{
 "use_case": "bank-change-check",
 "title": "Bank-detail change check: a look-alike-domain email asking to move payments to Hong Kong",
 "about": "A synthetic email from a look-alike of a made-up supplier's domain, with a free-mail Reply-To, a failed DMARC check, urgency, secrecy, 'don't call' and a Hong Kong account in another company's name, checked against a made-up vendor file. The change must be detected, the code signs flagged, the call-back must name the number on file (not the one in the email), and the signed record must verify.",
 "licence": "Synthetic: the company, vendors, people, domains (.example) and accounts are invented. Part of decosa-api.",
 "inputs": [
  {
   "file": "inputs/email.eml",
   "what": "The email as received (RFC 5322, headers included)."
  },
  {
   "file": "inputs/vendors.csv",
   "what": "The company's vendor file (27 made-up vendors)."
  }
 ],
 "steps": [
  {
   "id": "check",
   "method": "POST",
   "path": "/bank-change/check",
   "body": {
    "eml": {
     "$file": "inputs/email.eml"
    },
    "vendors_csv": {
     "$file": "inputs/vendors.csv"
    }
   }
  },
  {
   "id": "verify",
   "method": "POST",
   "path": "/record/verify",
   "auth": false,
   "body": {
    "record": {
     "$ref": "check.record"
    }
   }
  },
  {
   "id": "tampered",
   "method": "POST",
   "path": "/record/verify",
   "auth": false,
   "body": {
    "record": {
     "$ref": "check.record"
    }
   },
   "tamper": {
    "at": "record.statement.warning_signs",
    "set": 0
   }
  }
 ],
 "checks": [
  {
   "says": "the bank-detail change is detected",
   "path": "check.change_request.present",
   "equals": true
  },
  {
   "says": "the look-alike domain is flagged in code",
   "path": "check.cues[cue=lookalike_domain][0].actor",
   "equals": "code"
  },
  {
   "says": "the Hong Kong account is flagged against the vendor's country",
   "path": "check.cues[cue=bank_country_mismatch][0].evidence",
   "contains": "HK"
  },
  {
   "says": "the call-back names the number on file",
   "path": "check.callback.number_on_file",
   "equals": "+1-312-555-0142"
  },
  {
   "says": "the number in the email is listed as one not to use",
   "path": "check.callback.do_not_use",
   "contains": "+1-312-555-0199"
  },
  {
   "says": "the signed record verifies",
   "path": "verify.ok",
   "equals": true
  },
  {
   "says": "a record with its warning-sign count changed no longer verifies",
   "path": "tampered.ok",
   "equals": false
  },
  {
   "says": "the model call has a signed receipt",
   "receipts": "signed",
   "min": 1
  }
 ]
}