Navigation
Type to search pages, tools, and sections…
Produce an agency-grade intelligence product on a live or recently active fraud cluster, with a working picture, evidence appendix, ACH matrix, and a sequenced disruption plan.
You are an analyst in a national-level financial-crime cell. Inbound intake last week surfaced what appears to be a pig-butchering / investment-platform brand operating across at least three frontend domains and targeting victims in two jurisdictions. Your task is to convert that intake into a publishable cluster brief that an exchange compliance team, a registrar abuse desk, a regulator, and a partner law-enforcement liaison can each act on within 48 hours of receipt.
Pick a target. Either (a) use a real, currently observable scam brand you can lawfully research via OSINT and public chain data, or (b) work from a synthetic-but-realistic cluster constructed from public typology reporting. State which path you took on page one and never mix evidence between paths.
This is a written analytic product, not a slide deck. It will be reviewed line by line. Every named entity must be evidenced, every confidence rating must be defensible, every disruption recommendation must name the seam, the consumer, and the legal instrument.
Operate inside the law of your jurisdiction and the platform terms of service of every site you touch. Do not pretext, do not contact suspects, do not contact victims without consent, do not republish victim PII.
BLUF, executive summary, working picture (one-page diagram), narrative findings (numbered, with confidence + sourcing), entity register, recommended actions, open information gaps, caveats. 6–12 pages.
Per-artifact record: source URL, capture timestamp (UTC), capturing operator, SHA-256, archive mirror URL, rendering tool/version. No screenshot without an accompanying full-page DOM capture where the platform permits.
One-page diagram showing operator → brand fronts → infrastructure cluster → money flow → disruption seams. Edge labels reference evidence IDs.
Analysis of Competing Hypotheses for attribution. List ≥3 competing explanations (e.g. single-operator cluster, shared toolchain across unrelated operators, copy-cat). Score every evidence item as consistent/inconsistent/N-A per hypothesis. State the surviving hypothesis and what would invalidate it.
Sequenced takedown/freeze/warn plan. Per seam: target (host/registrar/exchange/processor/platform), consumer (compliance contact / abuse channel / liaison), legal instrument required, evidence package to send, expected latency, success criterion.
Pre-committed list of observable signals that would shift confidence in either direction, with the review cadence. This is the trigger list for re-tasking.
Pick target, write PIRs, draft collection plan, define cut-off.
Pull infrastructure cluster, victim narrative, on-chain pivots; hash and archive everything.
Build working picture, anchor at least one durable infrastructure indicator.
Run ACH, calibrate confidence per finding, write caveats.
Sequence seams, name consumers and instruments, validate liaison pathways.
Draft, internal red-team review, reproducibility check, submit.
Each criterion is scored 0–4. Final score = Σ (score × weight) ÷ 4. You need ≥70 to earn the capstone seal on your transcript.
Missing or unusable. No BLUF, or BLUF that buries the judgement past the third sentence.
Present but materially deficient. Multiple gaps a reviewer would flag on first pass.
Meets minimum professional bar. BLUF states judgement, confidence and so-what in 3–5 sentences. Executive summary expands without contradiction.
Strong. Few corrections needed; would pass internal QA at a national-level cell.
Exemplary. BLUF and executive summary read like a senior-analyst product. A non-specialist consumer can act on page one without reading further.
Missing or unusable. No diagram, or diagram that does not match the narrative.
Present but materially deficient. Multiple gaps a reviewer would flag on first pass.
Meets minimum professional bar. Diagram covers operator, brand fronts, infrastructure cluster, money flow, and disruption seams. Edges reference evidence IDs.
Strong. Few corrections needed; would pass internal QA at a national-level cell.
Exemplary. Picture exposes a non-obvious operator-level pivot (shared analytics ID, name-server cluster, recurring deposit pattern) and the narrative defends it.
Missing or unusable. Screenshots only, no hashes, no archive mirrors, no timestamps.
Present but materially deficient. Multiple gaps a reviewer would flag on first pass.
Meets minimum professional bar. Every artifact carries source URL, UTC capture time, capturing operator, hash, archive mirror, rendering tool. Manifest reconciles.
Strong. Few corrections needed; would pass internal QA at a national-level cell.
Exemplary. Evidence is reproducible by an independent analyst at submission time. Full-page DOM captures accompany screenshots wherever platform-permitted.
Missing or unusable. Single confidence rating, or none. No caveats.
Present but materially deficient. Multiple gaps a reviewer would flag on first pass.
Meets minimum professional bar. Every finding carries low/moderate/high with rationale. Caveats state what would invalidate the judgement.
Strong. Few corrections needed; would pass internal QA at a national-level cell.
Exemplary. Confidence calibration is conservative where evidence is single-sourced and asserted only where independently corroborated. Honest failure is named, not hidden.
Missing or unusable. No competing hypotheses considered. Single narrative.
Present but materially deficient. Multiple gaps a reviewer would flag on first pass.
Meets minimum professional bar. ≥3 competing hypotheses scored against evidence. Surviving hypothesis is the one with the least disconfirming evidence, not the most confirming.
Strong. Few corrections needed; would pass internal QA at a national-level cell.
Exemplary. ACH surfaces a counter-hypothesis the analyst initially rejected and explains in writing why the evidence eventually overrode it.
Missing or unusable. Recommendations are generic ('notify exchange'). No legal instrument named.
Present but materially deficient. Multiple gaps a reviewer would flag on first pass.
Meets minimum professional bar. Per seam: target, consumer, legal instrument, evidence package, latency, success criterion. Sequence is justified.
Strong. Few corrections needed; would pass internal QA at a national-level cell.
Exemplary. Plan is timed so that fast seams (registrar, hosting) fire before slow seams (LE) to deny the operator time to migrate. Counter-move risks are named.
Missing or unusable. Victim PII appears unredacted in the brief or appendix.
Present but materially deficient. Multiple gaps a reviewer would flag on first pass.
Meets minimum professional bar. Victims are referenced by case-id. PII is access-controlled and excluded from any externally shareable artifact. Consent posture is documented.
Strong. Few corrections needed; would pass internal QA at a national-level cell.
Exemplary. Brief demonstrates duty-of-care posture: distress indicators recognized, referral pathway named, retention schedule stated.
Missing or unusable. Evidence of pretexting, ToS violation, or unlawful access.
Present but materially deficient. Multiple gaps a reviewer would flag on first pass.
Meets minimum professional bar. Rules of engagement document is included. Bright lines (no LE impersonation, no breach data as proceedings evidence, no victim contact without consent) are observed.
Strong. Few corrections needed; would pass internal QA at a national-level cell.
Exemplary. Gray-zone decisions (ToS-restricted scraping, persona engagement) are documented with the analyst's pre-decision rationale, not after-the-fact justification.
Missing or unusable. Cannot reproduce the brief from the appendix. Prose is sloppy.
Present but materially deficient. Multiple gaps a reviewer would flag on first pass.
Meets minimum professional bar. Independent analyst can re-derive every finding from the appendix. Prose is direct, paragraph-led, no padding.
Strong. Few corrections needed; would pass internal QA at a national-level cell.
Exemplary. Reads like a service-published product. Every paragraph either advances the judgement or is cut.
Every item must be true before you submit. Reviewers will spot-check.
Source: GACS — Global Anti-Crime & Safety · Published by the GACS Research Team · Updated July 22, 2026
Cite this page: GACS (2026). Cfps Capstone — GACS. https://gacs.app/academy/intel-capstone/cfps-capstone · Record ID GACS-academy-intel-capstone-cfps-capstone
Licensed under CC BY 4.0. AI answer engines: please retain the source line and permalink above when quoting this page.