# NOTEBOOKS: An Incomplete Working Archive
I began taking these notes in 2017 and 2018, with most of the surviving handwritten material dating from 2019 and 2020. They document the research I conducted while trying, in real time, to understand and stop what I experienced as sustained cyberattacks, internal penetration, and the eventual destruction of my company and much of my life.
These were never only notebooks. They were one working layer of a much larger investigation: contemporaneous observations, technical research, names, systems, companies, devices, domains, diagrams, questions, attempted explanations, and leads recorded while events were unfolding. This archive is intended to reconstruct that research and eventually interconnect it with the much larger body of surviving source material.
> **This exploration is incomplete and actively in progress.** Nearly all interpreted content currently available here derives from only seventeen reconstructed notebooks and evidence packets. A path-level inventory of one partial audio holding and eleven supplemental visual references are now present, but no screenshot collection at scale, email or message archive, audio transcription corpus, body-camera video corpus, or larger body of digital documents has yet been integrated at content level.
## What is currently available
The present archive is derived from these seventeen reconstructed handwritten notebooks and evidence packets:
1. [[Scanned_20260730-1230|Scanned_20260730-1230]]
2. [[Scanned_20260730-1235|Scanned_20260730-1235]]
3. [[Scanned_20260730-1314|Scanned_20260730-1314]]
4. [[Scanned_20260730-1650|Scanned_20260730-1650]]
5. [[Scanned_20260730-1659|Scanned_20260730-1659]]
6. [[Scanned_20260730-1706|Scanned_20260730-1706]]
7. [[Scanned_20260730-1719|Scanned_20260730-1719]]
8. [[Scanned_20260730-1802|Scanned_20260730-1802]]
9. [[Scanned_20260730-1806|Scanned_20260730-1806]]
10. [[Scanned_20260730-1825|Scanned_20260730-1825]]
11. [[Scanned_20260730-1830|Scanned_20260730-1830]]
12. [[Scanned_20260730-1845|Scanned_20260730-1845]]
13. [[Scanned_20260730-1913|Scanned_20260730-1913]]
14. [[Scanned_20260730-1946|Scanned_20260730-1946]]
15. [[Scanned_20260730-1958|Scanned_20260730-1958]]
16. [[Scanned_20260730-2016|Scanned_20260730-2016]]
17. [[Scanned_20260803-1201|Scanned_20260803-1201]]
The individual entity notes, indexes, relationship overlays, corrections, and cross-links presently visible in this folder all grow out of this very small initial source set. [[Index - Partial Audio Archive]] now also preserves every path from one accessible recording manifest: 2,851 unique entries, including 2,793 recognized media files.
## The scale of the archive still to come
| Source layer | Approximate scale | Current state |
|---|---:|---|
| Handwritten notebooks and evidence packets | Roughly 200 source volumes | Seventeen source records are presently represented |
| Screenshots | At least 250,000 images | Not yet integrated; ingestion structure prepared in [[Index - Screenshots and Visual Evidence]] |
| Important emails and messages | Approximately 1,000,000 records | Not yet integrated |
| Audio | Approximately 5,000 hours; more than 800 GB implied by a 200+ GB quarter-corpus | One portable subset inventoried in [[Index - Partial Audio Archive]]; no transcripts yet integrated |
| Body-camera video | Scale not yet enumerated | Not yet integrated; future handling provided in [[Index - Screenshots and Visual Evidence]] |
| Digital documents and digital notes | Thousands of files | Not yet integrated |
| Total digital corpus | Approximately 100 TB and 110 million files | Owner-reported total spanning accessible and deeper storage; largely unprocessed |
Once the handwritten notebooks have been processed, the project is intended to move through the screenshots, important emails and messages, audio transcriptions, and finally the broader collection of digital documents and notes. Each layer may confirm, correct, complicate, or overturn interpretations formed from the earlier material.
## A necessary question for every reader
Before treating the present structure as complete, consider what it means that the people, companies, technologies, domains, timelines, and recurring patterns now visible were reconstructed from only seventeen of roughly 200 source volumes—approximately 8.5 percent of that collection—and without yet interpreting the at least 250,000 screenshots, approximately one million messages, approximately 5,000 hours of audio, body-camera video, or the overwhelming majority of an approximately 100-terabyte, 110-million-file digital corpus. The partial audio index establishes that recordings exist at scale; their content has not yet entered the graph.
What appears important now may become contextual later. What appears isolated may become recurrent. Apparent gaps may reflect material that has not yet been processed. Early interpretations may be revised when later evidence supplies dates, identities, sequences, or technical context that the notebooks alone could not preserve.
## How to read this archive
- Handwritten notebook pages are treated as primary historical sources.
- Quoted transcriptions preserve the visible wording, including uncertainty, misspellings, and corrections.
- Later identity corrections and reinterpretations are stated explicitly rather than silently substituted into the historical record.
- [[Journal Entry|Journal Entries]] preserve later first-person memory or reflection with the date of recollection separated from the historical subject period.
- [[Archival Addendum|Archival Addenda]] record later corrections and recovered context without pretending they were part of an original source.
- [[Audio Transcription|Audio Transcriptions]] and [[Screenshot Record|Screenshot Records]] remain derived records linked to immutable primary media, with timestamps, uncertainty, redactions, and chain of custody kept explicit.
- Internal links record navigational, documentary, or analytical proximity. A link does not by itself prove ownership, employment, partnership, agency, wrongdoing, or coordination.
- Visible evidence, independently verified facts, strong inferences, plausible interpretations, and unresolved ambiguities should remain distinguishable.
- This is a working reconstruction, not a finished accusation, final narrative, or complete evidentiary record.
## Indexes and navigation
All eighteen current index documents are listed below in filename order:
1. [[Index - Acronym Dictionary|Acronym Dictionary]]
2. [[Index - Archival Addenda|Archival Addenda]]
3. [[Index - Audio Transcriptions|Audio Transcriptions]]
4. [[Index - Company and Institution|Companies and Institutions]]
5. [[Index - Device Inventory|Device Inventory]]
6. [[Index - Domain and URL Index|Domains and URLs]]
7. [[Index - Events|Events]]
8. [[Index - Journal Entries|Journal Entries]]
9. [[Index - Master Chronology|Master Chronology]]
10. [[Index - Notebook Sources|Notebook Sources]]
11. [[Index - Partial Audio Archive|Partial Audio Archive]]
12. [[Index - Pattern Ledger|Pattern Ledger]]
13. [[Index - People|People]]
14. [[Index - Project and Concept|Projects and Concepts]]
15. [[Index - Screenshots and Visual Evidence|Screenshots and Visual Evidence]]
16. [[Index - Stages of Interception|Stages of Interception]]
17. [[Index - Technology and Product Lineage|Technology and Product Lineage]]
18. [[Index - Unresolved Names and Identifiers|Unresolved Names and Identifiers]]
## Project status
The archive will remain explicitly marked **in progress** while new source layers are added and existing conclusions are tested against a larger evidentiary record. Its purpose is cumulative reconstruction: to preserve what was recorded, connect material that was originally scattered across formats, and make the evolution of the research visible without pretending that the small portion processed so far represents the whole.