Corvus
RED × BLUE

Threat Playbook

Adversary vectors paired with the defensive controls that close them. Read top-to-bottom — engagements are sorted by severity. Baseline controls below apply across the surface.

0
Severe
3
Moderate
0
Low
2
Baseline

Moderate · Plan Mitigation

3 engagements

Baseline · Surface-Wide

2 controls
B-04 Baseline

Digital case-artifact chain-of-custody — fix the 2012 GIMP gap

The Charley Project panoramic (ent_020) carries a 2012-07-16 GIMP modification timestamp with no documented chain-of-custody between the 2007 kiosk digitization and the 2017 Charley Project upload. Baseline control: BCA / GINA / Charley Project should preserve and document the original 2007 digitization masters (and any 2012 derivative source) with hash-anchored archival, so subsequent re-uses can be authenticated against the master rather than against re-encoded derivatives.

B-05 Baseline

Periodic reverse-image sweep of the 2007 corpus

Quarterly automated reverse-image searches (Google Lens exact_matches has proven most productive for this corpus; Google Reverse Image returned zero on multiple URLs per ev_010 and ev_011) detect new appearances of the case imagery on tip-aggregator pages, fundraising pages, or impersonation accounts. The 2026-04 Medium article and the 2026 PSPTips reward post both surfaced this way; the next surfaces will surface the same way.