Full Report
This is an experiment about artificial intelligence for intelligence. Sorry for the length, but I wanted to detail all the steps and results. You will find here not only this description, but also the real results (mainly, skills and final intelligence product). If you are interested only in the product, you can go to the […]
Analysis Summary
# Research: Cyber Morocco: A Quick and Dirty Experiment about AI for Cyber Intelligence
## Metadata
- **Authors:** Lab52 (Threat Intelligence Division of S2 Grupo)
- **Institution:** S2 Grupo
- **Publication:** Lab52 Blog
- **Date:** October 05, 2026
## Abstract
This research documents a practical "laboratory experiment" evaluating the efficacy of Large Language Models (LLMs)—specifically Claude 3.5 Sonnet—in executing the full intelligence cycle. The author attempts to generate a comprehensive strategic intelligence report on Morocco’s cyberspace activities and intelligence ecosystem using only Open Source Intelligence (OSINT) and AI-driven analysis skills.
## Research Objective
The experiment seeks to determine how effectively an AI "private intelligence partner" can analyze complex geopolitical information and generate high-quality intelligence products with minimal human expert intervention.
## Methodology
### Approach
The researcher employed an **"Agent-in-the-Loop"** iterative process, simulating the traditional intelligence cycle:
1. **Direction:** Defining the scope (Moroccan cyberspace and its relation to Spain).
2. **Collection & Processing:** Using AI to gather and translate OSINT from multilingual sources (Spanish, French, Arabic).
3. **Analysis:** Utilizing specialized AI "skills" (personas) to evaluate data.
4. **Production:** Generating a structured report based on a predefined skeleton.
### Dataset/Environment
- **Sources:** OSINT exclusively, including legal documents (Dahirs), official bulletins, UN/EU records, technical forensic reports, and mainstream media from Morocco, Spain, and Algeria.
- **Language Scope:** Trilingual (Spanish, French, Arabic) translated into English.
### Tools & Technologies
- **Primary LLM:** Claude 3.5 Sonnet (referred to as "Claude Code" environment).
- **Secondary LLMs:** Microsoft Copilot and ChatGPT (used for refining skills and the final product).
- **Architecture:** A modular "Skill" system where specific prompts define specialized roles (Geopolitical Analyst, Military Analyst, Cyber Intelligence Analyst, etc.).
## Key Findings
### Primary Results
1. **Viability of AI as a Strategic Partner:** The experiment demonstrated that AI can generate a structured, "aseptic" strategic report that serves as a high-quality baseline for human analysts.
2. **Modular Analysis Works:** Breaking the intelligence task into specific "skills" (Geopolitical, Military, Cyber, and Reviewer) allows for deeper analysis than a single generic prompt.
3. **Cross-Lingual Synthesis:** The AI successfully integrated and synthesized information across multiple languages to provide a regional perspective.
### Supporting Evidence
- The production of a final intelligence product (attached as a PDF) achieved in fewer than 10 iterative cycles.
- Successful implementation of a "Reviewer Skill" that identified gaps and improved the final document quality.
### Novel Contributions
- **Skill-Based Framework:** The release of specific prompt "skills" and a report "skeleton" that other analysts can reuse.
- **Automated Intelligence Cycle:** Demonstrating a semi-automated transition from raw OSINT to an ACM-formatted intelligence report.
## Technical Details
The researcher developed a structured **"Skeleton"** (a 13-section template) that the AI was required to follow. This ensured the output included critical intelligence components such as:
- **BLUF** (Bottom Line Up Front).
- **Confidence Levels:** Explicitly requiring the AI to use estimative probability language.
- **Structured Persona Engineering:** Defining roles like the "Geopolitical Analyst" to specifically look for "mirror imaging" and "confirmation bias."
## Practical Implications
### For Security Practitioners
- AI can be used to quickly pivot into unfamiliar geographic or political regions where the practitioner lacks local expertise or language skills.
### For Defenders
- Automated reporting can speed up the production of situational awareness briefings, allowing defenders to stay updated on regional threats (e.g., the Morocco-Algeria cyber confrontation) without manual monitoring.
### For Researchers
- The methodology suggests a move toward "AI-Augmented OSINT," where the focus shifts from data collection to the orchestration of specialized AI agents.
## Limitations
- **Verification:** The author admits to not being a Morocco expert, meaning the AI's accuracy was not fully validated by a subject matter expert (SME) before publication.
- **Surface Level:** The resulting report is "aseptic" and general; it avoided "thorny issues" like the Pegasus spyware controversy in the initial phase.
- **Data Freshness:** Reliance on the LLM’s training data and available OSINT may miss real-time covert developments.
## Comparison to Prior Work
Unlike traditional OSINT research which focuses on data scraping tools, this work emphasizes the **analytical phase** of the intelligence cycle, moving beyond "data gathering" to "intelligence production" using generative AI.
## Real-world Applications
- **Strategic Briefings:** Generating executive-level summaries of regional cyber threats.
- **Resource Scaling:** Allowing small intelligence teams to cover more geographic regions simultaneously.
## Future Work
- Deep dives into specific "thorny" topics: Pegasus/surveillance, Western Sahara as a cyber-intelligence theatre, and Morocco-Algeria cyber operations.
- Further testing of the "Agent-in-the-Loop" model to improve the accuracy of estimative probabilities.
## References
- Lab52 Original Report: `https[://]lab52[.]io/blog/cyber-morocco-a-quick-and-dirty-experiment-about-artificial-intelligence-for-cyber-intelligence/`
- Associated Skills/Skeletons provided by S2 Grupo.