← Back to list

DISARM Playbooks

This post explores the development of DISARM Playbooks and how they support analysts working within the DISARM framework.

Adam in Disarming Disinformation · 2026-03-13 15:58 · 0 claps · 3.9 min read
#disinformation #disarm #mifi #influence-operations
Open on Medium ↗

DISARM Playbooks

This post explores the development of DISARM Playbooks and how they support analysts working within the DISARM framework.

What are DISARM Playbooks?

DISARM Playbooks are resources designed to help people use DISARM within given topic areas. This is an intentionally broad definition as we explore how we can support the range of ways people use DISARM, and what is achievable with available resources.

Most DISARM Playbooks are currently different types of documentation for analysts to refer to as they use DISARM, but have been produced with the goal of using Playbooks’ content to inform development of technical interventions (once DISARM has the resources to develop said interventions). These pieces of documentation come together to make a Playbook on a topic. Playbooks can focus on a variety of topics, including narrative / focus area (e.g. Technology Facilitated Gender-Based Violence (TFGBV)), defender type (e.g. Fact Checker), or threat actor (e.g. Portal Kombat).

The following are types of resources which have been developed in the last year as part of Playbooks focusing on those topics:

Key Techniques

There are a lot of different behaviours exhibited in influence operations, and as such DISARM has a lot of items in the Framework, which people have told us is overwhelming. The Key Techniques resource addresses this issue by providing a list of Techniques which are — key — to documenting behaviours in a given topic area.

Below are descriptions of how this resource has been produced over the course of different updates to the DISARM Framework, with links to each Playbook iteration:

  • **TFGBV: Key Techniques— DISARM v2 Alpha:** This first iteration of Key Techniques pulled out full descriptions of Techniques which document harms associated with TFGBV.
  • **Fact Checking: Key Techniques — DISARM v1.7: **We produced short descriptions of Techniques which were key for Fact Checkers and collated them in this document. Provision of short descriptions made the resource more concise, and better achieved the goal of providing an overview of Key Techniques.

Tagged Reports

DISARM applies TTPs to public third party reports, giving analysts real-world examples of how they have been used, and examples of how reports can be augmented using DISARM. This gives analysts the ability to double check their understanding of TTPs against DISARM’s work, improving inter-coder reliability, and DISARM’s ease of use.

Below are descriptions of how this resource has been produced over the course of different updates to the DISARM Framework, with links to each Playbook iteration:

  • **TFGBV: Tagged Reports — DISARM v2 Alpha:** The first iteration of Tagged Reports identified at least one third party report for each Key Technique, and provided a DISARM-augmented version of each. It also provided a Procedure (then called ‘Aggregate’) from each report.
  • **Fact Checking: Tagged Reports — DISARM v1.7: **There were more Key Techniques for Fact Checkers than for TFGBV, so a resource collating a tagged report for each would not be very usable. This resource instead highlighted reports for the most commonly occurring behaviours (the KEY Key Techniques), and for Techniques which required more nuance / analysis to apply. Analysts can still refer to the >100 DISARM-augmented third party reports introduced as part of the update within the framework — this resource just serves to highlight particularly useful / demonstrative ones.

Prefabricated Procedures

In DISARM v2, Procedures are DISARM Observations which are aggregated using DISARM’s standardised Procedure formula (you can read more about this here). The Prefabricated Procedures resource provides examples of commonly seen Procedures in a given topic area, or key behaviours which can be slotted into Procedures as an analyst sees fit. The goal of this resource is to help time-pressured analysts quickly benefit from DISARM’s Procedures system without having to learn it in-depth.

An example of this resource is provided below:

  • **TFGBV: Prefabricated Procedures — DISARM v2 Alpha**: This first iteration of Prefabricated Procedures was developed before ‘Observations as Procedures’ was a fully fleshed out concept, and attempted to minimise the use of the Procedure system with the goal of reducing potential overwhelm of readers. Future versions of this resource will lean more into the idea of DISARM Procedures, both how and why they should be used.

Tagging Support

We have explored ways to support analysts making real-time tagging decisions. This has included discussion of ‘decision trees’ — but something like this would be better suited to a technical intervention, which DISARM does not currently have the resources to produce. In the meantime, Playbook resources have been produced which support analysts in making choices about what to tag in an incident, examples of which are provided below:

  • **TFGBV: Tagging Support — DISARM v2 Alpha**: This first draft of a Playbook in DISARM combined Key Techniques, Tagged Reports, and Prefabricated Procedures into one large document. Initial feedback was that this was too much in one document — and as such it was broken down into separate resources (detailed above).
  • **Portal Kombat: Tagging Support — DISARM v2 Alpha:** This resource ties together an introduction to Portal Kombat, some Prefabricated Procedures based on common Portal Kombat behaviours, and provides an example tagging scenario to support the use of Procedures. It also provides support for mapping coordinated behaviour between Portal Kombat and other well known influence operations, showing how Playbooks can provide different types of support depending on their area of focus.
  • **Fact Checking: Tagging Support — DISARM v1.7: **This resource focused on helping Fact Checkers operationalise DISARM with two core sections. The first looked at DISARM as a way to answer intelligence questions, and used this to help analysts TTPs they would apply to their work (thinking about what information was important to them, and what they had the capability and capacity to uncover). The second section provided a guide on how to identify behaviours within content addressed by Fact Checkers, organising TTPs based on how commonly they occurred.

Other Resources

We welcome feedback, as well as insight into systems you have implemented and would be willing to share with the community, or pain points you’d like help overcoming. Please get in touch with any feedback on DISARM Playbooks, and watch this space for further updates.


메타데이터
post_id
180cf59cdc7f
slug
disarm-playbooks-180cf59cdc7f
url
https://medium.com/disarming-disinformation/disarm-playbooks-180cf59cdc7f
canonical_url
https://medium.com/disarming-disinformation/disarm-playbooks-180cf59cdc7f
author_url
https://medium.com/@adam.disarm
status
ok
fetched_at
2026-06-20 20:29:01