Skip to main content
 

Forensic Intelligence: Turning Fragments into Foresight

Richard Jonathan O. Taduran, Ph.D.  |  28 August 2025


When an improvised explosive device detonates, most people see wreckage: twisted metal, scorched soil, a crater in the ground. A forensic eye reads something else. Fragments, residues, and prints are not debris; they are starting points for strategy.


In today’s world, security threats no longer fit neatly into the categories of land or sea, rifles or missiles. Hybrid adversaries operate simultaneously in jungles and in chat rooms, with roadside bombs on one hand and propaganda memes on the other. In such a landscape, evidence is not just for prosecutors. It is for strategists, commanders, and policymakers who must see beyond the blast site to the networks that sustain violence.


Traditionally, forensics has been associated with courtroom justice — fingerprints, DNA, or ballistics used to prove guilt beyond reasonable doubt. Forensic intelligence takes those same methods but redirects them into operational strategy. Its three pillars are simple but powerful: evidence-based reasoning, pattern recognition, and the linking of micro-traces to macro-networks.


Instead of waiting for trials, forensic intelligence allows security forces to treat each recovered trace as a data point in an unfolding map of threats. A fragment of wire might connect to a known bomb-maker’s style; a DNA swab could tie one attack to a series of others; a metadata trail in a social media post might expose the location of an insurgent cell. The mindset is not retrospective but anticipatory.


The Philippine Experience


The Philippines has seen both the promise and the gaps of forensic intelligence. After the 2019 Jolo Cathedral bombing, DNA analysis identified the attackers as an Indonesian couple, confirming cross-border jihadist networks long suspected in the region. In a separate case months later, DNA testing in Indanan, Sulu, confirmed that the bomber was female. These breakthroughs were possible because of forensic science, not battlefield firepower.


Explosives carry signatures, too. The improvised explosive device used in the 2016 Davao night market bombing bore features consistent with older devices previously seen in Mindanao, suggesting common training or supply channels. Weeks later, investigators described the device planted near the U.S. Embassy in Manila as similar to the Davao bomb, pointing to recurring techniques among local bomb-makers. Such patterns demonstrate how explosives themselves can carry forensic “fingerprints” that link incidents across time.


The Marawi Siege (2017) underscored the digital front. Militants fought street to street but also online — recruiting, boosting morale, and shaping perception. Those posts, videos, and chats left traces that analysts could later piece together. The lesson is clear: the battlefield is physical, digital, and cultural at once. Unless institutions can integrate evidence across these layers, opportunities to disrupt networks are missed.


International Lessons


Elsewhere, forensic intelligence is already standard practice. In Iraq and Afghanistan, where I have been part of forensic missions, coalition forces pioneered Weapons Technical Intelligence (WTI), treating every IED as a forensic puzzle. Fragments from blast sites were catalogued at the U.S. Terrorist Explosive Device Analytical Center (TEDAC). Over time, patterns emerged: bomb-makers could be identified across provinces, and procurement chains could be mapped. Science turned fragments into a logistics picture.


Other cases show how diverse traces converge. The Salisbury poisonings (2018) were resolved not by a single dramatic clue but by layering chemical analysis with CCTV and travel records. The MH17 shoot-down (2014) combined missile-fragment forensics with open-source geolocation of a launcher’s route. In each instance, micro-evidence was linked to geopolitical accountability.


Digital trails can be just as revealing. In 2015, U.S. forces struck an ISIS command post after militants revealed its location in a seemingly routine social-media post. In 2021, Operation Trojan Shield saw law enforcement run an encrypted messaging app (ANOM), intercepting tens of millions of messages and enabling coordinated arrests around the world.


Even the information space is now approached forensically. In 2022, the European Union adopted a framework on Foreign Information Manipulation and Interference (FIMI), describing disinformation artifacts — posts, videos, URLs — as “observables” for structured analysis. The lesson: in an era of deepfakes and fake news, truth itself has become an evidence chain to defend.


The Officer’s Mindset


The unifying principle is simple: details are strategy. A DNA profile, a wiring diagram, a timestamp in a photo — each is a fragment that, when contextualized, can illuminate networks, reveal supply chains, or prevent the next attack. Forensic intelligence thrives at the convergence of science and security.


For the next generation of AFP officers, the challenge is not only courage under fire but also cultivating a forensic mindset — one that is evidence-based, pattern-oriented, and clear-eyed. The Jolo DNA matches, the Davao device signatures, and the Marawi digital traces point to the same lesson: train not only for combat but also for cognition. Learn to see how a small trace connects to a larger map, how a local incident may be linked to wider networks and narratives.


When we speak of national defense, we often picture borders and rifles. But in the 21st century, what we must also secure are traces — the tiny, often invisible signatures that adversaries leave behind. These fragments are not just for the courtroom. They are the raw material of foresight.


In a world where bombs, propaganda, and cyberattacks converge, the true officer must be more than a fighter — they must also think as an analyst, plan as a strategist, and lead with foresight.

 

More The Forensic Lens