This lab uses public incident reporting and sanitized synthetic artifacts for defensive OSINT training. Real incidents are referenced for educational context only. The interactive data is fictionalized and must not be used to identify, contact, expose, or accuse real people.
Three Sources, One Cabinet
Assess three fictional sources without mixing up trust in a source with trust in a claim.
Synthetic training evidence that stays internally consistent. Check the repository history, the timestamps, the hashes and the agreement between sources. Never extend the scenario to real people or infrastructure.
01Incident summary
One source saw clothing but no face. One had proper access to a maintenance register but was not watching the location the whole time. One repeated a public accusation and offered nothing you can test. The stage is not about picking the most confident voice. It is about access, reporting history, corroboration, contradiction and source protection.
02Analyst mission
Grade each source and each claim on its own. Find the source report with the best corroboration. Keep the limitation that a technical record is not continuous physical observation.
03Review the evidence
Evidence route
Open the public repository and preserve these records before you draw a conclusion.
| Indicator Type | Evidence path | Analytical Context |
|---|---|---|
| Source summaries | evidence/act-2/humint/source-handling.md | Apply the stated reliability and credibility scale the same way each time. |
| Cabinet service export | evidence/act-2/humint/cabinet-service-export.csv | Test the claims against an independent technical record. |
This table shows file paths and Git refs in the public evidence repository. None is a live scanning target.
04Tasks
4 steps- 01
Grade source reliability separately from information credibility.
- 02
Note each source's access, motive, corroboration and contradiction.
- 03
Say which report holds up best without spelling out role details you do not need.
- 04
Write one limitation that keeps you from overclaiming.
05Log your findings
Evidence Notebook
Use this panel to log individual threads of evidence. Your entries are saved locally in this browser only.
No evidence records logged yet.
06Write the report
Report Drafting Board
# CSINT Incident Lab Report ## Research Question Grade each source and each claim on its own. Find the source report with the best corroboration. Keep the limitation that a technical record is not continuous physical observation. ## Summary No analyst summary provided yet. ## Fact - No forensic facts recorded in the notebook. ## Signal - No analytical signals logged. ## Inference - No alternative explanations recorded. ## Recommendation - No next-pivot recommendations recorded. ## Confidence Low ## Limitations No limitation notes entered. ## Source reliability Not assessed. Annotate each source with its reliability tier before publishing. ## Information validity Not assessed. Confirm whether each item is directly observed, reported, or inferred. ## Missing context Not recorded. List what data is missing or could not be verified from public sources. ## Next safe steps - No next safe steps specified. ## Sources used - No source references listed. --- Generated at: pending

