Evidence desk
Sources
Important claims should point somewhere more useful than a screenshot of a social-media post quoting another screenshot.
Supported source types
| Source type | Role | What it can support |
|---|---|---|
| Official law-enforcement announcement | Primary | Confirms the action, agencies, date, and operation when stated. |
| Official machine-readable dataset | Primary | Supports reproducible catalogs, update histories, field-level filtering, and integrity snapshots. |
| Court record | Primary | Supports legal authority, scope, or procedural detail. |
| Regulator notice | Primary | Documents regulatory action or a formal warning. |
| Registrar notice | Primary / direct | Documents a domain-level suspension, hold, or registration response. |
| Hosting-provider notice | Primary / direct | Documents service termination or infrastructure action. |
| Cybersecurity research | Secondary / technical | Provides observed infrastructure, timeline, and technical context. |
| Credible journalism | Secondary | Provides reporting and corroboration with attribution. |
| Archived snapshot | Visual evidence | Shows what a page displayed at a particular captured moment. |
| Extortion Wiki record | Related research | Connects ransomware infrastructure to separately maintained actor research. |
| Verified community submission | Lead / evidence | Used after maintainers confirm dates, screenshots, and supporting material. |
What each citation displays
- Title and publisher
- Publication date, when available
- Source type
- Archived copy, when available
- Date last checked
A dead citation is kept with its metadata and archive link when possible. The source vanishing does not improve the claim, but it should not erase the audit trail either.