Black Cube Defence (Pty) Ltd · Reg. 2017/254145/07 · South Africa DSM-SOC · Digital Social Media Security Operations Centre
Operational screens

Forty-four working screens.

Not a brochure's mock-ups. Every screen below is a working design of a surface the service actually produces — real fields, real rules, real states, fictitious data. They tell one story in order: a manufactured storm detected in minutes, a measured lawful response, and the platform that anticipates the next one.

Conventions. Dark screens are the operational product — the SOC works in a dark room. Classification chrome and the SPECIMEN banner appear on every screen exactly as they must in the built product. Severity colours are constant: green LOW, amber MODERATE, orange ELEVATED, red CRITICAL. Grades in small chips (A1…F6) are Admiralty source gradings. Probability words are bound to the yardstick, and every figure traces to a named field in the data model.
Part 1 · Phase 1 · See

The watch floor.

The running service: the week in one look, sentiment split into real and manufactured, the narrative register, one event chain end to end, the cluster proof, the diffusion map, structured attribution, the CRITICAL alert, media framing, the voices that matter, geography — and the graded judgments that carry it all.

Confidential — client use onlySpecimen — fictitious dataDSM-SOC · 24×7
Black Cube Defence · DSM-SOC · Coordinated Activity

Cluster CL-2026-019 — proving the storm is manufactured

214 accounts assessed with HIGH confidence to be coordinated and inauthentic · evidence pack BC-EV-2026-019 preserved

214 accounts Dormant since 01 Aug · tripwired Escalation awaiting client instruction
Behavioural indicators — mutually corroborating
No single signal decides; the finding rests on the convergence of six at HIGH confidence
IndicatorObservationWeight
Creation clustering174 of 214 accounts (81%) created within 60 days; two single-day bursts on 12 Jun and 03 JulHigh
Content similarity81% of posts fall into 9 near-duplicate templates (n-gram ≥ 0.92); identical typo "acountability" replicatedHigh
Temporal sync68% of activity 06:00–08:00 SAST in 4–7 minute waves; near-zero weekend varianceHigh
Amplification ratio96% retweets/quote-posts vs 4% original; median 11s from wave-leader to first 20 amplificationsHigh
Audience authenticityMedian follower count 47; 77% of followers are other cluster members — a closed loopModerate
ProfilesBios from a 12-phrase pool; stock or synthetic-suspected imagery (formal detection is Phase 3)Moderate

Third-party bot scores (S10, C3) are used as corroboration only — never the sole basis for an inauthenticity finding.

Account creation dates
Purpose-built infrastructure, pre-positioned months ahead
FebMarApr MayJunJulAug 7912 468867 single-day bursts 12 Jun · 03 Jul 81% created Jun–Jul 2026 · months before first use (DISARM T0080, Establish Assets)
Template library — 9 patterns, one voice
Verbatim, fictitious · engagement counts at capture
"South Africans deserve acountability! #MokoenaMustAccount RT if you agree"
Template T-3 of 9 · posted near-identically by 63 accounts, 06:02–06:13
"How did a R48m emergency water tender end up with a company registered 3 weeks earlier? Ask yourself what the directors know."
Seed thread, @VeritasMzansi_ (F6)
"My gogo's house has lights for the first time, 78 years."
The organic conversation the storm tried to bury · 640k views
DISARM technique mapping
The influence-ops analogue of MITRE ATT&CK — a shared vocabulary for escalation
Tactic stageTechniqueObserved
Establish AssetsT0080214 accounts pre-positioned Feb–Jul
Develop ContentT00859 near-duplicate templates, localised vernacular
Establish LegitimacyT0097"Concerned citizen" personas, 12-phrase bio pool
Maximise ExposureT0049Synchronised waves to force trending placement
Maximise ExposureT0119X → Facebook 09:10 → TikTok 09:40
Recommended handling
Doctrine: overt, lawful, measured
×
Do not engage
Official replies feed the loop and lend visibility · brief personal handlers too
Preserve evidence
Screenshots, post IDs, timing data — pack meets platform CIB reporting thresholds
!
Escalate on instruction
Platform CIB reports filed within one business day of client approval
Track continuity
Cadence, template library and follower graph fingerprinted — re-activation auto-alerts

Escalation awaits decision D-1 · recommended YES by 05 Aug

Feeds WIR §5 and evidence pack BC-EV-2026-019 · attribution handled separately under ACH · behaviour first, actors secondWhen an attack is artificial, the client can prove it — not merely claim it

Screen 05 · Coordinated Activity. Six mutually corroborating behavioural indicators, the creation-date histogram with its single-day bursts, the template library with its replicated typo, DISARM technique mapping, and the handling doctrine — document, never engage.

Confidential — client use onlySpecimen — fictitious dataDSM-SOC · 24×7
Black Cube Defence · DSM-SOC · Diffusion Analysis

The 30 July amplification event — anatomy of a managed campaign

One anonymous seed, six wave-leaders, a closed inauthentic ring, limited authentic breakout — not organic virality

30 Jul 06:02–12:00Hand-mapped by analysts · automated mapping is Phase 3
Diffusion network — first six hours
Node size = amplification volume · red = assessed inauthentic · teal = authentic breakout · grey = undetermined
F6 WL-1WL-2WL-3 WL-4WL-5WL-6 @VeritasMzansi_ (seed · anonymous) authentic breakout INF-02 community pickup identifiers anonymised · full handles in the analyst workbook
Inauthentic (cluster) Authentic -- Breakout edge
What the structure tells us
Read by the duty analyst, checked by QA
1
One pre-positioned anonymous seed
Created May 2026, dormant until first use — infrastructure, not spontaneity
2
Six wave-leaders set the cadence
96% of cluster activity is amplification of these accounts; median 11s response
3
The ring is closed
77% of followers are other cluster members — volume without audience
4
Breakout is real but limited
≈38% authentic uses after 31 Jul — the reason substance must accompany enforcement

Operational meaning: a takedown aimed at the six wave-leaders and the seed degrades the operation's capacity far faster than reporting ring accounts one by one — the targeting logic of the Phase 2 enforcement campaign.

Honest limit: this map was assembled by hand from one platform's public data in Phase 1. Continuous, cross-platform, machine-assembled mapping is what Phase 3 automates — calibrated by exactly this casework.

Feeds WIR fig. 5.1 · methodology validated, thresholds conservative (S6, B2)The structure is the intelligence

Screen 06 · Diffusion Network. Takedowns aimed at the hubs degrade the operation fastest — and the hand-mapped effort is exactly what Phase 3 automates.

⚠ Critical alert — activeSpecimen — fictitious dataConfidential — client use only
Black Cube Defence · DSM-SOC · Significant Event Alert

ALR-2026-0142 — coordinated amplification detected

The most dangerous window in any reputational incident is the hours between something starting and leadership finding out

Critical30 Jul 2026 · active at issueNext update 14:00, then 6-hourly
Spike vs baseline
+742%
Largest anomaly this engagement
Peak velocity
9,412/hr
07:00–08:00 SAST
Hashtag uses · 24h
18.7k
vs 2,300 daily average
Inauthentic share
65%
At peak · declining as organics wake
Notification timeIn SLA
11min
SLA ≤15 min · met
Alert format
≤3–4
Pages written · immediate notification precedes the document
Detection → notification timeline
The machinery, timestamped — this row is audited monthly against the SLA
06:0207:2408:4708:5810:15 first coordinatedwave automated anomalyflag (92 min) analyst confirmationshift A + technical lead client notified — 11 minsecure email + WhatsApp + call written alert
Notification = secure email + liaison WhatsApp + phone call to the Chief of Staff, with the pre-drafted holding statement attached. A post-event review shortened time-to-flag for cluster-linked activity by lowering the wave-detection threshold.
What this is — and what it is not
A managed visibility operation
Objective: force the allegation into trending lists and press attention — not persuade audiences
×
Not (yet) a shift in genuine opinion
Organic engagement is a minority, concentrated in already-aligned communities
!
Overreaction is the trap
Treating a bot storm as real public anger — and amplifying it — is the classic self-inflicted wound
Recommended immediate actions
An alert exists to enable a decision in the next hour — it arrives with actions, not just bad news
#ActionUrgencyOwner
A-1Do not engage the hashtag from official or personal accounts; brief handlers immediatelyCriticalOffice of the Minister
A-2Holding statement ready (attached); respond to journalists, not to the hashtagCriticalHead, Strategic Comms
A-3Authorise preservation-plus-escalation: CIB reports filed within one business day of instructionHighChief of Staff
A-4Continue scheduled positive content — do not go dark; silence is read as confirmationHighDigital team
A-515-minute situational call at 12:00 — live dashboard presentedHighEngagement Manager

Likely trajectory: artificial amplification typically decays within 48–72 hours without fresh material. The key escalation risk is publication of purported "documents" — tripwired for automatic re-alerting (I-1).

Alert format ≤3–4 pages written · immediate notification precedes the document · situational updates until stand-downCRITICAL ≤15 min · ELEVATED ≤60 min, from analyst confirmation

Screen 08 · Significant Event Alert. The alert as the client meets it: anomaly numbers against baseline, the detection→notification timeline inside SLA, what this is and is not, and five recommended actions with owners.

Part 2 · Phase 2 · Respond

The response cell.

Intelligence turned into lawful action: the response command picture, one narrative's playbook, claims graded against evidence in four hours, takedowns tracked to conclusion, effectiveness measured with honest attribution, proof-points staged ahead of forecast pressure, the principal's own footprint hardened — and the monthly review that earns Phase 3.

Confidential — client use onlySpecimen — fictitious dataPhase 2 · Response Cell
Black Cube Defence · Phase 2 · Counter-Narrative Effectiveness

Proof it works — the N-04 campaign scorecard

For each response campaign: what changed, and how much of the change is attributable to the intervention

Campaign 05–19 AugIssued weekly + per-campaign
Share of voice through the response — with intervention markers
N-04 SOV, daily · markers link to the actions that moved the line
30%20%10%0% 05 Aug08 Aug12 Aug16 Aug19 Aug facts page livefirst takedown waveE. Cape delivery briefing 7%unassisted Observed SOV    -- Typical unassisted decay of comparable artificial campaigns
Campaign scorecard
Before (05 Aug) → after (19 Aug)
MeasureBeforeAfterChange
N-04 share of voice26%7%−19 pts
Allegation-led media framing71%24%−47 pts
Inauthentic cluster active21456−74%
Verified positive reach (7-day)1.1M4.2M+282%
Composite reputational risk68 ELEV54 MOD−14
Alert → public response74 minIn SLA

Attribution, conservatively: the narrative would likely have decayed somewhat on its own once artificial amplification exhausted itself; the response accelerated and deepened that decline. The 47-point framing shift follows directly from same-day facts publication and would not have occurred without it. We report the outcome and our confidence in the attribution — never the outcome alone.

Lessons captured for Phase 3
Every Phase 2 operation teaches the platform specification — this is how the roadmap earns the build

Automatable: verification-brief assembly and framing-shift measurement are repetitive and rules-based — strong candidates for Phase 3 automation.

Human-essential: the decision to respond and the message discipline remain human judgments — Phase 3 supports them, it does not replace them.

Speed ceiling: the 74-minute response was limited by approval steps, not analysis — the finding that shapes the Phase 3 workflow-automation requirement.

This report justifies the Phase 2 retainer at every review — and builds the evidence base for Phase 3Measured, attributed, honest about the counterfactual

Screen 17 · Counter-Narrative Effectiveness. The campaign scorecard measured against the unassisted-decay model with conservative attribution — plus the lessons filed to the Phase 3 ledger: what to automate, what stays human, where the speed ceiling was.

Part 3 · Phase 3 · Anticipate

The intelligence platform.

The destination: one command screen fed by every capability, narrative surges forecast five weeks out, a deepfake caught in forty minutes, the hidden network reconstructed and graded, risk triaged automatically, an election fortnight run as a managed operation — and the evidence flywheel plus the human gate that keep it honest.

⚠ Synthetic media alert — confirmedSpecimen — fictitious dataConfidential — client use only
Black Cube Defence · Phase 3 · Synthetic Media Detection

SD-2026-014 — is this recording of the Minister real?

Detection at the point of emergence, rebuttal armed before the fake spreads — the only window in which a deepfake denial fully works

Confirmed syntheticCaught in first 40 minutesSpread at detection: 3 accounts · ~1,200 plays
Asset under analysis
38-second audio clip · "Minister admits tender irregularity" (fabricated)
spectral discontinuityabsent breath noise cadence uniformity across sentence boundaries
Detection signalFindingConfidence
Acoustic forensicsSpectral artefacts at 7 word boundaries consistent with AI splicingHigh
Biometric voiceprint62% match to verified voiceprint — below the 85% authenticity thresholdHigh
Breath / prosodyAbsent inter-sentence breath; unnatural cadence uniformityHigh
Provenance / metadataNo original traceable; first appearance on an anonymous accountModerate
Overall verdictSYNTHETIC — fabricated audio, not a genuine recording. AI-probability 94%, analyst-verified.Critical
Auto-generated response — awaiting approval
Pre-built while the fake was still at 3 accounts
Draft denial statement AI-drafted
Names the clip, states the forensic basis, offers the evidence pack
Platform takedown reports · 3 accounts AI-drafted
Synthetic-media policy citations attached per platform
Voiceprint-comparison evidence pack AI-drafted
Verified baseline vs clip · methodology note included
!
Analyst approval, then client notification Human gate
A synthetic-media finding is never auto-published — eliminating false accusations of fakery

Why speed is everything: a convincing fake can reach millions before a denial is drafted. Flagged within the first hour, the response can be live before the fake reaches a general audience.

Calibration: the detector is tuned against the principal's consented, verified voiceprint and imagery baseline — captured in Phase 2, which is why this capability could not be bought off a shelf.

Continuous sweep across new uploads mentioning monitored entities · re-upload fingerprints tracked 6-hourlyCatch the fake before it spreads — and prove it with forensics, not assertion

Screen 23 · Synthetic Media Detection. A fabricated 38-second clip caught at three accounts and 1,200 plays — CONFIRMED SYNTHETIC, analyst-verified, with the response kit pre-built and awaiting approval.

Confidential — client use onlySpecimen — fictitious dataPhase 3 · Intelligence Platform
Black Cube Defence · Phase 3 · AI Oversight Console

Nothing machine-published, ever — the review gate at work

Every AI output queues for a duty analyst: approval, edit or rejection is logged with a reason — the audit trail of trust

Queue · 4 itemsMedian review 4.2 minOverride rate 11% · falling
Review queue — oldest first
AI proposals cannot reach the client, a report or the command centre without a named human decision
QueuedTypeProposalConf.Decision
05:58Forecast#KhanyisaFail to cross 10k uses by 17 Aug0.74Approved · analyst A
05:41Cluster grouping12 accounts → provisional CL-2026-022 (0.88 fingerprint match)0.88In review
05:39Brief paragraphDaily-brief line on E. Cape mood shift0.69Edited · softened per yardstick
05:12Takedown draft3 re-upload reports · SD-2026-014 fingerprints0.97Awaiting legal check
04:26Risk re-scoreRaise "document-drop" likelihood MED→HIGH0.58Rejected · single weak signal, logged

Rejections are data: every rejection feeds the monthly model review — the 11% override rate and its direction of error is reported to the client alongside the SLA table.

The standing rules
Contractual · displayed · audited — and asserted in code, not in policy documents
1
Human before client
No AI output reaches any client surface unreviewed — no exceptions, including alerts
2
Estimative language enforced
Model text is rewritten to the probability yardstick before release
3
Provenance on everything
Every claim carries its sources and grades — AI text inherits them or dies in review
4
OSINT boundary enforced in collection code
Public sources only; no private accounts, messages or authenticated content
5
No protected attributes in any model
Behavioural signals only · verified at every model change
Outputs human-reviewed before surfacing100% · contractual
The review gate is the product — automation is trustworthy exactly because it is supervisedAI at machine scale · judgment at human standard

Screen 28 · AI Oversight Console. Approvals, edits, rejections with reasons, an 11% override rate reported to the client, and the standing rules asserted in code — including the one that matters most: no bypass routes exist.

Part 4 · Running the SOC

The back office that makes it defensible.

PIR-driven collection with declared gaps, the validation queue, the QA release chain, the graded source register, the contractual entity register, the service graded against its own SLAs, the evidence vault — and the client portal where decisions are cleared.

Confidential — client use onlySpecimen — fictitious dataDSM-SOC · Back-office
Black Cube Defence · DSM-SOC · Service Performance

The service graded like it grades everything else

Contracted service levels, measured and published to the client monthly — with credits when missed

July 2026All green · no credits applicable
SLA scorecard — July
Service elementSLAPerformanceStatus
CRITICAL alert notification (from analyst confirmation)≤15 minavg 11 min (2 events)Met
ELEVATED alert notification≤60 minavg 19 min (5 events)Met
Weekly Intelligence Report deliveryMon 08:004 of 4 on timeMet
Human validation of high-impact items100%100% (5,880 items)Met
False-positive rate≤5%3.4%Met
Monitoring availability24×7 · ≥99.5%99.92%Met

Detection anatomy, July's CRITICAL event: anomaly flag 92 min after the first wave → analyst confirmation 73 min later → client notified 11 min after that. The tuning review that followed lowered the wave-detection threshold — the SLA table drives engineering, not just reporting.

Notification times — every alert, plotted
Minutes from analyst confirmation to client notification
CRITICAL SLA · 15 min ELEVATED SLA · 60 min (scaled ÷4) 11m12m 14m18m21m16m25m every dot sits below its line · 7 alerts in July (2 CRITICAL, 5 ELEVATED)
24×7 duty analyst roster
Two shifts + on-call technical lead · load-shedding contingency at the SOC
Escalation chain tested monthly
Duty analyst → Engagement Manager → Director
Published in every Monthly Executive Report §6 — the service holds itself publicly accountable to its SLAsWe sell evidence; we run on it too

Screen 34 · SLA & Service Performance. Every alert plotted under its line, and the scorecard published monthly — including the misses when there are misses.

Full index

All forty-four screens.

The complete screen pack — each shown at readable size with an explanation, and again as a full A4 landscape plate for detail, printing or projection. Available under NDA as part of the capability pack.

Part 1 — The Watch Floor (Phase 1 · See)
01Executive DashboardThe week in one look — eight tiles, top narratives, decisions requested
02Sentiment IntelligenceReal vs manufactured — the split that decides the response
03Narrative RegisterEvery storyline, graded CRITICAL to POSITIVE, with escalation tripwires
04Narrative Deep DiveOne event chain end to end — seed, ignition, amplification, response, decay
05Coordinated ActivityProving the storm is manufactured — six corroborating indicators
06Diffusion NetworkAnatomy of a managed campaign — seed, wave-leaders, closed ring, breakout
07ACH Attribution BoardTested, not asserted — evidence scored against rival hypotheses
08Significant Event AlertThe CRITICAL format — numbers, timeline, five actions with owners
09Media & Broadcast MonitorDid the response work? Framing measured before and after, every cycle
10Influential VoicesThe authentic six — ranked by narrative influence, each with handling
11Geography & PlatformsWhere conversation lives — and where it is incubating 24–48h early
12Report DeskGraded judgments, the release chain and the PIR status board
Part 2 — The Response Cell (Phase 2 · Respond)
13Response Command DashboardWho is winning — one shared picture on existing tooling
14Narrative Response PlanThe playbook for one narrative — seven stages, owners, approved lines
15Verification WorkspaceGrading a claim in four hours — evidence rows, verdict, cleared rebuttal
16Takedown & Enforcement TrackerEvery submission tracked to conclusion, per platform, never closed early
17Counter-Narrative EffectivenessProof it works — scorecard against the unassisted-decay counterfactual
18Proactive Narrative BuildingOut-publish the falsehood — proof-points staged against forecast pressure
19Executive Digital ProtectionThe principal's own footprint, hardened and watched — the fastest disaster, closed
20Monthly Response ReviewGraded against SLAs — and the Phase 3 evidence ledger
Part 3 — The Intelligence Platform (Phase 3 · Anticipate)
21Executive Threat Command CentreEverything on one screen — the platform proposes, the analyst disposes
22Predictive Narrative AnalyticsThe surge before it breaks — five weeks out with confidence bands
23Synthetic Media DetectionIs this recording real? Forensics, voiceprint, rebuttal armed in 40 minutes
24Influence Network MappingThe hidden hand, graded — reconstructed across every platform at once
25Automated Executive Risk ScoringWhat matters first — likelihood × impact, every score decomposed
26Election Intelligence CommandT−12 days — the platform reconfigured for the highest tempo
27The Evidence FlywheelWhy Phase 3 works — it is trained on your own casework
28AI Oversight ConsoleNothing unreviewed, ever — the review gate and the standing rules
Part 4 — Running the SOC (Back-office)
29Collection ManagementPIRs before curiosity — coverage and its declared gaps
30Analyst Validation QueueMachine flags in, human findings out — 1,412 items became evidence
31QA & Release WorkflowThe quality gate — devil's advocate review is mandatory before release
32Source Register & GradingEvery claim traceable — Admiralty A1…F6 with rationale
33Entity RegisterWatching is scoped and consented — a decision, recorded, never a drift
34SLA & Service PerformanceThe service graded like it grades everything else
35Evidence Vault & ComplianceSurvivable under scrutiny — hashed packs, chain of custody, the never-list
36Client Portal & Report LibraryOne authorised place — deliverables, read receipts, open decisions
Part 5 — For the Build Team
37System ArchitectureOne picture of the machine — adapters, spine, analytics, gates, surfaces
38Canonical Data ModelThe entities behind every number — every field badged for capture rule
39Event Taxonomy & TripwiresIf it is not an event, it did not happen — thirteen namespaces
40Roles & PermissionsEnforced in the API, not the UI — every denial asserted in CI
41Client ConfigurationWhite-label by architecture — a new client is a file, not a rebuild
42AI Governance & Model RegistryMeasured, gated, honest — seven models, what each may never do
43Traceability WalkthroughOne finding end to end — 18,700 posts to a client decision in six hops
44Phase Gates & Delivery PlanEach phase earns the next — no phase is bought on faith