Corvus
Investigation Colophon · Methodology · Provenance

About this investigation

Full audit trail of how this report was produced — target identification, analytical techniques applied, tools that ran, gaps recorded, and the schema and skill versions used. Reproducibility is a forensic posture.

Confirmed Target · Type: Org

Acclaim Health Analytics, LLC

A health analytics company specializing in data-driven solutions for insurance brokers and employee benefits professionals.

  • Domain registered September 2013 via GoDaddy
  • Provides health analytics and data transformation services
  • Based in Brownsville, Texas
§ 01

Investigation Metadata

Provenance
Investigation ID
64fec256-7262-443a-8ee3-f84ba5ede0be
Created
2026-05-28 20:10:43.84
Recon Started
Recon Completed
2026-05-28 20:20:05.25 · 9m 22s
Analysis Completed
2026-05-28 20:32:00.00 · 12m 0s
Total Duration
21m 22s · within 60-minute walltime budget
Wave Budget
39 enabled tools × multiplier 5 = 195 tool calls per wave
Stopping Rule M
4 consecutive empty calls · fired in Wave
Artifact Location
D:/RECON/acclaim-health-64fec2
§ 02

Analytical Methodology

Structured analytic techniques · ICD 203
KAC Applied

Identity, currency, and source-integrity assumptions hold (RDAP cross-confirms DNS; recon timestamps fresh; primary registry + CT sources). Completeness assumption is MOD-confidence: three independent passive enumerators (AnubisDB, HackerTarget, certspotter) converge on a single subdomain (www), which very likely reflects the actual marketing-apex surface but cannot rule out a separately-hosted PHI client portal. This HIGH-sensitivity / MOD-confidence assumption is reflected in kj_003 confidence and explicitly surfaced as the kj_007 watch judgment.

ACH Applied

Three competing hypotheses tested: H1 (WordPress.com platform-default brochureware), H2 (mature security org accepting platform defaults), H3 (dormant brochureware). H2 is contradicted by DMARC p=none + Observatory C- + 51-domain shared cert (A1/A2 inconsistencies). H3 is contradicted by 2025-04 Wayback capture showing active maintenance and 2025-09 RDAP update (A1/A2 inconsistencies). H1 is the leading hypothesis with lowest weighted inconsistency.

Premortem Applied

Walked back the leading hypothesis from a hypothetical 6-12 month future failure. Dominant failure mode is the existence of a separately-hosted PHI-handling client portal under a different apex that passive recon of the marketing apex did not enumerate. Surfaced as kj_007 (LOW confidence watch judgment) and r_07 / b_07 (recon-scope extension recommendation).

Red Hat Applied

Applied because target.type=org and the evidence base is non-trivial (18 entities, 13 relationships, 5 vulnerabilities surfaced). Generated 7 red vectors anchored to actual recon evidence: DMARC spoofing, XML-RPC amplification, REST API user enumeration, typosquat phishing, WP stack CVE exposure, shared-cert reputation contamination, and undiscovered sibling apex. Each paired with a blue control plus 3 baseline blues.

§ 03

Coverage

Schema v1.0
18
Entities
13
Relationships
8
Evidence
7
Judgments
5
Timeline
0
Geo
Confidence Distribution · Key Judgments
3 · High
3 · Moderate
1 · Low
High · multi-source, no surviving alternatives Moderate · KAC stress or ACH margin Low · sparse base or explicit caveat
§ 04

Tools Engaged

39 enabled · 39 fired · 0 gap
rdap_domain 1
dns_lookup 1
dns_mail_auth 1
mdn_observatory_scan 1
mdn_observatory_tests 1
mdn_observatory_recommendations 1
certspotter_enumerate 1
crtsh_search 1
anubisdb_subdomains 1
hackertarget_host_search 1
rapidapi_subdomain_finder 1
securitytrails_domain 1
securitytrails_subdomains 1
securitytrails_dns_history 1
securitytrails_whois 1
securitytrails_whois_history 1
shodan_count 1
shodan_dns_resolve 1
shodan_host_lookup 1
shodan_search 1
censys_search 1
censys_get_web_property 1
fofa_search 1
wayback_cdx_search 1
commoncrawl_search 1
urlscan_search 1
github_repo_search 1
github_code_search 1
github_commit_search 1
greynoise_community 1
greynoise_riot 1
abuseipdb_check 1
ripestat_blocklist 1
bgpview_asn 1
mnemonic_pdns_query 1
mnemonic_pdns_seen 1
ssllabs_scan 1
osv_query 1
deps_package 1
Integrity Hash
sha256:177b11692f6ef6a6e37741a830c44e808227ebe36bf8449256def0d856175304