Disclaimer

This lab uses public incident reporting and sanitized synthetic artifacts for defensive OSINT training. Real incidents are referenced for educational context only. The interactive data is fictionalized and must not be used to identify, contact, expose, or accuse real people.

GH 08Identity CorrelationACT 3 · STAGE 08 / 12

The Innocent Maintainer

Test a public accusation against account, badge, camera and service records without claiming an alibi you can't prove.

Difficulty: Advanced55 mins180 ptsBadge: Attribution Brake
Source Assessment

Synthetic training evidence that stays internally consistent. Check the repository history, the timestamps, the hashes and the agreement between sources. Never extend the scenario to real people or infrastructure.

Last Audited:2026-07-29

01Incident summary

The loudest version of the story says a maintainer changed the map in person. The evidence cannot place anyone somewhere for every minute of the night. It can test a narrower question. Which identity started the publication workflow? Keeping those two apart protects the analysis and the fictional person at the same time.

02Analyst mission

Find the publishing actor. Record the evidence that weakens the named-account allegation. Then say what those negative findings do not prove.

03Review the evidence

Evidence Console#01 / 02

Evidence route

Open the public repository and preserve these records before you draw a conclusion.

Indicator TypeEvidence pathAnalytical Context
Service-account auditevidence/act-3/logs/service-account-audit.jsonlResolve the actor, the session, the ref and the publication time.
Maintainer account reviewevidence/act-3/logs/maintainer-account-review.jsonTest the specific account allegation and keep the limitations visible.

This table shows file paths and Git refs in the public evidence repository. None is a live scanning target.

04Tasks

4 steps
  1. 01

    Keep person, user account, service identity, session and source address apart.

  2. 02

    Link the publish event to its actor and session.

  3. 03

    List the negative findings that weaken the maintainer-account claim.

  4. 04

    Explain why those findings say nothing about physical location or intent.

05Log your findings

Analyst Notebook

Evidence Notebook

Use this panel to log individual threads of evidence. Your entries are saved locally in this browser only.

No evidence records logged yet.

06Write the report

Report Desk

Report Drafting Board

REPORT PREVIEW
# CSINT Incident Lab Report

## Research Question
Find the publishing actor. Record the evidence that weakens the named-account allegation. Then say what those negative findings do not prove.

## Summary
No analyst summary provided yet.

## Fact
- No forensic facts recorded in the notebook.

## Signal
- No analytical signals logged.

## Inference
- No alternative explanations recorded.

## Recommendation
- No next-pivot recommendations recorded.

## Confidence
Low

## Limitations
No limitation notes entered.

## Source reliability
Not assessed. Annotate each source with its reliability tier before publishing.

## Information validity
Not assessed. Confirm whether each item is directly observed, reported, or inferred.

## Missing context
Not recorded. List what data is missing or could not be verified from public sources.

## Next safe steps
- No next safe steps specified.

## Sources used
- No source references listed.

---
Generated at: pending