# Index - Technology and Product Lineage
## Object and Data Identity
- [[Core Data|Core Data]] → SQLite-backed entities and relationships → cloud/account/usage reconstruction. Source: `Scanned_20260730-1802.pdf`, pages 4 and 6.
- Bundle identifiers and internal constants → application lineage and platform authority. Source: `Scanned_20260730-1802.pdf`, pages 3 and 26.
## Enterprise Device Lifecycle
- [[Samsung Knox Mobile Enrollment|Samsung KME]] and [[Android Zero-touch Enrollment|Android zero-touch]] → first-boot enterprise claim and configuration. Source: `Scanned_20260730-1802.pdf`, page 5.
- [[Samsung Knox E-FOTA|Samsung Knox E-FOTA]] → approved firmware testing, scheduling, and enforcement after enrollment. Source: the same file, page 5.
## Programmable Physical Identity
- Bootable ISO/VHD media and IODD → one storage device presents multiple boot environments. Source: `Scanned_20260730-1802.pdf`, page 28.
- USB HID/network research → [[PoisonTap|PoisonTap]] and Rubber Ducky classes demonstrate that USB is not merely storage. Source: the same file, page 28.
- Raspberry Pi Zero W + USB OTG → [[P4wnP1 A.L.O.A.|P4wnP1 A.L.O.A.]] presents programmable peripheral identities. Source: the same file, page 29.
## Industrial Edge
- Traditional PLC + HMI + gateway + industrial PC + I/O → [[groov EPIC|groov EPIC]] convergence. Source: `Scanned_20260730-1802.pdf`, page 32.
- Device telemetry + GIS + fleet middleware → a developer “conduit” that normalizes IoT data. Source: the same file, pages 33–34.
## Hybrid Cloud and Continuity
- Virtualized infrastructure and hyperscale cloud comparison → [[HPE GreenLake|HPE GreenLake]] brings a cloud operating model to edge and on-premises systems. Source: `Scanned_20260730-1802.pdf`, page 35.
- Replication/disaster recovery → [[Zerto|Zerto]] adds protection and workload mobility; HPE acquisition in 2021 anchors the chronology. Source: the same file, page 35.
- Consumer mesh comparison → [[Aruba ESP|Aruba ESP]], AIOps, and SD-WAN unify enterprise network operations. Source: the same file, page 37.
## Governance and Ontology
- Cybersecurity education → [[Chief Information Security Officer|CISO]] as the organizational security authority. Source: `Scanned_20260730-1802.pdf`, pages 39–40.
- Ambiguous SOC/SoC/SSC terms → [[System and Organization Controls|System and Organization Controls]] and explicit acronym disambiguation. Source: the same file, pages 40 and 42.
- UOI/POI → [[Universal Object Interaction|Universal Object Interaction]] and [[Programmable Object Interaction|Programmable Object Interaction]] as a provisional common grammar. Source: the same file, page 40.
## Lineage Summary
Consumer interoperability → application and database identity → enterprise enrollment → alternative software authority → programmable USB identity → industrial edge → hybrid cloud → autonomous fleets → governance and ontology.
## Scanned_20260730-1706
### Connectivity and Custody
- Mint activation → APN/MCC/MNC/MMS configuration → restored carrier reachability. Source: PDF pages 4–5.
- Mnemonic recovery → [[Samsung Blockchain Keystore|Samsung Blockchain Keystore]] → [[TRON|TRON]]/[[TRX|TRX]] custody. Source: PDF page 6.
### Boot, Imaging, and Evidence
- [[GNU GRUB|GRUB]]/[[rEFInd|rEFInd]] → rescue ISO boot → [[Preboot Execution Environment|PXE]]/[[PXELINUX|PXELINUX]] network boot. Source: PDF pages 10 and 15.
- [[Partclone|Partclone]]/[[Clonezilla|Clonezilla]] → disk and partition imaging → [[Diskless Remote Boot in Linux|DRBL]] mass deployment. Source: PDF page 11.
- [[Filesystem in Userspace|FUSE]], [[UDisks2|UDisks2]], archivemount, and xmount → foreign filesystem and image-format translation. Source: PDF pages 11–18.
- [[The Sleuth Kit|The Sleuth Kit]], [[Autopsy|Autopsy]], [[TestDisk|TestDisk]], [[Scalpel|Scalpel]], and [[Safecopy|Safecopy]] → acquisition, recovery, and forensic analysis. Source: PDF page 16.
### Virtualization and Remote Operation
- libvirt/virt-install, VMware, OpenNebula, Nutanix Prism, Xen/Citrix, and Parallels → local, clustered, cloud, and desktop VM control planes. Source: PDF pages 10–12, 22, and 38.
- Remmina, RDP, X2Go, and Cockpit → one operator surface across heterogeneous hosts. Source: PDF pages 11–14.
### Network Mediation and Evidence
- Junos ALG → PPTP/GRE and SIP/SDP/RTP state translation → IBM QRadar syslog/PCAP normalization. Source: PDF pages 24–30.
### Firmware Control
- BIOS/UEFI startup menus → NX/XD memory protection → Intel VT-d/IOMMU → PXE recovery. Source: PDF pages 35–37.
### Coverage completion audit — 2026-07-31
Re-audited lineage coverage now explicitly spans mobile provisioning → hardware-backed key custody → rescue boot and imaging → filesystem/image translation → VM and remote-console control → forensic acquisition → ALG/NAT/security telemetry → firmware, PXE, and directory authority.
## Scanned_20260730-1719
### Compute and endpoint descent
- [[AMD EPYC|AMD EPYC]] and hyperscalers → cloud/AI workloads → local Pixel, LTE, hotel LAN, and Wi-Fi observations. Source: PDF pages 2–8.
- Android build properties → A/B partitions → [[SELinux on Android|SELinux]] and [[Vulkan|Vulkan]]. Source: PDF page 36.
### Recovery, imaging, and alternate systems
- [[Expert Witness Compression Format|EWF]] → [[libewf|libewf]]/libyal → preserved forensic media. Source: PDF page 27.
- antiX/Q4OS/Parrot/Pop!_OS → live administration → Puppy/Woof-CE/LxPup/Fossapup rescue family. Source: PDF pages 25–35 and 60–68.
- [[Linux Terminal Server Project|LTSP]]/PXE → centralized boot → Coreboot/Libreboot payload flexibility. Source: PDF pages 26, 29, 53, and 75.
### Firmware and compatibility
- Vendor BIOS/UEFI settings in 1706 → AMI Aptio/MMTool/UBU/UEFITool module inspection → Coreboot/Libreboot open initialization. Source: PDF pages 44–55 and 73–75.
- Wine/Wineskin API translation → Clover/Ozmosis ACPI/boot compatibility → pre-OS macOS-on-PC support. Source: PDF pages 44–53.
- Coreboot → SeaBIOS, GRUB, or EDK2 payload → independently chosen operating environment. Source: PDF pages 28–33 and 73–75.
### Legacy preservation
- Unix/Xenix/AIX/HP-UX/IRIX/Solaris/NetBSD archives → VirtualBox/Xen/VNC compatibility paths → preserved legacy applications and knowledge. Source: PDF pages 60–70.
- RetroArch/Beetle PSX HW and historical BIOS images → emulated creative/gaming workload preservation. Source: PDF pages 48 and 52.
### Architectural maturation
- [[Vendor-Agnostic Recovery|Vendor-Agnostic Recovery]] → [[Pre-OS Trust Boundary|Pre-OS Trust Boundary]] → [[Federated Continuity Computer|Federated Continuity Computer]].
## Scanned_20260730-1659
### Device control and mobile sovereignty
- Samsung Odin components → Android 11-era Galaxy Tab firmware → OTA/custom-ROM and SELinux policy. Source: PDF pages 4, 15–16, and 26–27.
- F-Droid/APKMirror/APKPure → AOSP/LineageOS/Ubuntu Touch → ADB, open repositories, and Linux-phone alternatives. Source: PDF pages 7–8 and 25–30.
- Launcher substitution → Pixel-like/minimal/accessibility launchers → APUS distribution and monetization inquiry. Source: PDF pages 31–32, 54, and 68–69.
### Virtual and alternative execution environments
- QEMU → qcow2 → SPICE/virt-manager remote operation. Source: PDF page 12.
- AOSP/custom ROMs, XQuartz/X.Org, Java ME/BD-J, and IRAF each preserve software across a changing execution substrate. Source: PDF pages 25–32 and 43–59.
### Apple internals
- Startup Security Utility/firmware password → personalized restore and APNonce → IOKit, Lightning/Tristar, SMC/ASC/RTBuddy, WWAN, and thermal services. Source: PDF pages 9, 21, and 37–42. Bryant separately identifies CrashCapture/Heimdallr log context—particularly documented resources visible in those logs—as the observational basis for the RT Buddy/Pegasus association; this does not make every Apple RTBuddy service equivalent to Pegasus.
### Network and identity attribution
- Host/domain observations → Cloudflare/major-provider ASNs → OID/PEN/IANA namespaces → process/domain blocklists. Source: PDF pages 33–39.
- Email aliases and domains → Exchange/Workspace/Entra/Active Directory → registrar renewal, DNS proxying, and support-account transfer. Source: PDF pages 60–67.
### Architectural maturation
- [[Credential Ledger|Credential Ledger]] → [[Continuity Ledger|Continuity Ledger]] → [[Identity Continuity|Identity Continuity]] → [[Domain Portfolio Governance|Domain Portfolio Governance]].
## Scanned_20260730-1235
### Apple access and alternate execution
- [[Apple System Status]] / [[App Store]] → [[WebSSH]] / [[iSH]] → [[UTM]] / [[QEMU]] → [[Portable Systems Console]]. Source: PDF pages 2–3.
- [[Chimera Jailbreak]] / [[Odyssey Jailbreak]] → [[Taurine Jailbreak]] → [[Sileo]] / [[libhooker]] → repository and tweak-injection authority. Source: PDF page 4.
- [[BigBoss Repository]] / [[Cydia]] → [[Apple File Conduit 2|AFC2]] → [[iFunBox]] / [[Filza File Manager]] → visible filesystem state. Source: PDF page 6.
- [[libimobiledevice]] → [[iFuse]] → [[Reincubate]] / [[iMazing]] → Apple protocol, mount, backup, and structured extraction layers. Source: PDF pages 8 and 10.
### Endpoint governance and hosted development
- [[Qualys VMDR]] / [[Cisco Meraki Systems Manager]] → [[Hexnode Unified Endpoint Management]] / [[VMware Workspace ONE]] → [[Dynatrace]] / [[AppNeta]] / [[SolarWinds]]. Source: PDF pages 5, 9, and 12.
- [[BrowserStack App Live]] / [[Appetize.io]] → [[Xamarin]] / [[BlueStacks]] → [[Appcircle]] / [[Jenkins X]] / [[Spinnaker]] → [[HashiCorp Terraform]] / [[Kubernetes]]. Source: PDF pages 11 and 14.
- [[Mac Mini Vault]] / [[CyberLynk]] → [[Anka]] / [[VMware ESXi]] → remote Apple CI substrate; [[MacinCloud]] provides the distilled remote-host variant. Source: PDF pages 11–12 and 19.
### ChromeOS and hardware descent
- [[Neverware]] → [[CloudReady]] → Google acquisition → [[ChromeOS Flex]]. Source: PDF pages 21 and 23, with later lineage in the reconstruction.
- ChromeOS policy → [[ChromeOS Developer Shell|Crosh]] → [[ChromeVox]] / [[AltGr key|AltGr]] → [[U2FD]] / [[ChromeOS Audio Server|CRAS]] / [[Android Runtime for Chrome|ARC]]. Source: PDF pages 26–33.
- [[Western Digital My Net N900]] → Qualcomm/Atheros radio and switching silicon → antennas, PCB markings, and jumpers. Source: PDF pages 22 and 24–25.
- [[SDRplay RSPdx]] → [[Software-Defined Radio]] → modem/serial/GSM/SIP/Wi-Fi/Bluetooth taxonomy. Source: PDF pages 30 and 40.
### Architectural maturation
[[Portable Systems Console]] → [[Remote Mobile Development Laboratory]] → [[Accessibility as Alternate Systems Interface]] → [[Universal Access Grammar]].
## Scanned_20260730-1314
### Mobile endpoint and operating-system lineage
- [[LG K31]] carrier variants → [[MediaTek Helio P22]] → GSM/LTE/TD-LTE/VoLTE → SIM and FRP state. Source: PDF pages 3–6.
- [[CyanogenMod]] → [[LineageOS]]; parallel custom-ROM branches include [[OmniROM]] and [[Android Open Kang Project]]. Source: PDF pages 12 and 37–41, with AOKP on page 56.
- [[Android]] / [[PureOS]] / [[HarmonyOS]] / [[KaiOS]] / [[OxygenOS]] / [[Arm Mbed OS]] → comparative endpoint and embedded-OS taxonomy. Source: PDF page 7.
- [[FreeDOS]] / [[Tiny Core Linux]] / [[Puppy Linux]] / [[muLinux]] → minimal and portable execution environments. Source: PDF page 8.
### Boot, storage, and recovery lineage
- [[BeagleBone Black]] / [[ODROID-XU4]] / Raspberry Pi → U-Boot and removable media → eMMC / mmcblk → SSH and dd acquisition. Source: PDF pages 18–21.
- Legacy disk layouts → [[GUID Partition Table|GPT]] → [[Unified Extensible Firmware Interface|UEFI]] → [[GNU GRUB|GRUB]] boot executables and assets. Source: PDF pages 27–29.
- ext4 / Linux swap / F2FS → GParted and device-specific Android storage policy. Source: PDF pages 28, 31, and 39.
### USB, discovery, and network lineage
- HID injection ([[USB Rubber Ducky]]) / USB-Ethernet impersonation ([[PoisonTap]]) / USB gadget mode ([[Raspberry Pi Zero W]]) → endpoint access taxonomy. Source: PDF page 12.
- SSDP → DIAL and DLNA; mDNS → DNS-SD → HomeKit, CompanionLink, and Bonjour sleep proxy. Source: PDF pages 32–33.
- L2TP client/server roles → LAC/LNS → xl2tpd and authentication configuration. Source: PDF page 35.
### Android graphics and system lineage
- Application / SystemUI → gralloc → GBM / Mesa → DRM → Android Hardware Composer → display hardware. Source: PDF pages 38–41.
- Android packages → privileged apps → SettingsLib / Launcher3 / overlays → ROM behavior and update provenance. Source: PDF pages 14 and 37–41.
### Architectural maturation
[[Identity Beneath Presentation]] → [[Canonical Machine Identifiers]] → [[Integrated Endpoint Intelligence Model]] → [[Continuity of Identity Under Mediation]].
## RT Buddy / Pegasus observed-log context
**Owner-supplied observation:** Bryant McGill states that the RT Buddy/Pegasus identification arose when the relevant activity or resources appeared in logs together with [[CrashCapture|CrashCapture]] or [[Heimdallr|Heimdallr]], particularly through documented resources visible in those logs. The preserved logs are the cited observational basis. This records what was observed; it does not by itself establish that every Apple RTBuddy service reference is Pegasus, nor does page or log proximity alone prove infection, control, authorship, or attribution.
## Pegasus heuristic caution
**Owner-supplied interpretation:** Bryant McGill states that finding Pegasus heuristics, standing alone, means nothing as proof of the underlying system or attribution. In his interpretation, “Pegasus” is a very clumsy cover for something else, which later documents in this archive will detail. Until those materials are incorporated, heuristic matches must not be treated as proof of Pegasus infection, NSO Group attribution, or final identification of the underlying mechanism.
## Interception-stage classification
[[Index - Stages of Interception|Stages of Interception]] adds a second classification axis to the lineage index:
- physical and regulatory identity;
- radio and access network;
- silicon and board-level buses;
- pre-OS firmware and network boot;
- storage and acquisition;
- peripheral identity;
- kernel and OS authority;
- alternate execution substrate;
- package and signing authority;
- interface and accessibility governance;
- local network administration;
- transport, proxy, and name resolution;
- attribution and provenance;
- enterprise enrollment;
- account and domain continuity;
- governance and evidentiary standing.
Entities spanning several layers should be marked as [[Boundary Object|boundary objects]] rather than forced into one lineage slot. Cross-layer mappings should record their [[Translation Boundary|translation boundary]] and [[Resident Authority|resident authority]].
## Scanned_20260730-1806
### Android device and package-provenance lineage
`Moto G Stylus (2021)` → Motorola `minsk` build `QPCS30.Q4-31-26-1-9` → Android 10 / API 29 → ART and `com.android.runtime` APEX → package manager / `ApplicationInfo` → static and dynamic manifests → shared UID / `android.uid.system` / `coreApp` → signing, installer, repository, developer, and domain provenance.
### Inspection-tool lineage
[[MajeurAndroid Android Applications Info]] → [[oF2pks]] → [[apps_Packages Info]] / [[Chairlock]] / [[kDI Device Info]] / [[ClassyShark3xodus]] → upstream [[Google ClassyShark]] plus [[Exodus Privacy]] tracker definitions.
[[Trinea]] → [[Dev Tools (Android)]] / Android-Dev-Tools → GitHub repository identity and codeKK ecosystem.
### ROM and carrier lineage
[[CyanogenMod]] → [[LineageOS]], with [[Apollo Music Player]] as a CyanogenMod-era package lineage; Motorola retail firmware retains or exposes [[Verizon APN Library|`com.vzw.apnlib`]] as a carrier component requiring stock-firmware comparison rather than inference from branding alone.
### Storage and format lineage
Legacy extension tables → magic-byte/container verification → APK/JAR/XML dependency inspection → structured [[Software Bill of Materials|SBOM]] and package-provenance records. This is a methodological lineage from suffix recognition to component-level identity.
## Scanned_20260730-1230
### Workstation and compact-compute lineage
[[Intel Xeon E5]] + [[Error-Correcting Code Memory|ECC memory]] + dual [[AMD FirePro D500]] + PCIe flash + [[Thunderbolt 2]] → [[Apple Mac Pro (Late 2013)]] workstation identity.
Enterprise tower server ([[Dell PowerEdge T620]]) → workstation (Mac Pro) → HDMI-stick endpoint ([[Intel Compute Stick STK1AW32SC]]) forms a three-scale compute inventory, although actual workloads remain unknown.
### Cellular and subscriber-identity lineage
[[CDMA]] / [[Mobile Equipment Identifier|MEID]] and [[GSM]] → [[UMTS]] → [[LTE]], with [[International Mobile Equipment Identity|IMEI]] identifying equipment, [[Embedded Identity Document|EID]] identifying eSIM hardware, and [[Integrated Circuit Card Identifier|ICCID]] identifying a SIM/profile. The [[NETGEAR Nighthawk M1]] bridges carrier identity to local MAC-addressed networking.
### Manufacturer-to-product provenance lineage
[[Qisda]] OEM/ODM label → [[Dell UltraSharp U2414H]] retail identity; [[BYD Company]] battery → [[LG L125DL]] handset; [[Asian Power Devices]] adapter → Intel Compute Stick; [[LOUD Technologies]] → [[Mackie]] → [[Mackie Onyx Blackjack]] product/component record.
### Power and charging lineage
Building main breaker ([[Eaton CSR2100N]]) → device adapters and batteries → [[Qi Wireless Power Standard|Qi]] pad and Samsung watch chargers. The notebook treats electrical dependencies as part of technical continuity.
### Inventory-method lineage
Packaging label → model/serial → interface/cellular/subscription identifiers → paired-device annotation → [[Asset Management]] → [[Configuration Management Database|CMDB]] → [[Personal Digital Twin]]. The final terms are later analytical frameworks for the notebook's manual method, not products asserted to have been used.
## Scanned_20260730-1946
### Graphical and architecture compatibility lineage
X11 libraries / `libxcb` → [[Wayland]] → [[XWayland]] compatibility; Intel `x86-64` applications → [[Rosetta 2]] → Apple silicon; 32-bit Windows applications → [[WOW64]] → 64-bit Windows.
### Device-access and firmware lineage
Programmable USB ([[Cypress EZ-USB FX2]]) → firmware loader → [[Device Firmware Upgrade|DFU]] → FUSE-mounted device services → usbmuxd / iFuse / USB SSH → runtime instrumentation. Network boot adds [[iPXE]] → QEMU/libvirt as a parallel execution route.
### Pocket-computing and emulation lineage
[[Dingoo A320]] → [[Dingux]] → [[OpenDingux]] → [[BittBoy]] / [[PocketGo]] custom-firmware ecosystems → DOS, console emulators, game-engine ports, media server, and terminal file manager. One pocket device becomes a host for many historical machines.
### Legacy boot and portable-media lineage
FAT16 and BIOS limits → [[Ontrack Disk Manager]] overlays → [[NTLDR]] / BCD / [[EasyBCD]] → [[Windows Preinstallation Environment|WinPE]] recovery; USB virtual CD-ROM → [[U3 Launchpad]] → launch/remove tooling.
### Mobile analysis lineage
Device transport/decryption → [[JADX]] / [[APKTool]] / Hopper → [[Frida]] / Cycript → Objection / RMS / fridump → Burp/ZAP and SSL Kill Switch → MobSF / MASTG → root/jailbreak substrates. This is a verification workflow, not proof it was executed against any named target.
### Dependency and supply-chain lineage
MacPorts/Homebrew → zlib / XZ / Zstandard / libxcb / WebP / Ghostscript / D-Bus → manual dependency graph → [[Software Bill of Materials|SBOM]] and provenance. The 2024 XZ backdoor is retrospective validation of the dependency-risk model, not a predicted event.
### Identity and infrastructure lineage
GUID/UUID → distributed identity graph → edge/IoT policy → contact tracing, banking, industrial systems, and dual-use governance. Proximity sensing → encounter graph → identity resolution → classification → policy enforcement describes the possible transition from bounded health notification to [[Social sorting]]. Convergence of reusable technical primitives does not establish one operator or coordinated platform.
### Exposure-notification lineage
Bluetooth Low Energy proximity → rotating pseudonymous identifiers → Apple/Google Exposure Notification API in May 2020 → Exposure Notifications Express (`EN Express` / `ENX`) in September 2020 → Apple termination of Exposure Notifications in September 2023. EN Express reduced public-health implementation burden; it was not a separate tracking protocol and did not inherently add GPS, blockchain, or 5G.
### Contact-tracing architecture branches
Traditional interviews and case investigation → digital assistance. From there, architectures diverge: decentralized on-device exposure matching ([[Google-Apple Exposure Notification]]), authority-mediated Bluetooth encounter disclosure (BlueTrace/OpenTrace), and location/venue systems using GPS, QR, cellular, travel, or other records. Risks and claims must follow the specific branch rather than treating all “contact tracing” as one system.
## Scanned_20260730-1913
### Workflow-orchestration lineage
Point-to-point manual task → [[Zapier]] / [[Integromat]] → [[Make]] → [[Microsoft Power Automate]] / [[Tray.ai]] → enterprise [[Integration Platform as a Service|iPaaS]] and [[Robotic Process Automation|RPA]]. The page compares control scope, not merely brands.
### Apple and enterprise-management lineage
Apple ID / iCloud continuity → configuration profiles → managed Wi-Fi and SSO → ACME/SCEP certificate enrollment → TCC and web-content policy → Jamf Trust / PaperCut / Nudge / XCreds → fleet governance. Profile names evidence an administration vocabulary, not unauthorized enrollment.
### Account and domain lineage
EarthLink / AOL / CompuServe / MSN / AIM / ICQ → registrar and DNS control through Network Solutions, Tucows, and GoDaddy → Google Workspace / Microsoft identities → modern recovery and billing continuity.
### Privacy-interface lineage
Platform-native interface → Nitter / Invidious / Bibliogram → UntrackMe routing → OpenStreetMap and privacy search/browser layers. Control shifts from the upstream platform interface toward a user-selected mediation layer.
### Loyalty and commerce lineage
Physical loyalty card → Key Ring / Stocard / FidMe → AwardWallet / CardPointers / TripIt Pro → cross-merchant points, travel, cashback, and digital-wallet aggregation.
### Satellite-observation lineage
Starlink deployment → NORAD catalog identity → public orbital tracking → launch/decay history. A stable catalog identifier allows an ephemeral spacecraft record to persist after reentry.
## Scanned_20260730-1845
### Generative-interface lineage
OpenAI account/free credit → Playground → GPT-3 / DALL·E → API → natural-language query as platform → later model-mediated tool and service orchestration. The final step is a retrospective lineage interpretation, not a claim that a full agent system was deployed.
### Cloud-to-publication lineage
Oracle cloud instance → Ubuntu → LAMP → SFTP → custom domain → Webflow staging/custom-domain publication → Weglot localization → social, commerce, image, location, analytics, and email-marketing distribution.
### Web and institutional trust lineage
DNS apex / NS1 / Verisign → Let's Encrypt / ISRG Root X1 → RSA / PKCS #1 → OpenID / Okta / SMS OTP → CAC / ECA / PIV → RealMe and institutional identity/evidence portals.
### Account-incident lineage
Alias inventory → permission and data-path review → block list → complaint path → clean-device baseline → SIM/OTP recovery → controlled domain-role addresses. Each step narrows uncertainty but does not by itself establish compromise.
### Knowledge-graph lineage
Platform list → company ownership/history graph → typed identity and account edges → institutional evidence registry → [[Personal Knowledge Graph]] with provenance and confidence.
## Scanned_20260730-2016
### Telephone-identity lineage
Physical subscriber number → SIM/eSIM and carrier account → cloud number through [[Google Voice]] → geographic or project assignment → telephone number as authentication and recovery factor.
### Platform-identity lineage
Legacy provider email → Gmail project aliases → [[Google Account]] and Google Fi root identity → [[Apple Account]] alias continuity across `mac.com`, `me.com`, and `icloud.com` → social and domain recovery dependencies.
### Recovery lineage
Password notebook → multiple aliases and numbers → crossed-out obsolete factors → explicit “old Recovery patterns” → service-by-service reconstruction → proposed account dependency graph with time-stamped status and revocation.
### Asset-custody lineage
Bank and payment app → brokerage and exchange account → loyalty identity → [[Self-Custody Wallet]] → [[Mnemonic Seed Phrase]] as direct cryptographic asset-control key.
### Creative-production lineage
Instagram posting reminder → renewed writing → Bitbucket/Pastebin → Clubhouse and music spaces → microphones, monitor, iPhone, Watch, and hotspot → The Sandbox/NFT tools as virtual production and property interfaces.
### Architectural maturation
Account list → hand-built recovery graph → [[Continuity Engineering]] → explicit [[Identity Economy]]. The notebook moves from remembering credentials to modeling the economic and operational dependencies of a distributed person.
## Scanned_20260730-1830
### Alliance-sharing lineage
Postwar U.K.–U.S. cooperation → [[UKUSA Agreement]] → [[Five Eyes]] → ECHELON-associated distributed collection and sharing → later Nine/Fourteen Eyes labels. Five Eyes is the more formal core; expanded labels must not be treated as equivalent treaties without source-specific evidence.
### Signals-intelligence taxonomy
[[Signals Intelligence|SIGINT]] → [[Communications Intelligence|COMINT]] / [[Electronic Intelligence|ELINT]] / FISINT → agency and collection-system specializations.
### Collection-position lineage
Close-access and network collection → [[Room 641A]] infrastructure evidence → [[STELLARWIND]]/President's Surveillance Program history → [[PRISM Surveillance Program|PRISM]] downstream provider collection under [[FISA Section 702]]. This is a comparison lineage, not one continuous program.
### Legal-authority lineage
1978 FISA and FISC → post-2001 warrantless-surveillance controversy → [[FISA Amendments Act of 2008]] and Section 702 → 2018 six-year renewal → 2024 RISAA reforms → June 12, 2026 statutory lapse.
### Oversight and query-governance lineage
Ex parte application → court review → amicus participation → certification and procedures → provider directive → agency query controls and audit → compliance opinion → declassification → legislative sunset debate.
## Scanned_20260730-1825
### Platform and jurisdiction lineage
Huawei device ecosystem → [[HarmonyOS]] → distributed operating environment → [[Digital Sovereignty]]; Ripple/XRP → U.S. regulatory conflict → corporate relocation question → Collision and international fintech-policy network.
### Autonomous cloud lineage
Oracle Linux → [[Oracle Autonomous Linux]] → automated fleet patching; Oracle Database → [[Oracle Autonomous Database]] → serverless/shared and dedicated deployment → private endpoint and [[Data Isolation]]. IBM's Red Hat acquisition and AWS database products appear as comparison branches, not a single merged lineage.
### Biological inference lineage
Conversational fragment about an internship → flies → [[Drosophila melanogaster]] → [[Model Organism]] → longevity/fertility trade-offs → carefully bounded translational relevance to human aging.
### Social-impact platform lineage
CyberGrants, EveryAction, Network for Good, Social Solutions, and related products → [[Bonterra]] consolidated identity → [[Social Impact Technology]].
### Corporate and product lineage
Plantronics → Poly → HP; Anders Hejlsberg → Borland/Turbo Pascal/Delphi → Microsoft/C#. The Commodore, Borland, AT&T, and personal-name branches on PDF page 18 remain unresolved and are not normalized into a verified succession.
### Conversational-method lineage
Respectful facilitation → [[Holding Space]] → observed repeated [[Interruption]] → [[Journal - Manners and Speaking Space]] → archive-level recognition of [[Premature Closure]].
## Scanned_20260730-1958
### KDE and desktop-resource lineage
[[KDE]] → [[Akonadi]] personal-information data layer → [[KIO]] resource/protocol abstraction → [[Konqueror]] browser/file manager. [[Xfce]] → [[xfdashboard]] forms a separate desktop branch; [[Cockpit]] supplies browser-based server administration rather than a desktop shell.
### Virtual laboratory lineage
[[Kernel-based Virtual Machine|KVM]] → [[GNOME Boxes]] desktop VM interface; KVM and network appliances → [[EVE-NG]] network-emulation topology. These are distinct interfaces over virtual execution and network simulation.
### Recovery-media and pre-OS lineage
[[grub4dos]] bootloader substrate → [[Easy2Boot]] multiboot environment → recovery and diagnostic payloads. Dell Latitude firmware → Intel MEBx management configuration and Intel RST/RAID storage presentation.
### Organizational identity lineage
Owned domain → GoDaddy/Afternic registrar and marketplace → DNS/hosted mail → [[Google Workspace]] and [[Google Admin Console]] → role mailbox and platform recovery. Apple business identity → [[Apple Business Manager]] → organizational device/account authority.
### Managed-device lineage
Physical Chromebook transfer → retained `chisd.net` enrollment → [[ChromeOS]] under institutional management. The notebook correctly exposes the gap between possession and administrative deprovisioning.
### Device-name translation lineage
Google retail model → Android hardware codename `blueline` → account/dashboard label Nexus 5. The conflicting names are preserved as separate layers rather than normalized into one false device identity.
### Financial and civic-platform lineage
[[XRP]] → [[XRP Ledger]] → exchange/regulatory context; DemocracyOS and Open Collective → civic participation and fiscal-hosting layer → Council of Europe and World Justice Project governance context.
## Scanned_20260803-1201
### Laptop memory and service lineage
[[Lenovo ThinkPad T440s]] → Lenovo type/serial identity → [[Field Replaceable Unit|FRU]] `03X6656` → [[Samsung M471B5173DB0-YK0]] → [[DDR3L SDRAM]] in [[Small Outline Dual In-line Memory Module|SO-DIMM]] format.
### Financial-token lineage
Bank receipt and EMV fields → temporary instant-issue debit → pharmacy-routing card → merchant-specific [[Closed-loop Stored-value Card|stored value]]. Each token has a different issuer, authority scope, and evidentiary meaning.
### Institutional-access lineage
USPS key and identity verification → FBI/SAPD contact and case records → REDACTED → LAZ valet custody token. Physical tokens externalize temporary rights and later support event reconstruction.
### Robotics image lineage
### Devonshire wireless-discovery overlay
Paper map → marked location beyond fence behind shed → backpack inside garbage can plus powered, running wireless router → primary SSID `RedRider` plus additional SSID `REDACTED` → unresolved hardware, uplink, configuration, and custody record.
See [[Event - Devonshire Backyard Router Discovery]], [[Router - RedRider and REDACTED SSIDs]], and [[Service Set Identifier]].
## macOS transitional-trust lineage
[[InstallESD.dmg]] → [[BaseSystem.dmg]] → Apple-entitled installation transition → [[System Integrity Protection|SIP]]-protected mutation → [[Foundational Persistence]].
[[Migration Assistant]] → privileged systemmigrationd process → [[Perl]] or Bash interpreter state → [[CVE-2023-32369|Migraine]] → [[Interpreter-Mediated Privilege Transduction]].
[[Signed System Volume|SSV]] narrows the historical image-substitution model by binding system content into a cryptographically sealed boot chain. [[XNU]] and [[Mach]] remain separate kernel-level authorities requiring separate evidence.
## Cognitive-cyber defensive technology lineage
Campaign discovery through [[DARPA INCAS|INCAS]] + media analysis through [[DARPA SemaFor|SemaFor]] + propagation modeling through [[DARPA SocialSim|SocialSim]] → [[Modeling Influence Pathways|MIP]] → [[Information-Environment Radar]].
AI robustness through [[DARPA GARD|GARD]] → recurring operational red-teaming through [[DARPA SABER|SABER]] + autonomous vulnerability discovery through [[AI Cyber Challenge|AIxCC]] + attacker-bias defense through [[IARPA ReSCIND|ReSCIND]] → [[AI Immune Systems]].
Media forensics + [[C2PA]] provenance manifests + [[Content Credentials]] user presentation → [[Truth-Chain Infrastructure]]. Provenance authenticates claims and custody; it does not independently establish truth.