Lab 02 · evidence graph
Pivot without losing provenance.
This viewer reconstructs one published investigation as a graph. Click a node to see whether it is an observed artefact, a derived count or an analytical assessment—and what supports it.
Case boundary. The graph demonstrates investigative structure, not a live scanning system. Host counts refer to passive urlscan observations in the published research bundle. A page hostname is an observation context, not proof that its operator knowingly participated.
Reading order
Object → observation → assessment
observed
Exact objects
Captured script, response SHA-256 values and passive scan rows are facts recoverable from the cited material.
derived
Reproducible counts
Unique host counts are derived from released CSV rows. They can be independently recomputed.
assessed
Bounded conclusion
Functioning replacement capability is supported by code and validation. Successful theft or a named operator is not proven.