# Shift Zero demonstration case

> Portfolio sample only. This is a sanitized, authored simulation, not a real incident and not a completion credential.

## Case record

- Case: `SZ-DEMO-01`
- Lane: SOC analysis
- Scenario: suspicious invoice message
- Evidence: synthetic message headers and authentication summary
- Environment: documentation domains and reserved addresses only
- Assistance: one authored hint opened; no AI answer grading used
- Command execution: none inside Shift Zero

## Question

Does the visible sender identity align with the authenticated sending identity, and what is the safest first response?

## Evidence reviewed

```text
From: Accounts Team <billing@example.com>
Return-Path: <mailer@example.net>
Authentication-Results: mx.example.org;
  spf=fail smtp.mailfrom=example.net;
  dmarc=fail header.from=example.com
Received: from mail.example.net (192.0.2.44)
```

## Analyst notes

The visible `From` domain is `example.com`, while the return path and sending host use `example.net`. SPF and DMARC both failed. Those signals do not prove motive by themselves, but together they justify containment and a search for related messages before anyone acts on the invoice request.

## Commands recorded by the learner

These are examples a learner could run against a downloaded copy. Shift Zero displays and records commands but never runs them.

```bash
grep -iE '^(from|return-path|authentication-results|received):' message-headers.txt
```

## Finding

The visible sender and authenticated identity do not align. Treat the message as suspicious, preserve it, prevent user interaction, search for related mail, and notify the appropriate security or messaging owner.

## Safe next action

1. Preserve the original message and headers.
2. Quarantine or contain the message through the approved mail workflow.
3. Search for messages sharing the sender, return path, subject, or infrastructure.
4. Notify affected users without overstating what the evidence proves.
5. Record uncertainty and escalate if account compromise or broader delivery is suspected.

## What this sample demonstrates

- Evidence-first reasoning
- A bounded defensive decision
- Clear separation between observation and conclusion
- Honest disclosure of simulation and assistance
- A portable Markdown investigation record

Shift Zero stores the learner's working record in that browser. Mission answer checks occur server-side and return pass-or-retry results without sending back the private mission key. Network Foundations are separately labeled as guided, browser-checked teaching material.
