WorkspaceOperation desk
Analyst orderGH-26-07
ProgressSaved on this device
ValidationServer-side
← Incident Lab

Fictional defensive campaign · 12 stages · 4 acts

Operation Glass Harbor

A wrong mirror, a normal automation identity and a mismatched package record meet in the same incident window. Join mail, Git, TLS, DNS, visual, HUMINT and telemetry evidence into one technical timeline.

12linked stages
31evidence files
2,080base points
Ingest
Mail · Git · TLS · DNS
Correlate
Visual · HUMINT · shadow records
Deliver
Timeline · hypotheses · controls
Live evidence viewnorth-pier-frame-183.png
Fictional North Pier N-7 CCTV evidence frame
FRAME 183 · GH-NP-07Open GH 05

Running systems

Automation and validation layer

Ready
  1. 01

    Evidence workspace

    Loads the case files and keeps source paths visible.

    Active
  2. 02

    Local progress

    Keeps stage and notebook progress on this device.

    Active
  3. 03

    Evidence scoring

    Checks whether the minimum evidence record is ready.

    Active
  4. 04

    Server validation

    Checks flags with the server-side HMAC flow.

    Active
  5. 05

    Report output

    Builds a structured assessment from the analyst record.

    Active

Initial assessment

Incident triage

18 JUL 2026 · 04:17 UTC · GH-26-07

FACT

Observed signals

The mirror points to an unapproved address for eleven minutes. Release 0.8.4 has a branch and package digest that do not match the approval.

CLAIM

Unproven claim

The cropped CCTV frame shows North Pier but no face. The social post is an accusation, not identity evidence.

OUTPUT

Required output

An auditable incident report that explains the technical path, evidence limits and controls that must change before service resumes.

Campaign run

Easiest to hardest

ACT 1STAGE 01-04

Act I: First Light

Difficulty: Beginner

A believable handover message lands while the mirror briefly points somewhere it should not. Get the first technical facts down before the public narrative forms.

01 / 12GH 01

The 04:17 Handover

Follow a convincing handover message through its raw headers and find the point where trust breaks.

Header reconstruction

Email & Identity

Beginner · 20 mins100 pts
Not startedOpen
02 / 12GH 02

The Note That Isn't There

Pull a removed handover detail back out of repository history instead of searching only the current files.

Deleted Git history

Repository Forensics

Beginner · 20 mins100 pts
Not startedOpen
03 / 12GH 03

Certificate Drift

Tie a certificate observation to the mirror before the public DNS change shows up anywhere.

TLS and passive DNS correlation

Infrastructure OSINT

Beginner · 25 mins120 pts
Not startedOpen
04 / 12GH 04

Eleven Minutes on the Mirror

Measure the real exposure window by lining the DNS collectors up against the isolated redirect captures.

DNS and redirect timeline

Web Infrastructure

Intermediate · 35 mins140 pts
Not startedOpen

ACT 2STAGE 05-07

Act II: The Human Layer

Difficulty: Intermediate

A cropped image and three conflicting voices pull the review toward one person. Check the time and the place. Protect the sources. Keep early access apart from copycat noise.

05 / 12GH 05

Frame 183

Normalize one CCTV frame using what is visible in it, the camera inventory, the clock drift and the weather record.

Chronolocation and metadata

Visual Verification

Intermediate · 40 mins150 pts
Not startedOpen
06 / 12GH 06

Three Sources, One Cabinet

Assess three fictional sources without mixing up trust in a source with trust in a claim.

Source reliability grading

HUMINT Assessment

Intermediate · 45 mins160 pts
Not startedOpen
07 / 12GH 07

The Shadow Brief

Separate an early technical cluster from a later copycat without trying to identify a real operator.

Provenance-led clustering

Shadow Intelligence

Intermediate · 50 mins170 pts
Not startedOpen

ACT 3STAGE 08-10

Act III: The Build Room

Difficulty: Advanced

The normal automation identity publishes an abnormal artifact. Follow the sessions, refs, provenance, permissions and timing without treating a service account as a person.

08 / 12GH 08

The Innocent Maintainer

Test a public accusation against account, badge, camera and service records without claiming an alibi you can't prove.

Account and physical-evidence separation

Identity Correlation

Advanced · 55 mins180 pts
Not startedOpen
09 / 12GH 09

Trusted Build, Wrong Source

Compare approval, branch history, workflow permissions and provenance to find where the release source stops matching.

Workflow provenance

Software Supply Chain

Advanced · 60 mins200 pts
Not startedOpen
10 / 12GH 10

The Quiet Callback

Find the machine-like cadence in harmless synthetic telemetry and stop short of a malware or exfiltration claim.

Interval and limitation analysis

Network Telemetry

Advanced · 60 mins220 pts
Not startedOpen

ACT 4STAGE 11-12

Act IV: The Board

Difficulty: Advanced

Test the competing explanations. Define what the evidence supports and what it does not. Then deliver an incident assessment the board can act on.

11 / 12GH 11

Four Competing Stories

Test four explanations with inconsistency rather than by counting supporting evidence.

Analysis of competing hypotheses

Intelligence Assessment

Advanced · 75 mins240 pts
Not startedOpen
12 / 12GH 12

The Glass Harbor Board

Deliver the final timeline, the scope, the attribution boundary, the containment plan and what stays uncertain.

Evidence-led incident reporting

Final Synthesis

Advanced · 90 mins300 pts
Not startedOpen

The prompt is not the answer

Flags aren't stored in the public client. The later stages need full Git history, a deleted blob, a separate branch, a release tag, file hashes and agreement on timing across records. No honest CTF can promise that AI will never solve it. The goal here is narrower. A campaign you can't guess from the prompt and can only finish with real evidence work.

Open checksum manifest