Corvus
Investigation Colophon · Methodology · Provenance

About this investigation

Full audit trail of how this report was produced — target identification, analytical techniques applied, tools that ran, gaps recorded, and the schema and skill versions used. Reproducibility is a forensic posture.

Confirmed Target · Type: Org

Deutsche Bank AG

German multinational investment bank and financial services company headquartered in Frankfurt, one of the world's leading financial institutions.

  • Founded 1870 in Berlin
  • Headquartered in Frankfurt, Germany (Taunusanlage 12, 60325)
  • NYSE: DB; Frankfurt: DBK
  • LEI 7LTWFZYICNSX8D621K86
  • SEC CIK 0001159508
  • German commercial register HRB 30000
§ 01

Investigation Metadata

Provenance
Investigation ID
68817e97-fcbb-4d1f-b63a-24461a65df07
Created
2026-05-27 04:40:00 UT
Recon Started
Recon Completed
2026-05-27 06:32:00 UT · 67m 46s
Analysis Completed
2026-05-27 06:32:00 UT · 9m 0s
Total Duration
76m 46s · within 60-minute walltime budget
Wave Budget
0 enabled tools × multiplier 5 = 0 tool calls per wave
Stopping Rule M
4 consecutive empty calls · fired in Wave
Artifact Location
D:/RECON/deutsche-bank-ag-68817e
§ 02

Analytical Methodology

Structured analytic techniques · ICD 203
KAC Applied

Stress-tested 4 assumptions: (1) management-board roster currency [HIGH-sens, LOW-conf]; (2) HudsonRock corpus reflects current credentials vs rotated [HIGH-sens, MOD-conf]; (3) Russia self-disclosure indicates good-faith compliance vs material-conduct concern [HIGH-sens, LOW-conf]; (4) NYDFS+class-action Epstein settlements close the matter [MOD-sens, LOW-conf]. The three HIGH-sens findings limit confidence on kj_006, kj_007, kj_008.

ACH Applied

Two competing hypotheses tested on enforcement-pattern interpretation. H1 'systemic conduct-and-controls failure' vs H2 'Sewing-era corrective inflection'. H1 leading: 2026-04-30 OFSI penalty landing 7 years into Sewing tenure carries weight-2.0 inconsistency against H2 (ev_049 A-grade primary). H3 'isolated business-unit failures' eliminated by breadth across product silos.

Premortem Applied

Imagined 12-month failure modes for the leading hypothesis. Most material: (a) the 2026-04-30 OFSI penalty turns out to be the only post-2022 Russia lapse → H2 partially rehabilitated; (b) HudsonRock corpus is dated 2024 and DB rotated credentials at scale → R-01 / R-02 severity reduced. Both are plausible but not currently evidenced; surfaced as confidence-limiting on kj_001 (kept at HIGH given breadth) and kj_002 (kept at HIGH given naming pattern).

Red Hat Applied

Constructed adversary perspective against the recon-surfaced attack surface. Yielded 7 red vectors prioritized by severity × exploitability: Citrix-RAS credential-reuse (SEVERE), executive credential-reuse (SEVERE), third-party-vendor impersonation (SEVERE), CT-log internal-naming reconnaissance (MOD), sanctions-typology probing (MOD), insider-leak (MOD), executive pretexting (LOW). Paired with 7 baseline blue controls + 3 generic baselines.

§ 03

Coverage

Schema v1.0
168
Entities
123
Relationships
78
Evidence
9
Judgments
53
Timeline
17
Geo
Confidence Distribution · Key Judgments
3 · High
5 · Moderate
1 · Low
High · multi-source, no surviving alternatives Moderate · KAC stress or ACH margin Low · sparse base or explicit caveat
§ 04

Tools Engaged

0 enabled · 18 fired · 0 gap
rdap_domain 1
rdap_ip 2
greynoise_community 1
dns_mail_auth 1
certspotter_enumerate 1
vt_domain 1
gleif_record 1
sec_edgar_submissions 1
wikipedia_summary 11
nominatim_search 9
serper_search 35
gleif_search 7
serper_news 2
icij_offshore_reconcile 1
usaspending_recipient_autocomplete 1
urlscan_search 1
hudsonrock_domain 1
xposedornot_check_email 1
Integrity Hash
sha256:3129ddc9f59a984d6dc753ae20a0fe36aeb50c99bdaf77ff14bb9f07927867ac