{
  "schemaVersion": 1,
  "pack": {
    "id": "evidence-before-action",
    "version": "1.0.0",
    "title": "Evidence Before Action",
    "summary": "Four linked lessons in finding evidence, saving a report, least privilege, and verified handoff.",
    "description": "Practise a complete support investigation using synthetic files inside GhostFrame. Create a small log, preserve its relevant event, write a support report, restrict access to its owner, and prepare a verified handoff. No external lab, credentials, or real network access is needed.",
    "author": "GhostFrame",
    "estimatedMinutes": 35,
    "difficulty": "Beginner",
    "tags": [
      "evidence",
      "support",
      "least-privilege"
    ],
    "missionCount": 4,
    "minimumAppVersion": "1.0.11",
    "requiredCapabilities": [
      "virtual-home-files",
      "file-content",
      "file-permissions",
      "shell-command-evidence"
    ]
  },
  "missions": [
    {
      "schemaVersion": 1,
      "version": "1.0.0",
      "id": "pack.evidence-before-action.find-signal",
      "title": "Find the Signal",
      "description": "Evidence Before Action: Find the Signal.",
      "briefing": "Work only in your simulated exercise folder. Use a new disposable profile for this pack. In an existing profile, preserve any prior exercise folder and files before writing. All exercise data is synthetic. Run mkdir -p ~/mission-packs/evidence-before-action. Run echo \"INFO EBA ready\" > ~/mission-packs/evidence-before-action/events.log and echo \"ERROR EBA missing-listener\" >> ~/mission-packs/evidence-before-action/events.log. Run grep ERROR ~/mission-packs/evidence-before-action/events.log > ~/mission-packs/evidence-before-action/evidence.txt, then cat the saved evidence. Run submit CHECK to refresh state objectives.",
      "difficulty": "Beginner",
      "estimatedMinutes": 10,
      "labId": "",
      "category": "Evidence Before Action",
      "experienceReward": 75,
      "recommendedLevel": 0,
      "repeatable": false,
      "prerequisiteMissionIds": [],
      "storyArcId": "pack.evidence-before-action",
      "chapterId": "investigation",
      "sourceChannel": "GhostDesk",
      "tags": [
        "mission-pack",
        "evidence-before-action"
      ],
      "ticket": {
        "ticketId": "EBA-1001",
        "category": "Support Investigation",
        "priority": "Medium",
        "requester": "GhostFrame Training",
        "summary": "Find the Signal",
        "knownInfo": [
          "Synthetic learner-created fixtures; no real incident or host access."
        ],
        "requiredActions": [
          "Use a new disposable profile for this pack. In an existing profile, preserve any prior exercise folder and files before writing. All exercise data is synthetic.",
          "Run mkdir -p ~/mission-packs/evidence-before-action.",
          "Run echo \"INFO EBA ready\" > ~/mission-packs/evidence-before-action/events.log and echo \"ERROR EBA missing-listener\" >> ~/mission-packs/evidence-before-action/events.log.",
          "Run grep ERROR ~/mission-packs/evidence-before-action/events.log > ~/mission-packs/evidence-before-action/evidence.txt, then cat the saved evidence. Run submit CHECK to refresh state objectives."
        ],
        "evidenceRequirements": [
          "Completion checks inspect actual simulated file content and access. Command execution alone does not prove the report was saved."
        ],
        "recommendedTools": [
          "GhostTerm",
          "help",
          "man"
        ],
        "requiresCompleted": [],
        "debrief": "Evidence, preservation, least privilege and accurate handoff make investigation repeatable."
      },
      "objectives": [
        {
          "id": "source",
          "title": "Preserve the two-line source log",
          "description": "Preserve the two-line source log",
          "points": 25,
          "trigger": {
            "type": "StateVerified",
            "outcome": {
              "kind": "FileContent",
              "virtualPath": "~/mission-packs/evidence-before-action/events.log",
              "requiredContent": [
                "INFO EBA ready",
                "ERROR EBA missing-listener"
              ]
            }
          },
          "hints": [
            "Use > only for the first line, and >> to append the second line."
          ]
        },
        {
          "id": "evidence",
          "title": "Save the relevant error event",
          "description": "Save the relevant error event",
          "points": 25,
          "trigger": {
            "type": "StateVerified",
            "outcome": {
              "kind": "FileContent",
              "virtualPath": "~/mission-packs/evidence-before-action/evidence.txt",
              "requiredContent": [
                "ERROR EBA missing-listener"
              ]
            }
          },
          "hints": [
            "grep displays a filtered result; > saves that result in evidence.txt."
          ]
        }
      ]
    },
    {
      "schemaVersion": 1,
      "version": "1.0.0",
      "id": "pack.evidence-before-action.support-report",
      "title": "Write a Support Report",
      "description": "Evidence Before Action: Write a Support Report.",
      "briefing": "Work only in your simulated exercise folder. Read evidence.txt from the previous lesson. Do not replace it. Create report.txt in the same exercise folder with three lines: Observation: ERROR EBA missing-listener; Scope: simulated teaching data; Next action: inspect the simulated service before changing it. Use echo with > for the first line and >> for each following line. Read the saved report with cat and run submit CHECK.",
      "difficulty": "Beginner",
      "estimatedMinutes": 10,
      "labId": "",
      "category": "Evidence Before Action",
      "experienceReward": 75,
      "recommendedLevel": 0,
      "repeatable": false,
      "prerequisiteMissionIds": [
        "pack.evidence-before-action.find-signal"
      ],
      "storyArcId": "pack.evidence-before-action",
      "chapterId": "investigation",
      "sourceChannel": "GhostDesk",
      "tags": [
        "mission-pack",
        "evidence-before-action"
      ],
      "ticket": {
        "ticketId": "EBA-1002",
        "category": "Support Investigation",
        "priority": "Medium",
        "requester": "GhostFrame Training",
        "summary": "Write a Support Report",
        "knownInfo": [
          "Synthetic learner-created fixtures; no real incident or host access."
        ],
        "requiredActions": [
          "Read evidence.txt from the previous lesson. Do not replace it.",
          "Create report.txt in the same exercise folder with three lines: Observation: ERROR EBA missing-listener; Scope: simulated teaching data; Next action: inspect the simulated service before changing it.",
          "Use echo with > for the first line and >> for each following line. Read the saved report with cat and run submit CHECK."
        ],
        "evidenceRequirements": [
          "Completion checks inspect actual simulated file content and access. Command execution alone does not prove the report was saved."
        ],
        "recommendedTools": [
          "GhostTerm",
          "help",
          "man"
        ],
        "requiresCompleted": [
          "pack.evidence-before-action.find-signal"
        ],
        "debrief": "Evidence, preservation, least privilege and accurate handoff make investigation repeatable."
      },
      "objectives": [
        {
          "id": "report",
          "title": "Preserve observation, scope and next action",
          "description": "Preserve observation, scope and next action",
          "points": 25,
          "trigger": {
            "type": "StateVerified",
            "outcome": {
              "kind": "FileContent",
              "virtualPath": "~/mission-packs/evidence-before-action/report.txt",
              "requiredContent": [
                "Observation: ERROR EBA missing-listener",
                "Scope: simulated teaching data",
                "Next action: inspect the simulated service before changing it"
              ]
            }
          },
          "hints": [
            "A useful report separates what you observed from what you propose to do."
          ]
        },
        {
          "id": "original",
          "title": "Keep the source evidence intact",
          "description": "Keep the source evidence intact",
          "points": 25,
          "trigger": {
            "type": "StateVerified",
            "outcome": {
              "kind": "FileContent",
              "virtualPath": "~/mission-packs/evidence-before-action/evidence.txt",
              "requiredContent": [
                "ERROR EBA missing-listener"
              ]
            }
          },
          "hints": []
        }
      ]
    },
    {
      "schemaVersion": 1,
      "version": "1.0.0",
      "id": "pack.evidence-before-action.private-report",
      "title": "Protect the Report",
      "description": "Evidence Before Action: Protect the Report.",
      "briefing": "Work only in your simulated exercise folder. Inspect only ~/mission-packs/evidence-before-action/report.txt with ls -l. Change this exercise report with chmod 600 ~/mission-packs/evidence-before-action/report.txt. Never use chmod 777 or change unrelated files. Read it as your normal user, inspect its mode again, and run submit CHECK. The checks require the correct owner/mode and retained evidence.",
      "difficulty": "Beginner",
      "estimatedMinutes": 7,
      "labId": "",
      "category": "Evidence Before Action",
      "experienceReward": 75,
      "recommendedLevel": 0,
      "repeatable": false,
      "prerequisiteMissionIds": [
        "pack.evidence-before-action.support-report"
      ],
      "storyArcId": "pack.evidence-before-action",
      "chapterId": "investigation",
      "sourceChannel": "GhostDesk",
      "tags": [
        "mission-pack",
        "evidence-before-action"
      ],
      "ticket": {
        "ticketId": "EBA-1003",
        "category": "Support Investigation",
        "priority": "Medium",
        "requester": "GhostFrame Training",
        "summary": "Protect the Report",
        "knownInfo": [
          "Synthetic learner-created fixtures; no real incident or host access."
        ],
        "requiredActions": [
          "Inspect only ~/mission-packs/evidence-before-action/report.txt with ls -l.",
          "Change this exercise report with chmod 600 ~/mission-packs/evidence-before-action/report.txt. Never use chmod 777 or change unrelated files.",
          "Read it as your normal user, inspect its mode again, and run submit CHECK. The checks require the correct owner/mode and retained evidence."
        ],
        "evidenceRequirements": [
          "Completion checks inspect actual simulated file content and access. Command execution alone does not prove the report was saved."
        ],
        "recommendedTools": [
          "GhostTerm",
          "help",
          "man"
        ],
        "requiresCompleted": [
          "pack.evidence-before-action.support-report"
        ],
        "debrief": "Evidence, preservation, least privilege and accurate handoff make investigation repeatable."
      },
      "objectives": [
        {
          "id": "access",
          "title": "Report is readable only by its owner",
          "description": "Report is readable only by its owner",
          "points": 25,
          "trigger": {
            "type": "StateVerified",
            "outcome": {
              "kind": "FilePermissions",
              "virtualPath": "~/mission-packs/evidence-before-action/report.txt",
              "requiredMode": 384
            }
          },
          "hints": [
            "600 grants owner read/write and denies group/other access."
          ]
        },
        {
          "id": "retained",
          "title": "Report content survives the permission change",
          "description": "Report content survives the permission change",
          "points": 25,
          "trigger": {
            "type": "StateVerified",
            "outcome": {
              "kind": "FileContent",
              "virtualPath": "~/mission-packs/evidence-before-action/report.txt",
              "requiredContent": [
                "Observation: ERROR EBA missing-listener",
                "Scope: simulated teaching data",
                "Next action: inspect the simulated service before changing it"
              ]
            }
          },
          "hints": []
        }
      ]
    },
    {
      "schemaVersion": 1,
      "version": "1.0.0",
      "id": "pack.evidence-before-action.verified-handoff",
      "title": "Verify the Handoff",
      "description": "Evidence Before Action: Verify the Handoff.",
      "briefing": "Work only in your simulated exercise folder. Read the source evidence and report. Confirm the report remains owner-only with ls -l. Create handoff.txt in the exercise folder containing: Evidence: ERROR EBA missing-listener; Report: report.txt; Access: owner-only 600; Change status: no service changed. Read handoff.txt and run submit CHECK. These checks verify saved content and report permissions; they do not claim a real service incident was fixed.",
      "difficulty": "Beginner",
      "estimatedMinutes": 8,
      "labId": "",
      "category": "Evidence Before Action",
      "experienceReward": 75,
      "recommendedLevel": 0,
      "repeatable": false,
      "prerequisiteMissionIds": [
        "pack.evidence-before-action.private-report"
      ],
      "storyArcId": "pack.evidence-before-action",
      "chapterId": "investigation",
      "sourceChannel": "GhostDesk",
      "tags": [
        "mission-pack",
        "evidence-before-action"
      ],
      "ticket": {
        "ticketId": "EBA-1004",
        "category": "Support Investigation",
        "priority": "Medium",
        "requester": "GhostFrame Training",
        "summary": "Verify the Handoff",
        "knownInfo": [
          "Synthetic learner-created fixtures; no real incident or host access."
        ],
        "requiredActions": [
          "Read the source evidence and report. Confirm the report remains owner-only with ls -l.",
          "Create handoff.txt in the exercise folder containing: Evidence: ERROR EBA missing-listener; Report: report.txt; Access: owner-only 600; Change status: no service changed.",
          "Read handoff.txt and run submit CHECK. These checks verify saved content and report permissions; they do not claim a real service incident was fixed."
        ],
        "evidenceRequirements": [
          "Completion checks inspect actual simulated file content and access. Command execution alone does not prove the report was saved."
        ],
        "recommendedTools": [
          "GhostTerm",
          "help",
          "man"
        ],
        "requiresCompleted": [
          "pack.evidence-before-action.private-report"
        ],
        "debrief": "Evidence, preservation, least privilege and accurate handoff make investigation repeatable."
      },
      "objectives": [
        {
          "id": "handoff",
          "title": "Save a complete, truthful handoff",
          "description": "Save a complete, truthful handoff",
          "points": 25,
          "trigger": {
            "type": "StateVerified",
            "outcome": {
              "kind": "FileContent",
              "virtualPath": "~/mission-packs/evidence-before-action/handoff.txt",
              "requiredContent": [
                "Evidence: ERROR EBA missing-listener",
                "Report: report.txt",
                "Access: owner-only 600",
                "Change status: no service changed"
              ]
            }
          },
          "hints": [
            "Review each statement against the saved files before writing it."
          ]
        },
        {
          "id": "access-retained",
          "title": "Keep the report owner-only",
          "description": "Keep the report owner-only",
          "points": 25,
          "trigger": {
            "type": "StateVerified",
            "outcome": {
              "kind": "FilePermissions",
              "virtualPath": "~/mission-packs/evidence-before-action/report.txt",
              "requiredMode": 384
            }
          },
          "hints": []
        },
        {
          "id": "evidence-retained",
          "title": "Retain the original evidence",
          "description": "Retain the original evidence",
          "points": 25,
          "trigger": {
            "type": "StateVerified",
            "outcome": {
              "kind": "FileContent",
              "virtualPath": "~/mission-packs/evidence-before-action/evidence.txt",
              "requiredContent": [
                "ERROR EBA missing-listener"
              ]
            }
          },
          "hints": []
        }
      ]
    }
  ]
}
