Disclaimer

This lab uses public incident reporting and sanitized synthetic artifacts for defensive OSINT training. Real incidents are referenced for educational context only. The interactive data is fictionalized and must not be used to identify, contact, expose, or accuse real people.

GH 01Email & IdentityACT 1 · STAGE 01 / 12

The 04:17 Handover

Follow a convincing handover message through its raw headers and find the point where trust breaks.

Difficulty: Beginner20 mins100 ptsBadge: Relay Reader
Source Assessment

Synthetic training evidence that stays internally consistent. Check the repository history, the timestamps, the hashes and the agreement between sources. Never extend the scenario to real people or infrastructure.

Last Audited:2026-07-29

01Incident summary

The morning shift accepted the message because nothing about it looked odd. The display name, the subject and the send time all matched a routine map-desk handover. There is no malware in it and no attachment. The problem sits somewhere quieter. The identity you can see does not agree with the transport evidence. In this first stage you rebuild the mail path from the bottom up, without mistaking an internal relay for the sender.

02Analyst mission

Find the first untrusted public relay. Record the authentication result that most clearly contradicts the displayed sender. Then explain why the later internal hops do not replace that origin.

03Review the evidence

Evidence Console#01 / 02

Evidence route

Open the public repository and preserve these records before you draw a conclusion.

Indicator TypeEvidence pathAnalytical Context
Raw messageevidence/act-1/mail/dispatch-0417.emlRebuild the Received chain and read the Authentication-Results line.
Gateway exportevidence/act-1/mail/mail-gateway-export.csvCross-check the queue ID, the source address and how delivery was handled.

This table shows file paths and Git refs in the public evidence repository. None is a live scanning target.

04Tasks

4 steps
  1. 01

    Sort the Received headers from the origin side down to the final internal delivery.

  2. 02

    Tell the first external relay apart from the internal documentation-range hops.

  3. 03

    Note the SPF, DKIM and DMARC outcomes separately.

  4. 04

    Build the flag from the external IPv4 octets and the decisive authentication outcome.

05Log your findings

Analyst Notebook

Evidence Notebook

Use this panel to log individual threads of evidence. Your entries are saved locally in this browser only.

No evidence records logged yet.

06Write the report

Report Desk

Report Drafting Board

REPORT PREVIEW
# CSINT Incident Lab Report

## Research Question
Find the first untrusted public relay. Record the authentication result that most clearly contradicts the displayed sender. Then explain why the later internal hops do not replace that origin.

## Summary
No analyst summary provided yet.

## Fact
- No forensic facts recorded in the notebook.

## Signal
- No analytical signals logged.

## Inference
- No alternative explanations recorded.

## Recommendation
- No next-pivot recommendations recorded.

## Confidence
Low

## Limitations
No limitation notes entered.

## Source reliability
Not assessed. Annotate each source with its reliability tier before publishing.

## Information validity
Not assessed. Confirm whether each item is directly observed, reported, or inferred.

## Missing context
Not recorded. List what data is missing or could not be verified from public sources.

## Next safe steps
- No next safe steps specified.

## Sources used
- No source references listed.

---
Generated at: pending