Back

Incident preservation and reporting

P13-L07 · P13 · P13-M02

Prepare a factual record without doxxing or accusations beyond evidence

HISTORICAL · needs_review

Prerequisites: P13-L06

Learning objectives

  • Prepare a factual record without doxxing or accusations beyond evidence
  • Prepare a preservation handoff from an actual historical public report without expanding its forensic or identity claims.

Why this matters

A useful incident record preserves what a source actually says and what has not been independently captured. Adding private identities or an invented package hash can destroy both scope and trust.

Explanation

HISTORICAL PROVENANCE WARNING: this lesson reuses the accepted frozen Ledger company-report package collected on 1 October 2026. It concerns a 20 December 2023 publication about a 14 December 2023 incident. It is selective attributed publication evidence, not an independently reconstructed chain incident, malware sample or package-byte archive.

A preservation handoff needs record identity, source URL, publication and event dates with precision, retrieval date, bounded wording or attributed paraphrase, extraction method, claim pointers and limitations. For each captured transaction, preserve the exact chain, transaction ID, block locator, source timestamp and retrieval source; an address remains an address, not a human identity. If native transactions or package artifacts were not captured, list those arrays as empty; do not substitute plausible hashes. A newly computed checksum of a saved report checks that file’s integrity, not the integrity of the historic malicious package.

Keep time-to-event mappings exactly as bounded. The accepted record groups several publication times and versions without assigning a one-to-one mapping. Its cache statement is company-reported; it does not measure every device’s exposure or a worldwide end time. Preserve relevant public locators and precise attribution without collecting private employee or contact data. A recipient should be able to reproduce the publication claim and see the missing forensic layers.

Key terms

Preservation handoff: versioned public-source record plus method and limitations.

Selective extract: bounded statements rather than a full-byte archive.

Artifact hash: fingerprint of specific captured bytes; absent when bytes are absent.

Attribution: naming the source of a reported claim.

Historical example

Historical accepted record LR01 preserves report date 2023-12-20 and company-reported incident date 2023-12-14. LR02 groups CET times 09:49 / 10:44 / 11:37 with affected versions 1.1.5 / 1.1.6 / 1.1.7 without independently mapping each pair. LR03 retains reported awareness and alert/fix context; LR04 retains reported CDN propagation delay. The frozen package has no independent blockchain records, forensic artifacts, package artifacts, wallet identities or transactions.

Visual specifications

Historical preservation evidence panel with LR01–LR04, source/date/method/claim-boundary columns and empty artifact layer boxes. Distinguish report-file integrity from uncaptured package hash.

Caption: Historical Ledger-reported publication preservation; independent forensics and user exposure are not established.

SPECIFICATION_ONLY — the rendered visual has not been produced or independently reviewed.

What the evidence proves

OBSERVED: the accepted saved selective record and its public-source attribution. It records what Ledger reported about the historical incident at the stated publication boundary.

What the evidence does not prove

It establishes no independently measured global cache state, exact last-serving time, learner exposure, package hash, attacker identity, independent loss or chain reconstruction. Underlying events remain Ledger-reported.

Common mistakes

Inventing package hashes from version labels; assigning exact time/version pairs not preserved; deriving every user’s exposure from a company timeline; adding personal identities to make a report feel complete.

Practical exercise

Draft a five-field preservation handoff and a missing-artifact register. Reject the sentence “independent forensics verified the malicious package and all affected users.” State the record’s original retrieval time basis.

Show worked correction

Handoff: Ledger source URL; publication 2023-12-20 and company-reported incident 2023-12-14; original retrieval 2026-10-01 at day precision; selective paraphrases LR01–LR04 with pointers; publication-only boundary. Missing: native chain records, actual package bytes/hashes, device exposure and human identity. Revised statement: “The frozen public-source package preserves attributed Ledger report statements; independent package forensics and user exposure are not established.” A checksum of this handoff may preserve its integrity but must not be labelled a malware-package hash. No private identity collection is needed.

Checklist

  • Preserve exact public source and record pointers.
  • Separate event/publication/retrieval dates.
  • Label absent native/artifact evidence explicitly.
  • Avoid private identity and unverified exposure claims.

Summary

Preservation is strongest when missing artifacts and attribution survive the handoff rather than being filled with plausible details.

Summary

  • A report checksum is not a malicious-package checksum.
  • Selective publication evidence stays attributed.
  • Public factual reporting does not require doxxing.

Next lesson

P13-L08

Tools

Use the named ZECOIN tool only as an evidence-reading context. This lesson creates no tool output, account session or entitlement. Offline exercise; do not sign, deploy, approve or fund anything.

Sources & claim boundaries

  • LEDGER: Ledger official Security Incident Report — Accepted selective publication records LR01–LR04; reported dates / timeline / cache context remain attributed. Boundary: Accepted frozen selective paraphrases, no byte-identical archive, independent chain reconstruction, package-hash verification or human attribution.

Evidence classifications

HISTORICAL — event dates and retrieval dates are separate. See frozen package and collection gaps.

Observation date

2026-10-01 (original retrieval date at day precision; not event time)

Content version

1

Review date

null

Review status

needs_review

Visual specifications

P13-L07-V01

SPECIFICATION_ONLY · HISTORICAL

Prepare a factual record without doxxing or accusations beyond evidence

Historical Ledger-reported publication preservation; independent forensics and user exposure are not established.

Historical preservation evidence panel with LR01–LR04, source/date/method/claim-boundary columns and empty artifact layer boxes. Distinguish report-file integrity from uncaptured package hash.

Historical preservation evidence panel with LR01–LR04, source/date/method/claim-boundary columns and empty artifact layer boxes. Distinguish report-file integrity from uncaptured package hash.

Stack observations, assumptions, gaps and conclusion at 390 px; retain full IDs and a complete text equivalent. Any wide table scrolls locally.

Prose may follow RTL; IDs, quantities and time axes remain LTR. Preserve dependency direction.

P03-L07-LEDGER-REPORT-20231220-v1

Sources & claim boundaries

LEDGER · OFFICIAL_COMPANY_REPORT

Ledger official Security Incident Report

Supported claim
Accepted selective publication records LR01–LR04; reported dates / timeline / cache context remain attributed.
Verification boundary
Accepted frozen selective paraphrases, no byte-identical archive, independent chain reconstruction, package-hash verification or human attribution.
Checked at
2026-10-02
Open primary source
https://www.ledger.com/blog/security-incident-report

Dataset provenance

id: P03-L07-LEDGER-REPORT-20231220-v1

dataStatus: HISTORICAL

observedAt: 2026-10-01

timeBasis: Original accepted retrieval day;2023 event/report dates separate

source: content/academy-2/datasets/p03-l07/dataset.json

scope: Reuse accepted Ledger publication-only record; no new incident forensics or private identities.

Test your reasoning

P13-L07-Q1 · Which historical bytes can this package independently hash?
P13-L07-Q2 · Can LR02 assign 09:49 to version 1.1.5 as independent fact?
P13-L07-Q3 · What retrieval time basis travels with the reused package?
P13-L07-Q4 · What should an absent native-transaction collection contain?
P13-L07-Q5 · Does LR04 prove every device was clean at an exact time?