evilrobots.lol / tech

The Rosetta

This project names 102 method-markers. An independent framework names 71 techniques. Do they describe the same world? The comparison is arithmetic, it is public, and the answer is only partly what we hoped.

A taxonomy built by one project, from one reading list, is a hypothesis. It might name real recurring methods, or it might name the shape of its author’s attention. The way to find out is to check it against a taxonomy somebody else built, for a different purpose, without knowing this one existed.

DISARM is that check. It is the open influence-operations framework — MITRE ATT&CK’s shape applied to information campaigns, built by a community of disinformation researchers, 71 techniques under 13 tactics, CC-BY-4.0. Nobody involved has read these books.

So: 102 markers against 71 techniques, both sides shown in full, scored by arithmetic anyone can re-run. Three things came out of it, and only the first is the one we wanted.

The overlap is real but thin. Four of our markers reach a DISARM technique as closely as that technique’s own siblings reach each other. Several more are obvious relatives that the metric scores just under the line — discredit the messenger against Plan to discredit credible sources is plainly the same move, and the arithmetic gives it 0.096. Corroboration exists; it is weaker than we would like to claim, and it is shown at full resolution rather than summarised.

Most of the gap is scope, and that part is not a defect. A detector that reads prose will never see Purchase advertisements or Use physical broadcast capabilities. Sixteen DISARM techniques have no textual signature at all, and ten more are DISARM enumerating platforms — “use Reddit as a dissemination channel” — rather than naming a method. Those are not markers we are missing. They are a different layer of the same subject.

And some of the gap is ours. Eleven techniques describe things visible in prose that we have no marker for: the 5Ds, competing narratives advanced in parallel, demanding unsurmountable proof, denying involvement, manufactured experts. That is a work list, not a footnote, and it is on the page below with the rest.

One thing that did not survive contact with the data: the first version of this analysis reported “zero overlap” against a similarity threshold higher than known siblings inside DISARM manage to clear. The number was right and the reading was wrong. That is why the calibration panel is the first thing below the verdict and not an appendix — a similarity score without its own baseline is not evidence, it is decoration. The same correction applies to the classifier that sorts the gap: its first pass called eight platform-name entries “textual” because their summaries contain the word narrative, inflating our apparent blind spot by nearly half. It uses DISARM’s own tactic field now.

Nothing in the books rests on external validation of this taxonomy — checked, and no chapter makes that claim — so this changes no printed argument. It changes the work list.

measured

Loading the comparison…

Read the score against these, or not at all

Similarity here is TF-IDF cosine over names and summaries. It is crude, it is reproducible, and it is low for everything — which is why the same metric runs inside each framework first, where relatedness is guaranteed by construction. Those two bars are what “related” looks like on this instrument. The third is the actual measurement.

Every marker, and its nearest candidates

The machine ranks; you decide. Open any marker to see our description beside the three closest DISARM techniques in their own words, and judge whether they are the same thing. A cosine cannot tell you that, and a page reporting one as though it could would be doing the exact thing this corpus exists to catch.

The other direction — what we cannot see

DISARM techniques nothing of ours comes near. Some of that is scope: a detector that reads text will never catch Purchase advertisements or Use physical broadcast capabilities, and those are labelled operational. Some is DISARM enumerating platforms rather than methods — channel, taken from DISARM’s own tactic rather than from a guess of ours. What remains, textual, is the honest gap: methods visible in prose that we have no marker for. Hover a label to see what put it in that bucket.