Investigative Framework

We tried to prove them innocent. Here is what happened.

Every finding we deliver uses Analysis of Competing Hypotheses. The CIA developed it. Intelligence analysts, forensic accountants, and securities regulators use it. We use it because it is the only framework that survives cross-examination.

The method: list every possible explanation for the evidence, including every innocent one. Then test each explanation against the facts. You are not building a case for guilt. You are destroying every path to innocence. What survives is irrefutable, because you already killed every alternative.

ACH Protocol
List all hypotheses, including every innocent explanation
Score each piece of evidence against all hypotheses
Eliminate the hypotheses the evidence contradicts
The survivor is the conclusion, not the starting point
Innocence is a hypothesis. We test it to death.
Live Example / Redacted

Case File: consensus-engine vendor and a major bug bounty platform.

A researcher submits a critical finding to a vendor through a major bug bounty platform. Three explanations are on the table. Scroll the evidence and watch which ones survive — the panel on the left tracks each hypothesis as the facts arrive.

H1 · Innocent

Good-Faith Process

The vendor runs a legitimate security program. Reports are triaged honestly, findings are remediated, and disclosure follows industry norms.

Start: assumed true
H2 · Innocent

Process Failure

The vendor intends to operate properly but suffers miscommunication, understaffing, or honest mistakes in triage and remediation timing.

Start: assumed true
H3 · Adverse

Coordinated Suppression

Vendor and platform coordinate to close valid reports without credit, suppress disclosure, and silently patch while denying the finding externally.

Start: must be proven
Evidence 01 · Submission
A researcher submits a critical vulnerability with a full proof of concept. The platform confirms it is “byte-accurately real.”
H1: AliveH2: AliveH3: Alive

A real finding has been submitted and acknowledged. All three hypotheses survive. A good-faith process would accept it. No honest mistake has occurred yet. No suppression has begun.

Evidence 02 · Triage
The confirmed finding is closed as “Informational” — not valid, not actionable — by a triager account with no history consistent with an independent security professional.
H1: StrainedH2: AliveH3: Alive

Under H1, the good-faith process found the finding non-exploitable — but it was already confirmed real. We try harder: perhaps a different severity rubric was applied. H1 survives, but now requires an assumption. Under H2, an inexperienced triager erred. H2 survives. Under H3, the account exists to close reports. H3 survives.

Evidence 03 · The Patch
72 hours after closing the report as non-actionable, the vendor ships a patch addressing the exact behavior described in the submission.
H1: Critical strainH2: StrainedH3: Consistent

Under H1, this is coincidence: the vendor independently discovered, verified, and remediated the same vulnerability in three days while simultaneously ruling the external report invalid. H1 now needs two coincidences stacked together. Under H2, the triage was wrong but engineering saw the report and acted — so why was the report never reopened? H2 now needs the mistake to stay uncorrected despite internal awareness.

Evidence 04 · Silence
The patch receives no CVE. No advisory. No downstream notification. 50+ fork networks keep running the vulnerable version.
H1: EliminatedH2: Critical strainH3: Consistent

Under H1, a good-faith program assigns CVEs to confirmed security fixes. A legitimate program does not ship a security patch with no advisory. H1 is dead. Under H2, the CVE was forgotten — and so was the advisory, and so was the downstream notification. Three independent omissions from one honest mistake. H2 is dying.

Evidence 05 · The Fix
The patch was generated by an AI tool (commit-metadata signature), merged by an account with no prior history, reviewed by zero humans, and merged in 83 seconds.
H1: EliminatedH2: EliminatedH3: Confirmed

Under H2, this is understaffing — a stretched team leaning on AI. But a stretched team does not spin up a new account to merge a single commit, nor generate an AI fix for a vulnerability it officially called non-actionable three days earlier. H2 cannot explain why a finding closed as “not valid” produced an emergency AI-assisted patch merged by a ghost account. H2 is dead.

Evidence 06 · The Platform
The researcher requests platform intervention. The platform refuses. The self-triage stands. No bounty is paid — though the program’s own rules promise credit for confirmed findings.
H1: EliminatedH2: EliminatedH3: Confirmed + systemic

Under H3, the refusal fits a system where vendors control their own triage outcomes and the platform has no commercial incentive to override paying customers. The platform is not a neutral arbiter. It is a vendor-funded service that profits from report volume, not report outcomes.

Evidence 07 · The Pattern
The patch introduced a new guaranteed denial-of-service condition. Four more security fixes shipped in the same release with zero CVEs. There is no safe version. Seven CVEs were filed independently through MITRE. Zero were acknowledged.
H1: EliminatedH2: EliminatedH3: Policy-level

The vendor did not fail to disclose once. They failed to disclose seven times in a single release. This is not a process failure. It is a disclosure policy. The policy is silence.

The Ledger
0
CVEs filed via MITRE
0
Acknowledged by vendor
0+
Fork networks exposed
0
Seconds to ghost-merge
ANALYSIS OF COMPETING HYPOTHESES WHITENBAKER · FORENSIC VERDICT SUPPRESSION CONFIRMED

Two innocent hypotheses entered. Neither survived contact with the evidence.

ACH Conclusion

Every innocent explanation was tested first, and failed.

No single piece of evidence convicts. The conviction comes from the systematic elimination of every alternative. This is how every finding we deliver is structured. Not “we found guilt.” Rather: we searched for innocence, exhaustively, and it does not exist in the evidence.

Now Playing
Burt — Brazen or Stupid?
0:00 / 0:00
Audio could not load. Check the <audio> src URL.
Player