IARPG-OPS-1 online Intelligence operations standard Fictional missions · neutral authorities

Research archive / Espionage operations and tradecraft

Executive Summary

This report surveys open-source surveillance tradecraft and counter-surveillance best practices, highlighting how to record detailed 72‑hour logs. We draw on professional guides and training materials: for example, teams are taught to be highly vigilant for unusual patterns (e.g. repeated vehicles or odd behaviors) and to use techniques like Surveillance Detection Routes (SDRs) to flush out followers. Logs must be…

Executive Summary

This report surveys open-source surveillance tradecraft and counter-surveillance best practices, highlighting how to record detailed 72‑hour logs. We draw on professional guides and training materials: for example, teams are taught to be highly vigilant for unusual patterns (e.g. repeated vehicles or odd behaviors) and to use techniques like Surveillance Detection Routes (SDRs) to flush out followers. Logs must be meticulous and admissible: as UK guidance notes, surveillance records must comply with laws like RIPA/GDPR and preserve chain-of-custody (no erasures, no blank entries). A well-structured report is then written from those logs: it begins with date/time, subject ID, purpose, locations, and then a chronological narrative of all observations. This report (1) summarizes these tradecraft norms; (2) lists environmental/temporal factors to record (weather, traffic, guard shifts, lighting, events, transit, RF spectrum, CCTV, access points, etc.); (3) gives sample log-entry formats blending routine notes with hidden anomalies (signals, flashes, RF bursts) and how to flag subtle cues; (4) outlines best practices (UTC timestamps, legal/privacy notes, safety); (5) provides a 72‑hour example log for a generic urban asset; and (6–7) offers comparison tables and mermaid diagrams to illustrate format and relationships. Assumptions: The target’s exact coordinates, legal jurisdiction, and profile are unspecified (treated as open variables). The sample log assumes a generic urban U.S. environment with standard privacy laws (e.g. data minimization).

Tradecraft and Surveillance Detection Practices

Surveillance teams emphasize situational awareness and pattern-spotting: “detection is the first step” and teams watch for people or vehicles that seem out of place (e.g. repeatedly present or using unusual routes). Standard tradecraft includes planning Surveillance Detection Routes (SDRs): deliberate, twisty travel paths to prompt any follower to reveal themselves. Teams also perform electronic sweeps to find bugs or hidden cameras – using RF scanners or spectrum analyzers to catch odd signals. Maintaining a proper surveillance log is itself a basic rule: for instance, an LAPD procedure explicitly commands investigators to “maintain a chronological surveillance log” of all team observations. Training manuals stress that logs underpin the intelligence product – the formal report “is developed from the surveillance log or logs” – so details like exact time, location, and descriptions must be recorded (buildings and environments are described so others can visualize the scene). Throughout, teams balance vigilance with caution: non-intrusive monitoring (covert photography, triangulation via fixed cameras, etc.) is favored unless arrest is imminent. In summary, open sources instruct that surveillance logs should be complete, objective, and legal: note every sighting and event, however mundane, and mark any departure from routine or obvious sign of targeting.

Environmental & Temporal Factors to Record

Surveillance logs should capture a broad range of contextual variables. For example:

  • Weather/Visibility: Temperature, precipitation, fog, daylight vs. darkness – conditions that affect how well a team can see the target or move. (E.g. “rain began at 03:00, reducing visibility; target’s coat glistened under streetlights.”)
  • Foot/Vehicle Traffic: Pedestrian counts on sidewalks and car volumes by time of day. Periods of heavy traffic or crowds can obscure the target; note rush hours or road congestion.
  • Guard Rotations/Security Shifts: Schedules of any known security or police patrols near the asset, especially any uniformed presence or checkpoint changes. (E.g. “Guard relief at gate at 06:00, two uniformed officers now present.”)
  • Lighting Conditions: Changes in natural light (sunrise/sunset) and artificial lighting (streetlights on/off, building floodlights, vehicle headlights). (E.g. “By 19:20 streetlights switched on; target’s silhouette more visible.”)
  • Public Events: Nearby activities (festivals, concerts, protests, sports games) that generate crowds or unusual behavior. Such events may mask surveillance or signal risk. For instance, a parade at 12:00 attracted a crowd on 5th Avenue.
  • Transit Schedules: Local bus/train departure times or schedules, since targets may use public transport and patterns of commuters may cause surges of bystanders. (Noting e.g. “08:15 subway departure; influx of pedestrians at station.”)
  • RF/Communications Activity: Observations from RF scanners: e.g. unexpected bursts on suspect radio frequencies or cell towers. Teams often log when their spectrum receiver picks up a spike or unknown transmission. (E.g. “09:43 – short encrypted burst on 450 MHz heard on scanner.”)
  • CCTV and Sensors: Document fixed surveillance assets covering the area (CCTV cameras on buildings, traffic cams, license-plate readers). Also record use of team sensors (night-vision, thermal scopes, drones, vehicle tracking devices) – noting what was used and any data produced.
  • Building Access Points: The target’s building entry/exit points (doors, gates, loading docks) and whether they were locked or used. If the building is described (e.g. “brick 5‑story warehouse on corner of Elm & 4th”), note each entry. Detailed location notes help later analysis.

Figure: Example urban surveillance setting – heavy nighttime traffic and high-rise buildings. Logs would note traffic density, timing of streetlights, and any anomalies (e.g. a brief flash) under such conditions.

Each of these factors is logged regularly. For example, a log entry might read, “2026‑07‑18 17:30 – Weather: clear, 10°C. Traffic heavy (evening commute). Target remained on sidewalk near north entrance.” On the return commute, an unusually large crowd from a nearby event might also be noted. Capturing these environmental cues is crucial: they provide context for assessing anomalies (was a particular gesture masked by crowds? did a flash coincide with a lightning flash or an isolated event?).

Log Format and Sample Entries

Surveillance logs are usually tabular or narrative, with columns/fields for Date/Time, Observer(s), Subject ID, Location, and Observation Details. A typical paper log sheet might look like:

Surveillance Log
Date: _____   Subject: _____   Team Members: ____
Time        Observations

For example, one widely cited form uses columns labeled Date, Offender/Subject, Team, Time, Observations. Electronic systems similarly record timestamped entries (often auto-UTC) with rich details (GPS location, photos). The key is consistency and completeness: each entry should have an exact time (in UTC for clarity) and a concise description of what was seen or heard. According to PI training materials, the final surveillance report is constructed as a “detailed chronological narrative” from those logs, so every entry should stand alone intelligibly.

Example Log Entry:

2026‑07‑18 14:22 (UTC) – Subject (male, approx. 5′9″, dark coat) exits office building.

- Environment: Bright daylight, few pedestrians on street. Large white van parked at corner (license unreadable). *

- Observation: Subject shakes hand with a man in a gray cap who lingers ~10 m east (possible brief conversation, no audible dialog).*

- Anomalies: At the moment of handshake, a camera flash – unassociated with any flash unit – briefly illuminates from inside the van’s back window (possible hidden camera or strobe). Logged for analysis.

In this example, mundane details (subject appearance, traffic) are recorded alongside subtle clues (the handshake and flash). Note how the flash is specifically highlighted. In practice, teams often mark or flag such observations (e.g. in brackets or italics) to ensure they attract attention during review. Each entry should be factual (no speculation), but can annotate unusual signs: for instance, “(possible signal gesture)” or “(suspected RF spike)” as needed. Entries may also mention team coordination (when observers rotate) and equipment status (battery levels, scanner findings).

Best Practices in Log Structuring

  • Timestamping: Always use precise time (24‑hour format) and date. Standardize on UTC to avoid confusion from time zones or daylight‑saving shifts. For example, annotate “2026‑07‑18 03:45 UTC” even if local time is different. Include seconds if possible, since some anomalies (RF spikes, gestures) are fleeting.
  • Entry Discipline: Follow evidence-friendly conventions. Do not erase or white-out entries. If a mistake is made, cross it out with a single line, initial it, and continue. Never leave blank rows (write “No activity” if needed). Sign or initial each page to show continuity. Maintain originals (never remove pages) and use carbon copies or digitization for reports. This is often remembered by the mnemonic “ELBOWS” (no Erasures, Loose leaves, Blank spaces, Overwrites, Writing between lines, etc.).
  • Structure: Start each entry with date/time and location. Often it’s useful to bullet or number observations within an entry. Include subject descriptors (clothing, physical traits) at first contact and update if changed. Clearly separate separate events: e.g. put a blank line or line of dashes between distinct scenes (target’s car versus walking). Include the names/IDs of any surveillance operatives on duty for that entry if relevant.
  • Context & Notes: If certain observations raise privacy or legal issues, note them. For instance: “Note: nearby civilian whose face was inadvertently recorded (blurred on video) – no further action unless incident.” Many jurisdictions require minimizing bystander data; logs should note only what’s necessary and any legal approvals or constraints in effect. Also record your own team’s safety actions (e.g. “eyes off subject: suspect’s accomplice on sidewalk – obs 3 scanned address).
  • Privacy & Legal: Be aware of local laws. For example, UK training explicitly lists RIPA, GDPR and related laws as constraints on surveillance logs. If you’re in the U.S. or elsewhere, ensure compliance with consent and record-keeping laws. Always use data solely for the surveillance purpose and securely store logs. If any personal data (e.g. license plates) are collected, annotate purpose and restrict access. Treat the log itself as potentially sensitive evidence.
  • Operational Safety: Include periodic “heartbeat” notes (e.g. every hour) confirming all team members are safe (“Team A back in position, no incidents”). Note any unexpected security reactions (e.g. “target’s guard approached – kept distance”). Also record equipment malfunctions promptly (flat tire, radio glitch) as they can impact surveillance coverage.

72-Hour Surveillance Log (Sample)

The following is a representative excerpt of a 72-hour log for a generic urban target (times UTC). We assume a mid-sized city coordinate, standard legal framework, and a single subject of medium interest (details unspecified). The log blends routine notes with subtle anomalies.

  • 2026‑07‑17 00:00: Detail begins. Location: Outer lobby of target’s office (brick 3-story corner building). Weather: Clear, 12 °C. Observers (Team) in position; two parked unmarked cars nearby. Observation: Subject’s office lights remain on; no movement seen.
  • 2026‑07‑17 01:00: Quiet. Traffic: Light (occasional taxi). No people near target location. Nothing unusual; team maintains radio silence except routine check-in.
  • 2026‑07‑17 03:15: Anomaly: All team radios suddenly picked up a 3-second burst of static on 455 MHz with a periodic tone. No voice, then stopped. (No authorized radio use expected on that channel.) Logged as possible encrypted comm signal.
  • 2026‑07‑17 04:00: Environment: Streetlights still on. A lone cyclist passed by target lobby twice (9 min apart) then disappeared. Vehicle engine heard faintly; unconfirmed.
  • 2026‑07‑17 05:00: Early guard change at building entrance: two uniformed officers replaced sleeping guard. Observation: Both officers salute target’s building, unaware of our team.
  • 2026‑07‑17 06:30: Dawn. Weather: Light drizzle, visibility reduced. Foot Traffic: Several commuters heading east on Main St. Target building has silhouette of one person (likely guard) at ground floor window.
  • 2026‑07‑17 08:00: Morning rush. Traffic: Heavy vehicular flow on 1st Avenue. Pedestrians: Target subject (male, dark suit) exits building with coffee at 07:58 and walks north toward transit hub. Team note: subject holding smartphone to ear, appears unaware of surveillance.
  • 2026‑07‑17 09:00: Transit Data: City bus #5 arrives at 08:55 (per schedule); crosswalk crowd thick. Subject disappears briefly in crowd, reappears near cafe at 09:02. Observation: A man in a yellow jacket lingered 15 m behind subject in crowd – noted as possible tail.
  • 2026‑07‑17 10:15: Subject sitting near lobby entrance. Anomaly: At 10:17, subject makes a quick hand flick toward forehead (a “check clock” motion) while a patrol car with activated lights passes by. Logged as possible countersurveillance check. No one responded.
  • 2026‑07‑17 12:00: Public Event: Nearby street fair began at 11:45, crowd heavy. Surveillance is complicated by vendors and bystanders. Observation: Subject merged into fair crowd; team maintains wider distance. No contact noted.
  • 2026‑07‑17 15:45: Anomaly: While subject sat near fountain, a pedestrian (female, dark hat) tapped her cane three times on ground rhythmically. She then walked behind the same yellow-jacket man seen earlier. (Possible signal sequence.) Note added for analysis.
  • 2026‑07‑17 17:30: Evening commute. Lighting: Streetlights turned on at 17:25. Activity: Subject re-enters lobby at 17:27 (noted clothing: glasses removed). Equipment: All camera batteries changed. No alarms triggered.
  • 2026‑07‑17 18:00: Traffic: Very heavy. Vehicle horn honked nearby. Building: Target building’s neon sign flickered. Observation: Unrelated. Team maintains shadowing from 30 m back.
  • 2026‑07‑17 20:00: Random Event: Brief power flicker (city utility outage) from 19:59–20:01; CCTV cams momentarily offline. Result: No immediate impact.
  • 2026‑07‑17 21:15: Anomaly: Inside lobby, a bright reflective glint was seen at target’s midsection as he turned (possible metal badge or weapon briefly exposed). No visible gun drawn. Logged as possible metal object.
  • 2026‑07‑17 22:30: Traffic: Nearly empty. Observation: Target remains at location; building doors locked. Team pulls back one observer to rest post.
  • 2026‑07‑18 00:00: Maintenance: Team changeover. Brief hiatus (target likely asleep).
  • 2026‑07‑18 05:00: New day. Weather: Foggy. Guard: Night guard relieved. Observation: One radio unit picked up intermittent barking (probably distant dog) – irrelevant.
  • 2026‑07‑18 06:30: Transit: Subway train #3 arrived at 06:25 (timed). Dozens of commuters pass target building entrance, but no contact.
  • 2026‑07‑18 07:00: Subject Activity: Target exits with umbrella at 06:55 heading southbound. Target clothes: Dark overcoat, black umbrella. Anomaly: Target makes eye contact with a passerby (black sedan driver) who flashes headlights. Logged as possible signal.
  • 2026‑07‑18 10:30: A/V Check: Audio mic overheard a click (camera shutter sound) from inside a white van parked 20 m east of target at 10:29:58. No flash seen (high-end camera?). Van left at 10:33.
  • 2026‑07‑18 13:15: RF Scan: Scanner detected a short encrypted burst at 418 MHz lasting 0.5 s, source unknown. No civilian device uses that band. Logged as encrypted comm likely.
  • 2026‑07‑18 15:00: Weather Change: Light rain began at 14:50. Visibility: Reduced; team switched to night-vision gear (evening scope) at 15:02.
  • 2026‑07‑18 17:00: Traffic: Normal. Subject: Entered subway at 16:58 (cam footage). Target traveled to opposite district. Team: Primary unit followed on subway.
  • 2026‑07‑18 19:45: Subject meets unknown: At station east exit, subject greeted two individuals (male/female), exchanged documents. Female was in red coat (previously unknown). Possibly courier exchange.
  • 2026‑07‑18 21:00: Area Scan: Team scanned surrounding RF spectrum for drones; nothing found.
  • 2026‑07‑18 23:00: Night: Team regroups. No further events until next cycle.
  • 2026‑07‑19 01:00: Fog persists. Lone cat wandered by cameraman’s leg (logged humorously).
  • 2026‑07‑19 03:30: Anomaly: A nondescript grey van (plated out-of-state) was spotted idling near entrance from 03:25–03:29, then quickly left southbound. (Possible surveillance vehicle.)
  • 2026‑07‑19 08:00: Drone: A quadcopter (security drone) briefly appeared above adjacent building at 07:58. Possibly city security patrol.
  • 2026‑07‑19 12:00: Crowd: Lunchtime crowd again at nearby plaza. Subject: Observed exiting plaza at 12:05 wearing earphones.
  • 2026‑07‑19 15:00: Transit: Tram #2 passed at 14:50. Two men (in black jackets, seen prior) boarded the tram behind target – team suspects they were tracking him.
  • 2026‑07‑19 18:30: Anomaly: All radios scrambled briefly at 18:30 on frequency 315 MHz. (Suspect device? GPS jammer?). Cleared by 18:31.
  • 2026‑07‑19 20:00: Lighting: Evening arrives; team notes all exit lights at target’s block turned on (standard procedure).
  • 2026‑07‑19 23:00: End Log: Target remained on site; surveillance terminated at 23:15. Summary: no confirmed hostile act by target, but multiple signals (hand gestures, RF bursts, unknown vehicles) suggest possible counter-surveillance or contact attempts.

Each entry above is time-stamped and factual. Notice how mundane details (“traffic heavy”, “subject carries umbrella”) are listed alongside anomalies (“camera shutter sound”, “encrypted RF bursts”, “unusual van”). Clues such as the handshake or glint are explicitly noted as possible signals for later follow-up. This is in line with expert advice to provide a “detailed word picture” of all observed activities.

Figure: Typical daytime urban foot traffic. In logs we would record crowd density, entry/exit of buildings, and any out-of-place actions (e.g. the man in yellowcoat in our Day 1 log), since anomalies may occur amid normal pedestrian flows.

Tables: Log Formats, Sensors, Anomaly Indicators

Log Format Typical Fields Advantages Disadvantages
Handwritten book Date, Time, Team IDs, Subject ID, Observation (free-text) Always usable (no power needed); simple backup. Hard to search or share; prone to legibility issues.
Digital (app/DB) Timestamp, GPS, Photo/Video attach, notes, operator ID Precise timing, easy to search/filter, geotags and multimedia support. Depends on battery/coverage; may need encryption to secure.
Spreadsheets/PDF Structured columns (date, time, details) Easily formatted and stored; templates available. Risk of tampering if not locked; less field/mobile-friendly.
Sensor Type Data Output Use Case / Strengths Example
CCTV Camera Continuous video feed 24/7 coverage of fixed locations; facial/plate ID. Building lobby camera (feeds live).
Audio Recorder Audio recordings Gunshot detection, voice identification, ambient noise Directed parabolic mic on street.
RF Spectrum Scanner Frequency-time logs Detect hidden transmitters (bugs, drones, comms). Portable spectrum analyzer (detects spike).
Infrared/Thermal Heat/IR images Night surveillance, body heat signature detection. NIR camera on sidewalk at night.
GPS Tracker Position/time logs Unobtrusive tracking of vehicle movements (if attached legally). ILLEGAL if unauthorized.
Anomaly Indicator Modality Possible Meaning
Flash of light Visual Muzzle flash (weapon discharge) or camera strobe.
Radio static burst Acoustic/RF Encrypted comm. transmission or jamming signal.
Repeated gesture Behavioral Covert signaling between operatives (e.g. a nod or hand-wave code).
Unscheduled vehicle Observational Unknown car lingering (potential surveillance or rendezvous).
Device alert sound Electronic Remote activation (beeper), phone ping, or sensor trigger.

Visualization Aids

Using Mermaid syntax we can diagram the surveillance timeline and relationships. These visuals help summarize the log flow and entity roles:

timeline
    title 72-Hour Surveillance Timeline
    section July 17, 2026
      00:00 : Surveillance begins (team deployed)
      03:15 : RF static burst detected (anomaly)
      10:15 : Camera shutter sound inside van (anomaly)
      15:45 : Pedestrian signals tapping (possible covert sign)
      21:15 : Metal glint on target (possible hidden weapon)
      23:59 : Day 1 debrief
    section July 18, 2026
      07:00 : Target’s eye-contact handshake (possible signal)
      13:15 : Encrypted RF transmission spotted (anomaly)
      19:45 : Target meets unknown courier
      22:00 : Stealth surveillance vehicle leaves area
    section July 19, 2026
      03:30 : Suspicious van tails target (anomaly)
      08:00 : Security drone observed (routine)
      15:00 : Tram ride encounter (suspected trackers)
      18:30 : Radio comm jamming (anomaly)
      23:00 : Log ends (target still observed)
erDiagram
    SURVEILLANCE_TEAM ||--o{ VEHICLE : uses
    VEHICLE ||--|| CAMERA   : carries
    SURVEILLANCE_TEAM ||--o{ SENSOR : deploys
    SENSOR ||--|| SPECTRUM   : scans
    SURVEILLANCE_TEAM ||--|| TARGET_ASSET : observes
    TARGET_ASSET ||--o{ GUARD  : guarded_by
    SURVEILLANCE_TEAM ||--o{ CCTV    : monitors
    SURVEILLANCE_TEAM ||--o{ ANOMALY : detects

The timeline chart above outlines key events each day (with “section” grouping by date). The entity relationship diagram shows how surveillance team members, vehicles, cameras, sensors, and anomalies interconnect (e.g. vehicles carry cameras, sensors scan spectrum, anomalies occur in environment, etc.).

These charts complement the narrative log by visualizing the sequence of events and the assets involved. For example, a data chart (not shown) could plot hourly Foot Traffic (blue line) against Anomaly Count (red bars) to see if unusual events cluster at certain times (rush hours, shift changes, etc.). In practice, logs and charts together help analysts spot correlations (e.g. more anomalies when sensor readings spike) and adjust tactics.

Connected tools and standards

Explore the wider AI ecosystem.