This lab uses public incident reporting and sanitized synthetic artifacts for defensive OSINT training. Real incidents are referenced for educational context only. The interactive data is fictionalized and must not be used to identify, contact, expose, or accuse real people.
The Shadow Brief
Separate an early technical cluster from a later copycat without trying to identify a real operator.
Synthetic training evidence that stays internally consistent. Check the repository history, the timestamps, the hashes and the agreement between sources. Never extend the scenario to real people or infrastructure.
01Incident summary
The low-visibility posts hold two very different things. One is an early technical observation you can timestamp and corroborate. The other is a later accusation that copies the same wording after the evidence went public. Similar language does not prove common control. Timing, unique access, attachment provenance and attribution behavior carry more weight.
02Analyst mission
Cluster the preserved posts. Pick out the primary technical cluster. Explain why the copycat is separate. Stop before you attribute anything to a real person.
03Review the evidence
Evidence route
Open the public repository and preserve these records before you draw a conclusion.
| Indicator Type | Evidence path | Analytical Context |
|---|---|---|
| Public post archive | evidence/act-2/shadow-intel/public-posts.jsonl | Compare account age, post time, wording and attachment hashes. |
| Cluster worksheet | evidence/act-2/shadow-intel/cluster-assessment.csv | Test technical continuity and attribution behavior. |
This table shows file paths and Git refs in the public evidence repository. None is a live scanning target.
04Tasks
4 steps- 01
Build a timeline from the account first-seen dates and the post timestamps.
- 02
Compare unique technical detail against detail copied from public reporting.
- 03
Say why writing-style similarity is weak identity evidence.
- 04
Name the primary technical cluster without naming a person.
05Log your findings
Evidence Notebook
Use this panel to log individual threads of evidence. Your entries are saved locally in this browser only.
No evidence records logged yet.
06Write the report
Report Drafting Board
# CSINT Incident Lab Report ## Research Question Cluster the preserved posts. Pick out the primary technical cluster. Explain why the copycat is separate. Stop before you attribute anything to a real person. ## Summary No analyst summary provided yet. ## Fact - No forensic facts recorded in the notebook. ## Signal - No analytical signals logged. ## Inference - No alternative explanations recorded. ## Recommendation - No next-pivot recommendations recorded. ## Confidence Low ## Limitations No limitation notes entered. ## Source reliability Not assessed. Annotate each source with its reliability tier before publishing. ## Information validity Not assessed. Confirm whether each item is directly observed, reported, or inferred. ## Missing context Not recorded. List what data is missing or could not be verified from public sources. ## Next safe steps - No next safe steps specified. ## Sources used - No source references listed. --- Generated at: pending

