{
  "schema_version": 1,
  "case_id": "CASE-NORTHSTAR-TOY-001",
  "title": "Northstar Fictional Release-Integrity Incident",
  "classification": "inert-and-synthetic-course-capstone",
  "live_artifacts": false,
  "authorized_scope": ["Course-owned files listed in fixture-manifest.json", "Disposable offline course VM for the two declared benign source exercises"],
  "prohibited_scope": ["Real malware", "Employer or customer data", "Third-party systems", "Public callbacks", "Production blocking systems"],
  "evidence_sets": [
    { "id": "E-01", "path": "defensive-evidence-pack.json", "question": "What is supplied, sanitized, and authorized?" },
    { "id": "E-02", "path": "static/static-triage-fixtures.json", "question": "Which release metadata changed?" },
    { "id": "E-03", "path": "endpoint/synthetic-endpoint-events.jsonl", "question": "Which bounded process and release events are observed?" },
    { "id": "E-04", "path": "network/sanitized-network-events.jsonl", "question": "Which reserved network metadata correlates by time and identity?" },
    { "id": "E-05", "path": "memory/sanitized-memory-observations.json", "question": "Which volatile observations are corroborated or ambiguous?" },
    { "id": "E-06", "path": "frameworks/attack-d3fend-v19.2-1.5.0.json", "question": "Which behavior and defensive mappings are directly supported?" },
    { "id": "E-07", "path": "yara/", "question": "Does a narrow inert file rule pass positive, near-match, and negative tests?" },
    { "id": "E-08", "path": "sigma/", "question": "Does the synthetic behavioral rule preserve its schema and false-positive contract?" },
    { "id": "E-09", "path": "tabletop/", "question": "Which containment and recovery decision is authorized and measurable?" },
    { "id": "E-10", "path": "intelligence/", "question": "Can the toy report be validated and shared with compatible handling metadata?" },
    { "id": "E-11", "path": "architecture/developer-tool-architecture.json", "question": "Which source-to-runtime control prevents recurrence?" },
    { "id": "E-12", "path": "capstone/capstone-timeline.jsonl", "question": "Which facts, hypotheses, alternatives, and gaps define the incident timeline?" }
  ],
  "required_deliverables": [
    "Manifest verification and evidence-handling record",
    "Evidence-linked timeline with facts, hypotheses, alternatives, and gaps",
    "Inert YARA and synthetic Sigma test portfolio",
    "Version-pinned ATT&CK and D3FEND mapping with limitations",
    "Containment decision matrix and staged recovery acceptance criteria",
    "Executive report, technical report, and separately validated toy STIX bundle",
    "SSDF and SLSA-aligned developer remediation backlog",
    "Teardown and retention record"
  ]
}
