The previous test only tried section-1 targets. Closing that gap: the payload's three index-shaped u32s, followed into the point list and the plane list and checked for the target lying inside the referencing cell, all sit at the 0.203% random control. Two cells read 0.81%, 4x the baseline. I am not treating that as a lead: across this and the previous iteration roughly twenty such tests have been run, and at that count a single 4x enrichment on ~8000 trials is what noise looks like. Calling it a signal would be the multiple-comparisons error a long hypothesis sweep invites. So REGN's header, grid, points, planes and cell index are decoded, section 1's slot regions are censused, and the link between the grid and the geometry is not reachable by any static test I can construct. The honest next step is the PE code that reads a REGN object -- the same kind of work that cracked the .slb packing phase -- rather than a twenty-first correlation.