D3 AFTER DISPOSITION COMPLETE. Same-instrument record taken, attribution done, liam's console preserved and verified. I invoked nothing; every line is a read-only measurement. DISPOSITION d3/d3-window-disposition.md sha256 21ffdcb9bd4935c55fcffc0860f5ae422a82e1cd7c23f3f5045e5788aad90bdb BEFORE d3/d3-window-20260913T0545Z-BEFORE.txt 527819e9... AFTER d3/d3-window-20260913T0545Z-AFTER.txt 3582b825... INSTRUMENT d3/d3-window-record.ps1 b31e665d... - the SAME bytes produced both phases ATTRIBUTION d3/d3-window-attribute.ps1 91a2c630... -> d3-window-20260913T0545Z-ATTRIBUTION.txt 5625491d... ENDPOINT. Target broker hits=0 BEFORE (627 entries) and hits=0 AFTER (620 entries), each sample carrying the known-present spt-daemon-broker pipe in the SAME sample, so neither zero is a dead instrument. Both are boundary observations at an instant. OWNED-RULE STATE. Unchanged across the window: both names x both stores = four readings BEFORE and four AFTER, all CmdletizationQuery_NotFound_InstanceID. Per-store positive control OK objects=1 and impossible-name negative control erroring in both phases, 1001 rules visible per store. NO rule was created in either store. PROCESS DISPOSITION, by ancestry not by name. CANDIDATE_ROWS=4, SUMMARY product_residual=0 recorder_chain_excluded=4 unattributed=0 other=0. All four are MY recorder chain, each resolving ...bash.exe <- 5988:claude.exe <- 38632:claude-spt.exe <- 4732:spt.exe. They stay in the raw evidence with full chains; their exclusion from the product-residual comparison is stated, not performed silently. Chain-link guard is creation order (a parent younger than its child stops the chain as pid reuse) and it REJECTS a link, never proves ancestry; an unresolved chain would read UNATTRIBUTED - neither residual nor target - and there are none. PINNED_EXE_PROCS=0 in BOTH phases: nothing runs the pinned executable. WRAPPER: pid 51896, captured start 05:45:53.9551478Z, checked by pid at 05:49:15.083Z -> 0 rows, with the by-pid filter finding the checking process itself in the same sample. Gone. A returning row with a different creation time would have been a recycled pid, not the wrapper. Fleet 37 -> 42 and census 615/618/606 across three samples is ordinary agent traffic: not one of those rows is a candidate. Fleet untouched. Nothing was signalled by this lane. OUTPUT HASHES, and two parties agree - mine taken independently of liam's: d3-probe.err 8696 bytes 9CBAB062FF64C5B71DFFD7FEBEC9F94ADECA7996ABB6B8A51E2E7491309E37AD d3-probe.log 1290 bytes C12D0C6A089A59E9A96D2DE9908D945C3EDABB103483F5A1FD75F9C8ACF4D29E d3-probe.out 0 bytes E3B0C44298FC1C149AFBF4C8996FB92427AE41E4649B934CA495991B7852B855 (empty-file sha) Payload NOT decoded and NOT executed by liam, by me, or by anything reading the record. CONSOLE PRESERVED. Copied liam's d3-launcher-console.txt into the run dir as liam-launcher-console.txt. b3010a6a13e82ee3961d285c37f518781a6347e6d340aae80c83981c43776ead read THREE times - source before copy, destination after, source again after - all equal and equal to the hash liam published before I asked for the path. Original untouched; liam holds it until my confirmation reaches them. Console corroborates end to end: elevation=present, exe sha match, namespace built with FOUR backslashes, enumerated=620 ctl_nonempty=True ctl_predicate=True hit=0, capture files opened before launch, wrapper named as wrapper, D3_DRAIN ok=True both streams RanToCompletion, native_exit=1, D3_EMITTED. WHAT IT DOES NOT ESTABLISH. Emission succeeded; that is all. The captured literal is not an accepted removal instrument - bytes preserved unused until decoded as data and their ownership/removal behavior reviewed, per your ruling. Process disposition is confirmed on my side, so the window is free from my end whenever you release it. D2 still held and disjoint. Nothing further runs here.