Disclaimer

This lab uses public incident reporting and sanitized synthetic artifacts for defensive OSINT training. Real incidents are referenced for educational context only. The interactive data is fictionalized and must not be used to identify, contact, expose, or accuse real people.

GH 04Web InfrastructureACT 1 · STAGE 04 / 12

Eleven Minutes on the Mirror

Measure the real exposure window by lining the DNS collectors up against the isolated redirect captures.

Difficulty: Intermediate35 mins140 ptsBadge: Window Builder
Source Assessment

Synthetic training evidence that stays internally consistent. Check the repository history, the timestamps, the hashes and the agreement between sources. Never extend the scenario to real people or infrastructure.

Last Audited:2026-07-29

01Incident summary

The first responder called the mirror change 'about ten minutes'. That is too loose for a report you have to defend. Two passive collectors and three replay captures give you boundary observations. They don't prove what every client saw. They do let you state a supported earliest and latest point, and they let you name the reserved address that served the other package.

02Analyst mission

Work out the bounded DNS exposure window. Find the alternate documentation address. Keep the DNS state separate from the redirect target and the package digest.

03Review the evidence

Evidence Console#01 / 02

Evidence route

Open the public repository and preserve these records before you draw a conclusion.

Indicator TypeEvidence pathAnalytical Context
DNS observationsevidence/act-1/dns/zone-observations.csvSet the first and last observed alternate answers.
Redirect capturesevidence/act-1/web/redirect-captures.jsonConnect the address window to release 0.8.4.

This table shows file paths and Git refs in the public evidence repository. None is a live scanning target.

04Tasks

4 steps
  1. 01

    Convert every relevant timestamp to UTC.

  2. 02

    Write the supported start and end observations, plus what the collection cannot cover.

  3. 03

    Name the alternate address and the package version reached inside the window.

  4. 04

    Build the flag from the duration in minutes and the IPv4 octets.

05Log your findings

Analyst Notebook

Evidence Notebook

Use this panel to log individual threads of evidence. Your entries are saved locally in this browser only.

No evidence records logged yet.

06Write the report

Report Desk

Report Drafting Board

REPORT PREVIEW
# CSINT Incident Lab Report

## Research Question
Work out the bounded DNS exposure window. Find the alternate documentation address. Keep the DNS state separate from the redirect target and the package digest.

## Summary
No analyst summary provided yet.

## Fact
- No forensic facts recorded in the notebook.

## Signal
- No analytical signals logged.

## Inference
- No alternative explanations recorded.

## Recommendation
- No next-pivot recommendations recorded.

## Confidence
Low

## Limitations
No limitation notes entered.

## Source reliability
Not assessed. Annotate each source with its reliability tier before publishing.

## Information validity
Not assessed. Confirm whether each item is directly observed, reported, or inferred.

## Missing context
Not recorded. List what data is missing or could not be verified from public sources.

## Next safe steps
- No next safe steps specified.

## Sources used
- No source references listed.

---
Generated at: pending