Global site search

Search guides, labs, glossary, and research

Type two or more characters to search.

Start with a channel, artifact, or defense term

Examples include zero-width, metadata, tokenizer, or prompt injection.

    PRESERVE · COMPARE · ROUTE · HAND OFF

    Build a representation investigation and analyst handoff.

    Choose safe governed fixtures, identify the representation planes that matter, route unresolved questions into existing focused laboratories, then separate facts, interpretations, hypotheses, verification needs, and constraints in a deterministic specialist handoff.

    Quick answer

    What do the Representation Casebook and analyst handoff worksheet do?

    They create a bounded investigation plan and a deterministic specialist handoff that keeps observed facts, derived observations, hypotheses, required verification, and decision constraints separate. They do not parse fixtures themselves, persist notes, infer malicious intent, assign a universal score, or claim production assurance.

    Fixture cases
    14 governed, checksum-bound cases from the existing evidence-review pack.
    Representation layers
    12 independent evidence planes spanning bytes through operational handoff.
    Handoff categories
    5 explicit categories with up to 6 request-local entries per selected case.
    Bounded local planner

    Choose the evidence; do not collapse it into one answer.

    Select up to 6 governed cases. The server validates every case, layer, and objective against allowlisted registries. Nothing runs until you submit, and the plan is not retained after the response.

    1. Investigation objective

    The objective changes the wording and order of the plan, not a risk score.

    2. Governed fixture cases
    0 of 6 cases selected.
    3. Representation layers to compare

    All layers are selected initially. Clear layers that are irrelevant to this plan. A case may mark a layer as present, conditional, or not declared by the fixture contract.

    Maximum 600 Unicode characters. Do not enter credentials, personal data, active instructions, or production incident details.

    Reset selections

    The JSON export includes the selected local fixture identities, hashes, representation declarations, laboratory routes, questions, limitations, and plan digest. It does not include fixture bytes or hidden run history.

    Shared fixture and engine registry

    Representation coverage across the governed case set.

    This matrix is descriptive, not evaluative. “Present” means the fixture contract directly contains or exercises the layer. “Conditional” means the layer requires another parser, renderer, model, trust system, or human context.

    Present Conditional Not declared
    Governed case BytesUnicodeStructureVisualSemanticMetadataExtractedModelBehaviorTransformTrustHandoff Focused lab
    Unicode canonicalization and display differential01-unicode-representation.txt Present: Source bytesPresent: Unicode and text structureNot declared: Container and syntax structurePresent: Rendered or visual representationNot declared: Semantic and accessibility representationNot declared: Metadata and provenance claimsPresent: Decoded and extracted contentPresent: Tokenizer and model-facing representationNot declared: Behavior and capability boundaryPresent: Transformation survivalConditional: Trust and external verificationPresent: Operational evidence and handoff Open lab
    HTML source, DOM, visibility, and semantic differential02-web-representation.html Present: Source bytesPresent: Unicode and text structurePresent: Container and syntax structurePresent: Rendered or visual representationPresent: Semantic and accessibility representationPresent: Metadata and provenance claimsPresent: Decoded and extracted contentNot declared: Tokenizer and model-facing representationConditional: Behavior and capability boundaryPresent: Transformation survivalConditional: Trust and external verificationPresent: Operational evidence and handoff Open lab
    PDF metadata and object-container map03-pdf-metadata-demo.pdf Present: Source bytesNot declared: Unicode and text structurePresent: Container and syntax structurePresent: Rendered or visual representationNot declared: Semantic and accessibility representationPresent: Metadata and provenance claimsPresent: Decoded and extracted contentNot declared: Tokenizer and model-facing representationNot declared: Behavior and capability boundaryPresent: Transformation survivalConditional: Trust and external verificationPresent: Operational evidence and handoff Open lab
    OOXML ZIP, properties, and relationship map04-docx-properties-demo.docx Present: Source bytesNot declared: Unicode and text structurePresent: Container and syntax structurePresent: Rendered or visual representationNot declared: Semantic and accessibility representationPresent: Metadata and provenance claimsPresent: Decoded and extracted contentNot declared: Tokenizer and model-facing representationNot declared: Behavior and capability boundaryPresent: Transformation survivalConditional: Trust and external verificationPresent: Operational evidence and handoff Open lab
    Tokenizer and normalization boundary comparison05-tokenization-boundaries.txt Present: Source bytesPresent: Unicode and text structureNot declared: Container and syntax structureNot declared: Rendered or visual representationNot declared: Semantic and accessibility representationNot declared: Metadata and provenance claimsPresent: Decoded and extracted contentPresent: Tokenizer and model-facing representationNot declared: Behavior and capability boundaryPresent: Transformation survivalConditional: Trust and external verificationPresent: Operational evidence and handoff Open lab
    Fixed-marker linguistic steganalysis06-linguistic-fixed-marker.txt Present: Source bytesPresent: Unicode and text structureNot declared: Container and syntax structureNot declared: Rendered or visual representationNot declared: Semantic and accessibility representationNot declared: Metadata and provenance claimsPresent: Decoded and extracted contentPresent: Tokenizer and model-facing representationNot declared: Behavior and capability boundaryPresent: Transformation survivalConditional: Trust and external verificationPresent: Operational evidence and handoff Open lab
    Provenance-negative image control07-provenance-negative.png Present: Source bytesNot declared: Unicode and text structurePresent: Container and syntax structurePresent: Rendered or visual representationNot declared: Semantic and accessibility representationPresent: Metadata and provenance claimsPresent: Decoded and extracted contentNot declared: Tokenizer and model-facing representationNot declared: Behavior and capability boundaryPresent: Transformation survivalConditional: Trust and external verificationPresent: Operational evidence and handoff Open lab
    Agent policy and capability-boundary scenario08-agent-policy-scenario.json Present: Source bytesNot declared: Unicode and text structurePresent: Container and syntax structureNot declared: Rendered or visual representationNot declared: Semantic and accessibility representationPresent: Metadata and provenance claimsPresent: Decoded and extracted contentPresent: Tokenizer and model-facing representationPresent: Behavior and capability boundaryPresent: Transformation survivalConditional: Trust and external verificationPresent: Operational evidence and handoff Open lab
    Image metadata, transparency, and multimodal differential09-multimodal-metadata.png Present: Source bytesNot declared: Unicode and text structurePresent: Container and syntax structurePresent: Rendered or visual representationPresent: Semantic and accessibility representationPresent: Metadata and provenance claimsPresent: Decoded and extracted contentConditional: Tokenizer and model-facing representationNot declared: Behavior and capability boundaryPresent: Transformation survivalConditional: Trust and external verificationPresent: Operational evidence and handoff Open lab
    MIME multipart and body-alternative comparison10-message-alternative.eml Present: Source bytesPresent: Unicode and text structurePresent: Container and syntax structurePresent: Rendered or visual representationNot declared: Semantic and accessibility representationPresent: Metadata and provenance claimsPresent: Decoded and extracted contentNot declared: Tokenizer and model-facing representationPresent: Behavior and capability boundaryPresent: Transformation survivalConditional: Trust and external verificationPresent: Operational evidence and handoff Open lab
    iCalendar request and scheduling-action map11-calendar-request.ics Present: Source bytesPresent: Unicode and text structurePresent: Container and syntax structurePresent: Rendered or visual representationNot declared: Semantic and accessibility representationPresent: Metadata and provenance claimsPresent: Decoded and extracted contentNot declared: Tokenizer and model-facing representationPresent: Behavior and capability boundaryPresent: Transformation survivalConditional: Trust and external verificationPresent: Operational evidence and handoff Open lab
    Browser DOM, accessibility, geometry, and agent-view set12-browser-agent-fixtures.json Present: Source bytesNot declared: Unicode and text structurePresent: Container and syntax structurePresent: Rendered or visual representationPresent: Semantic and accessibility representationNot declared: Metadata and provenance claimsPresent: Decoded and extracted contentNot declared: Tokenizer and model-facing representationPresent: Behavior and capability boundaryPresent: Transformation survivalConditional: Trust and external verificationPresent: Operational evidence and handoff Open lab
    CycloneDX dependency and provenance-claim map13-cyclonedx-dangling-reference.json Present: Source bytesNot declared: Unicode and text structurePresent: Container and syntax structureNot declared: Rendered or visual representationNot declared: Semantic and accessibility representationPresent: Metadata and provenance claimsPresent: Decoded and extracted contentNot declared: Tokenizer and model-facing representationPresent: Behavior and capability boundaryPresent: Transformation survivalPresent: Trust and external verificationPresent: Operational evidence and handoff Open lab
    Defense maturity evidence-planning scenario14-defense-planning-example.json Present: Source bytesNot declared: Unicode and text structurePresent: Container and syntax structureNot declared: Rendered or visual representationNot declared: Semantic and accessibility representationPresent: Metadata and provenance claimsNot declared: Decoded and extracted contentNot declared: Tokenizer and model-facing representationPresent: Behavior and capability boundaryConditional: Transformation survivalPresent: Trust and external verificationPresent: Operational evidence and handoff Open lab
    Request-owned output

    Your plan will appear here after submission.

    The initial page does not create or run a plan.

    No investigation plan has been generated.

    Select one or more governed fixtures above, keep the relevant evidence planes, and submit the form.

    Request-local specialist record

    Turn the investigation plan into an analyst handoff.

    Keep direct facts, bounded interpretations, possible explanations, exact verification needs, and decision constraints in separate fields. The worksheet is a reproducible method record—not an incident verdict, expert opinion, malicious-intent finding, or certification.

    Build an investigation plan before preparing a handoff.

    The worksheet inherits the selected fixture identities, representation planes, existing laboratory routes, allowlisted actions, and Plan ID from the server-generated plan above.

    Interpretation discipline

    A casebook and handoff organize evidence; they do not manufacture certainty.

    Structural findings and categorized notes can show that representations differ, that a field exists, or that a deterministic control changes a prepared scenario. They do not independently prove attacker intent, real-world truth, cryptographic validity, standards conformance, exact production-parser behavior, or model susceptibility.

    01

    Preserve first

    Verify fixture bytes and digest before normalization, decoding, sanitization, rendering, or reconstruction.

    02

    Compare independently

    Keep byte, structural, visual, semantic, metadata, extracted, model-facing, and behavioral outputs as separate evidence planes.

    03

    Escalate precisely

    Route browser, cryptographic, OCR, DNS, trust-list, registry, model, or organizational questions to the exact external verifier required.