Corvus
Investigation Colophon · Methodology · Provenance

About this investigation

Full audit trail of how this report was produced — target identification, analytical techniques applied, tools that ran, gaps recorded, and the schema and skill versions used. Reproducibility is a forensic posture.

Confirmed Target · Type: Person

Elon Reeve Musk

Entrepreneur and businessman serving as CEO of Tesla and founder of SpaceX, xAI, and several other companies. Former Senior Advisor to the President of the United States.

  • Born June 28, 1971 in Pretoria, South Africa
  • Net worth: $827.7 billion USD (2026)
  • Education: University of Pennsylvania, Wharton School; founded or cofounded Tesla, SpaceX, OpenAI, xAI, and others
§ 01

Investigation Metadata

Provenance
Investigation ID
196e303e-e4b9-4926-9360-265d5daac7bb
Created
2026-05-26 00:00:00 UT
Recon Started
2026-05-26 00:00:00 UT
Recon Completed
2026-05-26 00:30:00 UT · 30m 0s
Analysis Completed
2026-05-26 01:00:00 UT · 10m 0s
Total Duration
40m 0s · within 60-minute walltime budget
Wave Budget
11 enabled tools × multiplier 5 = 55 tool calls per wave
Stopping Rule M
4 consecutive empty calls · fired in Wave
Artifact Location
D:/RECON/elon-musk-196e30
§ 02

Analytical Methodology

Structured analytic techniques · ICD 203
KAC Applied

Surfaced one HIGH-sensitivity/MOD-confidence assumption: that em@spacex.com is current (2019 leak is 7 years old). Surfaced second HIGH-sensitivity assumption: that breach corpora referenced in ev_028 actually contain @elonmusk-tied records (cannot verify without HIBP API). Both assumptions reflected as moderate-confidence ceilings on kj_002 and kj_003.

ACH Applied

Three thesis-level hypotheses generated covering personal-opsec posture; leading hypothesis H2 (consolidated-deliberate personal opsec offset by corporate-side breach exposure) retained over H1 (routine professional footprint) and H3 (heightened individual identity risk). Retained alternatives noted in kj_001 and kj_003 statements.

Premortem Applied

Failure modes considered: (a) em@spacex.com address has been rotated since 2019 (would invalidate kj_002 / r_01); (b) X Corp 2.8B figure is a repackaging that overlaps prior scrapes (would soften kj_003); (c) DOGE political alignment reverses by 2026Q3 (would invalidate kj_007). All three result in confidence-tier ceilings rather than judgment-removal — analytic conclusions are robust to each individual failure mode.

Red Hat Applied

Run despite target.type=person because the target controls five operationally-significant organizations and a federal-SSO surface. Output: 6 red vectors keyed to actual recon-surfaced surface (em@spacex.com, X Corp breach corpus, family-map pretexting, auth.spacex.com federal SSO, elonmusk.com domain posture, cross-corp lateral trust). Paired with 6 blue controls plus 2 baseline controls.

§ 03

Coverage

Schema v1.0
53
Entities
44
Relationships
33
Evidence
7
Judgments
33
Timeline
4
Geo
Confidence Distribution · Key Judgments
4 · High
3 · Moderate
High · multi-source, no surviving alternatives Moderate · KAC stress or ACH margin Low · sparse base or explicit caveat
§ 04

Tools Engaged

11 enabled · 7 fired · 3 gap
bsky_search_actors 1
github_code_search 1
mastodon_search 1
serper_search 19
vt_domain 7
wayback_cdx_search 2
wayback_check 1
brave_web_search gap
hibp_breached_account gap
hibp_pastes gap
§ 05

Tool Gaps

3 methodology steps could not run
mcp__dork-mcp__brave_web_search
Methodology step · Wave 1 mentions/breadth (independent index cross-verification) · medium severity — Brave hit monthly $5 cap; cross-verification breadth reduced this run
mcp__dork-mcp__hibp_breached_account
Methodology step · Wave 1/2 email breach pivot per pivot_policy · HIGH severity — blocks all email breach pivots; HIBP_API_KEY not configured server-side
mcp__dork-mcp__hibp_pastes
Methodology step · Wave 1/2 email paste pivot per pivot_policy · HIGH severity — blocks paste pivots; HIBP_API_KEY not configured
Integrity Hash
sha256:1f9e9d0ac38c31feb08e8e77a3330f2646d3c8cc12472f252c84ed102d9236d5