Corvus
RED × BLUE

Threat Playbook

Adversary vectors paired with the defensive controls that close them. Read top-to-bottom — engagements are sorted by severity. Baseline controls below apply across the surface.

3
Severe
3
Moderate
0
Low
2
Baseline

Severe · Act Now

3 engagements

Moderate · Plan Mitigation

3 engagements

Baseline · Surface-Wide

2 controls
B-07 Baseline

Bug-bounty / VDP parity across Musk-controlled orgs

Tesla operates a Bugcrowd VDP (ev_021); xAI publishes a HackerOne verification (h1-domain-verification on x.ai, ev_030). Neuralink, The Boring Company, SpaceX (consumer side), and X Corp have no surfaced VDP. Establish at minimum a published security.txt and a coordinated-disclosure email / portal across all five orgs. The cost is near-zero; the asymmetry (some orgs have it, others don't) is exploitable by adversaries who target the unmonitored disclosure surface.

B-08 Baseline

DMARC p=reject enforcement across all Musk-controlled domains

Audit and enforce p=reject DMARC policy across elonmusk.com, spacex.com, tesla.com, neuralink.com, boringcompany.com, x.com, x.ai. Several of the surfaced SPF records (ev_023 for boringcompany.com uses ~all softfail rather than -all strictfail) indicate at least one domain is not in hard-reject posture. Brand-impersonation phishing is a primary collateral risk given Musk's public profile.