CTIPilot

PRODAFT, Reports

prodaft · B · active

https://www.prodaft.com/reports

ch-euresearchlang: enfetch failures: 0quiet periods: 6last fetch: 2026-09-08

Swiss-Turkish CTI firm; reports index. WebFetch returns HTTP 403 (re-confirmed 2026-05-08). REQUIRED FETCH METHOD: `python3 tools/fetch_source.py url https://www.prodaft.com/reports`. | 2026-06-20 full audit (v2.62): RECOVERED via the Chrome-138 UA. FETCH → `url https://www.prodaft.com/reports` (research reports) and `url https://www.prodaft.com/resources` both return 200; drill /blog/<slug>. WebFetch still 403, use the bridge. url updated /reports; fetch_method stays bridge. | 2026-07-05 admiralty audit: B (HIGH->B) status active->active, independent CTI research lab, original threat-actor research; host live via bridge but SPA index needs a known /blog/<slug> to drill (could not auto-extract a dated report). Not a demotion. | 2026-07-30: fetch_method bridge -> jina. S2 reached https://www.prodaft.com/reports with HTTP 200 but the body is a pure client-hydrated Next.js shell with no server-rendered listing and no embedded JSON island carrying report titles/slugs/dates, so no dated report can be extracted without already knowing a /blog/<slug>. Switching fetch_method to jina, which renders page JS server-side and resolves exactly this class of SPA index. Transport block, not source death, no demotion (HTTP 200 throughout). | 2026-08-04 run: FETCH NOTE, the jina reader now hydrates https://www.prodaft.com/reports and returns real report titles/summaries (superseding the earlier "pure client shell" note), but the listing renders NO publication dates for any report, so recency cannot be established from it. Per-report dates require drilling /report/<slug> individually. | 2026-08-06: jina fetch of /reports succeeded and returned a hydrated listing; no in-window report published, so this is a genuine quiet period rather than a transport failure. | 2026-08-07: third consecutive run without a contribution, root-caused and NOT a transport failure or a death; the jina fetch of /reports returns HTTP 200 with a fully hydrated listing, but that listing is a STALE CACHED SNAPSHOT: page metadata reports 'Published Time: Wed, 08 Jul 2026' and the newest visible report is unchanged from a month ago, with no publication dates anywhere on the page so recency cannot be established. /blogs carries the same frozen 08 Jul 2026 stamp. Direct (non-jina) fetch confirms a Next.js SPA that serves an empty shell without JS, so the reader is the only route to content and its cache is what is stuck. resources.prodaft.com does not resolve; no RSS found. Do NOT demote (content axis untouched, transport healthy) and do not re-derive this each run; re-check whether the cache has moved past 08 Jul before spending another rotation slot on it. | 2026-08-08: fourth consecutive run with no contribution. Both S2 and S3 re-fetched via the jina reader; the listing is still the same frozen snapshot documented on 2026-08-07 (top item unchanged, no publication dates). Transport healthy (200), NOT demoted, content axis untouched. Next fire: check whether the cache has moved before spending a rotation slot. | 2026-08-09: fifth consecutive run with no contribution, re-confirmed independently by S1 and S3. Two distinct findings this run: resources.prodaft.com (the subdomain in the original candidate note) no longer resolves (NXDOMAIN on both direct and reader transports) and www.prodaft.com/reports returns HTTP 200 but is a client-side-rendered Next.js shell whose listing is the same frozen snapshot seen since 2026-08-07, with no publication dates anywhere. Future runs should target www.prodaft.com/reports and need a structured-endpoint recipe before this source can contribute to a recency-gated run. Deliberately NOT demoted: transport is healthy and a stale upstream cache is not evidence the source stopped publishing. | 2026-08-10: Sixth consecutive run with no contribution; www.prodaft.com/reports still returns a client-rendered shell serving the same frozen snapshot with no publication dates, so recency cannot be established. NOT demoted; transport is healthy and a stale upstream cache is not evidence the source stopped publishing. | 2026-08-11: SEVENTH consecutive run with no contribution, independently re-confirmed by S2 and S3. /reports still returns HTTP 200 as a client-rendered shell serving the same undated, frozen listing; /blog returns 403 to the reader. NOT demoted (transport healthy, stale upstream cache is not content death), but the pinned /reports URL can no longer establish recency for any item; the next audit should decide whether a different PRODAFT surface is pinnable or the record is parked. | 2026-08-15: not attempted this run; deprioritised after seven consecutive runs without a contribution; fetch_method is pinned to the reader, which was unavailable all run. | 2026-08-16: not attempted this run: the record is pinned to the reader transport, which was exhausted for the whole run. Eighth consecutive run without a contribution, all of them reader-pool failures rather than content death. | 2026-08-16 weekly: ninth consecutive run without a contribution, all reader-pool failures (HTTP 402 on all 7 keys, confirmed via jina-usage at run start). Direct fetch of /reports returns a JS-only Next.js shell with no server-rendered listing. NOT demoted; this is transport blocking plus an exhausted credit pool, not content death. Operator item: this record needs a structured discovery path (sitemap or API) or the reader pool restored. | 2026-08-18: tenth consecutive run without a contribution, every one a reader-pool failure rather than content death. Still needs a structured discovery path, operator item. | 2026-08-19: eleventh consecutive reader-pool failure; jina-only recipe with the pool exhausted. Content death is not indicated, needs a structured discovery path, operator item. | 2026-08-23: RECIPE FIX; the record was pinned to the reader (fetch_method: jina), which has been credit-exhausted for nine consecutive fires, so this source was silently unreachable that whole time. Verified this run that the direct bridge works: `python3 tools/fetch_source.py url https://www.prodaft.com/resources` returns HTTP 200 with the full ~272 KB body. Moved jina -> bridge. Note the listing is a Next.js render carrying no inline per-post dates, so recency needs a drill into individual resource URLs; no in-window (2026-08-20+) item was identified this run.

Cited in 0 entries

Not cited in any entry yet.