# Mithril Whitehat practice v1

## English instructions

This is public learning practice using synthetic data, not a hiring assessment or
certification. After signing into Mithril, create a Workspace project and explicitly
select `events.jsonl` and `assets.json`. Check actual usage charges and storage before
you use the service; this exercise does not promise free compute, paid work or hiring.

Investigate fictional identity gateway and storage configuration changes using only
the included files. Do not scan or access third-party systems. About 90 minutes:

1. Record input SHA-256 hashes, scope, timestamps and timezone.
2. Produce an event-ID-cited timeline. Separate facts, hypotheses and unknowns;
   assess whether intrusion or data disclosure can be established from these logs.
3. Compare events with inventory expectations. Propose prioritized investigation,
   remediation, verification and rollback; explain one benign control event too.
4. Produce a reproducible JSONL analysis script and tests for malformed JSON,
   duplicate IDs, reordered inputs and timezone handling.
5. Explain findings to both an engineer and a business reader. Document selected
   Mithril outputs/receipts, input/commands, AI assistance and manual verification.

Keep `scope.md`, `timeline.csv`, `findings.md`, `remediation.md`, analysis and tests,
`manifest.json` (relative path, hash, bytes, artifact role) and `mithril-usage.md`.
Exclude API keys, actual personal data, unauthorized code, full chat history and
absolute device paths. Keep your work yourself: no recruitment submission endpoint
is currently offered and nothing is sent to employers. Private hiring assessments
will use different, non-public variants and evidence-linked human review.

## 日本語の説明

公開練習用の合成データです。採用試験・認定・能力証明ではありません。
Mithril の登録／ログイン後、Workspace に新規プロジェクトを作り、この
`events.jsonl` と `assets.json` を明示選択して読み込んでください。
利用前に実際の画面で料金と保存先を確認してください。この資料自体は
無料computeや採用を約束しません。

## 課題

架空の Example Training の identity gateway で権限設定の変更がありました。
第三者へのアクセスや検査は行わず、添付資料だけを根拠に調査します。
目安90分（自主学習）。プロンプトだけを出すのでなく、Mithril でデータを
整理・分析し、再現できる結果を自分で検証してください。

1. 入力ファイルのSHA-256、対象範囲、時刻とタイムゾーンを記録する。
2. イベントIDを引用したタイムラインを作る。確認できる事実、仮説、確認
   できないことを分ける。資料だけで侵入や漏洩が確定できるか検討する。
3. inventory の期待値とログを比較し、優先する設定調査・修復・検証・
   ロールバックを提案する。1件の benign control も説明する。
4. JSONLを解析して時刻順に並べる再現可能なスクリプトと、そのテストを作る。
   不正JSON、重複ID、異なる入力順、タイムゾーンの扱いを検証する。
5. エンジニア向けの詳細と、事業担当者向けの短い説明を提出形式でまとめる。

## 自分で保管する成果物

`scope.md`, `timeline.csv`, `findings.md`, `remediation.md`, `analysis` と tests,
`manifest.json`, `mithril-usage.md`。manifest はパス・SHA-256・bytes・artifact
の役割を持つ。API鍵、実際の個人情報、全チャット履歴や端末の絶対パスを
含めない。Mithril 使用記録には選択した履歴／出力、入力、コマンド、
AI支援の範囲、手動検証を書く。共有は本人が内容を確認した選択ファイルのみ。

現在は採用目的の提出サーバーを提供していません。成果物をローカルで保持
できます。企業への送信はしません。私的な選考課題はこの公開データとは
別の版・解答非公開セットを用意し、人による説明確認とレビューを行います。
