← All mission packs

MISSION PACK / SUPPORT INVESTIGATION

Evidence Before Action

Find the signal. Preserve the evidence. Verify what happens next.

BeginnerAbout 35 minutes4 missionsPack 1.0.0

Author: GhostFrame · Requires GhostFrame 1.0.11 or later

Evidence comes first.

Practise a complete support investigation using synthetic files inside GhostFrame. Create a small log, preserve its relevant event, write a support report, restrict access to its owner, and prepare a verified handoff. No external lab, credentials, or real network access is needed.

  1. Find the Signal
    Identify relevant evidence in a synthetic log.
  2. Write a Support Report
    Preserve the observation in a concise report.
  3. Protect the Report
    Practice restricting access to the report's owner.
  4. Verify the Handoff
    Check the saved evidence and prepare a verified handoff.

Lessons follow this sequence through their prerequisites. Work through each briefing and use the mission's objective state to check your progress.

Before you begin

This pack requires GhostFrame 1.0.11 or later with virtual-home files, file-content checks, file-permission checks, and shell-command evidence support. It uses synthetic learner-home files and needs no separate lab, account credentials, or real network target.

Pause or finish any active mission before installing. Keep existing exercise files safe before following instructions that write files in the pack's working folder.

The file below is a mission pack, not a GhostFrame application installer. Earlier application builds may refuse it.

VERSION 1.0.0

Bring the investigation
into GhostFrame.

Download mission pack

JSON mission pack · 16,948 bytes · Schema version 1

SHA-256

905c6ee468f9a9ed7888673e49d316a24c796a6da9ac46129340d3d0bdd12851

The app compares catalog size and hash when downloading. A hash checks that bytes match; it does not establish author identity. Review the author and instructions before installation.

Check a downloaded file's hash

On Windows, use PowerShell's Get-FileHash with -Algorithm SHA256 on the downloaded file and compare the result with the value above. This checks the downloaded file; lesson commands belong inside GhostFrame.

Review before you install.

  1. In GhostDesk, open Mission packs and choose Refresh catalog.
  2. Select Evidence Before Action, then Download/review.
  3. Review its content and requirements, then choose Install reviewed pack.
  4. Select the first refreshed ticket, Find the Signal, and follow its briefing.

Alternatively, download the JSON file above, choose Import local file in Mission packs, and review it before installing.

Mission completion checks the authored simulated outcomes. It does not prove that a real incident has been resolved.