How the Everywhere War Tracker Categorises Incidents?
The Everywhere War Tracker focuses on the operationally observable dimensions of Russia’s sub-threshold warfare across the air, maritime, land, cyber and space domains. The cognitive domain is currently excluded because information and messaging effects cross borders and are difficult to pin to a specific location on the map.
Two things make categorisation hard. First, sub-threshold activity is designed to be deniable, so attribution is often unclear — and sometimes governments have political reasons not to name Russia even when they suspect it. Second, some incidents could reasonably fit more than one category. We therefore classify them according to the main action and security effect, rather than simply where they originated.
This page explains the logic we use, so readers know what to expect in each category and why.
The Five Domains and Beyond
Incidents are organised primarily according to a domain-based logic—Air, Maritime, Land, Cyber, and Space—with corresponding subcategories. To capture the full range of hostile activity, the framework also includes additional categories for incidents that cut across domains or fall outside a strictly domain-based structure like Electromagnetic Warfare (EW) or Potential Military Threats.
Airspace covers incursions or dangerous activity involving aircraft, drones and missiles. These are separated as subcategories because they pose different risks and require different responses. A drone launched from a ship but entering national airspace is classified as Airspace – Drone: the launch platform is maritime, but the violation occurs in the air.
Maritime covers suspicious or hostile activity at sea involving warships, submarines, shadow-fleet vessels and other commercial ships. Damage to undersea cables or pipelines is classified as Sabotage, because the main event is physical damage to infrastructure.
Cyber, Space, and Electromagnetic Warfare remain separate categories but are grouped together as a broader set both for visual clarity and because modern digital, satellite, and electronic systems are closely interconnected.
Given hundreds or even thousands of cyberattacks occurring each month, comprehensive tracking is not feasible. The Tracker therefore includes only significant incidents—those that caused, or had the potential to cause, distinct and harmful consequences.
Jamming and spoofing are classified here, not under Airspace, because the mechanism is interference with signals and data rather than violation of airspace. Jamming blocks a genuine signal; spoofing replaces it with false information. Tracking every incident in this category is impossible, as such activity has become a persistent feature of the (in)security environment and some states no longer record or publicly report each individual occurrence.
Though Cyber and EW remain distinct operational disciplines, they are often grouped together in Cyber and Electromagnetic Activities (CEMA) frameworks, including in NATO-related operational analysis and broader defence and security research.
Space-related incidents also remain within this group for now, as they are too limited in number, and most involve the disruption of satellite communications, navigation, or data rather than kinetic attacks on satellites—an option Russian military thinking increasingly discusses as a future prospect.
Land, however, doesn’t get its own bucket of incident types the way the others do — instead, land-based activity is captured through two categories that run across all domains: Sabotage and Potential Military Threats.
Sabotage covers deliberate or attempted physical attacks and is divided by target not domain:
Keeping sabotage together allows us to compare physical attacks across different domains rather than fragmenting them.
Potential Military Threats is a specific category, which covers activity that falls short of attack but may indicate preparation for force, military pressure or coercive signalling. This includes relevant military exercises, troop movements, new bases, weapons deployments and nuclear-related activity. We include only exercises that rehearse operations against Europe or form part of political-military pressure.
This category also includes weaponised migration: deliberate state-organised or state-facilitated movement of people toward another country’s border to exert political or security pressure.
Geography
The Tracker focuses on most European countries together with the United States and Canada, which Russian official discourse commonly portrays as part of the hostile “collective West.” Ukraine is not included, as Russia’s aggression against it has remained in the realm of open warfare since 2014 rather than sub-threshold confrontation.
Filters
Both the interactive map and the analytical graph-building tool allow users to trace trends by country, category or subcategory, time period, and attribution, enabling patterns in hostile activity to be explored across multiple dimensions.
While the Tracker initially prioritises officially attributed cases, this approach presents a trade-off: it strengthens the reliability of the dataset but also understates the likely scale of Russian sub-threshold activity. To address this dilemma, incidents within each subcategory are divided into two groups: officially attributed to Russian operations by government officials or intelligence agencies, marked in red, and those fitting the pattern of Russian activity but have not been formally attributed, marked in orange. This distinction allows researchers to choose whether to work only with confirmed cases or to include a broader set of incidents consistent with the established pattern.
Limitations
The Tracker does not attempt to cover every form of Russian hostile activity. Cognitive operations, interference in elections, lobbying, and traditional intelligence operations require different methodologies.
Update Schedule
The Tracker is updated twice a month, with major revisions and additions incorporated at the end of each month. Given that attribution can emerge weeks or even years after an incident, the Tracker is retrospectively updated as soon as credible attribution statements become available. Incidents initially classified as fitting the pattern are moved to officially attributed if they are subsequently officially attributed.