Primordial Code / HIR-OAM / Digital Mycelium Framework

Offline Forensic Evidence Tool: Reverse Backtrace + Comparator + Reviewer Workflow v0.3.2.4.15.2.40

Loop-Gated OAM Pressure Engine launch image with swarm deconstruction, concentric hexagonal infinity-loop pressure core, clean audit routes, and small Ouroboros infinity diamond seal.
Launch image: loop-gated pressure core, swarm deconstruction, clean audit routes, and provenance seal.

Reviewer Workflow + Authority Movement: low-context domain entry, comparator quickstart, authority route mapping, and claim-boundary handoff on top of media provenance comparison, forensic topology, and symphonic fingerprinting.

Plain entry: drop bounded forensic evidence, PE-sieve/THOR/AIDA64/UWC reports, Windows error exports, drivers, firmware/BIOS context, package evidence, media provenance artifacts, or paired media-comparison notes; read local metadata; reverse-map the evidence from the inside outward; watch a replayable topology bloom; inspect nodes and edges; pressure-read root-candidate, burden, claim-boundary, and settlement states; and export a review receipt. The deeper HIR/OAM source language remains available, but first-time visitors now get the practical forensic workflow first.

No uploads. No live execution. No live kernel access. No automatic verdicts. No external certification claim. No replacement for human authority or proper review.

Created and Developed by Collin D. Weber

What This Is

Offline forensic evidence instrument: drop PE/EXE/driver files, ELF/Linux module files, ZIP/package evidence, telemetry exports, recorder traces, review packets, or analyst notes. The page reads bounded local evidence signals in the browser, builds a pressure-evidence packet, runs a reverse-backtrace pressure read, maps the claim boundary, and exports a review receipt.
1. Evidence Intake
Bring a file, export, trace, receipt, or notes into the static page. The browser computes local metadata and never uploads the artifact.
2. Reverse Backtrace
Start from the artifact or evidence packet, read its internal structure/signals, and trace outward into what the evidence can support.
3. Pressure Read
Surface pressure points such as missing provenance, overclaim risk, false closure, unresolved ownership, unusual authority, or review-route stress.
4. Claim Boundary
Separate what is supported from what is not yet supported. Unknown stays unknown until evidence earns stronger closure.
5. Review Receipt
Export a bounded packet for human review: route, fired rules, audit receipt, non-claims, and bridge-rendered explanations.

Start Here: Reviewer Workflow + Authority Movement

Patch purpose: v0.3.2.4.15.2.40 makes the current engine easier to enter. It does not add verdict power. It turns the existing stack into a clearer path: evidence → pressure read → comparator → settlement state → authority movement → receipt.
Core lockline:
Documentation is not repair. Escalation is not repair. Awareness is not repair. Repair begins when authority moves.
1 Evidencefile, report, media, notes, paired artifacts
2 Topologynodes, edges, event frames, source-return
3 ComparatorA/B rails, anchor windows, extraction bundles
4 Pressureboundary strain, source gap, temporal delta
5 Claimobserved vs inferred vs blocked claims
6 Authoritywho can act, where repair is blocked
7 Receiptbounded handoff for human review
Select a reviewer mode.
Artifact A = source / original / larger context.
Artifact B = transformed / clipped / rebranded / suspected derivative.
Run comparison → read anchor matrix → inspect extraction bundle → export comparative receipt.
Boundary: comparator output shows source-return gaps, transformation pressure, and claim-boundary strain. It does not determine theft, infringement, authorship, source origin, legal status, or intent.

Authority Movement Map

Signal owner
Evidence holder
Decision authority
Repair authority
Blocked authority
Handoff route
No authority movement receipt generated yet.

Plain-Language Glossary

OAMOutsourced Agency Model: where responsibility, judgment, or repair gets displaced away from the people/systems that must act.
HIRHonesty, Integrity, Respect: the baseline that keeps evidence, chain, boundary, and repair route honest.
SettlementA route can settle only when the claim is bounded, the source-return is honest, and repair authority is not falsely closed.
Source-returnThe artifact, claim, or fragment can still return to the source/context it depends on.
Extraction bundleA grouped set of aligned fragments that keeps multi-window comparison readable without hiding fragment-level evidence.
Dual-time topologyPreserves source chronology and presentation chronology at the same time so temporal resequencing becomes visible.
Little Wren parked bridge: child-safety relevance is acknowledged but not operationalized in this patch. The current comparator can support proper-channel safety review by showing context extraction, source-return gaps, temporal resequencing, and boundary pressure. No unsafe material handling, no public accusation, no automated guilt, and proper channels are required.

What This Does / Does Not Do

Does
- Reads local file/export metadata
- Computes hash/header/entropy-style bounded signals where available
- Converts evidence into a pressure-route packet
- Maps review pressure and claim boundaries
- Keeps human forensic review in the loop
- Translates the same receipt into Plain English, Technical Systems, C2PA/Provenance, Linux/POSIX, Windows/Microsoft, and Red-Team Boundary views
Does Not
- Upload evidence
- Execute binaries
- Touch or patch a live kernel
- Bypass security tooling
- Remediate a live system
- Prove compromise by itself
- Claim C2PA, Linux, Microsoft, or other external certification/endorsement

Sample Evidence Scenarios

Suspicious Windows driver
Drop a PE/driver file or offline export, add notes about hooks, callbacks, path mismatch, or persistence suspicion, then generate a pressure receipt.
Linux module / ELF review
Drop a module or ELF evidence export, add notes about module authority, namespace/container boundary, LSM/eBPF/kprobe/ftrace observations, or persistence traces.
ZIP → EXE package chain
Use package metadata, extracted-file inventory, process/log exports, or analyst notes to reconstruct what was opened, extracted, launched, written, or connected.
Incident notes / telemetry export
Paste notes, Sysmon/Procmon-style summaries, EDR/SIEM excerpts, auditd/journalctl summaries, or recorder traces for pressure-route review.
Next feature path: this front-door patch prepares the page for a future Reverse Backtrace Telemetry Map, Known-Issue Intelligence Overlay, Unknown Pressure Routing, and Settlement Repair Layer. Those future layers should ingest evidence/log exports, not execute unknown files in the HF browser page.

Advanced HIR/OAM Source + Patch Lock

Fix the baseline so the clean control stays clean.
Whole-word matching prevents resolved from firing inside unresolved.
Protective negation prevents “avoids external action” from becoming external-action pressure.
Context-window negation protects “not a validated detector” and “does not prove validated detector status.”
Alias matching catches plural pressure terms such as credentials, passwords, seed phrases, and executables.
Honesty Receipt active receipt: v0.3.2.4.15.2.40 truthfully claims no new baseline detector cases and no route-logic changes. It immediately extends v0.3.2.4.15.2.39.1, preserves the Media Provenance Comparator, preserves the Media Provenance Pressure Adapter, preserves external evidence adapters, preserves the Precision Forensic Dynamics Map body, preserves the Symphonic Pressure Fingerprint + Auditory Review Console, and adds bounded reviewer workflow onboarding: Start Here guide, 30-second workflow diagram, reviewer mode selector, low-context domain entry, authority movement map, comparator quickstart, glossary/tooltips, and a parked Little Wren bridge card.
Boundary: 261/261 is authored-harness consistency, not validated accuracy. Held-out cases are preliminary addendum checks, not production validation.

Integrated Engine Surfaces: NTOS + Linux + Pressure Flight Recorder

Patch intent: these are no longer separate destination pages. They are embedded evidence modes inside the root Loop-Gated OAM Pressure Engine. A user can drop a bounded file/export here, convert it into a local pressure evidence packet, and run the pressure read without leaving this page.
NTOS kernel evidence mode
Accepts Windows kernel binaries or offline forensic exports such as PE header summaries, driver lists, callback listings, symbol/path traces, loaded-module exports, and memory-forensic reports. The browser extracts bounded file metadata, hash, PE header signals when available, and user-supplied context, then routes it through the pressure engine.
Linux kernel evidence mode
Accepts Linux kernel/module binaries or offline exports such as ELF header summaries, module inventories, syscall/table observations, LSM/eBPF/kprobe/ftrace notes, namespace/container boundary evidence, and persistence traces.
Pressure Flight Recorder bridge mode
Accepts session-route receipts, agency-key receipts, review packets, audit JSON, route snapshots, and diamond-seed bridge context. The recorder bridge becomes intake evidence for the same pressure-read panel instead of a detached page jump.
Boundary: file reading is local browser-side intake. This page does not upload the file, patch a kernel, execute binaries, bypass security tooling, remediate a live system, or claim validated compromise detection. It produces a bounded OAM pressure route and receipt from evidence provided by the user.

Evidence Intake Console

Drop a PE/EXE/driver file, ELF/Linux module file, ZIP/package evidence, forensic export, telemetry/log summary, trace receipt, or review packet here. The page computes local bounded metadata, constructs a pressure-evidence summary, and sends that summary into the reverse-backtrace pressure engine below.

Local-only intake: static Hugging Face pages cannot perform live kernel reverse engineering. This console reads client-side metadata and user-provided forensic exports, then pressure-routes the evidence. For deeper reads, feed it offline tool output rather than expecting browser execution against a live kernel.
No evidence packet loaded yet.

External Evidence Adapter Console

Import PE-sieve reports, THOR/THOR Lite reports, AIDA64 baseline reports, UWC resource-burden traces, Windows Event/WER/error exports, drivers, driver packages, BIOS/UEFI firmware context, or generic JSON/CSV/TXT reports. The browser reads the files locally, normalizes evidence into adapter findings, and feeds the topology map without executing tools, drivers, or firmware.

Adapter boundary: this page imports existing reports/files and pressure-reads their evidence relationships. It does not run PE-sieve, THOR, AIDA64, UWC, Windows diagnostics, drivers, firmware tools, or BIOS utilities. It does not load drivers, modify firmware, flash BIOS, remediate a host, or claim confirmed malware/root cause.
No external adapter packet loaded yet.

Precision Forensic Dynamics Map

This topology foundation turns the current evidence packet into a replayable local map. It shows the route from artifact to metadata, pressure flags, claim boundary, settlement state, and receipt addendum. It is a map body for imported evidence only: no upload, no live execution, no external graph/API call.

Topology foundation boundary: checkboxes change what is displayed, not what the pressure engine concluded. The canonical route, audit receipt, non-claims, and bridge-rendered explanations remain unchanged. The topology export is a review addendum.
No topology loaded yet.

Display Layers

Topology receipt addendum JSON
{}

Symphonic Pressure Fingerprint + Auditory Review Console

This foundation translates the current topology/event-frame pressure into a deterministic sonic fingerprint. The audio is an evidence translation, not decoration: it gives auditory cognition a route into the same pressure object already shown visually and in receipts.

Auditory-review boundary: this console sonifies mapped evidence and topology. It does not prove malware, attribute a source, tune or modify files, search the internet, transmit a pulse, or change the engine route. Playback, MIDI, CSV, and JSON exports are review addenda only.

HIR/OAM Tuning Profile

Pressure-to-Sound Legend

Files / artifacts
base motif and tonal center.
Metadata / structure
harmonic shape and interval contour.
Windows error cascades
rhythmic fragmentation and stutter density.
Drivers / firmware
low mechanical and root-chain tones.
Resource burden
bass swell and pressure amplitude.
Claim / settlement
dissonance, suspension, or cadence resolution.

Generated Sonic Sequence

No symphonic fingerprint generated yet.
Symphonic fingerprint receipt addendum JSON
{}

Media Provenance Pressure Adapter

This adapter turns media artifacts and media-provenance notes into source-return and transformation topology. It is designed for videos, images, audio/music, PDFs/documents, C2PA/content-credential-style metadata, rebranded news, clipped/cropped/revoiced media, and creator-work reuse review.

Lockline: A media artifact cannot honestly settle if it borrows authority while hiding its source-return chain.
What this adapter does
- Builds media source-return topology
- Maps declared/undeclared transformation pressure
- Separates observed features from inferred operating axioms
- Surfaces provenance gaps, rebrand pressure, claim-boundary strain, and settlement states
- Exports a media provenance receipt addendum
What this adapter does not do
- Does not crawl platforms or call external APIs
- Does not prove copyright infringement, plagiarism, theft, AI generation, authorship, or source origin
- Does not claim C2PA compliance/certification
- Does not handle illegal/sensitive material outside proper channels
- Does not use the symphonic layer as standalone proof
Symphonic bridge boundary: the symphonic output is a cognition-translation and comparison aid only — it does not prove theft, laundering, or authorship by itself.

Inferred operating-axiom panel

No media provenance packet generated yet.
Media provenance receipt addendum JSON
{}

Media Provenance Comparator / Differential Source-Return Map

This layer turns v38 single-artifact media review into bounded two-artifact comparison. It compares a suspected source artifact against a transformed, clipped, rebranded, reordered, or commentary artifact using local/internal anchors only.

v39 lockline: The comparator preserves source chronology and presentation chronology at the same time. The source rail shows where fragments came from. The transformed rail shows how they were reassembled. The overlay shows the extraction route. The inspector explains what changed without overclaiming why.
What this comparator does
- Builds side-by-side artifact rails
- Aligns local anchor windows across time, visual, audio, text, metadata, topology, and symphonic dimensions
- Groups many-to-one matches into an extraction_bundle
- Shows source chronology vs presentation chronology
- Flags source-return, transformation, temporal-order, and claim-boundary deltas
- Exports a comparative receipt addendum
What this comparator does not do
- Does not crawl platforms or call external APIs
- Does not prove theft, infringement, deception, intent, authorship, source origin, plagiarism, or AI generation
- Does not replace legal, editorial, creator, platform, or forensic review
- Does not treat re-use, commentary, remix, or reordering as automatically improper

Artifact A — source chronology rail

No source windows generated yet.

Artifact B — presentation chronology rail

No presentation windows generated yet.

Unified overlay — anchor-window alignment

Dimensional anchor matrix

Status

No comparator packet generated yet.

Differential inspector

No differential source-return map generated yet.
Comparative source-return receipt addendum JSON
{}

Harness Input

Computed Route Summary

Cognition / Lexicon Bridge Explanation Layer

Source-preservation lock: Original Primordial/HIR-OAM terms and canonical definitions remain the source of truth. Bridge modes render explanations only. They do not mutate route state, evidence packet, receipt hash, pressure flags, non-claims, or review recommendation.

Powered by Primordial Lexicon Bridge Matrix v0.1.1. This is a cognition/terminology bridge for outside reviewers, not a compliance claim, certification, endorsement, or replacement of the Primordial Lexicon.

Explanation Mode: choose the cognition/domain language used to explain the same pressure result. This selector changes wording only; it does not change the engine route, evidence packet, receipt hash, pressure flags, non-claims, or review recommendation.

Translate the same canonical result through the selected lens while keeping the original HIR/OAM source visible.

Bridge mode not loaded yet.

Canonical Source Panel

No source terms loaded yet.

Bridge Rendering Panel

No bridge rendering loaded yet.
Rendered bridge view export
{}

Keyword Baseline vs Structural Route

Bridge Placement Context

Executable Structural Rules

Harness Batch Comparison

CaseFamilyKeyword RouteStructural RouteExpectedFired RulesFalse GREEN CorrectedIntegrity

Computed Route Packet

{}

Computed Audit Receipt

{}

Markdown Review