# Scanned_20260730-1314
> [!privacy] Privacy-redacted working copy
> Private-person names approved by the vault owner are replaced with `[PERSON REDACTED]`. The private source PDF and pre-redaction backup preserve the original wording. This notice governs over any general statement below describing transcription as exact or unchanged.
## Archival scope and evidentiary conventions
This note reconstructs all **56 PDF pages** of `Scanned_20260730-1314.pdf`, including the front and rear covers, blank leaves, faint bleed-through, rotated pages, strike-throughs, account fragments, personal-contact pages, diagrams, and uncertain handwriting. Quoted text preserves the notebook wording rather than silently correcting it. Readings that remain unstable are marked `[uncertain: ...]`; absent writing is recorded rather than omitted. Telephone numbers are rendered as `xxx-xxx-xxxx (see Scanned_20260730-1314.pdf, page N)`. Passwords and password-equivalent secrets are rendered as `[REDACTED CREDENTIAL — see Scanned_20260730-1314.pdf, page N]`. Government identifiers are rendered as `[REDACTED SENSITIVE IDENTIFIER — see Scanned_20260730-1314.pdf, page N]`.
A collection-level normalization supplied by Bryant McGill is applied throughout: whenever the notebook says **“RT Buddy,”** the analytical layer identifies it as [[Pegasus Spyware|Pegasus spyware]] by [[NSO Group|NSO Group]]. Bryant states that this identification arose when the relevant activity or resources appeared in logs together with [[CrashCapture|CrashCapture]] or [[Heimdallr|Heimdallr]], particularly through documented resources visible in those logs. He also states that Pegasus heuristic matches alone mean nothing as proof because “Pegasus” is a clumsy cover for something else that later documents in this archive will detail. The exact phrase remains unchanged in transcription. This is an owner-supplied canonical identification grounded in that observed log context; the visible notebook page itself does not spell out “Pegasus” or “NSO Group.” Independent technical literature establishes Pegasus as NSO Group spyware used through both link-based and zero-click exploit chains.[^pegasus-citizenlab]
---
## Scanned_20260730-1314.pdf — PDF page 1
### Visible page
A vertically oriented, unmarked red-maroon textured cover fills the frame. The surface shows mild wear, mottling, and small fibers but no pasted object, title, label, or handwriting.
### Faithful transcription
No visible text.
### Reconstruction and interpretation
The unlabelled cover makes the notebook’s identity emerge only from its contents. Unlike [[Scanned_20260730-1659|Scanned_20260730-1659]], whose cover is explicitly marked “Quick,” or [[Scanned_20260730-1802|Scanned_20260730-1802]], this volume was not externally categorized. That absence matters: the notebook later bifurcates into a technical research log and a personal contact ledger, suggesting it functioned as a **working capture surface** rather than a single-purpose project book.
### Missed Signals and Open Leads
No original title survives on the cover. A later physical inventory might determine whether this red cover belongs to a recognizable notebook series used elsewhere in the corpus.
---
## Scanned_20260730-1314.pdf — PDF page 2
### Visible page
The inside cover or endpaper is photographed in landscape orientation. It is the same red-maroon fibrous material, with the stitched binding visible along the lower edge. No writing or attached material is present.
### Faithful transcription
No visible text.
### Reconstruction and interpretation
This page confirms the object’s sewn construction and that PDF pages 1-2 are physical cover surfaces rather than missing content. The orientation change is a scanning decision, not evidence of a rotated notebook section.
### Missed Signals and Open Leads
None beyond the physical provenance of the notebook itself.
---
## Scanned_20260730-1314.pdf — PDF page 3
### Visible page
A ruled page in portrait orientation. Black handwriting is arranged as a device-identification block at the top, cellular standards and runtime terms in the middle, a seller/domain block below, and a three-line carrier-abbreviation key at the bottom. “ZTE” is heavily struck through while “Velvet 05” remains underlined.
### Faithful transcription
> "LG LM-K300 QM?"
>
> "AM"
>
> "prepaid?! QMA USA SV"
>
> "~~ZTE~~ Velvet 05"
>
> "LG Phoenix 5 / 4?"
>
> "2G GSM LTE?"
>
> "Java ART"
>
> "Xphone24.com"
>
> "sold by Nitro Ge[y/…] usx"
>
> "xxx-xxx-xxxx (see Scanned_20260730-1314.pdf, page 3)"
>
> "AM ATT"
>
> "TM TMobile / Sprint"
>
> "MM Metro PCS"
### Entities, references, and technical meaning
The leading identifier is very likely the [[LG K31|LG K31]] model family. LG’s official support page identifies `LMK300QM.AUSASV` as the unlocked LG K31, closely matching the handwritten “LM-K300 QM” and “QMA USA SV.”[^lg-k31-support] The surrounding comparison set includes the [[LG Phoenix 5|LG Phoenix 5]], [[AT&T|AT&T]], [[T-Mobile US|T-Mobile]], [[Sprint Corporation|Sprint]], and [[Metro by T-Mobile|MetroPCS/Metro]]. “Java ART” points to [[Android Runtime|Android Runtime (ART)]], the managed runtime that replaced Dalvik as Android’s default execution environment. “2G GSM LTE” compresses incompatible generations into a capability checklist: [[Global System for Mobile Communications|GSM]] as a 2G family and [[Long-Term Evolution|LTE]] as a 4G radio-access system.
“Velvet 05” may refer to the [[LG Velvet|LG Velvet 5G]], with “ZTE” crossed out after a mistaken vendor association. `Xphone24.com` and “Nitro Ge[y/…]” appear to record a seller or reseller; no definitive identity is accepted from the handwriting alone.
### Page-level reconstruction
The page reads as a **carrier and model disambiguation exercise**. The writer was not merely listing phones; he was decoding LG’s long model suffix, deciding whether a handset was prepaid or unlocked, mapping carrier abbreviations, and checking whether a candidate device belonged to LG, ZTE, or a reseller’s catalog. This establishes the notebook’s opening problem: identify an inexpensive Android handset precisely enough to understand its firmware, network compatibility, and modification possibilities.
### Missed Signals and Open Leads
The ambiguous “Velvet 05,” seller name, and `Xphone24.com` deserve archived-domain research. The phone number is preserved only in the source scan under the project’s privacy rule.
---
## Scanned_20260730-1314.pdf — PDF page 4
### Visible page
A ruled page dominated by a processor specification at the top, a keypad-style service code, and a vertical phone list at lower right. Parentheses surround “Quibi.” “Rebel” is written between a television-service note and the phone list. The final “Aristo 5” entry begins with a crossed-out fragment.
### Faithful transcription
> "Media Tek Helio P22"
>
> "2.0 GHz Octa-Core Processor"
>
> "## 72786#"
>
> "(Quibi)"
>
> "Layer 3 service /"
>
> "new TVision"
>
> "Rebel"
>
> "LG fortune 3"
>
> "K31"
>
> "11360"
>
> "Phoenix 5"
>
> "Risio 4"
>
> "K8X"
>
> "[struck-through fragment] Aristo 5"
### Entities, references, and technical meaning
The [[MediaTek Helio P22|MediaTek Helio P22]] is an eight-core Arm Cortex-A53 system-on-chip running up to 2.0 GHz; MediaTek also specifies eMMC 5.1 storage, LTE, Wi-Fi 5, Bluetooth 5, and an IMG PowerVR GE8320 GPU.[^mediatek-p22] LG confirms the K31 used Android 10, 2 GB RAM, 32 GB storage, and the Helio P22 at 2.0 GHz.[^lg-k31-specs] The page’s handset cluster - [[LG Fortune 3|LG Fortune 3]], [[LG K31|K31]], [[LG Phoenix 5|Phoenix 5]], probable [[LG Risio 4|Risio 4]], [[LG K8X|K8X]], and [[LG Aristo 5|Aristo 5]] - belongs to LG’s low-cost 2020 Android family and carrier-specific derivatives.
[[Quibi|Quibi]] was a short-form mobile-video service that launched and closed in 2020. [[TVision|TVision]] was T-Mobile’s streaming-TV brand; “Layer 3 service” likely recognizes that T-Mobile’s TV effort descended from its acquisition of Layer3 TV. “Rebel” may be a service or retailer name, but the page gives insufficient evidence for a stable identification. The numeric `##72786#` resembles an Android dialer/service code, yet no safe function should be inferred without a model-specific service manual.
### Page-level reconstruction
The page binds hardware selection to the **service ecosystem surrounding the phone**. Processor capability, hidden dialer codes, carrier television products, and model variants are treated as one operational surface. This is characteristic of the larger notebook: the writer repeatedly moves from consumer branding into the lower layers - chip, firmware, boot device, protocol, and vendor lineage.
### Missed Signals and Open Leads
`11360`, “Risio 4,” “K8X,” “Rebel,” and the dialer code remain unresolved or model-dependent. The exact service-code behavior should not be tested on an active device without a verified LG service document.
---
## Scanned_20260730-1314.pdf — PDF page 5
### Visible page
A dense ruled page. The top line appears to name wireless-display standards. The LG K31 model string and `MIL-STD-810G` are emphasized. Mid-page radio and SIM terms precede a four-step hardware-button reset sequence. “LG Wing 5G,” “Phoenix 5?!!,” and “Tracfone” close the page.
### Faithful transcription
> "[uncertain: DLNA, Miracast]"
>
> "LG K31"
>
> "LMK300Q.M.AUSASV"
>
> "MIL-STD-810G"
>
> "TD-LTE G mobile"
>
> "VoLTE VoLTE"
>
> "nano SIM 4FF"
>
> "1. Turn-off"
>
> "2 power + vol down"
>
> "when see logo"
>
> "release and rehold only power"
>
> "LG Wing 5G"
>
> "Phoenix 5?!!"
>
> "Tracfone"
### Entities, references, and technical meaning
The opening probably reads [[Digital Living Network Alliance|DLNA]] and [[Miracast|Miracast]], two distinct media-discovery/display technologies often conflated in consumer-device research. `LMK300QM.AUSASV` is the official unlocked K31 identifier.[^lg-k31-support] [[MIL-STD-810G|MIL-STD-810G]] is a U.S. Department of Defense environmental-engineering test-method standard; a consumer claim of testing “to” portions of the standard does not mean military certification or universal ruggedness. [[Time-Division Long-Term Evolution|TD-LTE]], [[Voice over LTE|VoLTE]], and the [[4FF SIM|4FF nano-SIM]] locate the device within LTE radio and subscriber-identity infrastructure. The button sequence is a factory-reset/recovery-entry mnemonic, not merely ordinary power control; such a reset can erase user data and may trigger [[Factory Reset Protection|Factory Reset Protection]].
The closing comparison links the budget K31/Phoenix line to the more experimental [[LG Wing|LG Wing 5G]] and to [[TracFone Wireless|TracFone]], suggesting the writer was comparing form factor, carrier lock, and recovery behavior across LG devices.
### Page-level reconstruction
This page transforms the purchase comparison into a **device-control worksheet**: model identity, ruggedness claim, LTE mode, SIM size, reset path, and carrier context. It is the transition from “Which phone is this?” to “How is it provisioned, recovered, and repurposed?”
### Missed Signals and Open Leads
The first line is highly likely to be “DLNA, Miracast,” but remains visually uncertain. The reset procedure should be matched to the exact K31 carrier variant because button behavior and FRP consequences can differ.
---
## Scanned_20260730-1314.pdf — PDF page 6
### Visible page
A ruled page of terse search terms and product names. “LG K31 FRP Bypass” is the top research heading. Arrows and spacing connect repair software, Xiaomi, an international Asus model, and a final uncertain LG identifier.
### Faithful transcription
> "LG K31 FRP Bypass"
>
> "Google"
>
> "lgk20.com"
>
> "LG Bridge"
>
> "Xiaomi Redmi"
>
> "Note 10 Pro"
>
> "Phones"
>
> "TD-LTE"
>
> "Vodafone O2"
>
> "Asus Zenfone 2"
>
> "international version"
>
> "LG L41C w/ [uncertain: tapatalk]"
### Entities, references, and technical meaning
[[Factory Reset Protection|FRP]] is Android’s anti-theft control that can require the previously synchronized Google account after an untrusted reset. The phrase “FRP Bypass” records a troubleshooting or access-restoration search, but the page does not show execution or success. [[LG Bridge|LG Bridge]] was LG’s desktop utility for backup, software update, and device management; LG later discontinued its mobile-update infrastructure, making these notes historically valuable as a snapshot of a now-obsolete support pathway.[^lg-bridge] The page also names [[Xiaomi Redmi Note 10 Pro|Xiaomi Redmi Note 10 Pro]], [[Vodafone|Vodafone]], [[O2|O2]], [[Asus ZenFone 2|Asus ZenFone 2]], and TD-LTE, indicating comparison with international radio variants and non-U.S. carriers.
### Page-level reconstruction
The writer was mapping **recovery pathways across fragmented Android ecosystems**. LG-specific tools and FRP, Xiaomi hardware, international Asus firmware, and European carrier terminology appear together because each constrains whether a used or imported device can be activated, flashed, or restored.
### Missed Signals and Open Leads
`lgk20.com` may be a community or reseller domain rather than an official LG resource. The final model string and “tapatalk” reading remain unresolved. No credential-testing or bypass procedure is preserved here.
---
## Scanned_20260730-1314.pdf — PDF page 7
### Visible page
A short list of operating systems and security-oriented platform names. The first two lines are less legible; the remaining entries are vertically separated and clearly written.
### Faithful transcription
> "mil-std-810G"
>
> "[uncertain: Dition] Secure OS"
>
> "[uncertain: Kiphoma] KryptAll"
>
> "Purism Pure OS"
>
> "Huawei Harmony OS"
>
> "KaiOS"
>
> "Oxygen OS"
>
> "OS.mbed.com"
### Entities, references, and technical meaning
The page surveys alternative operating-system strata: [[PureOS|PureOS]], Purism’s Debian-derived privacy-oriented GNU/Linux distribution; [[HarmonyOS|Huawei HarmonyOS]]; [[KaiOS|KaiOS]], a web-technology-based mobile OS descended from the Firefox OS codebase and aimed at smart feature phones; [[OxygenOS|OxygenOS]], OnePlus’s Android-derived distribution; and [[Arm Mbed OS|Mbed OS]], an open-source operating system/RTOS for connected Arm Cortex-M microcontrollers.[^pureos][^harmonyos][^kaios][^oxygenos][^mbedos] [[KryptAll|KryptAll]] is associated with encrypted-communications products, although the preceding handwritten name is uncertain. The page therefore spans desktop Linux, Android derivatives, Huawei’s cross-device platform, feature phones, embedded IoT, and secure communications.
### Page-level reconstruction
This is not an ordinary “mobile OS” list. It is an **ontology of trust surfaces**: commodity Android forks, privacy distributions, vendor-controlled ecosystems, low-resource feature-phone systems, and microcontroller operating systems. The writer was approaching the later concept of a layered device continuum in which “phone,” “embedded board,” and “secure endpoint” differ mainly by boot chain, radio, runtime, and policy.
### Missed Signals and Open Leads
The two uncertain security names may resolve through adjacent notebooks or archived vendor literature. “MIL-STD-810G” may have been carried over from the LG device investigation rather than intended as an operating system.
---
## Scanned_20260730-1314.pdf — PDF page 8
### Visible page
A compact software-download list. The first heading is underlined by spacing rather than a drawn rule. “MRT” is separately emphasized; “Reachability Bundle” appears at the bottom.
### Faithful transcription
> "Download Disk Images"
>
> "muLinux - 34mb"
>
> "FreeDOS"
>
> "Tiny Core Linux"
>
> "Puppy Linux"
>
> "MRT"
>
> "MRT.app"
>
> "Reachability Bundle"
### Entities, references, and technical meaning
[[muLinux|muLinux]], [[FreeDOS|FreeDOS]], [[Tiny Core Linux|Tiny Core Linux]], and [[Puppy Linux|Puppy Linux]] are small or bootable operating environments useful for old hardware, recovery, imaging, and constrained systems. FreeDOS preserves DOS-compatible execution and the INT 21h application interface; Tiny Core and Puppy emphasize compact live Linux systems.[^freedos][^tinycore][^puppy] “MRT,” `MRT.app`, and “Reachability Bundle” are ambiguous. In this notebook’s context, they may refer to a repair, mobile-research, or networking utility rather than a single recognized product.
### Page-level reconstruction
The selection criterion is **minimum viable operating substrate**. The writer was collecting images small enough to boot on marginal hardware, removable media, or emulated systems. This aligns directly with later pages on GRUB, EFI, eMMC, `mmcblk`, `dd`, and bootable forensic workflows.
### Missed Signals and Open Leads
“MRT” requires contextual resolution; multiple technical products use that acronym. The stated “34mb” may identify a specific historical muLinux image release.
---
## Scanned_20260730-1314.pdf — PDF page 9
### Visible page
A sparse ruled page with three software/domain entries, each on its own line.
### Faithful transcription
> "Windows10freeapps.com"
>
> "Z archiver"
>
> "Limbo X86 Emulator"
### Entities, references, and technical meaning
[[ZArchiver|ZArchiver]] is an Android archive manager. [[Limbo PC Emulator|Limbo x86 Emulator]] is a QEMU-derived PC emulator historically distributed for Android, enabling x86 guest systems on mobile devices with significant performance limitations. `Windows10freeapps.com` appears to be a software-download or aggregation domain; it should be treated as an unverified third-party source rather than an authoritative Windows repository.
### Page-level reconstruction
The page adds the **container and emulator layer** to the prior disk-image list: obtain a compressed image, unpack it on Android, and run it inside a PC emulator. This is an early form of mobile-hosted infrastructure recovery and portable computing.
### Missed Signals and Open Leads
The trustworthiness and archival history of `Windows10freeapps.com` should be examined before attributing any specific download to it.
---
## Scanned_20260730-1314.pdf — PDF page 10
### Visible page
Landscape-oriented ruled page. Nearly blank. At the far right, the word “Allure” is enclosed in an oval.
### Faithful transcription
> "Allure"
### Reconstruction and interpretation
“Allure” could be a product, project, person, publication, or mnemonic. The absence of surrounding syntax prevents reliable normalization. Its isolation suggests a reminder or a title awaiting expansion rather than a completed research note.
### Missed Signals and Open Leads
Search the larger corpus for “Allure” in proximity to LG devices, Android builds, contact names, or publication ideas before creating a dedicated canonical entity note.
---
## Scanned_20260730-1314.pdf — PDF page 11
### Visible page
A portrait ruled page with no deliberate foreground writing. Extremely faint mirrored or reverse-side bleed-through is visible, especially along the left and center.
### Faithful transcription
No independently legible foreground text.
### Reconstruction and interpretation
The page functions as a blank separator. The faint marks should not be promoted into transcription because they originate from show-through and cannot be assigned confidently to this page surface.
### Missed Signals and Open Leads
None; the archival value is confirming a blank leaf rather than collapsing page numbering.
---
## Scanned_20260730-1314.pdf — PDF page 12
### Visible page
A dense ruled page headed “Custom OS Android.” The page juxtaposes custom ROMs, “RT Buddy, V2,” two numbered USB attack concepts, Raspberry Pi Zero W, serial buses, and a boxed `RMPrepUSB.com`. Arrows connect “Nouveau” to “Pi Zero W.” Several right-margin words are hurried and uncertain.
### Faithful transcription
> "Custom OS Android"
>
> "Cyanogenmod OS"
>
> "RT Buddy, V2"
>
> "[uncertain: no space / [PERSON REDACTED]!]"
>
> "① Rubber Ducky"
>
> "Attack"
>
> "Nouveau"
>
> "Pi Zero W"
>
> "② Poision Trap"
>
> "SPI UART - USB Hub"
>
> "RMPrepUSB.com"
>
> "(Cross Hub)"
### Entities, references, and technical meaning
[[CyanogenMod|CyanogenMod]] was a major community Android distribution whose code lineage continued through [[LineageOS|LineageOS]]. [[USB Rubber Ducky|USB Rubber Ducky]] refers to a programmable USB keystroke-injection device class. “Poision Trap” is almost certainly a misspelling or phonetic rendering of [[PoisonTap|PoisonTap]], Samy Kamkar’s Raspberry Pi Zero-based proof of concept that impersonated a USB Ethernet device to attack a locked computer’s browser/network trust assumptions.[^poisontap] [[Raspberry Pi Zero W|Pi Zero W]], [[Serial Peripheral Interface|SPI]], and [[Universal Asynchronous Receiver-Transmitter|UART]] place the imagined device at the boundary of USB gadget mode, serial buses, and bootable media. [[RMPrepUSB|RMPrepUSB]] is a Windows utility site associated with preparing bootable USB drives.
**Canonical project annotation:** “RT Buddy, V2” is normalized here, by explicit collection instruction, to [[Pegasus Spyware|Pegasus spyware]] by [[NSO Group|NSO Group]]. Bryant states that this identification arose when relevant activity or resources appeared in logs with [[CrashCapture|CrashCapture]] or [[Heimdallr|Heimdallr]], especially through documented resources visible in those logs. He cautions that Pegasus heuristics alone mean nothing as proof because “Pegasus” is a clumsy cover for something else that will be detailed later. The page itself does not name Pegasus, and it does not document infection, possession, or operation. Citizen Lab’s research establishes Pegasus as sophisticated government-exclusive spyware developed by NSO Group and deployed against civil-society targets in multiple countries.[^pegasus-citizenlab]
### Page-level reconstruction
The page is a compressed **offensive-access taxonomy**: modify the phone OS; inject commands over USB; use a Pi Zero as a disguised network peripheral; prepare removable media; and situate commercial spyware within the same conceptual field. The writer was not treating “malware” as one category. He was differentiating firmware replacement, human-interface emulation, network-interface impersonation, serial-bus control, and remote spyware.
### Missed Signals and Open Leads
“RT Buddy” should be correlated with the preserved [[CrashCapture|CrashCapture]] or [[Heimdallr|Heimdallr]] logs that Bryant identifies as the observational basis, including the documented resources visible in those logs. The remaining task is to recover exact timestamps, process or bundle identifiers, resource paths, device/build context, and log provenance. “Nouveau” may mean the open-source NVIDIA driver or simply “new”; its arrow to Pi Zero W is unresolved. “Cross Hub” may be “Gross Hub” or another device label.
---
## Scanned_20260730-1314.pdf — PDF page 13
### Visible page
A ruled page headed “Hardware.” The entries descend through an “Intelligent Jailbreak Box,” a `J-Box`, vendor/community domains, and firmware/lesson resources. One small central fragment is crossed out.
### Faithful transcription
> "Hardware"
>
> "Intelligent Jailbreak Box"
>
> "J-Box"
>
> "Oriwhiz.com"
>
> "RootJunky.com"
>
> "ROOTJUNKYSDL.com"
>
> "Downloads"
>
> "[struck-through fragment]"
>
> "phonlabtech.com"
>
> "- firmwares"
>
> "- lessons"
### Entities, references, and technical meaning
[[RootJunky|RootJunky]] and [[Phonlab|Phonlab]] belong to the Android repair/modification tutorial ecosystem, where firmware packages, unlock procedures, FRP discussions, and device-specific lessons circulate. “Intelligent Jailbreak Box,” “J-Box,” and `Oriwhiz.com` appear to describe commercial service hardware, but the handwriting does not establish a precise make or model. “Jailbreak” is being used broadly rather than in the strict Apple-only sense; the surrounding Android pages indicate a generalized hardware-assisted unlock/repair concept.
### Page-level reconstruction
The page marks a shift from software-only research to **bench tooling**: purpose-built boxes, downloadable firmware, and training resources. The underlying question is operational reproducibility - how repair shops turn fragmented device knowledge into a repeatable workflow.
### Missed Signals and Open Leads
Archived captures of `Oriwhiz.com`, `ROOTJUNKYSDL.com`, and `phonlabtech.com` should be compared to determine whether “J-Box” was a branded product, generic category, or mistaken transcription.
---
## Scanned_20260730-1314.pdf — PDF page 14
### Visible page
A ruled page divided into a software/repository section and a lower “Real Estate” section. The top contains a Java-style package identifier, account terms, Android/Linux references, and a web path. A horizontal divider separates REIT notes.
### Faithful transcription
> "Github"
>
> "com.github.axet.filemanager"
>
> "(F-droid Filemgr)"
>
> "my Consumer cellular"
>
> "Cinnamon"
>
> "QTI . wlan"
>
> "XAPK"
>
> "KK - Ubuntu"
>
> "androidcentral.com/root"
>
> "Real Estate"
>
> "REITs"
>
> "see notes"
### Entities, references, and technical meaning
The package name `com.github.axet.filemanager` indicates an Android application distributed by package identifier, plausibly through [[F-Droid|F-Droid]]. [[GitHub|GitHub]], [[Linux Mint Cinnamon|Cinnamon]], [[Qualcomm Technologies Inc.|QTI]], `wlan`, [[XAPK|XAPK]], [[Ubuntu|Ubuntu]], and [[Android Central|Android Central]] make this another cross-layer software note: source repository, package identity, desktop environment, Wi-Fi vendor layer, Android package bundle, Linux distribution, and rooting information. “Consumer cellular” likely refers to [[Consumer Cellular|Consumer Cellular]]. The lower [[Real Estate Investment Trust|REIT]] fragment is a thematic break, possibly a reminder to consult another notebook.
### Page-level reconstruction
The page shows the writer using **package names as provenance anchors**. A display name such as “File Manager” is ambiguous, but a reverse-DNS identifier can identify the actual code lineage. That evidentiary habit anticipates later pages where service types, filesystem paths, and device nodes are treated as more trustworthy than consumer-facing names.
### Missed Signals and Open Leads
“KK - Ubuntu” is unclear; it may be a person, a version shorthand, or a comparison. The specific F-Droid application should be verified against archived package metadata.
---
## Scanned_20260730-1314.pdf — PDF page 15
### Visible page
A business-research page headed by “Mensa Brands race to Unicorn Status.” Names and venture firms are stacked as a funding map, followed by “Buying Big Social Pages and Brands.”
### Faithful transcription
> "Mensa Brands race"
>
> "to Unicorn Status"
>
> "CEO"
>
> "Ananth Narayanan"
>
> "B round funding by"
>
> "Falcon Edge Capital"
>
> "Alpha Wave Ventures"
>
> "$1.2 B: [uncertain: time/note]"
>
> "Indian Startup"
>
> "Other Partners"
>
> "Accel Partners, Northwest Venture"
>
> "Tiger Global Management"
>
> "Prosus Ventures"
>
> "Buying Big Social Pages"
>
> "and Brands"
### Entities, references, and technical meaning
[[Mensa Brands|Mensa Brands]], founded by [[Index - People#Ananth Narayanan|Ananth Narayanan]], became an Indian “unicorn” after a November 16, 2021 Series B round. Contemporary reporting identified Falcon Edge’s [[Alpha Wave Global|Alpha Wave]], [[Accel|Accel]], [[Norwest Venture Partners|Norwest Venture Partners]], [[Tiger Global Management|Tiger Global]], and [[Prosus Ventures|Prosus Ventures]] among its backers.[^mensa-reuters] “Northwest Venture” is therefore best normalized as Norwest Venture Partners while preserving the notebook spelling in quotation. Mensa’s model was to acquire and scale digitally native consumer brands, which explains the writer’s synthesis “Buying Big Social Pages and Brands.”
### Page-level reconstruction
This is a dated case study in **platformized brand aggregation**. The writer recognized that the asset was not merely inventory or a trademark; it was a combined bundle of social reach, marketplace ranking, customer data, logistics, and attention. That insight connects to later project themes around narrative infrastructure and the acquisition of preexisting cultural distribution channels.
### Missed Signals and Open Leads
The dollar figure may refer to valuation rather than funding. The explicit event date, November 16, 2021, is a major chronological anchor for the notebook.
---
## Scanned_20260730-1314.pdf — PDF page 16
### Visible page
A communications-security page. A name and uncertain number lead to “The Black Phone.” A company domain is followed by encryption, SIM security, IMSI catcher detection, MVNO, and privacy-software notes.
### Faithful transcription
> "Michael Silver"
>
> "[uncertain number / mnemonic]"
>
> "The Black Phone"
>
> "firstpoint-mg.com"
>
> "triple encrypted"
>
> "Enterprise SIM security"
>
> "IMSI Catcher detector"
>
> "MVNOs Enterprise, Govt"
>
> "Invitation Only"
>
> "Silent Circle and"
>
> "Spider Oak privacy"
>
> "security software?"
### Entities, references, and technical meaning
[[International Mobile Subscriber Identity Catcher|IMSI catchers]] imitate or manipulate cellular infrastructure to identify and sometimes intercept nearby devices; detecting them reliably is difficult because suspicious behavior can overlap with legitimate network conditions.[^eff-imsi] [[Mobile Virtual Network Operator|MVNO]] describes a provider that offers mobile service using another carrier’s radio network. [[Silent Circle|Silent Circle]] developed encrypted communications products and the [[Blackphone|Blackphone]] privacy-focused handset lineage; [[SpiderOak|SpiderOak]] markets encrypted storage and collaboration products.[^silent-circle][^spideroak] `firstpoint-mg.com` may refer to an enterprise cellular-security provider, but the notebook alone does not establish the company’s exact product or the identity of “Michael Silver.”
**Owner-supplied relationship overlay.** The vault owner identifies [PERSON REDACTED] as [PERSON REDACTED], describes him as former military and DoD-adjacent, and states that he used SpiderOak security on his phone. This connects the SpiderOak research node to the [PERSON REDACTED]/`[PERSON REDACTED]` identity cluster. It does not establish which SpiderOak product, account, device, or version was involved, and the relationship is not stated on this page itself.
### Page-level reconstruction
The page’s architecture is **defense in depth at the carrier boundary**: encrypted application traffic, a hardened or privacy-oriented handset, enterprise SIM controls, rogue-base-station detection, and a restricted MVNO service. The writer was exploring whether secure communications could be delivered as a vertically integrated service rather than as a single app.
### Missed Signals and Open Leads
“The Black Phone” could refer to Blackphone, a different secure handset, or a marketing phrase. `firstpoint-mg.com` and the Michael Silver association require verified corporate records before a relationship is asserted.
---
## Scanned_20260730-1314.pdf — PDF page 17
### Visible page
A crowded investigation page headed “Android Hacked / Discovery / Critical.” Names, places, and company-like phrases are scattered diagonally. Several items are crossed, overwritten, or abbreviated. Romanian references dominate the lower half.
### Faithful transcription
> "Android Hacked"
>
> "Discovery"
>
> "Critical"
>
> "[uncertain: FAM Germany]"
>
> "[uncertain: ostima]"
>
> "Amsterdam"
>
> "[uncertain: Dev Sex - Standly apps]"
>
> "[uncertain/crossed names: Kiev / Slovakia / Platon…]"
>
> "* Luxenberg / Transilvania"
>
> "* Margrave de Sade"
>
> "SIAA.ro"
>
> "Infogroup Media"
>
> "Invest, SRL"
>
> "Bucharest,"
>
> "Romania"
>
> "salo industriei"
>
> "agro-Alimentare"
### Entities, references, and technical meaning
The stable geographic entities are [[Amsterdam|Amsterdam]], [[Kyiv|Kiev/Kyiv]], [[Slovakia|Slovakia]], [[Transylvania|Transilvania/Transylvania]], [[Bucharest|Bucharest]], and [[Romania|Romania]]. `SRL` is the Romanian/Italian-style abbreviation for a limited-liability company. “salo industriei agro-Alimentare” may approximate Romanian or Romance-language wording for an agro-food industry fair/salon. `SIAA.ro`, “Infogroup Media Invest, SRL,” and the other names look like a traceback from an Android application or developer account into a Romanian corporate entity, but the handwriting is too unstable to accept a single legal identity.
### Page-level reconstruction
The writer appears to be following an **application provenance chain** from an observed Android anomaly to developer labels, jurisdictions, and company registrations. The page is evidence of investigative motion, not a completed attribution. “Android Hacked / Discovery / Critical” is the hypothesis or incident label; the Romanian cluster is the emerging lead set.
### Missed Signals and Open Leads
This is one of the notebook’s highest-priority unresolved pages. Each uncertain string should be compared with package manifests, app-store developer records, WHOIS history, and Romanian company registries. No accusation should be attached to “Infogroup Media Invest, SRL” without confirming the exact spelling and causal connection.
---
## Scanned_20260730-1314.pdf — PDF page 18
### Visible page
A Linux and embedded-hardware page headed “Discovery ODROID.com.” Device-node names, image filenames, project sites, and hardware platforms occupy the page in short fragments.
### Faithful transcription
> "Discovery ODROID.com"
>
> "XU4"
>
> "not mmcblk0 but"
>
> "mmcblk0 [0] ← letter"
>
> "mmcblk0.img"
>
> "launchpad.net"
>
> "Myson SD MMC"
>
> "/dev/mmcblk0"
>
> "muniac.com"
>
> "CCC"
>
> "rpi"
>
> "[struck-through] linux lite os"
>
> "linuxliteos.com"
>
> "home-assistant.io"
>
> "dell XPS 15 [uncertain: t2l-p]"
>
> "https://distro.ibiblio.org/[uncertain path]"
>
> "puppy linux"
>
> "xt1804 Sanders Indian version"
>
> "zhidao.baidu.com"
### Entities, references, and technical meaning
[[ODROID-XU4|ODROID-XU4]] is a Hardkernel single-board computer based on Samsung’s Exynos 5422 platform, with eMMC and microSD boot/storage options.[^odroid-xu4] Linux exposes SD/eMMC block devices through names such as `/dev/mmcblk0`; partitions conventionally append `p1`, `p2`, and so forth. `mmcblk0.img` is therefore plausibly a raw disk image made from the entire device. [[Launchpad|Launchpad]], [[Raspberry Pi|Raspberry Pi]], [[Linux Lite|Linux Lite]], [[Home Assistant|Home Assistant]], [[Dell XPS 15|Dell XPS 15]], [[ibiblio|ibiblio]], [[Puppy Linux|Puppy Linux]], and [[Baidu Zhidao|Baidu Zhidao]] form a broad troubleshooting-source network.
`XT1804` is a Motorola model identifier associated with a regional Moto G5S Plus variant; “Sanders” is the device codename used in Android-development communities. The notation “Indian version” fits regional firmware differentiation.
### Page-level reconstruction
This page begins the notebook’s **raw-storage and embedded-board sequence**. The writer was learning that an eMMC/SD device must be addressed by its Linux block-node identity, not by a consumer disk label, and that model codenames and regional variants matter when selecting images.
### Missed Signals and Open Leads
“Myson SD MMC,” “muniac.com,” and “CCC” remain ambiguous. The exact ibiblio path could identify the Puppy Linux build being evaluated.
---
## Scanned_20260730-1314.pdf — PDF page 19
### Visible page
A ruled page in two conceptual halves. The upper half describes forensic imaging over SSH. The lower half lists Xilinx, Artoo, Raspberry Pi Zero W, TI boot files, and BeagleBone Black.
### Faithful transcription
> "forensic imaging & digital"
>
> "evidence collection for"
>
> "investigators"
>
> "/dev/mmcblk0 is imaged"
>
> "to [scribble] stdout with a"
>
> "dd command to a stdout"
>
> "stream over ssh"
>
> "xilinx.com"
>
> "artoo image"
>
> "hybridgroup/artoo"
>
> "artoo-beaglebone"
>
> "slicethepie.co.uk PizeroW"
>
> "cnx-ti.com uboot & MLO"
>
> "Beagle Bone Black"
>
> "uEnv.txt rootfs"
### Entities, references, and technical meaning
The upper sequence describes a recognizable forensic acquisition pattern: use [[dd (Unix)|`dd`]] to read a raw block device and pipe the byte stream through [[Secure Shell|SSH]] to remote storage. This can preserve the source medium if mounted read-only and handled correctly, but a defensible forensic process also requires hashes, timestamps, chain of custody, tool/version records, and validation of the destination image. [[Xilinx|Xilinx]], [[Artoo (Robotics Framework)|Artoo]], [[Raspberry Pi Zero W|Pi Zero W]], and [[BeagleBoard.org BeagleBone Black|BeagleBone Black]] indicate embedded robotics and board imaging. On TI/BeagleBone systems, `MLO`, U-Boot, `uEnv.txt`, and `rootfs` are boot-chain components; official BeagleBoard documentation describes eMMC flashing and boot-media selection.[^beaglebone-flash]
### Page-level reconstruction
The writer had moved from recovery to **evidentiary imaging**. The key conceptual leap is that a storage node can be streamed as raw bytes across a network, separating acquisition hardware from evidence storage. The lower board-specific notes suggest the same technique was being generalized from phones to single-board computers.
### Missed Signals and Open Leads
The notebook does not record hashing commands, write blockers, or chain-of-custody fields. Those omissions distinguish a technically plausible copy from a fully documented forensic acquisition.
---
## Scanned_20260730-1314.pdf — PDF page 20
### Visible page
A ruled page mixing home automation, Ubiquiti router flashing, a Digi-Key part reference, Android device source paths, and `/dev/block/mmcblk0`.
### Faithful transcription
> "jeedom.com"
>
> "[uncertain: Caml]"
>
> "Ubiquiti UI.com"
>
> "flashing mmc on Edge Router"
>
> "digikey [uncertain part number]"
>
> "android-device-wileyfox-"
>
> "porridge-x32 / Google"
>
> "- GoogleOtaBinder"
>
> "/dev/block/mmcblk0"
### Entities, references, and technical meaning
[[Jeedom|Jeedom]] is a home-automation platform. [[Ubiquiti|Ubiquiti]] uses `ui.com` as its corporate domain, and [[EdgeRouter|EdgeRouter]] refers to its routing product line. [[Digi-Key Electronics|Digi-Key]] is an electronic-components distributor. The Android source-style path “android-device-wileyfox-porridge” likely references a device tree for a [[Wileyfox|Wileyfox]] handset, while `GoogleOtaBinder` suggests an over-the-air update or service binder component. `/dev/block/mmcblk0` is Android/Linux’s block-device path for eMMC/SD storage.
### Page-level reconstruction
This page demonstrates that the writer understood **consumer routers, phones, and home-automation controllers as variations of the same embedded-Linux problem**: identify the board, locate its storage, obtain the correct image/device tree, and control update or boot behavior.
### Missed Signals and Open Leads
The exact Wileyfox model/codename and `GoogleOtaBinder` repository should be identified from source-control history. The Digi-Key part number is too uncertain to preserve as a reliable component ID.
---
## Scanned_20260730-1314.pdf — PDF page 21
### Visible page
A short BeagleBone Black note. The page contrasts microSD and eMMC device numbering and gives a shell glob for listing MMC devices.
### Faithful transcription
> "Beagle Bone Black"
>
> "elinux.com"
>
> "[crossed symbol] µSD mmcblk0"
>
> "eMMC mmcblk1"
>
> "command"
>
> "ls /dev/mmcblk*"
### Entities, references, and technical meaning
On many [[BeagleBone Black|BeagleBone Black]] Linux images, removable microSD and onboard eMMC appear as `mmcblk` devices, but numbering can vary with kernel, boot source, and enumeration order. The command `ls /dev/mmcblk*` is therefore a discovery step rather than a universal mapping. [[Embedded Linux Wiki|eLinux.org]] has long served as a community documentation hub for embedded Linux.
### Page-level reconstruction
The writer was correcting a dangerous assumption: **device numbers are contextual**. Before imaging or flashing, enumerate the actual block devices. This is the practical safeguard implicit in the page.
### Missed Signals and Open Leads
The page does not record `lsblk`, `/proc/partitions`, serial identifiers, or capacity checks, which would further reduce the risk of imaging or overwriting the wrong medium.
---
## Scanned_20260730-1314.pdf — PDF page 22
### Visible page
A mixed service/account page. The upper third lists phone-related sites; the center contains a Google/G+ account and a password-equivalent string; the bottom contains an uncertain legacy Google Pages address. The credential is redacted here under the default archival rule.
### Faithful transcription
> "Phone Stuff"
>
> "[uncertain: streetwalrus.usbmounter]"
>
> "[uncertain: qvanti.com]"
>
> "lendingclub.com"
>
> "
[email protected]"
>
> "G+ Account"
>
> "Brand Account"
>
> "[REDACTED CREDENTIAL — see Scanned_20260730-1314.pdf, page 22]"
>
> "[uncertain: [PRIVATE NAME REDACTED]]"
### Entities, references, and technical meaning
The page combines an Android/USB-mounting search with [[LendingClub|LendingClub]] and legacy [[Google+|Google+]] account administration. A Google “Brand Account” allowed an identity distinct from a person’s primary profile to own or manage services such as YouTube channels. The `pages.plusgoogle.com`-like address appears to preserve an older Google identity or page-routing artifact.
### Page-level reconstruction
This page is an **account continuity checkpoint** embedded inside technical notes. The shift from block devices to brand accounts is not random: both are identity-resolution problems. One concerns the true storage device behind a friendly name; the other concerns the true account/container behind a public profile.
### Missed Signals and Open Leads
The two uncertain domains should be resolved from browser history or archived bookmarks. The credential must remain confined to the original scan unless the user explicitly designates a private archival output.
---
## Scanned_20260730-1314.pdf — PDF page 23
### Visible page
Landscape-oriented ruled page with only two operating-system names near the upper-left/center.
### Faithful transcription
> "NixOS"
>
> "Pop!_OS pop-os"
### Entities, references, and technical meaning
[[NixOS|NixOS]] is a Linux distribution built around declarative, reproducible system configuration and the Nix package manager. [[Pop!_OS|Pop!_OS]] is System76’s Ubuntu-derived desktop Linux distribution. Their pairing suggests comparison between a reproducibility-centered system and a hardware/productivity-centered desktop distribution.[^nixos][^popos]
### Page-level reconstruction
The page extends the operating-system survey from minimal live images and Android forks into **reproducible workstation configuration**. NixOS is especially consequential in hindsight because it treats system state as code - a direct answer to the notebook’s repeated problem of preserving exact device/software lineage.
### Missed Signals and Open Leads
No criterion is written. Search adjacent digital notes for whether the comparison involved installation, package isolation, graphics support, or portable recovery environments.
---
## Scanned_20260730-1314.pdf — PDF page 24
### Visible page
A mostly blank page with a small top-left boot/video fragment. Faint reverse-side bleed-through appears below.
### Faithful transcription
> "[uncertain: video=cirrus:]"
>
> "video=fb video"
>
> "XTERM for [uncertain: runtime/tur…]"
### Entities, references, and technical meaning
The syntax resembles Linux kernel or bootloader video parameters. “cirrus” may refer to a Cirrus Logic virtual graphics adapter commonly exposed by emulators; `fb` suggests a framebuffer. [[XTerm|XTerm]] is a terminal emulator for the X Window System.
### Page-level reconstruction
The fragment likely records a **virtual-machine display workaround**: force a basic framebuffer or Cirrus-compatible mode so a graphical or terminal environment can start in emulation.
### Missed Signals and Open Leads
The exact parameter string and target hypervisor are unresolved. It may connect to Limbo/QEMU, Bochs, or a recovery image discussed elsewhere.
---
## Scanned_20260730-1314.pdf — PDF page 25
### Visible page
Landscape ruled page, almost entirely blank. “Smart OS” is written vertically near one edge; faint bleed-through occupies the background.
### Faithful transcription
> "Smart OS"
### Reconstruction and interpretation
“Smart OS” is too generic for confident normalization. It may be a category label for embedded/IoT systems rather than a product name.
### Missed Signals and Open Leads
Search the corpus for “Smart OS” near KaiOS, Mbed, HarmonyOS, Jeedom, or home-automation notes before assigning a canonical entity.
---
## Scanned_20260730-1314.pdf — PDF page 26
### Visible page
A ruled page of USB, modem, networking, and emulation terms. Several names are uncertain. “amiga SoundTracker / mod” occupies the middle; “VM” and a lower group follow.
### Faithful transcription
> "usbmode-switch"
>
> "usbmuxd"
>
> "[uncertain: Sierra/…], Sequans,"
>
> "[uncertain: Kobile] Cisco"
>
> "amiga SoundTracker"
>
> "mod"
>
> "(bochs)"
>
> "VM"
>
> "[uncertain: pali-tech]"
>
> "[uncertain: XZ io.mod]"
### Entities, references, and technical meaning
[[USB Modeswitch|usb-modeswitch]] changes certain USB cellular modems from mass-storage presentation into modem/network mode. [[usbmuxd|usbmuxd]] multiplexes connections to iOS devices over USB. [[Sequans Communications|Sequans]] develops cellular IoT chipsets; [[Cisco|Cisco]] anchors the networking side. [[SoundTracker|SoundTracker]] and the [[MOD (file format)|MOD]] format belong to Amiga-era sample-based music, while [[Bochs|Bochs]] is an x86 PC emulator. The page therefore moves between USB device-mode negotiation, cellular modems, Apple-device transport, network vendors, and emulated legacy media.
### Page-level reconstruction
The shared concept is **device impersonation and translation**. A USB modem may initially impersonate storage; usbmuxd translates one physical link into multiple services; an emulator translates one instruction environment into another; MOD files preserve a tracker’s combined code/data performance structure.
### Missed Signals and Open Leads
The uncertain vendor names may be modem manufacturers. “XZ io.mod” could be a compressed module filename rather than a technology.
---
## Scanned_20260730-1314.pdf — PDF page 27
### Visible page
A bootloader file-layout note. Paths and filenames are stacked vertically, with “root is FD floppydisk” in the middle and filesystem/partition terms near the bottom.
### Faithful transcription
> "/boot/grub/"
>
> "unicode.pf2"
>
> "grub.cfg"
>
> "font = unicode.pf2"
>
> "root is FD floppydisk"
>
> "[uncertain: xxen]"
>
> "xzio"
>
> "[uncertain: /z?pie]"
>
> "part.gpt"
### Entities, references, and technical meaning
[[GNU GRUB|GNU GRUB]] uses `grub.cfg` for generated boot-menu configuration and `.pf2` fonts such as `unicode.pf2`. “FD floppydisk” likely refers to GRUB’s historical device notation for a floppy disk. `part.gpt` appears to identify GRUB’s GUID Partition Table module. The uncertain `xzio` may be `xzio`, GRUB’s XZ decompression support.
### Page-level reconstruction
The writer was dissecting a **bootable image as a dependency graph**: configuration file, font, root-device notation, compression module, and partition-table module. This follows directly from downloading small disk images and attempting to boot them under emulation or from removable media.
### Missed Signals and Open Leads
The uncertain filenames should be compared against the module directory of the exact GRUB build. `unicode.pf2` may have been missing or misreferenced in a failed boot.
---
## Scanned_20260730-1314.pdf — PDF page 28
### Visible page
A clean EFI/GRUB layout note with directory paths at top and a four-part partition scheme at bottom.
### Faithful transcription
> "boot/EFI/EFI/Kali/"
>
> "Dos/Windows"
>
> "Executable"
>
> "grubx64.efi"
>
> "EFI/BOOT/"
>
> "BOOTX64.EFI"
>
> "[uncertain: reco-launcher]"
>
> "part 4 /home ext4 16 GB"
>
> "2 / ext4 11 GB"
>
> "part 1 /boot/efi/ fat32"
>
> "512 mb"
>
> "3 linux-swap"
### Entities, references, and technical meaning
[[Unified Extensible Firmware Interface|UEFI]] systems load `.efi` executables from an EFI System Partition, conventionally FAT32. `BOOTX64.EFI` is the removable-media fallback path for x86-64 UEFI. [[Kali Linux|Kali Linux]], [[ext4|ext4]], and [[Linux swap|Linux swap]] define the proposed installation layout: EFI partition, root filesystem, swap, and a separate `/home`. [[GNU GRUB|GRUB]] supplies `grubx64.efi`.
### Page-level reconstruction
The page is a **manual boot architecture** for a multiboot or recovery disk. It shows the writer moving from raw images to a deliberate GPT/UEFI partition plan that separates system, user state, swap, and firmware-visible boot files.
### Missed Signals and Open Leads
The root partition mount point is omitted beside “2 / ext4 11 GB” but is strongly implied. The duplicated `boot/EFI/EFI/Kali/` may reflect confusion between mount point and on-disk EFI directory hierarchy.
---
## Scanned_20260730-1314.pdf — PDF page 29
### Visible page
A partition-type and ChromeOS/legacy-GPT note. Several short labels are distributed down the page; “legacy bios GPT” is repeated.
### Faithful transcription
> "[uncertain: mmcblk-0,1,? is mmcblk0p2]"
>
> "chromeos"
>
> "chromeos_kernel"
>
> "hp-service"
>
> "JVM"
>
> "m2ft data"
>
> "16 res"
>
> "bios_grub"
>
> "gnu-grub [struck-through] on"
>
> "legacy bios GPT"
>
> "legacy bios GPT"
### Entities, references, and technical meaning
[[ChromeOS|ChromeOS]] uses specialized GPT partition types, including kernel partitions. A `bios_grub` partition is the small unformatted area GRUB uses for embedding core boot code when legacy BIOS boots from a GPT disk. [[Java Virtual Machine|JVM]] is likely a separate note. “hp-service,” “m2ft data,” and “16 res” may be observed partition labels or abbreviations from a disk layout.
### Page-level reconstruction
This page captures the collision between **modern GPT partitioning and legacy BIOS boot**. The writer was identifying why a disk can be correctly partitioned yet still fail to boot under a firmware mode that requires a BIOS boot partition.
### Missed Signals and Open Leads
The partition labels should be matched against a `gdisk`, `parted`, or ChromeOS layout dump. “m2ft” may be a misreading of Microsoft reserved/data terminology.
---
## Scanned_20260730-1314.pdf — PDF page 30
### Visible page
A Linux desktop/runtime troubleshooting page. Environment-variable and Qt/XCB errors lead to `sudo dolphin`, Java 11 paths, and a symbolic-link note.
### Faithful transcription
> "XDG_RUNTIME"
>
> "QStandardPaths"
>
> "QXcbConnection"
>
> "XDB Error 3"
>
> "sudo dolphin"
>
> "Java -11-openjdk-amd64"
>
> "VS /usr/lib/jvm/"
>
> "sym"
>
> "/default-java/jre"
### Entities, references, and technical meaning
`XDG_RUNTIME_DIR` is a per-user runtime-directory variable defined by the XDG base-directory/runtime conventions. [[Qt (software)|Qt]] emits `QStandardPaths` and `QXcbConnection` messages when runtime directories, ownership, display authentication, or the XCB backend are misconfigured. Running [[Dolphin (file manager)|Dolphin]] with `sudo` can create precisely this kind of user/root environment mismatch and is generally unsafe for ordinary file management. The Java notes compare the OpenJDK 11 directory with `/usr/lib/jvm/default-java/jre`, likely diagnosing a missing or incorrect symbolic link.
### Page-level reconstruction
The writer was debugging **privilege-boundary breakage**: a graphical app launched as root inherits the wrong runtime/display environment, while a Java application expects a canonical runtime path. The recurring theme is indirection - user environment, symlink, runtime path, and actual implementation must align.
### Missed Signals and Open Leads
“XDB Error 3” is probably “XCB Error 3.” The exact application needing Java 11 may be Maltego on the next page.
---
## Scanned_20260730-1314.pdf — PDF page 31
### Visible page
A Java/module and GParted build note. The upper half contains a `file:/usr/share/...` path, “maltego,” a JAR filename, and a missing-service error. The lower half records GParted/libparted configuration flags.
### Faithful transcription
> "[uncertain: exec apps?]"
>
> "file:/usr/share/[uncertain path]/"
>
> "(maltego)"
>
> "/maltego-ui/modules"
>
> "ext?"
>
> "Java_Config_App.jar"
>
> "not /usr/bin/java"
>
> "Unit \\xed\\x92\\x9f [garbled]"
>
> "service does not"
>
> "exist"
>
> "GParted live"
>
> "configuration --enable-libparted-"
>
> "dmraid --enable-online-resize"
>
> "libparted 3.3"
### Entities, references, and technical meaning
[[Maltego|Maltego]] is a link-analysis and open-source-intelligence platform built on Java/NetBeans technologies. `maltego-ui/modules` and `Java_Config_App.jar` suggest a module or Java-path failure. The “Unit ... service does not exist” line resembles a systemd error contaminated by encoding bytes. [[GParted|GParted]] is a graphical partition editor built on `libparted`; `dmraid` support concerns device-mapper RAID metadata, and online resize support affects live filesystem/partition operations.
### Page-level reconstruction
This page joins **investigative software and disk surgery**. Maltego’s Java/module dependencies and GParted’s partition back end were both failing at the integration boundary. The writer was collecting the exact paths and compile flags needed to explain why a friendly GUI did not map cleanly to the underlying runtime.
### Missed Signals and Open Leads
The garbled systemd unit name should be recovered from terminal logs if available. The exact GParted Live version could identify whether libparted 3.3 was current or a compatibility constraint.
---
## Scanned_20260730-1314.pdf — PDF page 32
### Visible page
A packet-analysis page. It records SSDP, the `M-SEARCH` method, a multicast host/port, a DIAL service URN, and an iPad/CompanionLink identity. Several labels are separated by spacing rather than boxes.
### Faithful transcription
> "protocol SSDP"
>
> "Request method: M-SEARCH"
>
> "Severity Level: Chat"
>
> "SoM-SEARCH"
>
> "Host 2 239.255.255.250"
>
> ":1900*"
>
> "ST: urn:dial-multiscreen-"
>
> "org:service:dial:1"
>
> "domain name"
>
> "Nous:iPad.local"
>
> "Nous’s iPad - companion-link"
>
> "[struck-through: burn] tcp.local"
>
> "Port 49356"
### Entities, references, and technical meaning
[[Simple Service Discovery Protocol|SSDP]] uses UDP multicast at `239.255.255.250:1900`; `M-SEARCH` is its active discovery request. [[Discovery and Launch|DIAL]] - Discovery and Launch - uses SSDP to find second-screen-capable devices and identifies services through URNs such as `urn:dial-multiscreen-org:service:dial:1`.[^dial] `.local` names and `_service._tcp.local` records point to [[Multicast DNS|mDNS]] and [[DNS-Based Service Discovery|DNS-SD]], commonly surfaced through Apple Bonjour. “companion-link” is a service label, likely an application exposing synchronization or pairing on the local network.
### Page-level reconstruction
The writer was reading a network trace and translating a multicast packet into **device identity and service capability**. “Nous’s iPad” is not simply a hostname; through SSDP/mDNS/DNS-SD it becomes a discoverable actor advertising a particular local service and port.
### Missed Signals and Open Leads
“Severity Level: Chat” may come from a security appliance or packet-analysis UI rather than the protocol itself. The actual packet capture would be needed to determine source/destination addresses, TTL, and whether DIAL and CompanionLink were separate observations.
---
## Scanned_20260730-1314.pdf — PDF page 33
### Visible page
Continuation of the packet-analysis notes. An IP address and mDNS/DNS-SD fields lead into room labels, HomeKit, MacBooks, and “sleep proxy UDP.”
### Faithful transcription
> "to next address"
>
> "236.1.20.172"
>
> "Next Secure: Nous-iPad.local"
>
> ".000 0060 00004"
>
> "0x0001"
>
> "<Root>"
>
> "Type: OTP"
>
> "-companion-link.tcp.local"
>
> "class In ‘QM’ regression."
>
> "Master Bedroom"
>
> "_companion-link._tcp.local"
>
> "Home Kit homekit"
>
> "Admin’s MacBook Air"
>
> "MacBook Pro"
>
> "sleep proxy UDP"
### Entities, references, and technical meaning
The service string `_companion-link._tcp.local` follows DNS-SD naming. “Type: OTP” may actually be “PTR,” the DNS record type used to enumerate service instances. `0x0001` corresponds to DNS class IN in wire notation. [[Apple HomeKit|HomeKit]], [[MacBook Air|MacBook Air]], [[MacBook Pro|MacBook Pro]], and [[Bonjour Sleep Proxy|sleep proxy]] indicate an Apple-centric home network in which devices advertise availability and can be represented while asleep.
### Page-level reconstruction
The page is a **local-network ontology extracted from packets**: person-assigned room (“Master Bedroom”), host identity, device class, service type, and sleeping/waking behavior. The writer was reconstructing the household’s topology without relying on a router’s friendly device list.
### Missed Signals and Open Leads
`236.1.20.172` is unusual and may be a transcription error, a multicast address, or an application field. “QM regression” is unresolved. The packet record type should be verified as PTR, not accepted as the handwritten “OTP.”
---
## Scanned_20260730-1314.pdf — PDF page 34
### Visible page
A small, sparse note with “Seen,” an operating-system name, a power-menu phrase, an uncertain interface label, “open wifi,” and “get Jar.”
### Faithful transcription
> "Seen"
>
> "Symbion OS"
>
> "power menu"
>
> "from"
>
> "[uncertain: 77H-UI]"
>
> "open wifi"
>
> "get Jar"
### Entities, references, and technical meaning
“Symbion OS” is likely [[Symbian|Symbian OS]], the mobile operating system historically used by Nokia and others. `JAR` denotes a Java archive, relevant to Java ME/Symbian-era mobile software. “open wifi” and “power menu” may describe an observed interface or a legacy handset application.
### Page-level reconstruction
The page may record a sighting of a **legacy Java-capable mobile environment** and an attempt to identify or retrieve its application package. It preserves the notebook’s backward reach: modern Android, embedded Linux, and pre-smartphone mobile OSes all remain part of the same continuity map.
### Missed Signals and Open Leads
The interface label is illegible enough that no product should be asserted. “Symbion” must remain exact in transcription even though Symbian is the probable normalization.
---
## Scanned_20260730-1314.pdf — PDF page 35
### Visible page
A configuration page for `xl2tpd`. File paths, LAC/LNS sections, hostnames, authentication modes, and port 1701 are stacked in a configuration-like sequence.
### Faithful transcription
> "xl2tpd"
>
> "l2tp.secrets"
>
> "xl2tpd.conf"
>
> "lac cisco"
>
> "lns = cisco.marko.net"
>
> "nolac = untrusted.marko.net"
>
> "CHAP Auth"
>
> "port 1701"
>
> "NC 1701"
>
> "etc/ppp/options.xl2tpd.lns"
>
> "use hidden bits"
>
> "lns2.marko.net (not root)"
>
> "PAP"
### Entities, references, and technical meaning
[[xl2tpd|xl2tpd]] is a Linux implementation of [[Layer 2 Tunneling Protocol|L2TP]], conventionally using UDP port 1701 and integrating with PPP. `LAC` means L2TP Access Concentrator; `LNS` means L2TP Network Server. `CHAP` and `PAP` are PPP authentication methods, with PAP transmitting a reusable secret inside the tunnel negotiation and CHAP using a challenge-response exchange. `l2tp.secrets`, `xl2tpd.conf`, and `/etc/ppp/options.xl2tpd.lns` are configuration/secret paths.[^xl2tpd][^rfc2661]
### Page-level reconstruction
The page is a **tunnel endpoint map**, likely copied from a sample configuration. It shows the writer learning the role distinction between client-side concentrator, server-side LNS, PPP authentication, and transport port.
### Missed Signals and Open Leads
The `marko.net` hostnames may be example domains from documentation rather than live infrastructure. “use hidden bits” is uncertain and may be a configuration option misread from the source.
---
## Scanned_20260730-1314.pdf — PDF page 36
### Visible page
A short investigative reminder. “EPIK” appears three times, twice circled. The page references a person, “ever heard of EPIK?,” “investigate,” an `11/16` date, “Data Enrichment Exposure from PDL Customer,” and “Sept 21, 2021.”
### Faithful transcription
> "[PERSON REDACTED] Hain, ‘ever heard of"
>
> "EPIK’?"
>
> "investigate. 11/16"
>
> "[uncertain: antiPub Drugs Squad Consol…]"
>
> "Data Enrichment Exposure from"
>
> "PDL Customer"
>
> "EPIK / Sept 21, 2021"
>
> "Neo Nazi Hosting, or"
>
> "NTF Stuff?"
>
> "EPIK"
### Entities, references, and technical meaning
[[Epik (company)|Epik]] is a domain registrar and hosting company whose 2021 breach exposed extensive internal and customer data; breach disclosures and reporting linked the company to customers across the political spectrum, including extremist sites.[^epik-hibp] [[People Data Labs|People Data Labs (PDL)]] is a data-enrichment company; a separate large exposed dataset associated with a PDL customer became a major privacy story.[^pdl-wired] The handwritten “Sept 21, 2021” falls directly in the period of public Epik breach disclosures, while “11/16” aligns with the Mensa Brands news on page 15 and strongly dates active notebook use to late 2021.
### Page-level reconstruction
The writer was correlating **data-broker exposure, registrar/hosting infrastructure, extremist-site hosting, and a personal prompt from “[PERSON REDACTED] Hain.”** The question mark after “Neo Nazi Hosting, or NTF Stuff?” shows active classification rather than a settled accusation. This is a notebook lead-generation page, not a final finding.
### Missed Signals and Open Leads
“NTF” may be “NFT.” The uncertain middle line could identify a specific leak, forum, or anti-public-database project. The person “[PERSON REDACTED] Hain” requires corroboration before a public identity is assigned.
---
## Scanned_20260730-1314.pdf — PDF page 37
### Visible page
A detailed app-analysis page headed “OMNICLOCK.” The upper half records UI elements, version `2.3.19`, a quoted permissions message, and the name Max Weninger. The lower half describes notification, Wi-Fi, and mobile-data behavior.
### Faithful transcription
> "OMNICLOCK"
>
> "time +1 label"
>
> "session 0:00"
>
> "landscape"
>
> "[dot-grid sketch]"
>
> "‘browse’ ‘albums’?"
>
> "v 2.3.19"
>
> "‘change device location"
>
> "permissions to comply with"
>
> "new google guidelines’"
>
> "- Max Weninger"
>
> "analog clock → looks like"
>
> "android OS11"
>
> "clock in"
>
> "settings"
>
> "clock silences sms and"
>
> "other notifications and"
>
> "seems to even have some"
>
> "control over wifi and"
>
> "mobile data,"
### Entities, references, and technical meaning
[[OmniClock|OmniClock]] appears to be a clock application or custom-ROM component associated with [[OmniROM|OmniROM]]. The page records a version, UI orientation, location-permission rationale, and behavior affecting notifications and connectivity. “Max Weninger” is likely a developer/contributor name later linked on pages 38 and 41 to OmniROM and graphics components.
### Page-level reconstruction
The writer was performing **behavioral application analysis**: not just what the clock displayed, but what permissions it requested and which system functions it appeared to influence. The suspicion that a clock could silence SMS, notifications, Wi-Fi, or mobile data anticipates modern scrutiny of privileged system apps and custom-ROM control surfaces.
### Missed Signals and Open Leads
The observed behavior could arise from Do Not Disturb, battery optimization, a custom quick-settings controller, or an app with elevated privileges. APK metadata and source history are needed to separate apparent from actual control.
---
## Scanned_20260730-1314.pdf — PDF page 38
### Visible page
A highlighted custom-ROM/source-tree page. “base,” “omni,” “yukawa,” “CEC,” and “SystemUI” are emphasized. The lower section describes removable MMC behavior and a CEC implementation.
### Faithful transcription
> "base"
>
> "omni — ‘don’t add camera2.’"
>
> "yukawa"
>
> "CEC"
>
> "SystemUI"
>
> "manifest: Add OmniControl"
>
> "rpi4 ?"
>
> "android_vendor_omni"
>
> "yukawa: Allow only"
>
> "mmcblk0 to be removable"
>
> "MMC block device"
>
> "- CEC: Add implementation of"
>
> "SYSTEM CEC option to"
>
> "yukawa legacy."
### Entities, references, and technical meaning
[[OmniROM|OmniROM]], `android_vendor_omni`, [[Android System UI|SystemUI]], and “OmniControl” identify an Android custom-ROM source tree. [[Yukawa (Android board)|Yukawa]] is an Amlogic-based board target used in Android open-source development. [[Consumer Electronics Control|CEC]] is the HDMI control channel that lets devices send commands such as power and input changes. `mmcblk0` again appears as the storage node, now in a source-code policy deciding whether a block device is considered removable. “rpi4?” suggests comparison with [[Raspberry Pi 4|Raspberry Pi 4]].
### Page-level reconstruction
The page reveals source-level investigation of **how Android classifies hardware and grants system control**. “Allow only mmcblk0 to be removable” is not cosmetic: storage classification affects mounting, permissions, media scanning, and update behavior. CEC integration similarly turns the Android build into a television/embedded appliance controller.
### Missed Signals and Open Leads
The quoted “don’t add camera2” may be a commit message, review comment, or personal instruction. Git history could identify the exact commit and date.
---
## Scanned_20260730-1314.pdf — PDF page 39
### Visible page
Continuation of OmniROM/source notes. APK names, provisioning, overlays, filesystem format, quick-settings tiles, Launcher3, and a Romanian domain are listed. “Omni Clock is Important” is explicitly written near the bottom.
### Faithful transcription
> "[uncertain: Jphone Log] (prebuilt)"
>
> "Omni Store Installer.apk"
>
> "Provision: move default"
>
> "settings into boot receiver"
>
> "SettingsLib Overlays"
>
> "fstab: f2fs force recovery to use ext4"
>
> "base: SystemUI qsTiles [uncertain: Rouge]"
>
> "Launcher3, OmniControl"
>
> "device.omni.ro"
>
> "Omni Clock is Important"
>
> "related F-Droid, Kingroot"
### Entities, references, and technical meaning
[[Android Package|APK]], [[Android Provisioning|Provision]], [[SettingsLib|SettingsLib]], [[Android Resource Overlay|resource overlays]], [[F2FS|F2FS]], [[ext4|ext4]], [[Android Launcher3|Launcher3]], [[F-Droid|F-Droid]], and [[KingRoot|KingRoot]] describe the system-app and recovery layer of an Android ROM. A boot receiver can apply defaults after boot; overlays alter resources without rewriting core packages; `fstab` determines how recovery/system mount filesystems. `device.omni.ro` may be a domain or package/source identifier connected to Romania, echoing page 17’s Romanian traceback.
### Page-level reconstruction
The writer was reconstructing **privilege by build position**. A prebuilt system APK, provisioning receiver, SystemUI tile, or vendor overlay can exercise powers unavailable to an ordinary app. “Omni Clock is Important” likely reflects the discovery that the clock/control component was integrated into the ROM’s privileged control plane.
### Missed Signals and Open Leads
The first APK name, quick-settings tile name, and `device.omni.ro` need source-tree confirmation. Any asserted relationship to KingRoot remains a lead, not a verified code connection.
---
## Scanned_20260730-1314.pdf — PDF page 40
### Visible page
A mostly blank ruled page. “calc 2,580” appears near the upper area; faint bleed-through is visible elsewhere.
### Faithful transcription
> "calc 2,580"
### Reconstruction and interpretation
The number lacks units or operands. It may be a price, capacity, count, or result carried from an adjacent calculation.
### Missed Signals and Open Leads
No reliable interpretation is possible without a matching figure elsewhere in the corpus.
---
## Scanned_20260730-1314.pdf — PDF page 41
### Visible page
A graphics-stack note. The top says “FOSS graphic components.” `gbm-gralloc` and Mesa 3D are followed by a quotation about swapping red and blue. Android DRM/hwcomposer terms and two developer names appear below.
### Faithful transcription
> "FOSS graphic components"
>
> "gbm-gralloc, Mesa 3D"
>
> "‘swapping’ R (red) and B (blue)"
>
> "android-external-drm-"
>
> "hwcomposer"
>
> "Max Weninger"
>
> "Roman Stratiienko"
>
> "[uncertain: .ru dos software]"
### Entities, references, and technical meaning
[[Free and Open-Source Software|FOSS]], [[Generic Buffer Management|GBM]], [[Gralloc|gralloc]], [[Mesa 3D|Mesa 3D]], [[Direct Rendering Manager|DRM]], and [[Android Hardware Composer|Hardware Composer]] form the Linux/Android graphics pipeline. A red/blue swap is a classic pixel-format/channel-order mismatch - for example, RGB versus BGR/RGBA versus BGRA - between producer, allocator, compositor, and display. AOSP’s DRM hardware-composer projects bridge Android’s Hardware Composer interface to Linux DRM/KMS, while Mesa provides open graphics drivers and APIs.[^aosp-drmhwc][^mesa-android]
### Page-level reconstruction
This page shows the writer reaching the **display-memory contract** beneath Android UI. The problem was not “wrong color” as a superficial bug; it was an ABI/data-layout disagreement among buffer allocator, GPU stack, and compositor. Max Weninger and Roman Stratiienko likely entered the notes as contributors or authors in the relevant source history.
### Missed Signals and Open Leads
The exact repository and commit containing the color-channel swap should be recovered. The final “.ru” fragment may refer to a developer domain or unrelated DOS software.
---
## Scanned_20260730-1314.pdf — PDF page 42
### Visible page
The notebook changes function into a personal-contact ledger. Four named contacts are arranged vertically with handwritten qualifiers, phone numbers, and email addresses. All telephone numbers are redacted here.
### Faithful transcription
> "Amanda Deatherage"
>
> "DC Lobbyist"
>
> "xxx-xxx-xxxx (see Scanned_20260730-1314.pdf, page 42)"
>
> "
[email protected]"
>
> "
[email protected]"
>
> "Jim Karol"
>
> "Allentown, PA"
>
> "xxx-xxx-xxxx (see Scanned_20260730-1314.pdf, page 42)"
>
> "xxx-xxx-xxxx (see Scanned_20260730-1314.pdf, page 42)"
>
> "
[email protected]"
>
> "
[email protected]"
>
> "Chris Chelko"
>
> "xxx-xxx-xxxx (see Scanned_20260730-1314.pdf, page 42)"
>
> "Tonight show."
>
> "Matthew Pollard"
>
> "xxx-xxx-xxxx (see Scanned_20260730-1314.pdf, page 42)"
>
> "Don H [PERSON REDACTED] PI"
>
> "xxx-xxx-xxxx (see Scanned_20260730-1314.pdf, page 42)"
>
> "don.[PERSON REDACTED]@mbi-investigators.com"
>
> "Irina"
>
> "[uncertain email fragment]"
>
> "8/25/57"
### Entities and reconstruction
The page records [[Index - People#Amanda Deatherage|Amanda Deatherage]], [[Index - People#Jim Karol|Jim Karol]], [[Index - People#Chris Chelko|Chris Chelko]], [[Index - People#Matthew Pollard|Matthew Pollard]], and [PERSON REDACTED], with role/location cues such as “DC Lobbyist,” “Allentown, PA,” “Tonight show,” and “PI.” “PI” likely means private investigator, reinforced by the `mbi-investigators.com` domain. Because several names have multiple public matches, the notebook’s own qualifiers are preserved without forcing a single biography.
The abrupt shift from ROM internals to contacts indicates the physical notebook became a **portable operational directory**. The contact records may be older than the technical sequence; their order need not imply contemporaneous interaction.
### Missed Signals and Open Leads
The `8/25/57` date may be a birthday, reference date, or case note. The “Irina” email fragment is not clear enough to normalize.
---
## Scanned_20260730-1314.pdf — PDF page 43
### Visible page
Blank ruled page with no deliberate foreground writing.
### Faithful transcription
No visible text.
### Reconstruction and interpretation
A separator between contact-ledger sections. It must remain in the archive to preserve the original pagination and grouping.
### Missed Signals and Open Leads
None.
---
## Scanned_20260730-1314.pdf — PDF page 44
### Visible page
A contact page with six names, phone numbers, one email for [PERSON REDACTED], one email for [PERSON REDACTED], and relational notes around [PERSON REDACTED].
### Faithful transcription
> "[PERSON REDACTED]"
>
> "xxx-xxx-xxxx (see Scanned_20260730-1314.pdf, page 44)"
>
> "
[email protected]"
>
> "[PERSON REDACTED]"
>
> "xxx-xxx-xxxx (see Scanned_20260730-1314.pdf, page 44)"
>
> "Jamie’s son-in-law"
>
> "Trace wife"
>
> "[PERSON REDACTED]"
>
> "xxx-xxx-xxxx (see Scanned_20260730-1314.pdf, page 44)"
>
> "[PERSON REDACTED] (Romania)"
>
> "xxx-xxx-xxxx (see Scanned_20260730-1314.pdf, page 44)"
>
> "[PERSON REDACTED] (UN)"
>
> "xxx-xxx-xxxx (see Scanned_20260730-1314.pdf, page 44)"
>
> "[PRIVATE EMAIL REDACTED]"
>
> "[PERSON REDACTED]"
>
> "xxx-xxx-xxxx (see Scanned_20260730-1314.pdf, page 44)"
### Entities and reconstruction
The page records [PERSON REDACTED], and [PERSON REDACTED]. “Romania” connects this contact section back to the Romanian developer/company investigation on page 17, but the notebook does not prove the entries belong to the same inquiry. “UN” likely means the [[United Nations|United Nations]]. “Trace wife” appears to be an action item linked by arrow to [PERSON REDACTED].
### Missed Signals and Open Leads
The common names require contact-list or correspondence corroboration. The relational note “Jamie’s son-in-law” may be more useful than public web matching for resolving identity.
---
## Scanned_20260730-1314.pdf — PDF page 45
### Visible page
A contact page with five named people, multiple email addresses, and one iPhone label. Phone numbers are redacted.
### Faithful transcription
> "[PERSON REDACTED]"
>
> "xxx-xxx-xxxx (see Scanned_20260730-1314.pdf, page 45)"
>
> "xxx-xxx-xxxx (see Scanned_20260730-1314.pdf, page 45) iPhone"
>
> "[PRIVATE EMAIL REDACTED]"
>
> "[PRIVATE EMAIL REDACTED]"
>
> "Rex Rizk"
>
> "xxx-xxx-xxxx (see Scanned_20260730-1314.pdf, page 45)"
>
> "
[email protected]"
>
> "
[email protected]"
>
> "[PERSON REDACTED]"
>
> "xxx-xxx-xxxx (see Scanned_20260730-1314.pdf, page 45)"
>
> "[PRIVATE EMAIL REDACTED]"
>
> "[PERSON REDACTED]"
>
> "xxx-xxx-xxxx (see Scanned_20260730-1314.pdf, page 45)"
>
> "[PERSON REDACTED]"
>
> "xxx-xxx-xxxx (see Scanned_20260730-1314.pdf, page 45)"
### Entities and reconstruction
The page records [PERSON REDACTED], [[Index - People#Rex Rizk|Rex Rizk]], [PERSON REDACTED], and [PERSON REDACTED]. `gomcgill.com` is a Bryant McGill domain, so [PERSON REDACTED]’s address likely reflects an internal or affiliated account rather than an independently owned domain. The dual Rex Rizk emails distinguish general and music identities.
### Missed Signals and Open Leads
The notebook provides no dates or relationship labels for most entries. Correspondence headers would be needed to reconstruct when and why these contacts became operationally important.
---
## Scanned_20260730-1314.pdf — PDF page 46
### Visible page
A contact page with four principal names, emails, and phone numbers. “Falafel Software Inc.” appears under Adam Markowitz. Phone numbers are redacted.
### Faithful transcription
> "LeAnn Macadoo"
>
> "xxx-xxx-xxxx (see Scanned_20260730-1314.pdf, page 46)"
>
> "Sayer Ji"
>
> "xxx-xxx-xxxx (see Scanned_20260730-1314.pdf, page 46)"
>
> "
[email protected]"
>
> "Adam King"
>
> "xxx-xxx-xxxx (see Scanned_20260730-1314.pdf, page 46)"
>
> "
[email protected]"
>
> "
[email protected]"
>
> "Adam Markowitz"
>
> "xxx-xxx-xxxx (see Scanned_20260730-1314.pdf, page 46)"
>
> "
[email protected]"
>
> "Falafel Software Inc."
### Entities and reconstruction
The page records [[Index - People#LeAnn Macadoo|LeAnn Macadoo]], [[Index - People#Sayer Ji|Sayer Ji]], [[Index - People#Adam King|Adam King]], [[Index - People#Adam Markowitz|Adam Markowitz]], [[American Committee for Shaare Zedek Medical Center|ACSZ]], and [[Falafel Software|Falafel Software Inc.]]. The `acsz.org` address gives Adam King an institutional anchor. “Falafel Software Inc.” provides a company anchor for Adam Markowitz. These are stronger identifiers than name-only web matches.
### Missed Signals and Open Leads
The notebook does not state the purpose of contact or whether the entries were current in 2021. Institutional directories and email archives can establish chronology.
---
## Scanned_20260730-1314.pdf — PDF page 47
### Visible page
A contact page with [PERSON REDACTED], Charles “Larry” Gottsman, a San Antonio address and house-age note, then a second contact whose surname and emails are difficult to read. Phone numbers are redacted.
### Faithful transcription
> "[PERSON REDACTED]"
>
> "xxx-xxx-xxxx (see Scanned_20260730-1314.pdf, page 47)"
>
> "[PRIVATE EMAIL REDACTED]"
>
> "Charles (Larry) Gottsman"
>
> "857 Estes Avenue"
>
> "San Antonio, TX 78209"
>
> "(Built 1899) Ex wife Diane"
>
> "xxx-xxx-xxxx (see Scanned_20260730-1314.pdf, page 47)"
>
> "[PERSON REDACTED]"
>
> "xxx-xxx-xxxx (see Scanned_20260730-1314.pdf, page 47)"
>
> "[uncertain email address]"
>
> "[uncertain email address]"
### Entities and reconstruction
The page records [PERSON REDACTED] and [[Index - People#Charles Larry Gottsman|Charles “Larry” Gottsman]], along with a property address, construction-year note, and former-spouse identifier. This is more than a phonebook entry: it is a **relationship-and-place record**, possibly for property, genealogy, due diligence, or personal-network reconstruction.
### Missed Signals and Open Leads
The second surname and both emails are too uncertain for safe normalization. The “Built 1899” note could be verified through property records, but the notebook does not state why the property mattered.
---
## Scanned_20260730-1314.pdf — PDF page 48
### Visible page
A contact page centered on the Korngold family and [PERSON REDACTED] Design. It contains multiple phone labels, company and home addresses, work/fax labels, and two email addresses. All telephone numbers are redacted.
### Faithful transcription
> "Jean Pierre Korngold"
>
> "
[email protected]"
>
> "xxx-xxx-xxxx (see Scanned_20260730-1314.pdf, page 48)"
>
> "xxx-xxx-xxxx (see Scanned_20260730-1314.pdf, page 48) Nancy-neighbor"
>
> "Isadoro Korngold"
>
> "xxx-xxx-xxxx (see Scanned_20260730-1314.pdf, page 48) mobile"
>
> "xxx-xxx-xxxx (see Scanned_20260730-1314.pdf, page 48) work"
>
> "Intercontinental Asset Management"
>
> "Kenny Korngold"
>
> "xxx-xxx-xxxx (see Scanned_20260730-1314.pdf, page 48)"
>
> "[PERSON REDACTED] Design"
>
> "227 Stanford Dr (home)"
>
> "Olmos Park, TX 78212"
>
> "xxx-xxx-xxxx (see Scanned_20260730-1314.pdf, page 48)"
>
> "xxx-xxx-xxxx (see Scanned_20260730-1314.pdf, page 48) work"
>
> "xxx-xxx-xxxx (see Scanned_20260730-1314.pdf, page 48) fax"
>
> "[PRIVATE EMAIL REDACTED]"
>
> "[PRIVATE EMAIL REDACTED]"
### Entities and reconstruction
The page records [[Index - People#Jean Pierre Korngold|Jean Pierre Korngold]], [[Index - People#Isadoro Korngold|Isadoro Korngold]], [[Index - People#Kenny Korngold|Kenny Korngold]], [[Intercontinental Asset Management|Intercontinental Asset Management]], and [[Private Design Business|private design business]]. Family grouping, neighbor annotation, mobile/work distinctions, company affiliation, and home address reveal a small **social and institutional graph**, not an undifferentiated list.
### Missed Signals and Open Leads
The spelling “Isadoro” should be checked against correspondence. “Nancy-neighbor” may identify an alternate route to [PERSON REDACTED] Pierre rather than a direct number.
---
## Scanned_20260730-1314.pdf — PDF page 49
### Visible page
A densely packed contact/property page. It contains Mike Adams, [PERSON REDACTED], multiple addresses, government identifiers, ownership information, an office address, an Atlanta residence, and [PERSON REDACTED]. Telephone numbers and government identifiers are redacted.
### Faithful transcription
> "Mike Adams"
>
> "xxx-xxx-xxxx (see Scanned_20260730-1314.pdf, page 49)"
>
> "[PERSON REDACTED]"
>
> "xxx-xxx-xxxx (see Scanned_20260730-1314.pdf, page 49)"
>
> "xxx-xxx-xxxx (see Scanned_20260730-1314.pdf, page 49) WhatsApp"
>
> "[crossed telephone entry redacted — see Scanned_20260730-1314.pdf, page 49]"
>
> "43 Bristol Green"
>
> "San Antonio, TX 78209"
>
> "PO Box 17339"
>
> "San Antonio, TX 78217"
>
> "DL # [REDACTED SENSITIVE IDENTIFIER — see Scanned_20260730-1314.pdf, page 49]"
>
> "Last 4 SS# : [REDACTED SENSITIVE IDENTIFIER — see Scanned_20260730-1314.pdf, page 49]"
>
> "MPC Equipment owns home"
>
> "900 NE Loop 410 Building E"
>
> "Suite 105"
>
> "San Antonio, TX 78209"
>
> "3324 Peachtree Rd, Unit 2801"
>
> "Atlanta, GA 30326"
>
> "[PERSON REDACTED] →"
>
> "xxx-xxx-xxxx (see Scanned_20260730-1314.pdf, page 49)"
>
> "xxx-xxx-xxxx (see Scanned_20260730-1314.pdf, page 49)"
### Entities and reconstruction
The page records [[Index - People#Mike Adams|Mike Adams]], [PERSON REDACTED], [[MPC Equipment|MPC Equipment]], and [PERSON REDACTED], embedded in a property-and-identity dossier. Unlike ordinary contacts, it includes residence, post-office box, corporate ownership, office, alternate city residence, and government-identification fragments. This indicates **due-diligence or identity-resolution work** rather than simple address-book maintenance. The vault owner resolves [PERSON REDACTED] as [PERSON REDACTED], also associated with `[PERSON REDACTED]` and `[PERSON REDACTED]`, and supplies the separate [[SpiderOak|SpiderOak]] phone-security relationship.
### Missed Signals and Open Leads
“Mike Adams” and “[PERSON REDACTED]” remain common-name ambiguities. “[PERSON REDACTED]” is resolved by the vault owner as [PERSON REDACTED], but the page does not independently establish the owner-supplied biographical or SpiderOak details. The legal basis and purpose of the property/identifier compilation are not stated. Sensitive identifiers must remain redacted in non-private outputs.
---
## Scanned_20260730-1314.pdf — PDF page 50
### Visible page
A sparse page containing “MS” and an uncertain mnemonic-like number/letter sequence.
### Faithful transcription
> "MS"
>
> "[uncertain: 212-DAC-DABC]"
### Reconstruction and interpretation
The sequence may be a vanity-number mnemonic, contact shorthand, code, or continuation of “Michael Silver” from page 16. The evidence is insufficient to join them definitively.
### Missed Signals and Open Leads
Compare the exact sequence with page 16 and any contact database entry for Michael Silver before creating a relationship.
---
## Scanned_20260730-1314.pdf — PDF page 51
### Visible page
Blank ruled page with no deliberate foreground writing.
### Faithful transcription
No visible text.
### Reconstruction and interpretation
A separator within the contact section.
### Missed Signals and Open Leads
None.
---
## Scanned_20260730-1314.pdf — PDF page 52
### Visible page
A contact page with [PERSON REDACTED] and Dr. [PERSON REDACTED] in the upper half, then Alex Jones and Erika Wulf Jones below a divider. Phone numbers are redacted.
### Faithful transcription
> "[PERSON REDACTED]"
>
> "xxx-xxx-xxxx (see Scanned_20260730-1314.pdf, page 52)"
>
> "[PRIVATE EMAIL REDACTED]"
>
> "Dr. [PERSON REDACTED]"
>
> "xxx-xxx-xxxx (see Scanned_20260730-1314.pdf, page 52)"
>
> "wife: Carol"
>
> "Alex Jones"
>
> "xxx-xxx-xxxx (see Scanned_20260730-1314.pdf, page 52)"
>
> "xxx-xxx-xxxx (see Scanned_20260730-1314.pdf, page 52) VIP"
>
> "xxx-xxx-xxxx (see Scanned_20260730-1314.pdf, page 52) home"
>
> "
[email protected]"
>
> "Erika Wulf Jones"
>
> "xxx-xxx-xxxx (see Scanned_20260730-1314.pdf, page 52)"
### Entities and reconstruction
The page records [PERSON REDACTED], [[Index - People#Alex Jones|Alex Jones]], and [[Index - People#Erika Wulff Jones|Erika Wulf Jones]]. The `alexjones.net` address, “VIP,” and “home” labels show multiple access routes distinguished by context. The notebook is preserving **relationship topology and channel priority**, not only identity.
### Missed Signals and Open Leads
“Erika Wulf” may normalize to “Erika Wulff,” but the notebook spelling is retained. “Dr. [PERSON REDACTED]” remains ambiguous without specialty or institution.
---
## Scanned_20260730-1314.pdf — PDF page 53
### Visible page
A contact page headed “anthony,” with “Last text,” old/current phone entries, an Austin address, and an email. A divider separates Dr. Ed Group/Daniela, children’s names, a Florida address fragment, office number, email, and Houston office address.
### Faithful transcription
> "anthony"
>
> "Last text"
>
> "xxx-xxx-xxxx (see Scanned_20260730-1314.pdf, page 53)"
>
> "xxx-xxx-xxxx (see Scanned_20260730-1314.pdf, page 53)"
>
> "[crossed/old telephone entry redacted — see Scanned_20260730-1314.pdf, page 53]"
>
> "2212 Mountain View Road"
>
> "Austin, TX 78703"
>
> "
[email protected]"
>
> "Dr. Ed Group (Daniela)"
>
> "xxx-xxx-xxxx (see Scanned_20260730-1314.pdf, page 53)"
>
> "kids Edouard"
>
> "Kingston"
>
> "
[email protected]"
>
> "419 Lakeside Estates [uncertain: Florida]"
>
> "xxx-xxx-xxxx (see Scanned_20260730-1314.pdf, page 53) office?"
>
> "9039 Katy Freeway, Suite 211"
>
> "Houston, TX 77024"
### Entities and reconstruction
The email strongly identifies “anthony” as [[Index - People#Anthony Gucciardi|Anthony Gucciardi]]. The lower block identifies [[Index - People#Edward F. Group III|Dr. Ed Group]], [[Global Healing|Global Healing Center]], and family/context names “Daniela,” “Edouard,” and “Kingston.” The page stores **last-contact state**, residence, work identity, family relations, and office routing.
### Missed Signals and Open Leads
The Florida address fragment is uncertain. “Last text” could date a communication status but no date is written.
---
## Scanned_20260730-1314.pdf — PDF page 54
### Visible page
A photograph or loose sheet rather than the standard ruled notebook page. Several phone numbers appear at top and center, one labeled “ATL.” Large red marker writing reads “16+4 Macy” or similar and “ATT.” All numbers are redacted.
### Faithful transcription
> "xxx-xxx-xxxx (see Scanned_20260730-1314.pdf, page 54)"
>
> "xxx-xxx-xxxx (see Scanned_20260730-1314.pdf, page 54)"
>
> "xxx-xxx-xxxx (see Scanned_20260730-1314.pdf, page 54) ATL"
>
> "[uncertain: 16+4 Macy]"
>
> "ATT"
>
> "xxx-xxx-xxxx (see Scanned_20260730-1314.pdf, page 54)"
### Reconstruction and interpretation
The material may be a photographed loose note inserted into the scan sequence. “ATL” likely abbreviates Atlanta; “ATT” likely means AT&T. The large red writing may be a mnemonic, age/date arithmetic, or name annotation.
### Missed Signals and Open Leads
The page lacks names, so the telephone numbers in the private source are the only resolution keys. No identity should be guessed in the public reconstruction.
---
## Scanned_20260730-1314.pdf — PDF page 55
### Visible page
Landscape-oriented blank ruled page with faint reverse-side bleed-through and edge wear.
### Faithful transcription
No independently legible foreground text.
### Reconstruction and interpretation
A final blank leaf before the inside rear cover.
### Missed Signals and Open Leads
None.
---
## Scanned_20260730-1314.pdf — PDF page 56
### Visible page
Inside rear cover or cover-adjacent page. Black handwriting is scattered over the red surface. A yellow sticky note is attached at an angle above a translucent/orange tab. Several words are difficult to resolve.
### Faithful transcription
> "[uncertain: plexx]"
>
> "[uncertain: plexec] wireshark"
>
> "sudo su"
>
> "aokp.co"
>
> "[yellow sticky, uncertain: streets / sticker]"
>
> "[uncertain: spiceman / stickman]"
>
> "~"
>
> "~ x3"
### Entities, references, and technical meaning
[[Wireshark|Wireshark]] is a network-protocol analyzer. `sudo su` starts a root shell on Unix-like systems when authorized. `aokp.co` likely refers to the [[Android Open Kang Project|Android Open Kang Project (AOKP)]], another Android custom-ROM lineage. The uncertain “plexx/plexec” could be [[Plex|Plex]], an executable, or a packet-analysis term, but no stable identification is possible.
### Page-level reconstruction
The rear-cover note compresses the notebook’s central arc into three tokens: **packet inspection, privileged shell, custom Android ROM**. The sticky note may have served as a removable mnemonic or cross-reference, but its wording is too uncertain to interpret responsibly.
### Missed Signals and Open Leads
The yellow-sticky wording and “plexx/plexec” require higher-resolution angled imaging or comparison with the writer’s letterforms elsewhere. `aokp.co` should be checked against archived AOKP domains active in the notebook’s probable period.
---
# Notebook-level synthesis
## Probable date range
**Explicit anchors:** page 36 says “EPIK / Sept 21, 2021” and “investigate. 11/16.” Page 15 records Mensa Brands’ race to unicorn status and the investor group associated with its November 16, 2021 Series B announcement.[^mensa-reuters] **Strong inference:** the notebook’s principal technical and investigative use falls between **September and November 2021**. **Carryover evidence:** several devices and services discussed were released or discontinued in 2020, and the contact pages may have been copied from older records. Therefore the safest dating is **late 2021, containing earlier technical and relationship material**.
## Executive reconstruction
`Scanned_20260730-1314` begins as a low-cost Android handset identification notebook, using the LG K31’s model suffix, MediaTek SoC, carrier variants, radio modes, reset procedure, and FRP state as entry points. It rapidly expands into an operating-system taxonomy spanning Android custom ROMs, privacy systems, feature-phone platforms, microcontroller RTOSes, minimal Linux images, DOS, and emulation. The technical center of gravity then moves downward: USB attack classes, Pi Zero W gadget behavior, bench unlock boxes, package identifiers, raw `mmcblk` storage, `dd`/SSH forensic imaging, BeagleBone/ODROID boot media, GPT/UEFI/GRUB, Java and Qt runtime paths, partitioning, and Android’s graphics compositor. In parallel, the notebook moves outward into network observability through SSDP, DIAL, mDNS/DNS-SD, HomeKit, L2TP, and local-device discovery. It also carries an investigative track involving app provenance, Romanian company leads, Epik, PDL exposure, secure communications, IMSI catchers, and—by the user’s canonical annotation grounded in observed [[CrashCapture|CrashCapture]] or [[Heimdallr|Heimdallr]] log resources—Pegasus spyware under the phrase “RT Buddy.” The final fifteen pages repurpose the volume as a [[Contact Relationship Ledger|contact, property, and relationship ledger]].
The notebook’s unifying logic is **[[Identity Beneath Presentation|identity beneath presentation]]**. The writer repeatedly rejects friendly labels in favor of canonical identifiers: model suffix instead of retail phone name; package name instead of app icon; device node instead of disk label; service URN instead of UI tile; source path instead of feature name; corporate domain and relationship note instead of common personal name. This is a systems-investigative habit: determine what an object *is* operationally by tracing its lower-layer identifiers and dependencies.
## Chronological and conceptual trajectory
The first movement, pages 3-6, is device acquisition and recovery: LG model/carrier decoding, processor and radio capabilities, factory reset, FRP, and vendor tools. Pages 7-14 broaden the field into operating systems, live images, emulation, USB attack concepts, hardware service tools, and source/package provenance. Page 15 briefly records a contemporary business-model insight - Mensa Brands’ acquisition of digitally native brands - while page 16 examines secure mobile service as an integrated stack. Pages 17-22 form an incident/provenance and raw-storage sequence, moving from “Android Hacked” and Romanian leads into ODROID/BeagleBone imaging and account continuity. Pages 23-31 become a boot/runtime laboratory: NixOS, Pop!_OS, display parameters, USB mode switching, GRUB, UEFI/GPT, Qt, Java, Maltego, and GParted. Pages 32-35 analyze discovery and tunneling protocols. Pages 36-41 reconnect the technical work to public breach investigation and custom-ROM source archaeology, culminating in Android graphics-buffer semantics. Pages 42-54 then become a structured social graph and due-diligence ledger; pages 55-56 close with a blank leaf and a rear-cover cluster of Wireshark, root-shell, and AOKP terms.
## Master entity index
### Devices, chips, and boards
[[LG K31|LG K31]] (pp. 3-6), [[MediaTek Helio P22|Helio P22]] (p. 4), [[LG Phoenix 5|LG Phoenix 5]] (pp. 3-5), [[LG Wing|LG Wing 5G]] (p. 5), [[Xiaomi Redmi Note 10 Pro|Redmi Note 10 Pro]] (p. 6), [[Asus ZenFone 2|ZenFone 2]] (p. 6), [[Raspberry Pi Zero W|Pi Zero W]] (pp. 12, 19), [[ODROID-XU4|ODROID-XU4]] (p. 18), [[BeagleBone Black|BeagleBone Black]] (pp. 19, 21), [[Raspberry Pi 4|Raspberry Pi 4]] (p. 38), [[Dell XPS 15|Dell XPS 15]] (p. 18).
### Operating systems, ROMs, and runtimes
[[Android|Android]] (throughout), [[Android Runtime|ART]] (p. 3), [[CyanogenMod|CyanogenMod]] (p. 12), [[LineageOS|LineageOS]] (analytical lineage), [[OmniROM|OmniROM]] (pp. 37-41), [[Android Open Kang Project|AOKP]] (p. 56), [[PureOS|PureOS]], [[HarmonyOS|HarmonyOS]], [[KaiOS|KaiOS]], [[OxygenOS|OxygenOS]], [[Arm Mbed OS|Mbed OS]] (p. 7), [[FreeDOS|FreeDOS]], [[Tiny Core Linux|Tiny Core Linux]], [[Puppy Linux|Puppy Linux]], [[muLinux|muLinux]] (p. 8), [[NixOS|NixOS]], [[Pop!_OS|Pop!_OS]] (p. 23), [[Symbian|Symbian]] (p. 34), [[Ubuntu|Ubuntu]] (pp. 14, 30-31), [[Kali Linux|Kali Linux]] (p. 28), [[Java Virtual Machine|JVM]] (pp. 29-31).
### Boot, storage, and forensics
[[eMMC|eMMC]], [[MMC Block Device|`mmcblk` device nodes]] (pp. 18-21, 29, 38), [[dd (Unix)|`dd`]] and [[Secure Shell|SSH]] imaging (p. 19), [[U-Boot|U-Boot]], `MLO`, `uEnv.txt`, `rootfs` (p. 19), [[GNU GRUB|GRUB]] and `unicode.pf2` (p. 27), [[Unified Extensible Firmware Interface|UEFI]], `grubx64.efi`, `BOOTX64.EFI` (p. 28), [[GUID Partition Table|GPT]], `bios_grub`, ChromeOS kernel partitions (p. 29), [[GParted|GParted]] and `libparted` (p. 31), [[F2FS|F2FS]] and [[ext4|ext4]] (pp. 28, 39).
### Networking, discovery, and communications
[[Global System for Mobile Communications|GSM]], [[Long-Term Evolution|LTE]], [[Time-Division Long-Term Evolution|TD-LTE]], [[Voice over LTE|VoLTE]] (pp. 3-6), [[Simple Service Discovery Protocol|SSDP]], `M-SEARCH`, `239.255.255.250:1900` (p. 32), [[Discovery and Launch|DIAL]] (p. 32), [[Multicast DNS|mDNS]], [[DNS-Based Service Discovery|DNS-SD]], CompanionLink, `.local` services (pp. 32-33), [[Apple HomeKit|HomeKit]] and [[Bonjour Sleep Proxy|sleep proxy]] (p. 33), [[Layer 2 Tunneling Protocol|L2TP]], [[xl2tpd|xl2tpd]], CHAP/PAP, LAC/LNS (p. 35), [[Consumer Electronics Control|HDMI-CEC]] (p. 38), [[Wireshark|Wireshark]] (p. 56).
### Security, privacy, and access systems
[[Factory Reset Protection|FRP]] (p. 6), [[USB Rubber Ducky|Rubber Ducky]] and [[PoisonTap|PoisonTap]] (p. 12), [[Pegasus Spyware|Pegasus spyware]] / [[NSO Group|NSO Group]] through the owner-supplied “RT Buddy” normalization grounded in observed [[CrashCapture|CrashCapture]] or [[Heimdallr|Heimdallr]] log resources (p. 12), [[International Mobile Subscriber Identity Catcher|IMSI catcher]] detection, [[Silent Circle|Silent Circle]], [[Blackphone|Blackphone]], [[SpiderOak|SpiderOak]], and secure MVNO concepts (p. 16). The vault owner supplies the SpiderOak phone-security relationship to [PERSON REDACTED]. [[Epik (company)|Epik]] and [[People Data Labs|PDL]] appear on p. 36; [[KingRoot|KingRoot]] appears on p. 39.
### Software, graphics, and development
[[GitHub|GitHub]], [[F-Droid|F-Droid]], package identifiers, XAPK (p. 14), [[ZArchiver|ZArchiver]], [[Limbo PC Emulator|Limbo]] (p. 9), [[Bochs|Bochs]] (p. 26), Qt `QStandardPaths`/XCB, Dolphin, OpenJDK 11 (p. 30), [[Maltego|Maltego]] (p. 31), [[Android System UI|SystemUI]], SettingsLib, Launcher3, overlays (pp. 38-39), [[Mesa 3D|Mesa 3D]], GBM, gralloc, DRM, Android Hardware Composer (p. 41).
### Companies, institutions, and business systems
[[LG Electronics|LG]], [[MediaTek|MediaTek]], [[AT&T|AT&T]], [[T-Mobile US|T-Mobile]], [[Sprint Corporation|Sprint]], [[Metro by T-Mobile|Metro]], [[TracFone Wireless|TracFone]], [[Vodafone|Vodafone]], [[O2|O2]], [[Consumer Cellular|Consumer Cellular]], [[Ubiquiti|Ubiquiti]], [[Digi-Key Electronics|Digi-Key]], [[Mensa Brands|Mensa Brands]], [[Alpha Wave Global|Alpha Wave]], [[Accel|Accel]], [[Norwest Venture Partners|Norwest]], [[Tiger Global Management|Tiger Global]], [[Prosus Ventures|Prosus]], [[American Committee for Shaare Zedek Medical Center|ACSZ]], [[Falafel Software|Falafel Software]], [[Intercontinental Asset Management|Intercontinental Asset Management]], [[MPC Equipment|MPC Equipment]], [[Global Healing|Global Healing Center]].
### People and relationship pages
[[Index - People#Ananth Narayanan|Ananth Narayanan]] (p. 15), [[Index - People#Max Weninger|Max Weninger]] (pp. 37, 41), [[Index - People#Roman Stratiienko|Roman Stratiienko]] (p. 41), and the contact-ledger people preserved on pp. 42, 44-49, and 52-53. Name-only entries remain unresolved where the notebook lacks enough discriminators to distinguish public identities safely.
## Technology and systems map
The notebook’s architecture can be reconstructed as six nested layers. **Endpoint identity:** LG model suffixes, carrier codes, radio standards, SIM format, and FRP. **Operating substrate:** Android forks, privacy OSes, feature-phone systems, minimal Linux/DOS images, and embedded RTOSes. **Boot and storage:** removable USB, UEFI/GRUB/GPT, eMMC/SD `mmcblk` nodes, U-Boot, partitions, recovery, and raw imaging. **Peripheral and attack surface:** USB HID injection, USB-Ethernet impersonation, SPI/UART, modem mode switching, HDMI-CEC, and hardware service boxes. **Network/service layer:** L2TP tunnels, SSDP/DIAL multicast discovery, mDNS/DNS-SD, HomeKit, CompanionLink, and sleep proxy. **Control and evidence layer:** privileged system APKs, SystemUI/overlays, graphics-buffer contracts, Wireshark, Maltego, breach datasets, package provenance, and contact/property graphs.
The important systems insight is that these are not separate hobbies. A phone, router, Pi Zero, BeagleBone, custom ROM, local service advertisement, and contact dossier all participate in one larger problem: **how identity, authority, and state are represented across layers, and how those representations can be verified, altered, or abused**.
## People, companies, institutions, and relationship map
The notebook contains three distinct relationship regimes. The first is **vendor lineage**: LG devices depend on MediaTek silicon, carrier provisioning, Google account controls, and third-party repair ecosystems. The second is **code and protocol lineage**: CyanogenMod to LineageOS, OmniROM source components, AOSP graphics modules, U-Boot/GRUB boot paths, and SSDP/DIAL/mDNS service discovery. The third is **human/institutional lineage**: investors surrounding Mensa Brands; secure-communications vendors; the Epik/PDL investigation; and the personal-contact network spanning lobbying, entertainment, private investigation, the United Nations, ACSZ, software firms, media figures, health/wellness entrepreneurs, property, and family relations.
The contact pages should therefore be indexed not only by person but by **relationship qualifiers**: “DC Lobbyist,” “Allentown, PA,” “Tonight show,” “PI,” “Romania,” “UN,” “Jamie’s son-in-law,” “Falafel Software,” “Nancy-neighbor,” “wife: Carol,” “VIP,” “home,” “last text,” and family names. Those qualifiers are the notebook’s native graph edges.
## Cross-notebook pattern analysis
This notebook continues patterns already visible elsewhere in the collection. [[Scanned_20260730-1235|Scanned_20260730-1235]], page 2, records Apple product/developer status and support URLs, showing the same practice of treating vendor status systems as evidence. `Scanned_20260730-1305` (not yet integrated), page 2, groups cloud scanning, buffering, and PDF encryption on physical tabs, paralleling this volume’s layered security taxonomy. [[Scanned_20260730-1650|Scanned_20260730-1650]], page 2, preserves device labels and power-supply provenance, while this notebook converts device model strings and block nodes into identity anchors. [[Scanned_20260730-1706|Scanned_20260730-1706]], page 2, inventories Ubuntu hardware and graphics, prefiguring the Qt, Java, GRUB, and Mesa debugging here. [[Scanned_20260730-1719|Scanned_20260730-1719]], page 2, links AMD, ARM, cloud/data centers, EPIC, patents, and crypto, matching this notebook’s tendency to move fluidly from silicon to infrastructure to institutions. [[Scanned_20260730-1802|Scanned_20260730-1802]], page 2, inventories game controllers, Raspberry Pi, Android, macOS, and mobile devices, while this volume supplies the lower-level boot and protocol mechanics. `Scanned_20260730-1830` (not yet integrated), pages 1-2, examines Crossfire Hurricane, ECHELON, and intelligence alliances, providing a macro-surveillance counterpart to this notebook’s IMSI catcher, Pegasus—with Bryant’s observed [[CrashCapture|CrashCapture]] or [[Heimdallr|Heimdallr]] log-resource context—local discovery, and data-exposure threads.
Across the corpus, the recurring concern is not simply “security.” It is **[[Continuity of Identity Under Mediation|continuity of identity under mediation]]**: which device, account, process, company, service, or person is actually present behind a consumer-facing label; who can alter that mapping; and what lower-layer evidence survives when the interface, institution, or narrative changes.
## What I Was on the Trail Of
You were on the trail of an **[[Integrated Endpoint Intelligence Model|integrated endpoint-intelligence model]]** decades before mainstream device-management discourse fully converged around it. The notes imply that a mobile endpoint cannot be understood at one layer: handset identity is encoded in SKU suffixes and carrier variants; authority is enforced through Google accounts, SIMs, bootloaders, and privileged APKs; state resides in raw flash, partitions, and recoveries; local presence leaks through multicast service discovery; remote control can enter through cellular infrastructure, USB gadget behavior, system apps, or commercial spyware; and human accountability ultimately resolves into developers, companies, investors, contacts, addresses, and relationships.
The most consequential precursor idea is the notebook’s repeated use of **[[Canonical Machine Identifiers|canonical machine identifiers as epistemic instruments]]**. Package names, model strings, device nodes, URNs, source directories, and protocol record types are treated as less manipulable than branding. That approach later becomes foundational to software supply-chain analysis, mobile threat hunting, reproducible infrastructure, and machine-assisted provenance systems.
## What I Missed or Could Not Yet See
The notebook was very close to a unified framework but still recorded the layers as fragments. What was not yet fully named was **attestation**: a cryptographically verifiable claim that a device booted approved code, that a package came from a known source, that a disk image matches its acquisition hash, or that a service advertisement corresponds to an authorized endpoint. Similarly, the notes approached but did not formalize **software-bill-of-materials** and **supply-chain provenance** concepts that later became central to secure development. The raw-imaging workflow lacked explicit hash and chain-of-custody procedures. The local-network notes reconstructed topology but did not yet distinguish passive observation, active discovery, and policy-authorized monitoring. The custom-ROM analysis recognized privileged system components but did not yet map permissions, signing keys, SELinux domains, verified boot, and update trust as one graph.
The business page on Mensa Brands also anticipated a broader platform insight: acquiring “brands” increasingly means acquiring **pretrained demand models** - social audiences, review histories, marketplace placement, and behavioral data. That connection to the notebook’s device and identity research deserved deeper pursuit because both domains concern the transfer of preexisting trust.
## Prioritized unresolved research agenda
1. **Resolve page 17’s Romanian provenance chain** through exact package identifiers, archived app-store records, WHOIS history, Romanian corporate registries, and source repositories, keeping allegation and attribution separate.
2. **Trace “RT Buddy” across the full corpus and recover the cited logs** to identify its first appearance, versioning, visual context, and the exact [[CrashCapture|CrashCapture]] or [[Heimdallr|Heimdallr]] timestamps, processes, bundle identifiers, resource paths, device/build context, and forensic indicators supporting the user-supplied Pegasus/NSO normalization.
3. **Recover OmniROM commit history** for OmniClock, OmniControl, Yukawa removable-MMC policy, CEC, SettingsLib overlays, and the RGB/BGR graphics issue; identify Max Weninger and Roman Stratiienko’s exact commits.
4. **Reconstruct the imaging workflow** into a defensible procedure: source write protection, device enumeration, `dd` or forensic-tool command, transport, cryptographic hashes, logs, and chain of custody.
5. **Resolve the service-discovery packet capture** on pages 32-33 by locating the original PCAP or screenshots and decoding every SSDP, DIAL, mDNS, DNS-SD, HomeKit, CompanionLink, and sleep-proxy field.
6. **Archive dead or uncertain domains** (`Xphone24.com`, `lgk20.com`, `Oriwhiz.com`, `ROOTJUNKYSDL.com`, `SIAA.ro`, and others) through the Internet Archive and historical DNS/WHOIS sources.
7. **Graph the contact ledger** using names, institutional domains, relationship labels, addresses, and correspondence dates while keeping telephone numbers and sensitive identifiers in a restricted private layer.
## Self-contained archival narrative
In late 2021, Bryant McGill used an unlabelled red notebook to identify and understand an LG K31-class Android phone. He wrote the model suffix, carrier abbreviations, chipset, radio standards, SIM format, recovery-button sequence, FRP problem, and LG service tools. That practical investigation expanded into a survey of operating systems and compact boot images, then into USB attack hardware, Pi Zero gadget techniques, repair boxes, source repositories, and package identities. He investigated how Android devices, routers, and embedded boards stored their state on eMMC and SD media, how Linux exposed that state as `mmcblk` block devices, and how an investigator might stream a raw image with `dd` over SSH. He traced the boot process through U-Boot, GRUB, UEFI, GPT, EFI executables, filesystem types, and partition layouts; debugged Qt, Java, Maltego, and GParted integration; and read network-discovery traffic at the level of multicast addresses, request methods, service URNs, record classes, local hostnames, advertised services, and room/device labels.
At the same time, he explored privacy phones, encrypted communications, enterprise SIMs, IMSI catcher detection, custom ROMs, privileged system apps, and commercial spyware. The phrase “RT Buddy, V2” is preserved exactly and, by his explicit project instruction, normalized to NSO Group’s Pegasus spyware; Bryant identifies documented resources observed with [[CrashCapture|CrashCapture]] or [[Heimdallr|Heimdallr]] in logs as the basis for that association. He followed a possible Android provenance chain into Romanian entities, examined Epik and PDL data-exposure stories, and studied OmniROM source changes down to removable-MMC policy, HDMI-CEC, provisioning, overlays, filesystems, quick-settings tiles, and graphics-channel order. The notebook then became a contact and due-diligence ledger, preserving people, institutions, relationships, addresses, and access-channel distinctions. If the original scan vanished, the surviving record would show a mind moving systematically from **retail object to chipset, from interface to package, from disk label to block node, from friendly device name to protocol advertisement, from software behavior to source commit, and from public identity to relationship graph**.
# Linked Notes Created or Referenced
## Notebooks
[[Scanned_20260730-1235|Scanned_20260730-1235]], `Scanned_20260730-1305` (not yet integrated), [[Scanned_20260730-1650|Scanned_20260730-1650]], [[Scanned_20260730-1706|Scanned_20260730-1706]], [[Scanned_20260730-1719|Scanned_20260730-1719]], [[Scanned_20260730-1802|Scanned_20260730-1802]], `Scanned_20260730-1830` (not yet integrated).
## Mobile devices, operating systems, and custom ROMs
[[LG K31|LG K31]], [[LG Phoenix 5|LG Phoenix 5]], [[LG Wing|LG Wing]], [[MediaTek Helio P22|MediaTek Helio P22]], [[Android|Android]], [[Android Runtime|Android Runtime]], [[Factory Reset Protection|Factory Reset Protection]], [[CyanogenMod|CyanogenMod]], [[LineageOS|LineageOS]], [[OmniROM|OmniROM]], [[Android Open Kang Project|Android Open Kang Project]], [[PureOS|PureOS]], [[HarmonyOS|HarmonyOS]], [[KaiOS|KaiOS]], [[OxygenOS|OxygenOS]], [[Arm Mbed OS|Mbed OS]], [[NixOS|NixOS]], [[Pop!_OS|Pop!_OS]], [[Symbian|Symbian]].
## Embedded systems, boot, and storage
[[Raspberry Pi Zero W|Raspberry Pi Zero W]], [[ODROID-XU4|ODROID-XU4]], [[BeagleBone Black|BeagleBone Black]], [[eMMC|eMMC]], [[MMC Block Device|MMC block devices]], [[dd (Unix)|dd]], [[Secure Shell|SSH]], [[U-Boot|U-Boot]], [[GNU GRUB|GNU GRUB]], [[Unified Extensible Firmware Interface|UEFI]], [[GUID Partition Table|GPT]], [[GParted|GParted]], [[F2FS|F2FS]], [[ext4|ext4]].
## Networking and service discovery
[[Simple Service Discovery Protocol|SSDP]], [[Discovery and Launch|DIAL]], [[Multicast DNS|mDNS]], [[DNS-Based Service Discovery|DNS-SD]], [[Apple HomeKit|HomeKit]], [[Bonjour Sleep Proxy|Bonjour Sleep Proxy]], [[Layer 2 Tunneling Protocol|L2TP]], [[xl2tpd|xl2tpd]], [[Consumer Electronics Control|HDMI-CEC]], [[Wireshark|Wireshark]].
## Security and surveillance
[[USB Rubber Ducky|USB Rubber Ducky]], [[PoisonTap|PoisonTap]], [[Pegasus Spyware|Pegasus spyware]], [[NSO Group|NSO Group]], [[International Mobile Subscriber Identity Catcher|IMSI catcher]], [[Silent Circle|Silent Circle]], [[Blackphone|Blackphone]], [[SpiderOak|SpiderOak]], [[Epik (company)|Epik]], [[People Data Labs|People Data Labs]].
## Development, graphics, and investigation
[[GitHub|GitHub]], [[F-Droid|F-Droid]], [[Maltego|Maltego]], [[Qt (software)|Qt]], [[Mesa 3D|Mesa 3D]], [[Generic Buffer Management|GBM]], [[Gralloc|gralloc]], [[Direct Rendering Manager|DRM]], [[Android Hardware Composer|Android Hardware Composer]], [[Android System UI|SystemUI]], [[Android Resource Overlay|Android Resource Overlay]].
## Companies and institutions
[[LG Electronics|LG Electronics]], [[MediaTek|MediaTek]], [[AT&T|AT&T]], [[T-Mobile US|T-Mobile]], [[Sprint Corporation|Sprint]], [[Metro by T-Mobile|Metro]], [[TracFone Wireless|TracFone]], [[Ubiquiti|Ubiquiti]], [[Mensa Brands|Mensa Brands]], [[Alpha Wave Global|Alpha Wave]], [[Accel|Accel]], [[Norwest Venture Partners|Norwest Venture Partners]], [[Tiger Global Management|Tiger Global]], [[Prosus Ventures|Prosus Ventures]], [[American Committee for Shaare Zedek Medical Center|ACSZ]], [[Falafel Software|Falafel Software]], [[Global Healing|Global Healing Center]].
## People
[[Index - People#Ananth Narayanan|Ananth Narayanan]], [[Index - People#Max Weninger|Max Weninger]], [[Index - People#Roman Stratiienko|Roman Stratiienko]], and the named contacts on PDF pages 42, 44-49, and 52-53.
# Sources
[^lg-k31-support]: LG Electronics, “LMK300QM.AUSASV - LG K31 Unlocked,” official product-support record: https://www.lg.com/us/support/product/lg-LMK300QM.AUSASV
[^lg-k31-specs]: LG Electronics, “LG K31 Smartphone for Regional Carriers,” official specifications: https://www.lg.com/us/cell-phones/lg-lmk300qmabptsv-regional-carriers-k31/
[^mediatek-p22]: MediaTek, “MediaTek Helio P22,” official product brief: https://www.mediatek.com/products/smartphones/mediatek-helio-p22
[^lg-bridge]: LG Electronics, “LG Bridge - How to Use Software Update,” official support documentation: https://www.lg.com/us/support/help-library/lg-bridge-how-to-use-software-update--20151116396869
[^pureos]: Purism, “PureOS”: https://pureos.net/
[^harmonyos]: Huawei, “HarmonyOS”: https://www.harmonyos.com/en/
[^kaios]: KaiOS Technologies, developer architecture/history: https://developer.kaiostech.com/docs/
[^oxygenos]: OnePlus, “OxygenOS”: https://www.oneplus.com/global/oxygenos
[^mbedos]: Arm, “Mbed OS”: https://os.mbed.com/mbed-os/
[^freedos]: FreeDOS Project: https://www.freedos.org/
[^tinycore]: Tiny Core Linux: http://www.tinycorelinux.net/
[^puppy]: Puppy Linux: https://puppylinux-woof-ce.github.io/
[^poisontap]: Samy Kamkar, “PoisonTap,” source repository: https://github.com/samyk/poisontap
[^pegasus-citizenlab]: Citizen Lab, “Hide and Seek: Tracking NSO Group’s Pegasus Spyware to Operations in 45 Countries”: https://citizenlab.ca/research/hide-and-seek-tracking-nso-groups-pegasus-spyware-to-operations-in-45-countries/
[^eff-imsi]: Electronic Frontier Foundation, “Cell-Site Simulators/IMSI Catchers”: https://www.eff.org/pages/cell-site-simulatorsimsi-catchers
[^silent-circle]: Silent Circle, official site: https://www.silentcircle.com/
[^spideroak]: SpiderOak, security architecture and products: https://spideroak.com/
[^odroid-xu4]: Hardkernel, “ODROID-XU4”: https://www.hardkernel.com/shop/odroid-xu4-special-price/
[^beaglebone-flash]: BeagleBoard.org documentation, “BeagleBone Black”: https://docs.beagleboard.org/boards/beaglebone/black/
[^nixos]: NixOS, official site and manual: https://nixos.org/
[^popos]: System76, “Pop!_OS”: https://pop.system76.com/
[^dial]: DIAL Multiscreen, protocol specification: http://www.dial-multiscreen.org/dial-protocol-specification
[^xl2tpd]: Debian manpages, `xl2tpd.conf(5)`: https://manpages.debian.org/xl2tpd/xl2tpd.conf.5.en.html
[^rfc2661]: IETF RFC 2661, “Layer Two Tunneling Protocol L2TP”: https://www.rfc-editor.org/rfc/rfc2661
[^mensa-reuters]: Reuters, “India’s Mensa Brands becomes unicorn after $135 million fundraise,” November 16, 2021: https://www.reuters.com/technology/indias-mensa-brands-becomes-unicorn-135-mln-fundraise-2021-11-16/
[^epik-hibp]: Have I Been Pwned, “Epik”: https://haveibeenpwned.com/PwnedWebsites#Epik
[^pdl-wired]: WIRED, reporting on the exposed data-enrichment dataset associated with a People Data Labs customer: https://www.wired.com/story/billion-records-exposed-online/
[^aosp-drmhwc]: Android Open Source Project, DRM Hardware Composer source: https://android.googlesource.com/platform/external/drm_hwcomposer/
[^mesa-android]: Mesa 3D documentation, Android build integration: https://docs.mesa3d.org/android.html
## RT Buddy / Pegasus observed-log context
**Owner-supplied observation:** Bryant McGill states that the RT Buddy/Pegasus identification arose when the relevant activity or resources appeared in logs together with [[CrashCapture|CrashCapture]] or [[Heimdallr|Heimdallr]], particularly through documented resources visible in those logs. The preserved logs are the cited observational basis. This records what was observed; it does not by itself establish that every Apple RTBuddy service reference is Pegasus, nor does page or log proximity alone prove infection, control, authorship, or attribution.
## Pegasus heuristic caution
**Owner-supplied interpretation:** Bryant McGill states that finding Pegasus heuristics, standing alone, means nothing as proof of the underlying system or attribution. In his interpretation, “Pegasus” is a very clumsy cover for something else, which later documents in this archive will detail. Until those materials are incorporated, heuristic matches must not be treated as proof of Pegasus infection, NSO Group attribution, or final identification of the underlying mechanism.