This lab uses public incident reporting and sanitized synthetic artifacts for defensive OSINT training. Real incidents are referenced for educational context only. The interactive data is fictionalized and must not be used to identify, contact, expose, or accuse real people.
The Glass Harbor Board
Deliver the final timeline, the scope, the attribution boundary, the containment plan and what stays uncertain.
Synthetic training evidence that stays internally consistent. Check the repository history, the timestamps, the hashes and the agreement between sources. Never extend the scenario to real people or infrastructure.
01Incident summary
The board does not want a detective story. It needs an assessment it can act on. Say what changed and how the trusted publication path was misused. Explain why the public accusation does not hold. Set out what is known about exposure. List the controls that have to change before service comes back. Every judgment that matters points back to preserved evidence.
02Analyst mission
Produce a short executive summary and a UTC timeline. Separate affected scope from unproven scope. Give the most likely root condition and the alternatives. Close with immediate containment, recovery gates and collection gaps.
03Review the evidence
Evidence route
Open the public repository and preserve these records before you draw a conclusion.
| Indicator Type | Evidence path | Analytical Context |
|---|---|---|
| Executive questions | evidence/act-4/executive-questions.md | Make sure the final report answers the operational decisions. |
| Custody and containment | evidence/act-4/chain-of-custody.csv | Tie the conclusions to preserved items and prioritized controls. |
This table shows file paths and Git refs in the public evidence repository. None is a live scanning target.
04Tasks
6 steps- 01
Write an executive summary with the judgment, the confidence and the business impact.
- 02
Build a UTC timeline that keeps observed events apart from inferred causality.
- 03
State what was affected, what was not affected on current evidence and what is unknown.
- 04
Prioritize containment and set recovery gates that rest on evidence.
- 05
Correct the unsupported personal accusation without making a new attribution.
- 06
Record the final root condition in the required normalized form.
05Log your findings
Evidence Notebook
Use this panel to log individual threads of evidence. Your entries are saved locally in this browser only.
No evidence records logged yet.
06Write the report
Report Drafting Board
# CSINT Incident Lab Report ## Research Question Produce a short executive summary and a UTC timeline. Separate affected scope from unproven scope. Give the most likely root condition and the alternatives. Close with immediate containment, recovery gates and collection gaps. ## Summary No analyst summary provided yet. ## Fact - No forensic facts recorded in the notebook. ## Signal - No analytical signals logged. ## Inference - No alternative explanations recorded. ## Recommendation - No next-pivot recommendations recorded. ## Confidence Low ## Limitations No limitation notes entered. ## Source reliability Not assessed. Annotate each source with its reliability tier before publishing. ## Information validity Not assessed. Confirm whether each item is directly observed, reported, or inferred. ## Missing context Not recorded. List what data is missing or could not be verified from public sources. ## Next safe steps - No next safe steps specified. ## Sources used - No source references listed. --- Generated at: pending

