporting UTS, they have access to tools and datasets from the cyber domain in the form of data dumps and ransomware. They possess sophisticated information domain and influence operations capacity such as setting up fake job interviews, masquerading as officials, setting up honeypots to entrap and lure individuals. They also have access to large botnets to build influence operations campaigns to entice insider threats and ideologically aligned blue force individuals to their cause. Add this to traditional Intelligence, Surveillance, and Reconnaissance (ISR) capabilities and targeting at scale is trivialized.

Pattern of Life as a Weapon

Pattern of life is the reduction of a person's movement into a model with predictive power. It is a schedule, expressed probabilistically, and the reason it is dangerous is that it converts observation into anticipation. Having your whereabouts known by an adversary can be dangerous, but it requires them to have persistent ISR assets dedicated to you or your organization. Adversaries who know where you will be do not need to deploy ISR until the end of their kill chain for ISR purposes.

If they even need that much corroboration to begin with. If a state actor knows from UTS that servicemembers congregate at the chow hall at 1715 local or know which mess that officers or SOF forces attend with high probability, launching cluster munitions or drone swarms to line up with that time is all they need. It’s just a spatiotemporal clustering exercise at that point, with the Circular Error Probability (CEP) much lower than the effective fragmentation range of a warhead.

The lawmakers' letter to the Department I mentioned at the beginning of this piece named the operational output precisely, which is that commercial location data reveals where troops congregate and their pattern of life, and that this supports missile, drone, and IED targeting as well as counterintelligence work.

Read that as an engineer rather than a policymaker: congregation is a density function over space and time. Pattern of life is a periodicity detection over a movement history. Both are cheap to compute; both are robust to noise, and both improve monotonically with the length of the observation window, which is why indefinite retention is the load-bearing element of the whole threat. The adversary does not necessarily need real time to be lethal; historical data does just fine for his dark machinations.

There is a corollary that security programs consistently miss. The most exploitable pattern is not the sensitive one; it is the boring one. Nobody's operational movements are regular enough to model, because operations are irregular by construction. Outside of true “Black Swan” events, the likelihood of your Delta operator, USSOCOM S-shop leader, or other specialized forces won’t get ganked or targeted CONUS in their SCIF or compound.

Everything else an adversary needs to put a person in a known place at a known time lives entirely outside the classified portion of that person's life, which means every dollar spent hardening the operational portion has purchased nothing against this attack. Trips to specific watering holes or restaurants, a gym, a school, a church for Sunday Liturgy, or any other mundane and boring places we frequent are the targetable portion.

This is also where the visual-physical vector rejoins the electronic one. A pattern of life derived from device coordinates tells you where to put the camera. Automated license plate readers, municipal CCTV, and commercially operated camera networks then confirm the pattern with imagery, resolve the vehicle, and defeat the tradecraft of anyone who left the phone at home. The vectors are not independent. They are a fusion problem for the adversary, which is precisely why they must be a fusion problem for the defender.

Approaches: The Adversary Rehearses Before You Ever See Him

Every fixed site has approaches, and the approaches are where the reconnaissance happens. This is doctrinally old and technically new. What is old is that an attacker studies the ground before he uses it, walks the route, times the guard rotation, and identifies the seam. What is new is that he can do most of it without ever coming within a hundred kilometers of your fence.

Commercial location data resolves the approaches for him. Foot traffic patterns around a facility, highly accurate geotechnical datasets, congregation points, the times of shift change, the gate that everyone actually uses versus the gate on the plan, the off-site parking lot where the day shift leaves their trucks, the diner where the night shift eats at 0200 because the DFAC is closed.

All of it is derivable from movement data alone, at population scale, with no human source and no physical presence. The bid stream vendors describe this capability openly as understanding foot traffic patterns around critical infrastructure and identifying unusual congregation points. They are selling it as retail analytics. It is also targeting preparation, and the two are the same product.

The physical rehearsal, when it comes, is now the part with the smallest signature, because the attacker has already done the analysis and needs only to confirm it. He arrives once, briefly, with a clean phone or no phone, and looks at the one thing he could not resolve remotely. If you are only watching for the man with the camera at the fence, you are watching the last five percent of a process that ran for six months in a database.

This inverts what a good approaches assessment has to look for. The question is not who is watching my perimeter today. It is what my approaches emit, continuously, to anyone who cares to buy the emissions, and whether there are devices or vehicles that recur along those approaches with a periodicity that does not match any population we can account for. That is an anomaly detection problem over a fused device census and movement history.

It is the exact problem a port faces regarding vessels that are loitering off the approach lanes, and the analytic is close to identical, which is one of the reasons we ended up building both surfaces on the same engine. That said, if there is not data available by happenstance or your own hardening mechanisms, this may force adversaries to commit to traditional surveillance, which is one of the better outcomes of DFP. You will never blunt UTS collection efforts, but for certain types of collections, the adversary still needs to be “close to the action”. Flushing them out, interdicting them, and turning them over to counterintelligence and law enforcement organizations can help to further collapse kill webs that use UTS as a targeting mechanism.

The Five-Year Ledger

Doctrine persuades nobody, so here is a small collection of what has happened regarding UTS targeting efforts. I have tried to be careful with attribution, because several of these cases are more contested than the popular retelling admits, and a research shop that launders speculation into fact deserves to be ignored.

Makiivka, 1 January 2023

A HIMARS strike destroyed a vocational school in occupied Makiivka housing newly mobilized Russian soldiers. Russia's Ministry of Defense publicly blamed its own troops, stating that the main cause was the mass use of cell phones contrary to the ban, which allowed Ukraine to determine the soldiers' coordinates. The confirmed Russian death toll was raised to 89.

And then it fell apart, publicly, which is an interesting part. Ukraine's own spokesman for the Eastern Group called the phone explanation ridiculous and said the real cause was the failure to deploy the personnel covertly. Russian military bloggers with state decorations called it a blatant attempt to smear blame, pointing out that drone surveillance or a local informant could have produced the same coordinates, and that ammunition had been stored beside the barracks, which is what produced the casualty count. A Chatham House analyst offered the sober version: uncontrolled phone use was plausibly a contributing factor, and was certainly not the only one.

Take the honest lesson rather than the convenient one. Makiivka does not prove that phones killed 89 men. It proves something more useful and more uncomfortable, which is that a modern military instantly recognized mass handset emission as a sufficient explanation for a precision strike on a barracks, and that its adversary considered the claim technically credible enough to bother mocking. Nobody in that argument disputed that the capability exists. They argued about which of several available targeting paths had been used.

It is important to note that Ukraine is a proxy force of the United States, HIMARS is an American system, and it is connected to a large combat control network. There were certainly additional intelligence collection mechanisms that completed the kill chain, using any number of airborne-, ground-, and/or space-based assets in addition to UTS.

Krasnodar, 10 July 2023

Stanislav Rzhitsky, a Russian naval officer and former commander of the Kilo-class submarine Krasnodar, was shot seven times with a Makarov pistol at around six in the morning while jogging in a park near the Olimp sports complex. Ukraine's military intelligence directorate announced the killing on Telegram with unusual specificity, including the number of shots and the observation that heavy rain had left the park deserted, while declining to claim responsibility. Russian media reported that his killer may have tracked him via Strava, the fitness application. A profile in his name showed his regular jogging circuits, including the loop through the park where he was killed, and cycling activity in Sevastopol going back to 2014.

The detail that has stayed with me is that one of the small number of accounts that had liked his final posted run carried the name of the head of Ukraine's military intelligence. That account was subsequently deleted, and Kyrylo Budanov publicly stated that claims tying his directorate to Rzhitsky's death had no basis. CNN could not independently authenticate the Strava profile. So: unproven, publicly, and likely to remain so.

What is not unproven is the exposure. A serving-then-recently-separated officer of a strategic weapons platform published his running routes, on a public profile, in his own name, for years, including a fixed loop through a fixed park at a fixed hour. Whether or not that is how he was found, it is how he could have been found, by anyone, for free, from anywhere on earth. There is no operational security failure here in the classical sense. He disclosed nothing classified. He disclosed himself.

Mexico City, 2018, disclosed 2025

On 26 June 2025 the Department of Justice's Office of the Inspector General published a partially redacted report on the FBI's efforts to mitigate ubiquitous technical surveillance, and inside it was the case that gave the term teeth. A hacker working for the Sinaloa cartel obtained the mobile phone number of an FBI assistant legal attaché at the U.S. Embassy in Mexico City. From the number, he obtained the calls made and received and the geolocation data associated with the phone. He then used Mexico City's camera system to follow the official and identify the people he met. According to the report, the cartel used that information to intimidate and in some cases kill potential sources and cooperating witnesses.

Lawfare's analysis of the report made the point that matters most: the hacker did not, as far as the OIG describes it, break into the phone. He used the phone number to obtain records associated with it. The compromise happened in the infrastructure, not the endpoint. Every hardening measure applied to that handset was irrelevant to the attack that was actually run against it.

A drug cartel, without a SIGINT agency, without satellites, and without a single asset inside the Bureau, achieved persistent surveillance of a federal law enforcement officer abroad and used it to kill people. The barrier to entry in this case was a phone number and a municipal camera network.

The Hague, April 2018

Four GRU officers travelling on diplomatic passports arrived in the Netherlands, rented a Citroën, and parked it in the lot of the Marriott adjacent to the headquarters of the Organization for the Prohibition of Chemical Weapons (OPCW), trunk facing the target, with an antenna concealed inside aimed at the OPCW's wireless network. Dutch counterintelligence had them under surveillance and rolled them up on 13 April, mid-operation.

What had exposed this GRU intelligence team was not clever countersurveillance work, but counterintelligence enabled by UTS. In the car and in their hotel garbage, the Dutch recovered laptops, multiple mobile phones, and a taxi receipt showing a ride from a GRU facility in Moscow to the airport. Some of the phones had been activated in Moscow near the agency's own headquarters. The laptop carried traces of prior activity in Brazil, Switzerland, and Malaysia, tying the same team to operations against the MH17 investigation and a Swiss laboratory. One GRU officer unsuccessfully tried to destroy his phone as the operation collapsed.

These were professional intelligence officers of a first-rate service, conducting a close-access operation, and they were reconstructed backwards from their own digital exhaust across four countries and two years. They were careful as they could be according to their own doctrine, even going as far as removing their garbage out of their hotel rooms. It did not matter, because the exhaust had already been emitted, retained, and made available to a competent adversary who thought to look. If the GRU cannot do this cleanly, neither can your protective detail, nor can mine.

Wiesbaden and Ramstein, 2023 to 2025

In late 2024, WIRED, Bayerischer Rundfunk, and netzpolitik.org published a joint investigation built on a free sample of location data obtained from a Florida-based broker, Datastream Group, reached through an online data marketplace after filling out a form and having a brief phone call. The sample covered eight weeks and contained 3.6 billion coordinates from as many as 11 million devices; some recorded at millisecond intervals. The full subscription ran roughly fourteen thousand dollars a month.

Inside that sample were the movements of American military and intelligence personnel in Germany. Reporters traced a device on its daily commute from a home near Wiesbaden into Lucius D. Clay Kaserne, the Army's European headquarters. They observed a device broadcasting coordinates from inside a windowless building reportedly used for NSA surveillance and another moving through a restricted weapons testing range.

Subsequent analysis identified up to 189 devices inside a high-security installation where U.S. nuclear weapons are reportedly stored in underground bunkers, roughly two thousand devices at Ramstein Air Base, and a set of devices that travelled from Ramstein to the elementary and high school attended by service members' children, and a handful that travelled from Ramstein to off-base brothels. Aside from the dangerous targeting information about secure facilities and their personnel, the brothel and school visits can also be used for leverage by adversary counterintelligence as well.

The data itself, it later emerged, had been sourced from a Lithuanian AdTech company, which denies involvement, and resold by an American broker. And this was the exact scenario the contractor Mike Yeagley demonstrated to various government agencies. He was able to use AdTech data from Grindr and basic geofencing to reconstruct the routes, rendezvous, and government employ of several users of the application. That is one out of tens of thousands of apps that gather this data for AdTech brokers, so even in miniature the UTS problem side is widespread.

The Telephone Network Itself

This case is not about your device at all. Salt Typhoon, an espionage campaign attributed to contractors working for China's Ministry of State Security, spent years inside the backbone of Western telecommunications, exploiting edge routers and, in the American case, the lawful intercept systems that carriers are legally required to maintain. The intrusion reached over 200 organizations in more than 80 countries. Recorded Future's assessment of the U.S. compromise is the sentence that should end any argument about device hygiene as a complete answer: the group obtained broad access, stole metadata, and geolocated millions of individuals at will.

Metadata for over a million users was accessed, most of them in the Washington, D.C. metropolitan area, and a large number of those individuals were, in the words of a deputy national security advisor, government targets of interest. An FBI official described the collection of call records on ordinary Americans, including children, as indiscriminate, and noted that it is data China will keep forever. The campaign also swept through the Indo-Pacific, hitting telecommunications, transportation, lodging, and military infrastructure networks across the region.

You cannot reset your way out of this one. There is no advertising ID to disable, no app to delete, no setting to toggle. The adversary compromised the layer beneath every mitigation available to the individual, which is why signature management has to be an institutional program with a technical measurement capability behind it, and why treating UTS as a personal responsibility problem is a category error that will get people killed.

Tehran, March 2026

The next case is the join, run to its conclusion, against the most heavily protected human being in an adversary state. According to a Financial Times investigation corroborated across numerous outlets, Israel spent years inside Tehran's traffic camera network, footage encrypted and streamed to servers inside Israel, as one feed among hundreds. The camera network was municipal surveillance infrastructure, built by the regime to hunt its own protesters, co-opted and pointed back at the regime's own leadership.

The method is the entire thesis of this piece expressed as an operation. Israel did not track Ayatollah Khamenei directly. It worked his co-travelers, the bodyguards and drivers, because they were easier to observe, and their pattern of life resolved him. One camera angle showed where the protective detail parked their personal cars, and algorithms were used to build dossiers on the guards' home addresses, duty hours, commuting routes, and, in the words of the reporting, which official each was assigned to protect.

Unit 8200 signals intelligence, Mossad human sources, and a mathematical technique the reporting calls social network analysis were fused over billions of data points into what one source described as an assembly line with a single product: targets. On the morning of the strike, hacked cameras and penetrated mobile networks confirmed the principal was present, a CIA human source corroborated it, and the cell towers around the compound were disrupted so the detail could not receive a warning call. Then thirty munitions arrived in daylight.

Sit with what that demonstrates, independent of how you feel about the target. The protective detail was the vulnerability. The guards were disciplined, professional, and loyal, and they were also the sensor that located the man they were guarding, because their own pattern of life, observed through infrastructure nobody thought to defend, resolved his. There is no amount of personal discipline by the principal that closes this hole.

It is closed only by someone measuring what the detail emits, which is co-traveler analysis pointed inward, defensively, at your own people. This is the single clearest argument in the public record for why signature management has to be run at the level of the protected element and not the protected person, and it is why we build the analytic to look at your own formation first.

And then account for what the strike did, because thirty munitions into a compound do not kill one man cleanly. Iranian state media reported that Khamenei's daughter, son-in-law, and daughter-in-law were killed alongside him, and that among the dead was his granddaughter, fourteen months old, later named as Zahra Mohammadi Golpayegani and buried with her grandfather. Whatever you believe about the legitimacy of killing a head of state who directed the deaths of a great many people, the fusion did not resolve to a single guilty man standing alone in a room. It resolved to a coordinate, and a coordinate contains whoever is standing on it, including a one-year-old. This is the thing the assembly line abstracts away. The output is called a target, and the word does a great deal of quiet work to make a family legible as a point. The reconstruction that finds the guilty man also finds the child asleep two rooms away, and the munition does not distinguish between them.

Kryvyi Rih and Dnipro, 2026

Consider a pattern that circulates constantly in war-watcher channels: a volunteer, filming inside of a depot, narrating a pallet of drones and batteries bound for the front, the courier's red logo plainly in frame. This sort of thing is not very rare without the information operations realm related to the Ukraine war. Everyone from politicians, to mercenaries, to volunteers, and unabashed propagandists happily take selfies in front of everything from ATACMs guided missiles, Small-Diameter Ground Launched Bombs, Starlink terminals, and FPV drones. For all the feel-good information warfare “points” that one side gets, the other gets a high value targeting package.

In this case, it was a British volunteer inside of a Nova Poshta depot. The logo identifies the facility, the interior identifies the room, the cargo identifies the value, and a verified account with a high follower count broadcast all three to an adversary who is ever watchful in the information domain despite public indications to the contrary. Not only that, but the Russian combined arms forces also have a massive amount of OWA drones, ballistic missiles, and cruise missiles with a willingness to expend them on civilian logistics nodes.

Russian OSINT channels have pointed to specific posts of this kind as the tip that cued a subsequent strike. I treat that as an adversary claim rather than an established fact, because those channels have every incentive to assert that a Ukrainian volunteer's post got people killed whether it did or not, and the assertion is itself an information operation.

However, the causal claim is not what matters and arguing about it is a distraction from the thing that is not arguable. Filming the inside of a military-logistics facility, with its function and its brand and its cargo in frame, and posting it to a public account, is a catastrophic OPSEC failure on its own terms, whether or not any single clip was ever the specific cue. You do not get credit for the strike that did not happen because of your post. Stop taking war selfies!

What is documented extensively is that the logistics network in question is being systematically destroyed. Reporting through 2026 records strikes on Nova Poshta terminals in Kharkiv in January, where four employees were killed, and on facilities in Lutsk, Dnipro, Kryvyi Rih, Zaporizhzhia, where a partner carrier's driver was killed, Chernihiv, and Kyiv, struck with Geran-2 loitering munitions, Kh-101 cruise missiles, and Iskander ballistic missiles. Whether any single facility was cued by a social post, by satellite imagery, or by an agent on the ground is, for the defender, beside the point. Once the facility's function and location are established, by any path, the pattern of life of a logistics node is as legible as the pattern of life of a man, and a distribution hub that has been filmed, geotagged, and posted has volunteered the first and hardest piece of the targeting problem for free.

A defense company that posts its shipping dock, a volunteer who films the warehouse, a contractor who geotags the loading of a truck, and a port that publishes its throughput are all emitting the same class of indicator that killed conscripts in Makiivka and a submariner in Krasnodar. UTS does not care which flag you fly. The joins run identically against the righteous and the guilty, and the only defense that has ever worked is to control the emission before it leaves the fence, because you cannot recall it afterward, and you cannot out-argue a coordinate.

Again, there is nothing to flex about here. Publishing the location of a warehouse full of other people's ammunition is not a highlight reel. It is a targeting cue with a body count attached, and the fact that it earns engagement is exactly what makes it dangerous.

INDOPACOM Is Where This Gets Worse

The United States’ strategic focus on the Indo-Pacific continues to deepen as governments, militaries, industry, and regional infrastructure prepare for sustained competition (and the possibility of conflict) with the People’s Republic of China (PRC). U.S. Pacific Command is the geographic combatant command responsible for the theater. Its area of responsibility which spans more than 100 million square miles covers approximately half of the Earth’s surface, and encompasses 36 nations, from small Pacific Island states to major powers such as Japan, India, and China.

The true tyranny of the Indo-Pacific is geography: thousands of miles of open ocean broken by island chains, dense jungles, limited infrastructure, difficult maritime approaches, and an increasingly capable PRC reconnaissance-strike complex. Distributed operations across the First and Second Island Chains place small teams at austere sites, often inside civilian populations and dependent on commercial or host-nation infrastructure they do not own.

The forces expected to operate forward in that environment must be mobile, distributed, operationally relevant, and difficult to detect. Two of the Marine Corps’ principal operating concepts for doing so are Expeditionary Advanced Base Operations (EABO) and Stand-In Forces (SIFs).

The Marine Corps defines EABO as “a form of expeditionary warfare that involves the employment of mobile, low-signature, operationally relevant, and relatively easy to maintain and sustain naval expeditionary forces from a series of austere, temporary locations ashore or inshore within a contested or potentially contested maritime area in order to conduct sea denial, support sea control, or enable fleet sustainment.”

EABO’s principal mission sets include:

  • Sea Control Operations: Enable friendly forces to use a specified portion of the maritime domain for a required period while limiting adversary interference. Examples include securing key maritime terrain, screening fleet movement, supporting surface warfare, conducting air and missile defense, contributing to antisubmarine warfare, and enabling amphibious or logistical access.
  • Sea Denial Operations: Prevent or impose unacceptable risk on adversary use of littoral areas without requiring permanent friendly control. Examples include land-based anti-ship fires, maritime strike, mines and obstacles, control of chokepoints, and the employment of mobile sensing and firing units from distributed expeditionary bases.
  • Maritime Domain Awareness: Develop and share an accurate, persistent picture of activity across the littorals. Examples include coastal and airborne surveillance, detecting departures from normal patterns, classifying maritime contacts, tracking surface, subsurface, and airborne activity, and feeding tactical information into the maritime common operating picture.
  • Forward C5ISRT and Counter-C5ISRT: Provide distributed command and control, communications, sensing, intelligence, surveillance, reconnaissance, and targeting while disrupting the adversary’s ability to do the same. Examples include cueing naval and joint fires, passing targeting-quality data, maintaining resilient communications, conducting electromagnetic warfare and deception, managing friendly signatures, and defeating adversary reconnaissance and targeting.
  • Forward Sustainment: Maintain naval, joint, allied, and partner forces from austere and distributed locations inside the contested littorals. Examples include forward arming and refueling points, expeditionary fuel and ammunition distribution, maintenance and repair, tactical power and water production, and the refueling, rearming, and replenishment of ships, aircraft, and unmanned systems.

Stand-In Forces (SIFs) describes how USMC forces persist forward inside contested areas, normally alongside allies and partners, to provide the fleet and joint force with access, awareness, targeting support, and additional operational options. Marine Littoral Regiments are the most visible formations designed around this concept.

The enduring function of SIF is maritime Reconnaissance & Counter- Reconnaissance (RXR). In doctrinal terms, reconnaissance helps the fleet to locate and understand the adversary sufficiently to act against it. Counter-reconnaissance prevents the adversary from doing the same to friendly forces. When required, SIFs also conduct sea denial operations in support of the naval campaign.

Army Multi-Domain Task Forces are not exactly modeled on the USMC Stand-In Forces, but they perform complementary functions across the theater. In June 2026, the Army combined the 7th Infantry Division and 1st Multi-Domain Task Force into Multi-Domain Command-Pacific, a forward covering force intended to integrate maneuver with long-range fires, intelligence, cyber, space, and electromagnetic capabilities. The Army explicitly describes the formation as operating forward of the main body to develop the situation, conduct reconnaissance and counter-reconnaissance, prevent enemy observation, and disrupt adversary systems before decisive operations begin.

These forces will increasingly depend on Combined Joint All-Domain Command and Control (CJADC2) to connect distributed sensors, decision-makers, and effects across services and allied forces. But connecting every sensor to the wider force also creates a reciprocal problem: every connected sensor, platform, operator, and support element becomes a potential observable inside the adversary’s own collection architecture. That is precisely the class of problem Empyrean Defense is built to address.

The reason I laid all of this out within this blog in particular is that every element of this new Indo-Pacific strategy continues to harp on lethality and low-signature/low-visibility. Low signature is not separate from lethality; it is what allows a forward force to remain survivable long enough to sense, target, and employ that lethality. A force can field hundreds of NMESIS launchers and other anti-surface systems, but once those systems are found, fixed, and held at risk, their theoretical lethality matters very little.

Empyrean Defense Research examined this twice, regarding hypersonic ballistic missile defense (BMD) as well as if USMC organic IADS used with these SIFs (such as the Marine Littoral Regiment) would be enough against old-generation People’s Liberation Army Rocket Forces (PLARF) munitions. The findings are detailed in the hyperlinked reports with grave outcomes, as built upon the Empyrean Defense Wargaming & Simulation Cyber Range.

Back to the topic of UTS: a Marine Littoral Regiment dispersed across the Ryukyus or the Batanes is embedded in host-nation cellular networks, host-nation power, host-nation transportation, and a civilian population carrying several thousands to millions of emitting devices. Some of these islands are small enough that a device census is a tractable computational problem for anyone with the data.

On small islands with limited roads, ports, towers, settlements, and transportation patterns, concealment becomes behavioral as much as physical. There may be terrain in which to hide a launcher, but far fewer places to hide the people, vehicles, communications, logistics, and commercial-device activity that sustain said launchers.

Now add the adversary's specific advantages. The People's Republic of China is the state that has invested most heavily in exactly this technology stack, domestically, for two decades, and exports it. Salt Typhoon has demonstrated persistent access to telecommunications infrastructure across the theater, including in Japan, the Philippines, Taiwan, Australia, and New Zealand.

The commercial-data supply chain remains difficult to police even after the United States imposed new restrictions on bulk sensitive-data transactions. Third-country brokers, non-U.S. vendors, opaque sourcing relationships, and multiple layers of resale continue to create pathways through which sensitive movement data may reach foreign actors. Every UTS mechanism described in this piece is available to the PRC, at scale, in the theater where we intend to fight.

Then add the thing that makes INDOPACOM genuinely different from CENTCOM, which is that the phase of the conflict where UTS does the most damage is the phase before the conflict. In counterinsurgency, the adversary collection is contemporaneous and local. In a peer competition, the adversary spends the decade before the fight quietly assembling the pattern of life of every logistics node, every fuel contract, every dependent school, every port call, every family, in a database that is queried on day one. The retroactivity property compounds with the length of the competition.

An old advertising identifier may be stale, but the historical pattern attached to it may not be. New observations can reconnect replacement identifiers, devices, households, vehicles, and associates to an older identity graph, effectively rehydrating years of previously dormant movement data. Again, advertising IDs are just selectors, but human behaviors are a unique fingerprint unto themselves; it would just expose many selectors that survive randomization and/or deletion.

And now run the join at a strategic scale, because the same fusion that resolves a person resolves a mobilization. The Tehran UTS operation undertaken by Unit 8200 and Mossad pointed the join at one man. Pointed at a theater, the identical logic reads indicators no single collector would trust on its own. Commercial device census data shows personnel buildup at a garrison. Space-based imagery shows new construction, vehicle counts and increased thermal and atmospheric signatures over a port or airfield. Trade and shipping data shows materiel flowing into a region. Aviation data shows a spike in flights and a cluster of NOTAMs closing airspace that is usually open.

Each indicator alone is deniable and ambiguous, which is exactly why strategic surprises have historically been possible. Fused, the ambiguity collapses, and the buildup that any one analyst would have hedged on becomes a warning with a date attached. This cuts precisely both ways: it is how an adversary would read our preparations for a Taiwan contingency from open and commercial sources, and it is how we should be reading theirs. The side that can fuse the widest relevant set of feeds is more likely to recognize the other side’s movement first. In the Indo-Pacific the feeds that matter most are commercial, space-based, and buyable, which means the advantage goes to whoever built the join, not whoever owns the most exquisite sensor.

I am not qualified to write operational doctrine, and I am not going to pretend otherwise. What I will say, as someone who builds the fusion layer, is that the theater's defining characteristic is dispersion, and dispersion is the one posture that co-traveler analysis and device census work is best at defeating. A concentrated force has an obvious signature and knows it. A dispersed force believes it is concealed and is often wrong, because it has never measured what it emits. That gap between believed and actual signature is where the first day of a war gets decided, and it is a measurement problem before it is a doctrine problem.

Going Dark Is Still a Signature

After reading this far, the instinct is obvious: go quiet. Turn off the phone. Leave it at home. Buy a burner. Put it in a Faraday pouch.

These are all legitimate controls, but none of them creates true invisibility. More precisely, not all of them are emissions, but every one of them changes the signature environment. The National Security Agency itself warns that there is no way to eliminate completely the location risk associated with a mobile device; phones, wearables, vehicles, Wi-Fi, Bluetooth, and other connected systems all contribute pieces of the user’s location and pattern of life.

In a sufficiently instrumented environment, an expected signal disappearing can be as useful as one appearing. A handset that goes dark at 2100 UTC every Thursday has established a schedule. A cluster of devices that disappear immediately before every movement has established a warning indicator. A familiar device that stops visiting homes, shops, and workplaces and begins spending its nights near an airfield has established a change in behavior.

The analyst does not necessarily need the content. Discontinuity may be enough. There are three versions of this problem: silence, substitution, and convergence.

Silence occurs when an expected signature disappears. That does not automatically indicate hostile intent; batteries die, networks fail, people travel, and devices are replaced. But when disappearance is repeated, synchronized with other activity, or confined to operationally significant periods, absence does become evidence. In a population in which almost everyone carries a phone, the person who does not may become an anomaly. A completely quiet patch inside an otherwise active electromagnetic environment can be equally conspicuous.

Substitution occurs when one identifier disappears, and another begins reproducing its behavior. One handset powers down, and another begins appearing in the same places, following the same routes, visiting the same associates, and disappearing during the same periods. No single observation proves that the devices belong to the same person. Repeated continuity across time, space, and relationships can make the inference increasingly difficult to dismiss. Bulk location analytics already correlate movement histories across enormous populations to identify relationships that no individual record reveals.

This is entity resolution over time, with pointed analytics; it is not some form of UTS black magic.

A burner phone fails when it is treated as a new identity but continues the old identity’s pattern of life as new hardware — does not automatically produce new behavior. The device may change while the routes, timing, associates, destinations, and surrounding devices remain the same. The analyst is not being asked to break the handset. The analyst is being asked to determine whether two identifiers describe one human being.

Convergence is the third and more operationally dangerous signature. A device can be individually ordinary and still become collectively revealing. Ten locally sourced phones may each possess years of mundane history, and their identifiers may never become attributable selectors. However, when all ten abandon their previous routines, congregate near an airfield, travel along the same restricted roads, or cycle among temporary expeditionary positions, the cluster becomes the selector.

The deeper problem is that disciplined behavior can produce contrast inside an undisciplined population. A person with no cellular presence, no wearable, no recurring Bluetooth emissions, and no ordinary commercial-device activity may disappear from one collection layer while becoming more conspicuous when that absence is fused with vehicle movements, access records, imagery, transactions, associates, or physical observation. One sensor may lose the person, but the wider system may simply shift weight to the others; that is the power of data and intelligence fusion cutting both ways.

Perfect hygiene practiced by a tiny minority does not necessarily look normal. It can look deliberate.

This is why signature management is not synonymous with emissions control. The objective is not to reduce every observable to zero, but rather to create a signature that is consistent with the mission, stable across time, compatible with the surrounding environment, and difficult for the adversary to interpret correctly. Marine Corps doctrine reflects this directly: signature management includes understanding friendly indicators, masking true signatures, and, when necessary, projecting false signatures to protect the force or mislead the adversary. It addresses physical, technical, and administrative signatures together rather than treating radio silence as the whole problem.

Signature management is therefore achieved through measurement and shaping, not suppression alone.

Earlier in this piece, I argued that forces operating among civilian populations should reduce their contrast by using locally common infrastructure, services, equipment, and patterns where lawful and operationally appropriate. EABO guidance similarly recognizes that conspicuous military movement and support assets can make forward forces easier to locate and recommend using host-nation government and commercial support where feasible.

That said, locally common equipment does not confer locally normal behavior. A device with years of ordinary history can still betray a force the moment its routine changes. It may have wandered unremarkably among homes, farms, cafés, and workplaces for years. If it suddenly begins traveling with military personnel, sleeping beside an expeditionary base, or converging with a dozen other devices near a firing position, its previous normality becomes part of the evidence. The before-and-after contrast is precisely what makes the change visible.

Against a UTS architecture operating at PRC scale, going dark is therefore not an end state. It is one maneuver inside a much larger signature-management problem. The adversary can observe what appears, what disappears, what replaces it, what moves together, and what changes its behavior.

The objective is not silence. The objective is controlled ambiguity.

And without measuring both the force and the environment around it, “low signature” is only a story the force tells itself.

What You Can Actually Do About It

I promised countermeasures. They are ordered by leverage rather than convenience, and I have deliberately kept them at the level of policy, architecture, configuration, and assessment. A public blog should explain what outcomes an organization must engineer. It should not become a field manual for evading surveillance.

The first principle is that signature management is not a privacy checklist. Marine Corps doctrine describes signature management as a deliberate, mission-focused component of operations security: understand friendly signatures and indicators, understand how the adversary can collect and analyze them, apply countermeasures to mask them, and, where authorized and necessary, project signatures that complicate the adversary’s understanding. It combines intelligence, counterintelligence, OPSEC, deception, counter-reconnaissance, and fires rather than treating emissions control as an isolated technical function.

The same doctrine emphasizes assessment: observable indicators must be measured, including indicators of failure and unintended consequences, so that commanders can determine whether a countermeasure changed the outcome. The point is not to complete a checklist. The point is to become harder to understand, target, and exploit. See MCWP 8-10, Information in Marine Corps Operations.

For the Individual

Remove unnecessary advertising identifiers, but do not mistake one identifier for the entire tracking system

On Android, delete the advertising ID rather than merely resetting it. Google exposes both options, and deletion causes applications requesting that specific identifier to receive no usable advertising ID. Android users should separately review the platform’s newer advertising controls and disable Ad Topics, App-Suggested Ads, and Ad Measurement where those functions are available. These mechanisms are independent of the legacy advertising ID. See Google’s guidance on deleting the advertising ID and managing Android ad-privacy settings.

On iOS, there is no equivalent “delete IDFA” button exposed to the user. Go to Settings → Privacy & Security → Tracking, revoke any permissions previously granted, and disable Allow Apps to Request to Track. Separately disable Apple’s own personalized advertising under Privacy & Security → Apple Advertising. These controls reduce two different classes of advertising activity and should both be addressed. See Apple’s guidance on app-tracking permissions and Apple personalized ads.

Resetting or deleting an advertising identifier does not order any broker, application, analytics provider, or downstream customer to erase what it already holds. It also does not prevent relinking through accounts, IP addresses, locations, household associations, application-specific identifiers, or movement history.

Research using carrier mobility data found that four approximate points in space and time uniquely distinguished 95 percent of the studied mobility traces. The token is useful, but the behavior around the token is often more durable. See the Scientific Reports study “Unique in the Crowd”. Treat advertising-ID controls as data minimization, not invisibility.

Audit both live location access and stored location history

Review every application with location access. “Always” should be granted on an exception basis. “While Using” or “Ask Next Time” is usually sufficient for applications that have a legitimate location function, and approximate location is preferable when precise coordinates are unnecessary. On iOS, precise location can be disabled separately for each application. Apple also added a Limit Precise Location cellular control in 2026; where supported, it should be evaluated as another layer rather than treated as anonymity. See Apple’s Location Services guidance and Limit Precise Location guidance.

Review stored location history as well as active permissions. Google Maps Timeline can retain visits and routes and supports full deletion, range deletion, and automatic deletion. Apple Maps can retain Visited Places and Significant Locations and Routes, which can also be reviewed or cleared. A person who has disabled current sharing but retains years of detailed history has solved only the forward half of the problem. See Google’s Timeline controls and Apple’s guidance for clearing location history.

Deleting history from a device or account does not guarantee deletion from every application vendor, advertising exchange, location aggregator, or prior purchaser. The FTC has repeatedly brought actions involving the collection and sale of precise location data, including data associated with military installations, private homes, health facilities, and places of worship. That enforcement history is evidence that the downstream market is real, not that the market has been eliminated.

Treat applications, wearables, vehicles, and household systems as sensors

Fitness applications deserve top-tier scrutiny because location is not an incidental permission for them; it is frequently the product. The same is true of family-safety applications, vehicle telematics, smartwatches, connected bicycles, pet trackers, shared-photo applications, and applications that continuously estimate arrival times or household presence.

The Department of Defense’s 2018 geolocation policy explicitly identified smartphones, fitness trackers, smartwatches, applications, and related services as risks capable of exposing personnel locations, routines, and numbers. It prohibited geolocation functionality in designated operational areas unless an authorized, threat-based exception was made. That policy was not about just one defective application; it rightfully recognized the entire category as an OPSEC problem. See the DoD memorandum on geolocation-capable devices, applications, and services.

Public fitness profiles for personnel assigned to sensitive missions should therefore be treated as an organizational exposure condition, not merely a personal preference. The correct response is not necessarily prohibiting exercise tracking entirely. It is to disable public publication, review historical activities, restrict precise start and end locations, understand what the associated wearable and cloud service retain, and apply policy proportionate to mission risk.

Photography is another sensor. Disable location metadata when it serves no purpose, and remove it before publishing imagery associated with personnel, facilities, vehicles, or travel. Marine Corps OPSEC guidance specifically identifies location information embedded in personal-photo metadata as information that Marines should prevent from reaching public social-media feeds.

Household systems matter because identity resolution does not stop at the employee’s phone. Repeated overnight co-location can identify a home. Repeated travel can identify a spouse, child, caregiver, or vehicle. A protected individual with disciplined settings can still be resolved through a family member who shares locations continuously, publishes fitness activity, tags photographs, or carries a device whose history repeatedly converges with the protected person.

This does not mean imposing operational controls on families without consent. It means providing them with the education, technical assistance, deletion support, and devices necessary to avoid making them the unfunded edge of the organization’s force-protection program.

Harden the device as a system

Privacy settings do not compensate for a compromised device. Keep the operating system and applications supported and current. Use a strong passcode, a short automatic-lock period, encrypted storage, restricted lock-screen notifications, and applications obtained only through approved sources. Review connected computers, accessories, keyboards, configuration profiles, VPNs, certificates, and accessibility permissions, because each can expand the collection surface.

NSA’s public mobile guidance emphasizes that there is no way to eliminate completely the location risk associated with a mobile device. Its recommendations reduce exposure; they do not turn a commercially connected handset into a non-observable object. NSA’s current mobile security page includes an updated April 2026 edition of Limiting Location Data Exposure.

End-to-end encryption is still necessary for protecting communications content, but it does not erase the surrounding metadata. A carrier or network may still observe that a device exists, which infrastructure it uses, when it connects, and approximately where it is. Encryption protects what was said. Signature management must also address the fact that communication occurred.

Manage recurrence and association, not theatrical randomness

The advice to “vary your route” is directionally correct but incomplete. Modern pattern-of-life analysis does not eat only periodicity. It exploits frequently visited locations, sequences, dwell times, social associations, synchronized movement, changes from baseline, and the relationship between ordinary and sensitive events. Taking a different route home may be enough for the most basic countersurveillance, but staying there is still a target.

Do not turn normal life into a badly improvised surveillance detection route. Randomly changing every commute creates safety costs and may itself become distinctive. The more defensible principle is to reduce unnecessary, durable linkage around sensitive activity. Avoid publishing predictable schedules. Avoid carrying unnecessary connected devices into sensitive locations. Avoid allowing applications to record recurring associations they do not need. Do not let every member of a team arrive, park, connect, exercise, and depart in a digitally synchronized pattern simply because each person followed the same individual checklist.

The objective is not randomness. It is to deny the adversary analyst clean, repeated relationships.

For the Small Team

Select a device-ownership model deliberately

High-risk teams should default to organization-owned and centrally managed devices, or to a tightly controlled, personally enabled model in which the organization owns the security boundary. Bring-your-own-device (BYOD) may reduce procurement friction, but it transfers a large portion of the application, account, telemetry, household, and lifecycle control surface to the individual while leaving the organization exposed to the resulting risk.

NIST’s enterprise-mobile guidance recommends managing mobile devices throughout deployment, use, and disposal and explicitly addresses centralized management, endpoint protection, organization-provided devices, and personally owned devices. See NIST SP 800-124 Revision 2.

The DoD’s mobile-application policy similarly distinguishes managed from unmanaged applications, requires controls that prevent unmanaged applications from handling non-public information, permits allowlisting, requires enforcement of prohibited-application policies, and directs the use of enterprise mobile-security and Mobile Threat Defense capabilities. See Use of Unclassified Mobile Applications in the Department of Defense.

At minimum, managed devices should enforce:

  • A supported operating system baseline.
  • Full-device encryption and strong authentication.
  • Application allowlisting or a controlled application catalog.
  • Per-application location and sensor permissions.
  • Restrictions on unmanaged data transfer and cloud backup.
  • Certificate, VPN, and network configuration.
  • Mobile Threat Defense and device integrity checks.
  • Remote locking, recovery, and wipe capabilities.
  • Defined remediation for noncompliant devices.

Mobile device management proves that a configuration was applied. It does not prove that an approved application or embedded analytics SDK is not exporting unnecessary telemetry. That requires an application security (AppSec) assessment and supply-chain governance as well. The cyber domain still poses a risk even if the information domain surface associated with it is handled with due care.

Make geolocation policy risk-tiered and technically enforceable

A single worldwide rule is usually either too weak for the operational environment or too restrictive for normal life. Establish risk tiers for home station, routine training, high-risk travel, exercises, designated operational areas, and specific missions. Define which devices and geolocation functions are permitted in each tier; what mission necessity justifies an exception, who accepts the risk, and what configuration profile the device receives.

That tiered approach directly follows the 2018 DoD geolocation policy, which calls for threat-based OPSEC assessment and rational categorization of location and operational sensitivity. The distinction is important: the answer is not that every device must always be off. The answer is that geolocation functionality must be tied to mission necessity and local threat conditions rather than convenience.

Deploy those policies through MDM rather than expecting a tired person to remember twenty settings during movement. A policy that exists only as a PDF is a statement of aspiration. Warfighters, port security personnel, police officers, and anyone else in high stress environments should not be expected to become DFP experts; make it automatic or stupid simple for them.

Replace “burners” with dedicated mission devices

A second unmanaged telephone is not automatically a second identity. If it shares the same holder, routes, associates, accommodations, Wi-Fi networks, transportation, and timing as the first device, it can become another selector attached to the same person.

Public guidance should therefore recommend dedicated mission or travel devices, not casual burner phones. A dedicated device (such as an EUD) is issued for a defined purpose, centrally configured, populated with only the accounts and data needed for that purpose, monitored during its lifecycle, recovered afterward, and sanitized or retired under an approved process.

NSA’s public OCONUS guidance recommends preparing dedicated devices with limited contacts and email for imminent travel. The significance is organizational control and data minimization, not the mythology of purchasing an anonymous handset. See NSA’s mobile-device guidance for OCONUS travel.

The team must rehearse the transition points surrounding those devices: issue, enrollment, movement, arrival, mission use, displacement, recovery, and retirement. Changes in device population and behavior are signatures. A technically clean configuration deployed at an operationally conspicuous moment can still expose the operation.

Measure the team, not merely its members

Assume one member’s failure can expand the compromise radius of the entire group. The relevant question is not whether four individuals passed annual training. It is whether an outside observer can infer that the four belong together, identify where they stage, predict when they move, or distinguish their equipment and support network from the background population.

Measure group behavior during realistic exercises. Instrument the unit across RF, Wi-Fi, Bluetooth, network, physical, administrative, and publicly observable sources within the limits of law and policy. Establish a baseline, apply the countermeasure, and measure again.

The Marine Corps is moving explicitly toward instrumented signature training. Its 2025 Force Design update describes systems that allow evaluators to observe physical signatures in real time and assess how units appear across multiple sensors. That is the right model: not “Did the Marine remember the setting?” but “What did the unit look like to the collection system?” See the 2025 Force Design update.

Separate measures of performance from measures of effectiveness.

Measures of performance include:

  • Percentage of devices enrolled in management.
  • Percentage running an approved configuration.
  • Number of unauthorized applications detected.
  • Number of unaccounted-for emitters identified.
  • Time required to remediate a noncompliant device.

Those metrics tell the commander whether the control was executed.

Measures of effectiveness include:

  • Whether a red team could resolve team membership.
  • Whether it could infer the movement or deployment window.
  • Whether it could identify the operating site.
  • Whether it could associate a device with a named individual.
  • Whether it could distinguish the force from the civilian baseline.
  • Whether the countermeasure created a new and more obvious anomaly.

Those metrics tell the commander whether the control worked. That said, a unit can achieve 100 percent device compliance and remain perfectly targetable.

Expand the compartment to include the support system

The team is not only the operators. It includes drivers, maintainers, logisticians, contractors, interpreters, vendors, hotel and transportation arrangements, family communications, replacement personnel, and the devices and accounts used to coordinate them.

Map the compromise radius of each person, device, application, and support relationship. The compromise radius is the number of otherwise protected entities that become easier to resolve when one node is attributed. A phone used by one person may expose a fire team. A transportation account may expose an entire rotation. A vendor scheduling application may expose the cadence of a site. A family member’s public activity may identify a supposedly unattributed traveler.

This is why signature management cannot be delegated to personal discipline. The relevant security boundary is the operational graph, not the employee.

For the Institution

Establish a leadership-owned signature-management program

Signature management must have an accountable owner, a recurring battle rhythm, and representation from operations, intelligence, counterintelligence, communications, cyber, electromagnetic warfare, force protection, logistics, legal, privacy, acquisition, and public affairs. For the non-military audience, perhaps that can be a Director of Security, a Director of Operations, a Chief Security Officer, or otherwise. Whether you’re a warfighter, a cop, or a security professional, your organization owes it to you to have accountable leadership.

For each operation, shift, or mission, identify:

  1. The critical information the threat actor must not learn.
  2. The observable indicators from which that information could be inferred.
  3. The sensors, commercial datasets, intermediaries, and analytic methods available to the threat actor.
  4. The countermeasures intended to change those indicators.
  5. The measures that demonstrate success, failure, regression, and unintended effects.
  6. The residual risk and the leadership personnel authorized to accept it.

Build an expected signature envelope for each phase of the mission. The envelope defines what the force expects to be observable, by which collectors, during what period, and within what tolerance. An unexpected emitter outside the envelope is a finding. So is an expected civilian background signal that suddenly disappears. So is an unusual convergence of otherwise authorized devices.

Over time, this becomes a signature twin: a living model of how the organization expects to appear across physical, electromagnetic, cyber, administrative, commercial, and human datasets. The twin is not a glossy digital model. It is a continuously tested hypothesis about what an adversary can observe in varying conditions. This is just as important for military exercises, officer patrol routes, or even fixed sites like energy production facilities, airports, seaports, and otherwise.

Build a governed emitter inventory and environmental baseline

“You cannot manage what you have not measured” is correct, but a device census must be defined honestly. No single sensor produces a complete census of cellular, Wi-Fi, Bluetooth, satellite, vehicle, industrial, and embedded devices. Carrier visibility, network telemetry, passive RF observation, MDM inventory, access-control records, asset systems, and physical surveys each reveal different portions of the environment.

Reconcile them into an authorized-device and emitter inventory:

  • What is authorized?
  • What is expected but unmanaged?
  • What is the environmental background?
  • What is a known unknown?
  • What appears only during specific activities?
  • What disappears during those same activities?
  • What repeatedly approaches, shadows, or converges with protected assets?
  • Which devices or accounts bridge otherwise separated groups?

Do not build only a list of identifiers, but instead model expected behavior and confidence. An unknown Bluetooth device observed once in a parking lot is noise; it could be an Android Auto device hooked up to a car. A device that returns during every classified event, follows personnel to a second facility, and sleeps near one employee’s residence is a different problem.

The collection itself must be governed. Establish legal authority, notice where required, data minimization, retention limits, role-based access, auditing, and procedures for resolving false positives. A comprehensive friendly-force device census is also a preassembled targeting package. Treat it accordingly. This is exactly what Empyrean Defense builds in our own Digital Force Protection workspace.

Require a Telemetry Bill of Materials

Organizations now expect a Software Bill of Materials (SBOMs) to understand software dependencies and potential software supply chain weaknesses and vulnerabilities. It is my argument that organizations susceptible to UTS (read: every organization) should require a Telemetry Bill of Materials, or TBOM, for every application, device, platform, and commercial service used by sensitive personnel.

The TBOM should identify:

  • Every requested permission and sensor.
  • Every persistent or resettable identifier.
  • Every embedded advertising, analytics, crash-reporting, mapping, and attribution SDK.
  • Every network destination and subprocessor.
  • What precise, approximate, derived, or inferred location is collected.
  • The purpose and necessity of each collection.
  • Retention and deletion behavior.
  • Whether data is sold, shared, licensed, or used for advertising.
  • Whether data is combined with third-party information.
  • Whether foreign personnel, affiliates, vendors, or infrastructure can access it.
  • What happens when the contract terminates.
  • How can an individual or institution verify deletion.

This is not a bureaucratic invention for its own sake. The Justice Department’s Data Security Program tells regulated entities to “know their data,” identify data flows, revise policies, change vendors, alter access, and revise contracts. Its compliance guidance also warns that tracking pixels and software-development kits embedded in applications or websites can create regulated data-brokerage exposure. The program took effect on April 8, 2025, with its additional due-diligence and audit obligations effective October 6, 2025. See the DOJ Data Security Program and its Compliance Guide.

No advertising SDK belongs in a mission application unless somebody can articulate a mission requirement worth the exposure. “The vendor bundled it” is not a requirement.

Stand up a signature red cell, but govern it like an intelligence activity

Auditing one vector at a time is the defender’s game. An adversary will fuse what is available. The institution should therefore authorize a red or purple team to examine the organization as an integrated targeting problem.

The team should assess public records, organizational websites, press releases, contract notices, professional profiles, financial intelligence, beneficial ownership, social media, public imagery, exposed metadata, public network information, authorized RF observations, consenting participant data, approved commercial services, and synthetic or exercise-generated datasets. It should test whether those sources can reveal personnel, facilities, associations, schedules, movements, logistics, or operational transitions when joined.

It should not purchase gray-market location histories, query advertising exchanges against unwitting personnel, or run named employees through commercial surveillance systems merely because the capability exists. Those activities create legal, privacy, counterintelligence, and insider-threat risks of their own. The FTC’s Mobilewalla case alleged that the company harvested information from real-time advertising auctions, retained hundreds of millions of advertising identifiers paired with location, and handled data associated with military installations and other sensitive sites. Reproducing the harm internally without authority is not red teaming. It is building an ungoverned surveillance program.

Use consenting exercise participants, synthetic identities, approved test devices, carefully scoped external-assessment vendors, and counsel-reviewed data sources. Record collection provenance. Separate assessors from operational users. Minimize named person reporting unless attribution is necessary to remediate the vulnerability.

The output should answer operational questions:

  • What could be inferred?
  • With what confidence?
  • From which combination of indicators?
  • How quickly?
  • At what cost?
  • Which control would break the analytic chain?
  • Did that control work when retested?

The output should be shaped as an adversary threat model tied to remediation, and not a voyeuristic dossier.

Run it periodically and after major organizational changes, deployments, application rollouts, facility moves, vendor changes, or policy revisions. A signature is not static, and a clean assessment expires as soon as the force, environment, or commercial ecosystem changes.

Manage commercial-data exposure as a formal threat surface

Assign an owner for commercial data exposure. That owner should know which brokers, applications, SDKs, services, and vendors may possess information about protected personnel and facilities; what deletion, correction, sale opt-out, and access rights exist; and which populations require assistance exercising them.

California’s Delete Request and Opt-out Platform, or DROP, launched for consumers on January 1, 2026. California residents can currently submit one deletion request covering more than 600 registered data brokers. Brokers are required to begin processing those requests on August 1, 2026, and then process them repeatedly at least every 45 days. It is free, centralized, and materially better than asking everyone to find hundreds of opt-out pages. It is also limited to California residents, registered brokers, matching records, non-exempt data, and organizations that comply with the law. See the official California DROP portal.

Other state rights and broker processes vary. The institution should provide a supported deletion program rather than emailing their personnel a list of websites. That support should extend, where appropriate and consensual, to dependents and household members whose exposure can identify the protected person.

Deletion is risk reduction, not retroactive erasure. Measure which brokers acknowledged the request, what identifiers matched, what remained exempt, and whether the same data reappears later.

Put commercial-data restrictions into procurement and contracts

The organization should not merely ask vendors whether they “take privacy seriously.” Contracts should specify:

  • No sale or advertising use of personnel or operational data.
  • No precise location collection unless expressly required.
  • Purpose limitations and minimum necessary collection.
  • Defined retention periods.
  • Deletion upon request and contract termination.
  • Restrictions on subprocessors and onward transfer.
  • Restrictions governing foreign access.
  • Disclosure of SDKs and network destinations.
  • Audit and assessment rights.
  • Breach and unauthorized-access notification.
  • Evidence supporting consumer or employee consent.
  • Data return and destruction certification.
  • Remedies for noncompliance.

For organizations subject to the DOJ Data Security Program, contracts involving foreign persons may also require restrictions against onward transfer to countries of concern or covered persons, accompanied by due diligence and reporting. Contract language alone does not satisfy the obligation; the organization must have systems capable of monitoring whether the restriction is being followed.

Apply the same scrutiny to free services. “Free” frequently means the procurement office never saw the contract.

Integrate signature assessment into training and readiness

Every major exercise should include a signature-control plan, an adversary collection model, baseline observations, instrumented execution, and an after-action assessment.

Record signature debt in the same manner that engineering organizations record technical debt. Signature debt includes known emitters without owners, unmanaged applications, unsupported devices, unexplained network destinations, untested policies, missing broker deletions, procurement exceptions, recurring personnel correlations, and countermeasures whose effectiveness has never been measured.

Assign each item to an owner, operational consequence, remediation plan, and acceptance authority. Do not allow “everyone knows about it” to substitute for disposition.

The readiness question should be: “Can this force perform its mission while denying the adversary sufficient information to classify, locate, target, or predict it?” That much is different from asking whether the force passed a cybersecurity inspection.

Protect the signature-management system itself

The data required to protect a force can also compromise it. Device inventories, household associations, co-traveler graphs, red-cell findings, emitter baselines, movement histories, vendor records, and identity-resolution results should be treated as highly sensitive operational data.

Segment the system and minimize collection. Separate raw data from operational findings. Limit access by role and mission and allow auditing of searches and exports. Establish retention and deletion schedules and prohibit secondary use. Plan for insider misuse and compromise such as bulk access, data exfiltration, and other cyber-attack vectors.

A signature-management platform that leaks its own graph has done the adversary’s fusion work for them.

Escalate systemic problems as specific policy requirements

Individuals and units cannot repair the lawful-intercept architecture, foreign access to carrier infrastructure, opaque international data resale, application-store defaults, or the absence of nationwide data-broker deletion rights. Those problems belong with acquisition authorities, service headquarters, combatant commands, regulators, lawmakers, carriers, and platform vendors.

Escalate them precisely:

  • Which data is exposed? Through which legal or commercial mechanism?
  • Which population is affected?
  • What operational inference does it enable?
  • Which organization has the authority to change it?
  • What configuration, contract, funding, regulation, or statutory language are required?
  • How will success be measured?

Broad warnings produce broad acknowledgments. Specific requirements can produce decisions.

The countermeasure to UTS is not “turn off your phone.” It is a governed system that reduces unnecessary collection, controls the collection that remains, measures the aggregate signature of the force, tests that signature against realistic adversary analytics, and continuously adapts when the environment changes.

A dashboard showing that every device is compliant is useful. A system demonstrating that the adversary can no longer resolve the unit is force protection.

Anything less is paperwork. And that will get you killed in the streets.

You Cannot Manage a Signature You Cannot See

Everything above reduces to one observation, which is that the adversary is running a fusion problem and the defender is running an awareness campaign.

Our adversaries are joining five vectors of data across time and resolving individuals. We are handing out pamphlets. The asymmetry is not in the collection. It is in the analysis, and analysis is a software problem. This is why Empyrean Defense's digital force protection work exists, and I will keep this short because you have read this far, and you did not come here for a sales pitch.

We built the capability to see your own signature the way a fused adversary would see it, which means running the join defensively before someone runs it offensively. A device census across radio types, correlated over time into tracks with identity resolution, and fused with some of the same external feeds the adversary uses, meaning commercial ALPR, wardriving and positioning databases, imagery, and open-source footprint, so that the picture you audit is the picture they can assemble.

Co-travel detection that answers whether an unknown device is holding proximity to a protected person or asset, and whether your own protective detail is the thing resolving the principal. Anomaly detection over approaches, so that a vehicle or a handset recurring on your ingress route at a periodicity that matches no explicable population surfaces as a track with provenance rather than a hunch. Cell-site simulator and GNSS interference detection, because the electronic vector includes things being done to you and not merely things leaking from you. All of it is edge-deployable and air-gap capable, because a force protection tool that phones home is an instrument of the problem it claims to solve.

I am not going to describe the scoring, the trust lifecycle, or the internals, and you should be skeptical of anyone in this field who does.

What I will describe is the doctrine, because it is the same doctrine that governs everything we build: Sense, Make Sense, Act. Sense is the census, meaning an honest inventory of emissions in a volume of space. Make Sense is the fusion layer, meaning correlation across vectors into identity, pattern, and anomaly, with the provenance visible so a human can disagree with the machine. Act is the policy layer, meaning the automated response you have decided in advance and can defend afterward. The adversary has all three. Most defenders have none of them, and they have been told that awareness is a substitute.

It is not a substitute. Awareness without measurement is superstition. You either know what you emit, or you are guessing, and the people who are guessing are the people in the ledger above.

Frequently Asked Questions

What is ubiquitous technical surveillance?

Ubiquitous technical surveillance, or UTS, is the collection and long-term retention of digital and physical observables that allow an adversary to connect a person to other people, places, activities, devices, and organizations after the fact. Its defining advantage is retroactivity: the target does not need to be identified before the data is collected.

How does commercial location data threaten military personnel?

Commercial location data can reveal where personnel sleep, work, train, congregate, travel, and deploy. When device identifiers and coordinates are fused with public records, imagery, social media, vehicle data, or access records, pseudonymous movement histories can become named patterns of life and targeting intelligence.

What is Digital Force Protection?

Digital Force Protection is the defensive measurement and management of a force's observable digital signature. It combines device census, identity resolution, co-travel detection, anomaly detection, environmental baselining, and policy controls so defenders can see what an adversary could infer from their emissions and behavior.

What is co-traveler analysis?

Co-traveler analysis identifies entities whose movements repeatedly correlate across space and time. It can surface unknown associates of a known target, devices that appear to shadow a protected person, or friendly devices whose repeated convergence unintentionally exposes a team, facility, or mission.

Why is going dark still a signature?

Silence becomes meaningful when an expected signal disappears in a repeated or operationally significant pattern. Analysts can also detect substitution when a new identifier reproduces an old device's behavior, and convergence when otherwise ordinary devices begin gathering near sensitive locations or moving together.

What is signature management?

Signature management is the deliberate measurement and shaping of observable indicators so a force is harder to classify, locate, target, or predict. The objective is not zero emission. It is a controlled, mission-consistent signature whose meaning is difficult for an adversary to resolve.

How does UTS affect EABO and Stand-In Forces?

EABO and Stand-In Forces depend on mobile, distributed, low-signature units operating inside contested littorals. Commercial networks, civilian devices, constrained island geography, and long pre-collection windows can expose the personnel, logistics, sensors, and behavioral patterns that sustain those formations.

What can individuals do to reduce UTS exposure?

Individuals can remove unnecessary advertising identifiers, restrict location permissions, delete stored location histories, lock down fitness and social profiles, minimize connected devices around sensitive activity, keep devices supported and updated, and treat household accounts, wearables, vehicles, and photographs as part of the exposure surface.

What should small teams do about UTS?

Small teams should use centrally managed devices, enforce risk-tiered geolocation policies, issue dedicated mission devices when necessary, measure group-level correlations during exercises, and include support personnel, vendors, transportation, and households in the operational security boundary.

What should institutions do about UTS?

Institutions should establish an accountable signature-management program, maintain a governed emitter inventory, require a Telemetry Bill of Materials from vendors, run lawful signature red-team assessments, manage commercial-data exposure, contractually restrict telemetry, and measure whether an adversary can resolve the force—not merely whether devices are compliant.

Stay Dangerous.

Empyrean Defense

Want to discuss this topic?

We're always happy to talk about the problem space, the platform, or how we might work together.