154 techniques occupying 77 terrain×form cells. The interactive matrix presents the same data as a scoreable board.
M1 · 15 techniques
| ID | Technique | Ground | Phases | What it does | Success indicator | Assessed by |
|---|---|---|---|---|---|---|
M1.01 | External Attack Surface Enumeration | T3 | 0,I | Continuously enumerate everything the agency exposes to the internet, from the outside in, on the same cadence an adversary would. | New exposure appears in the terrain register before it appears in an alert. | TM-1, TM-6, KT-3 |
M1.02 | Shadow and Forgotten Asset Discovery | T3 | 0 | Reconcile discovered internet-facing assets against the authoritative inventory and drive the difference to zero. | The unreconciled-asset count trends to zero and stays there. | TM-1, TM-6, TM-7, FO-3, DV-1 |
M1.03 | Certificate and Domain Watch | T3 | 0,I | Watch certificate transparency and registration feeds for lookalike domains and unsanctioned certificates issued in the agency name. | Impersonation infrastructure is identified while it is still being staged. | TM-1, KT-3 |
M1.04 | Perimeter Canary Tokens | T5 | 0,I | Seed uniquely identifying tokens in externally reachable surfaces so that reconnaissance touching them is unambiguous. | A token fires before any production system records the actor. | KT-3, CE-2 |
M1.05 | Authentication Geography Baseline | T1 | 0,II | Baseline where, when and from what the population legitimately authenticates, so deviation is measurable rather than anecdotal. | Account-takeover precursors are detected on deviation, not on damage. | CE-2, TA-1 |
M1.06 | Credential Exposure Monitoring | T1 | 0,I | Monitor public and criminal sources for agency credentials, session artifacts and tokens offered for sale or dumped. | Exposed credentials are invalidated before they are used against the estate. | CE-2, TA-4 |
M1.07 | Partner and Advisory Intake | TX | 0,I | Operate a named, timed intake path for CISA, sector and law-enforcement reporting that ends in a decision rather than a mailbox. | Every advisory reaches a disposition within its stated intake window. | CE-2, CG-4 |
M1.08 | Public Service Abuse Telemetry | T4 | 0,II | Instrument public-facing services for abuse patterns — enumeration, scripted submission, credential stuffing — distinct from application errors. | Abuse is distinguished from load, and named, before it becomes an incident. | CE-2, TA-1, EN-1 |
M1.09 | Supply Chain and Vendor Watch | TX | 0 | Track the security posture and incident disclosures of vendors and integrators whose products sit on key terrain. | A vendor compromise reaches the terrain owner before it reaches the news. | TM-7, CG-5 |
M1.10 | Named-Campaign Indicator Watch | TX | 0,I | Maintain standing collection against the specific campaigns the intelligence requirements name, not against indicators in general. | Every priority intelligence requirement has live collection against it. | CE-2, CE-3 |
M1.11 | Operational Technology Asset Discovery | T6 | 0 | Discover control-system assets passively, because active scanning of a safety-instrumented network is itself an availability risk. | The OT inventory is built without a scan-induced outage. | TM-1, TM-2, FO-4 |
M1.12 | Workforce Credential Exposure Monitoring | T7 | 0,I | Watch the outside world for agency credentials and staff identities appearing where they should not, on the same cadence you watch the network perimeter. | Exposed staff credentials are found and revoked before they are used. | WF-1, WF-2, TM-6 |
M1.13 | Physical Access Anomaly Detection | T8 | 0,II | Read badge and access-control telemetry as an intelligence source rather than an audit artifact, and correlate it with logical access. | Impossible-travel and after-hours physical anomalies raise a finding. | FC-1, FC-2, CE-3 |
M1.14 | Supplier Exposure Monitoring | T9 | 0,I | Monitor the suppliers and components that reach into the estate for breach disclosure, advisory and exposure, because their compromise is your compromise. | A supplier incident reaches the agency from monitoring, not from the news. | LC-1, LC-2, TM-6, FO-6 |
M1.15 | Device Estate Discovery | T2 | 0 | Discover devices reaching the estate from the identity plane outward rather than from the management console, because the console can only report what it already manages. | Devices authenticating to the estate but absent from the inventory trend to zero. | TM-1, TM-6, DV-1 |
M2 · 18 techniques
| ID | Technique | Ground | Phases | What it does | Success indicator | Assessed by |
|---|---|---|---|---|---|---|
M2.01 | Trust Zone Architecture | T3 | 0 | Define trust zones that reflect real boundaries and assurance differences, and record which elements sit in which. | Every element on the terrain resolves to exactly one declared zone. | TM-4, TM-5 |
M2.02 | Policy Enforcement Point Placement | T3 | 0 | Place an enforcement point at every zone boundary so that crossing is a decision, not a route. | No path reaches a higher-trust zone without transiting an enforcement point. | TM-4, KT-2, ID-5 |
M2.03 | Crown-Jewel Enclave | T5 | 0,I | Isolate the decisive data behind its own enforcement point, with its own authorization policy and its own telemetry. | Reaching the data layer requires defeating controls nothing else shares. | KT-1, KT-2 |
M2.04 | Independent Control Redundancy | TX | 0 | Ensure the controls guarding key terrain fail independently — no shared agent, identity, console or vendor across a protection floor. | No single control, credential or vendor failure exposes a decisive point. | KT-2, KT-5 |
M2.05 | Endpoint Detection and Response Coverage | T2 | 0 | Achieve and prove sensor coverage across the managed fleet, with unmanaged devices treated as a measured gap rather than an assumption. | Coverage is reconciled to the inventory, not to the console. | TM-2, TM-6, DV-1, DV-3 |
M2.06 | Device Posture Gating | T2 | 0,I | Make device health a precondition of access, so a compromised or non-compliant endpoint cannot spend a valid credential. | Failing posture denies access rather than raising a ticket. | KT-2, SM-2, DV-2 |
M2.07 | Web Application Protection | T4 | 0 | Front public applications with request-level inspection tuned to the application, not to a generic ruleset. | Application-layer attacks are stopped at the edge and counted. | KT-2, SM-2 |
M2.08 | API Authorization Enforcement | T4 | 0 | Enforce per-call authorization at an API gateway rather than trusting network position or a shared key. | No API path authorizes on network location alone. | KT-2, SM-2 |
M2.09 | Data-at-Rest Encryption and Key Separation | T5 | 0 | Encrypt decisive data with keys held outside the system that reads it, so storage compromise is not data compromise. | Exfiltrating storage does not yield readable records. | KT-2, TM-3, FO-2 |
M2.10 | Egress Data Loss Prevention | T5 | 0,III | Inspect and constrain outbound movement of the record types the campaign exists to protect. | Bulk movement of protected records is blocked or alerted at egress. | KT-2, KT-5 |
M2.11 | Workload Hardening Baseline | T2 | 0 | Hold servers, images and containers to a declared baseline, and treat drift from it as a finding. | Baseline drift is detected on a stated cadence and dispositioned. | TM-6, CG-4, DV-4 |
M2.12 | Secrets Management | T4 | 0 | Remove long-lived secrets from code, images and configuration into brokered, rotated, audited storage. | No decisive system authenticates with a static embedded secret. | KT-2, SM-3, ID-2 |
M2.13 | Backup Isolation and Immutability | T5 | 0,IV | Hold recovery data outside the blast radius of the production identity plane and make it immutable for its retention window. | Recovery is possible after full compromise of production identity. | KT-2, SM-5 |
M2.14 | Control Failure Detection | TX | 0 | Detect when a control stops working — sensor silent, policy unapplied, agent removed — as a security event in its own right. | A silent control is detected in hours, not at the next assessment. | SM-3, SM-6, CE-6, DV-3 |
M2.15 | Safety Instrumented Layer Integrity | T6 | 0 | Keep the safety layer independent of the control layer, so a compromise of operations cannot defeat the function that prevents harm. | Safety functions hold when the control network is assumed hostile. | KT-2, FO-4 |
M2.16 | Role-Based Privilege Minimization | T7 | 0 | Give each role the least authority its work requires, so a compromised person yields the least ground. | No role holds authority its documented duties do not require. | WF-2, WF-3 |
M2.17 | Facility Defense in Depth | T8 | 0 | Layer physical controls so that defeating one barrier does not deliver the floor, the rack or the media inside it. | Reaching a decisive asset physically requires defeating three independent controls. | FC-2, FC-1 |
M2.18 | Component Provenance Verification | T9 | 0 | Know what is inside what you deploy, and verify it came from who it claims, before it runs on your ground. | Every deployed component resolves to a verified origin and a current inventory. | LC-2, LC-4 |
M3 · 20 techniques
| ID | Technique | Ground | Phases | What it does | Success indicator | Assessed by |
|---|---|---|---|---|---|---|
M3.01 | Phishing-Resistant Authentication | T1 | 0,I | Move the population to authenticators that cannot be relayed or replayed by a proxy. | Credential phishing yields no usable authentication. | KT-2, SM-2, ID-2, ID-3 |
M3.02 | Conditional Access Policy Engine | T1 | 0,I | Concentrate access decisions in one policy decision point that sees identity, device, network and behavior together. | Access decisions are made in one place and are inspectable. | KT-1, SM-2, ID-1 |
M3.03 | Continuous Authorization | T1 | 0,II | Re-evaluate authorization during a session on changed signal, rather than only at sign-in. | A session that becomes risky is downgraded mid-flight. | SM-2, TA-4, ID-5 |
M3.04 | Just-in-Time Privilege | T1 | 0,I | Grant privilege for a bounded task and window, with the grant itself recorded as an event. | Standing privileged sessions approach zero. | KT-2, SM-2 |
M3.05 | Privileged Access Workstations | T2 | 0,I | Require administration of decisive systems from dedicated, hardened, separately governed endpoints. | No decisive system is administered from a general-purpose desktop. | KT-2, TM-2, DV-2 |
M3.06 | Machine and Service Identity Governance | T1 | 0 | Give non-human identities owners, expiry and scope on the same terms as human ones. | Every service account has a named owner and an expiry date. | TM-7, SM-3, ID-2 |
M3.07 | Standing Privilege Elimination | T1 | 0,I | Systematically remove permanent administrative rights, replacing them with request-and-grant paths. | Permanent privileged entitlements trend to a declared floor. | KT-2, SM-3 |
M3.08 | Identity Lifecycle Enforcement | T1 | 0 | Bind joiner, mover and leaver events to authoritative sources so access follows the person, not the ticket. | Departure removes access within the stated interval, provably. | SM-3, TM-6 |
M3.09 | External-User Identity Assurance | T1 | 0,I | Apply proportionate identity assurance to public and partner users of mission services without denying access to the public. | Account takeover of external users falls while service access holds. | KT-2, SM-2, ID-3 |
M3.10 | Device-Bound Credentials | T2 | 0,I | Bind credentials cryptographically to hardware so that stolen material cannot be spent elsewhere. | Exported credential material is unusable off its device. | KT-2, SM-2, ID-2, DV-2 |
M3.11 | Session and Token Revocation Path | T1 | 0,III | Maintain a tested path to invalidate sessions and tokens estate-wide within a stated interval. | Revocation completes inside the interval the rules of engagement assume. | TA-4, TA-1, ID-4 |
M3.12 | Authorization Policy as Code | T1 | 0 | Express access policy as reviewed, version-controlled, testable code rather than console state. | Policy change is reviewable and revertible like any other change. | SM-2, SM-3, ID-5 |
M3.13 | Federation Trust Boundary Control | T1 | 0,I | Enumerate every federated trust into the estate, own each one, and constrain what it may assert. | Every inbound trust has an owner, a scope and a suspension path. | TM-5, CG-5, ID-1 |
M3.14 | Entitlement Recertification | T1 | 0 | Review entitlements on a cadence against actual use, and remove what is not used. | Unused entitlements are removed rather than recertified. | SM-3, CG-4 |
M3.15 | Break-Glass Account Control | T1 | 0,IV | Hold emergency accounts under split control with alerting on any use, so the last resort is not the soft target. | Break-glass use is always deliberate and always noticed. | KT-2, CG-3 |
M3.16 | Token Replay Protection | T1 | 0,II | Bind issued tokens to sender and context so a captured token cannot be replayed from elsewhere. | Replayed tokens fail outside their issuing context. | SM-2, KT-5, ID-4 |
M3.17 | Authentication Anomaly Scoring | T1 | 0,II | Score authentication against the behavioral baseline and feed the score back into the policy decision point. | Anomalous authentication changes the access decision automatically. | CE-2, SM-2, ID-3 |
M3.18 | Identity Provider Tamper Detection | T1 | 0,III | Treat the identity provider as decisive terrain: alert on federation, policy, key and admin changes independently of the provider itself. | Changes to the identity plane are detected out-of-band. | KT-1, CE-2, ID-1, ID-5 |
M3.19 | Human-to-Account Binding | T7 | 0,I | Bind every privileged account to a named, current, cleared human, so an orphaned credential has nowhere to hide. | No privileged account exists without a named accountable holder. | WF-2, WF-5 |
M3.20 | Supplier Identity Federation | T9 | 0,I | Bring supplier access under the agency's own identity plane rather than standing local accounts the agency cannot see or revoke. | Supplier access is revocable by the agency in one action. | LC-3, WF-2 |
M4 · 17 techniques
| ID | Technique | Ground | Phases | What it does | Success indicator | Assessed by |
|---|---|---|---|---|---|---|
M4.01 | Microsegmentation | T3 | 0,I | Reduce reachability between workloads to what is declared, so lateral movement requires defeating policy rather than finding a route. | Reachable-neighbor counts fall against a declared target. | TM-4, KT-5 |
M4.02 | East-West Deny by Default | T3 | 0,I | Make the default answer between segments "no", with exceptions declared, owned and expiring. | New east-west paths exist only where they are declared. | TM-5, KT-5 |
M4.03 | Egress Filtering and Allow-Listing | T3 | 0,I | Constrain outbound destinations so command channels must use paths you inspect. | Outbound connections resolve to an allow-listed destination or fail. | KT-5, TM-5 |
M4.04 | DNS Control and Sinkholing | T3 | 0,I | Route resolution through controlled resolvers, log it, and sinkhole known-bad and newly registered domains. | Resolution to staged infrastructure fails and alerts. | KT-5, CE-2 |
M4.05 | Application Allow-Listing | T2 | 0,I | Constrain what may execute on decisive endpoints to what is approved and signed. | Unapproved executables do not run on decisive endpoints. | KT-2, TM-2, DV-4 |
M4.06 | Administrative Path Restriction | T3 | 0,I | Confine administrative protocols to declared corridors from declared sources. | Administrative access from outside the corridor fails and alerts. | TM-5, KT-2 |
M4.07 | Cloud Boundary Enforcement | T3 | 0 | Enforce account, VPC and role boundaries in the cloud with the same rigor as network segments on the ground. | Cross-account reachability matches the declared design exactly. | TM-4, TM-5 |
M4.08 | Instrumented Corridor Design | T3 | I,II | Deliberately leave the paths you want an adversary to take, and instrument them heavily. | Observed lateral attempts land in instrumented segments. | KT-5, CE-2 |
M4.09 | Removable Media Control | T2 | 0 | Constrain and log removable media on endpoints holding or reaching decisive data. | Media use on decisive endpoints is either denied or recorded. | KT-2, TM-2, DV-5 |
M4.10 | Bastion and Jump-Host Enforcement | T3 | 0,I | Force privileged access to decisive systems through recorded, brokered hosts. | Privileged sessions to decisive systems are recorded without exception. | KT-2, CG-3 |
M4.11 | Protocol and Port Restriction | T3 | 0 | Permit only the protocols the design requires, and treat the rest as a canalization opportunity. | Non-design protocols are denied at the boundary and counted. | TM-5, KT-5 |
M4.12 | Denied-Path Register Enforcement | T3 | 0 | Maintain the explicit register of paths that must never exist, and test continuously that they do not. | Every denied path is tested on a stated cadence and holds. | TM-5, SM-6 |
M4.13 | Operational Technology Segregation | T6 | 0,I | Separate control-system networks from the enterprise with an enforced, inspectable boundary rather than a documented intention. | No route exists from an office endpoint to a controller without transiting an enforcement point. | TM-4, KT-5, FO-4 |
M4.14 | Control Protocol Constraint | T6 | 0,I | Permit only the industrial protocols and function codes the process requires, and deny engineering commands from outside the corridor. | Write and program commands originate only from declared engineering stations. | KT-5, FO-4 |
M4.15 | Physical Zone Segregation | T8 | 0,I | Divide facilities into zones whose boundaries are enforced and logged, so physical movement is as canalised as network movement. | Movement between physical zones is enforced and recorded. | FC-2, FC-1 |
M4.16 | Maintenance Access Constraint | T8 | I,II | Force vendor and remote maintenance onto a supervised, time-boxed path instead of standing access into the estate. | No maintenance path is available outside an approved, supervised window. | FC-3, LC-3 |
M4.17 | Supplier Access Canalisation | T9 | I,II | Route every supplier into a defined broker rather than directly onto mission systems, so their traffic crosses ground you instrument. | No supplier reaches a mission system except through the brokered path. | LC-3, TM-5 |
M5 · 13 techniques
| ID | Technique | Ground | Phases | What it does | Success indicator | Assessed by |
|---|---|---|---|---|---|---|
M5.01 | Decoy Records in the Data Layer | T5 | I,II | Seed the record stores with realistic decoy records whose only purpose is to be accessed by someone who should not. | Access to a decoy produces a high-confidence detection with no false-positive tail. | KT-2, CE-2, SM-7 |
M5.02 | Honeytokens in Document Stores | T5 | I,II | Place tokenized documents in collaboration and file estate where staged collection would find them. | Staging for exfiltration is detected during collection, not after. | CE-2, TA-1, SM-7 |
M5.03 | Decoy Credentials | T1 | I,II | Seed credential stores, memory and configuration with credentials that are valid-looking and monitored but powerless. | Credential harvesting is detected on use of a planted credential. | CE-2, KT-4, FO-1, SM-7, ID-2 |
M5.04 | Honeypot Services in Corridors | T3 | I,II | Place responsive services in the lateral corridors so that scanning and movement produce contact rather than silence. | Lateral reconnaissance produces an alert on first contact. | KT-5, CE-2, SM-7 |
M5.05 | Canary Files on Endpoints | T2 | I,II | Distribute monitored files across the endpoint fleet to detect mass encryption and mass collection early. | Mass file operations are detected within the first affected hosts. | CE-2, TA-1, SM-7 |
M5.06 | Decoy Service Endpoints | T4 | I,II | Publish plausible but unused API and administrative endpoints that only enumeration would find. | Enumeration of the application surface produces contact. | CE-2, KT-3, SM-7 |
M5.07 | Identity-Plane Deception | T1 | I,II | Plant privileged-looking accounts and group memberships that no legitimate process ever touches. | Directory reconnaissance is detected at the enumeration stage. | CE-2, KT-4, SM-7 |
M5.08 | Decoy Cloud Resources | T4 | I,II | Stand up monitored buckets, roles and secrets that legitimate workloads never call. | Cloud credential abuse is detected on first exploratory call. | CE-2, KT-4, SM-7 |
M5.09 | Deception Alert Routing | TX | I,III | Route deception alerts on a separate, high-trust path that bypasses ordinary triage queues. | Deception alerts reach a decision-maker without queueing. | CE-3, TA-4, SM-7, EN-1 |
M5.10 | Deception Coverage Measurement | T5 | 0,I | Measure what share of the data layer is actually seeded, and treat the unseeded remainder as a gap. | Deception coverage is a reported number, not an impression. | CE-4, SM-6, SM-7 |
M5.11 | Control Network Deception | T6 | I,II | Place decoy controllers and engineering workstations on the control network, where legitimate traffic is narrow and predictable. | Any interaction with a decoy controller is unambiguous. | CE-2, FO-4, SM-7 |
M5.12 | Phishing Deception and Reporting | T7 | 0,I | Exercise the workforce against realistic lures and treat the reporting rate, not the click rate, as the measure that matters. | Reporting rate exceeds click rate and the first report arrives within minutes. | WF-3, CE-2, SM-7 |
M5.13 | Physical Deception | T8 | I | Seed facilities with tokens whose only plausible use is by someone who should not have them — dropped media, decoy badges, decoy racks. | Physical decoy interaction produces findings with no false-positive tail. | FC-1, CE-3, SM-7 |
M6 · 10 techniques
| ID | Technique | Ground | Phases | What it does | Success indicator | Assessed by |
|---|---|---|---|---|---|---|
M6.01 | Adaptive Rate Limiting | T4 | II,III | Slow request rates as risk rises, so automation loses its advantage while humans keep service. | Automated abuse degrades while legitimate service holds. | TA-5, SM-2 |
M6.02 | Step-Up Authentication on Anomaly | T1 | II,III | Demand stronger proof at the moment behavior deviates, rather than uniformly at sign-in. | Anomalous sessions must re-prove before continuing. | SM-2, TA-4, ID-3 |
M6.03 | Bulk Export Throttling | T5 | II,III | Cap the rate and volume of bulk retrieval so a successful intrusion cannot become a successful exfiltration in one pass. | Bulk collection takes long enough to be detected and stopped. | KT-2, TA-5 |
M6.04 | Session Duration Reduction Under Alert | T1 | II,III | Shorten session and token lifetimes automatically while the estate is in contact. | Session lifetimes contract on phase change without an outage. | TA-4, CG-2, ID-4 |
M6.05 | Approval Gates on High-Impact Actions | TX | II,III | Require a second, human authorization for the small set of actions that would be decisive if abused. | Decisive actions cannot be completed by one compromised identity. | CG-3, TA-4, EN-4 |
M6.06 | Tarpitting and Response Delay | T3 | II | Introduce deliberate latency on suspicious paths, so an adversary spends time you are spending on decision. | Adversary tempo drops below defender decision tempo. | TA-1, TA-5 |
M6.07 | Progressive Lockout | T1 | II | Escalate friction against an identity under attack without handing an attacker a denial-of-service lever. | Guessing is defeated without locking the population out. | SM-2, TA-5 |
M6.08 | Change and Deploy Freeze Under Contact | T4 | III | Suspend routine change into decisive systems while in contact, so the adversary cannot hide in the noise of normal deployment. | Change into decisive systems stops on phase declaration. | CG-2, TA-5 |
M6.09 | Query Complexity Limits | T4 | II,III | Bound the cost and breadth of a single query against mission data stores. | No single query can enumerate the corpus. | KT-2, TA-5 |
M6.10 | Update Staging and Soak | T9 | II,III | Hold vendor updates in a staging ring long enough to observe them, trading a little currency for the ability to not deploy a compromised build estate-wide. | No supplier update reaches the whole estate without a stated soak period. | LC-4, LC-2 |
M7 · 17 techniques
| ID | Technique | Ground | Phases | What it does | Success indicator | Assessed by |
|---|---|---|---|---|---|---|
M7.01 | Hypothesis-Driven Hunting | TX | II,III | Hunt against stated hypotheses drawn from the intelligence requirements, not against whatever the queue surfaced. | Every hunt traces to a priority intelligence requirement. | CE-2, CE-3 |
M7.02 | Fusion-Fed Hunt Backlog | TX | II,III | Convert fused assessments into a ranked, worked hunt backlog with explicit confidence on each entry. | Fusion output becomes hunt work rather than a report. | CE-3, CE-5, EN-1 |
M7.03 | Automated Containment Playbooks | TX | III | Encode containment as tested automation so the decision, not the execution, is the slow step. | Containment executes in seconds once the decision is made. | TA-4, SM-5, EN-4 |
M7.04 | Host Isolation on Confirmation | T2 | III | Sever a host from the network on confirmed compromise while preserving it for analysis. | Confirmed hosts are isolated inside the stated interval. | TA-4, TA-1, SM-4 |
M7.05 | Credential Reset Sweep | T1 | III | Execute a scoped, ordered reset of credentials and tokens across the compromised blast radius. | The reset completes without leaving a re-entry credential. | TA-4, SM-5 |
M7.06 | Build Pipeline Integrity Hunt | T4 | III | Hunt the build pipeline specifically, because poisoning it envelops everything downstream. | Pipeline integrity is verified rather than assumed after contact. | KT-1, SM-6 |
M7.07 | Persistence Sweep | T2 | III,IV | Sweep systematically for persistence across identity, endpoint, cloud and application layers before declaring eradication. | Eradication is declared on evidence across every layer. | SM-6, CG-4, EN-5 |
M7.08 | Lateral Path Audit | T3 | II,III | Recompute what the adversary could reach from where they stand, and close the paths ahead of them. | Reachability from the foothold is reduced during the engagement. | KT-4, KT-5 |
M7.09 | Detection Engineering from Hunt | TX | III,V | Convert every hunt finding into a durable detection with an owner and a test. | No hunt finding is left as tribal knowledge. | SM-6, CE-5 |
M7.10 | Purple-Team Validation | TX | 0,V | Test whether each emplaced maneuver actually performs, using the cell success indicator as the pass condition. | Every claimed maneuver has been demonstrated, not asserted. | SM-6, CE-4 |
M7.11 | Eviction Sequencing | TX | III | Plan eviction as a single sequenced action, so the adversary cannot re-enter through what is evicted last. | Eviction happens once, not in rounds. | SM-5, TA-3, EN-5 |
M7.12 | Adversary Dwell Reconstruction | TX | III,IV | Reconstruct how long the adversary held the ground, so temporal advantage is computed rather than estimated. | Dwell is measured from evidence for every engagement. | TA-2, CE-6, EN-2 |
M7.13 | Hunt Coverage Accounting | TX | V | Track which terrain has been hunted, how recently, and against which hypotheses. | Unhunted terrain is visible and dispositioned. | CE-4, CE-6 |
M7.14 | Process Anomaly Hunting | T6 | II,III | Hunt for deviation in the physical process itself, not only in the network, because a competent adversary will look correct on the wire. | Process behavior outside its engineering envelope is investigated as a security event. | CE-2, FO-4 |
M7.15 | Insider Risk Investigation | T7 | III | Run a defined, rights-respecting process to resolve an insider indication, rather than improvising one under pressure. | Insider indications reach a documented disposition within a stated period. | WF-4, CG-4 |
M7.16 | Supply Chain Compromise Hunting | T9 | III | Hunt for the specific behaviors a compromised supplier or component would produce, on the assumption that it is already inside. | Supplier-origin behaviors are hunted on a stated cadence, not only on advisory. | LC-2, LC-4, CE-2 |
M7.17 | Malicious Message Eviction | T4 | III | Remove a delivered malicious message from every mailbox it reached, including forwards and delegated copies, rather than only from the originally reported one. | A reported message is removed estate-wide, not only where it was reported. | EN-5, TA-4, DV-3 |
M8 · 17 techniques
| ID | Technique | Ground | Phases | What it does | Success indicator | Assessed by |
|---|---|---|---|---|---|---|
M8.01 | Automated Segment Severing | T3 | III | Hold a tested capability to sever a segment or zone on decision, without an unplanned outage of everything else. | A zone can be severed inside the interval the plan assumes. | TA-4, SM-5, EN-4 |
M8.02 | Estate-Wide Session Revocation | T1 | III | Invalidate every session and token across the estate as one action when the identity plane is in doubt. | Estate-wide revocation is exercised and timed, not theoretical. | TA-4, SM-5, ID-4 |
M8.03 | Read-Only Service Degradation | T4 | III,IV | Degrade mission services to read-only or queued operation rather than exposing or losing the corpus. | Service degrades gracefully instead of failing open or dark. | SM-5, TA-5 |
M8.04 | Fail-Secure Default Posture | TX | 0,III | Ensure that when a control fails, the estate denies rather than permits — including under load and during recovery. | Control failure denies access rather than bypassing the control. | KT-2, CG-3 |
M8.05 | Federation Trust Suspension | T1 | III | Suspend an inbound federated trust independently, without dismantling the identity plane around it. | A compromised trust is suspended without an estate outage. | TM-5, TA-4 |
M8.06 | Cloud Account Quarantine | T4 | III | Quarantine a cloud account or subscription — revoking roles and cutting peering — as one rehearsed action. | A cloud account is isolated inside the stated interval. | TA-4, TM-4 |
M8.07 | Egress Blackhole | T3 | III | Cut outbound reachability for a defined scope to stop exfiltration and command channels while analysis continues. | Exfiltration stops without severing the whole estate. | KT-5, TA-4 |
M8.08 | Statutory Availability Floor | TX | III,IV | Declare in advance which mission functions may never be taken offline, and design containment around them. | Containment never breaches the declared availability floor. | CG-1, CG-3 |
M8.09 | Contained Forensic Preservation | T5 | III,IV | Preserve evidence in a way that survives containment and recovery, on storage the adversary could not reach. | Evidence survives the response intact and admissible. | KT-2, CE-6, EN-3 |
M8.10 | Third-Party Connection Cutout | T3 | III | Cut a specific partner or vendor connection on decision without taking down the shared boundary. | A single external connection can be cut in isolation. | TM-5, CG-5 |
M8.11 | Restoration Preconditions | TX | IV | Define what must be true before anything comes back — no restoration on hope. | Nothing is restored until its preconditions are evidenced. | SM-5, CG-4, EN-5 |
M8.12 | Degradation Rehearsal | TX | 0,IV | Rehearse degradation and severing on the real estate, because an untested retrograde is a plan, not a capability. | Every severing action has been exercised within its stated period. | SM-6, CE-1 |
M8.13 | Safe-State Isolation | T6 | III | Sever the control network to a defined safe state that preserves the physical process, rather than a network state that abandons it. | Isolation leaves the process safe, not merely disconnected. | SM-5, FO-4, RC-1 |
M8.14 | Rapid Offboarding and Revocation | T7 | III,IV | Remove all access from a departing or suspended person in one action, in a time measured against the tempo an insider needs. | Full revocation completes within the stated tempo, evidenced by exercise. | WF-5, TA-1, DV-5 |
M8.15 | Facility Isolation | T8 | III | Be able to sever a building or floor from the estate without severing the mission, and know in advance what that costs. | A facility can be isolated on a rehearsed procedure without an unplanned outage. | FC-2, FC-4, SM-5 |
M8.16 | Supplier Severance | T9 | III,IV | Be able to cut a supplier's access immediately and continue the mission, because the alternative is negotiating with an intrusion. | A supplier can be severed within a stated period without halting the mission. | LC-5, SM-5 |
M8.17 | Device Decommissioning and Sanitization | T2 | 0,V | Remove a retired, lost or reassigned device from the estate's trust and sanitize its media within a period derived from what its retained trust could do. | No device holds estate trust without a current accountable holder. | DV-5, WF-5, TM-7 |
M9 · 9 techniques
| ID | Technique | Ground | Phases | What it does | Success indicator | Assessed by |
|---|---|---|---|---|---|---|
M9.01 | Advisory-Driven Pre-Blocking | TX | 0,I | Block infrastructure named in partner reporting before it is used against you, on a stated clock. | Named infrastructure is blocked within the intake window. | CE-2, TA-4 |
M9.02 | Targeted Emergency Patching | T4 | 0,I | Patch out of cycle when intelligence — not the calendar — says a specific weakness is being used now. | Actively exploited weaknesses are closed ahead of the routine cycle. | CE-5, CG-4 |
M9.03 | Staged Infrastructure Denial | T3 | 0,I | Deny resolution and reachability to infrastructure observed staging against the sector, not only against you. | Sector-staged infrastructure never reaches an avenue of approach. | KT-3, CE-2 |
M9.04 | Sector Intelligence Exchange | TX | 0,V | Contribute and consume in the sector and federal exchanges so pre-emption is possible at all. | The agency both receives and contributes actionable reporting. | CE-7, CG-5, EN-6 |
M9.05 | Pre-Emptive Credential Invalidation | T1 | 0,I | Invalidate credentials on exposure intelligence, before misuse, accepting the friction. | Exposed credentials are dead before they are tried. | TA-4, CE-2 |
M9.06 | Vendor Compromise Response | TX | 0,I | Hold a rehearsed path to constrain a compromised vendor or integrator connection on disclosure. | A vendor disclosure produces a constraint, not a meeting. | CG-5, TM-5 |
M9.07 | Exploited-Vulnerability Catalog Enforcement | T4 | 0 | Treat authoritative known-exploited catalogs as a directive with an owner and a due date on the terrain register. | Catalog entries are closed on their due dates, with exceptions owned. | CE-5, CG-4 |
M9.08 | Workforce Threat Briefing | T7 | 0,I | Tell the workforce what is actually being attempted against agencies like yours, so recognition happens before the click. | Briefings cite current campaigns and reach the roles those campaigns target. | WF-3, CE-2 |
M9.09 | Supplier Advisory Pre-emption | T9 | 0,I | Act on supplier and component advisories before exploitation reaches you, including by staging the update or constraining the access. | Advisories affecting named suppliers are dispositioned within the stated window. | LC-1, LC-4, CE-2 |
M10 · 7 techniques
| ID | Technique | Ground | Phases | What it does | Success indicator | Assessed by |
|---|---|---|---|---|---|---|
M10.01 | Indicator-to-Detection Conversion | TX | IV,V | Convert every indicator observed in contact into a durable, tested detection rather than a one-time block. | Contact leaves behind detection, not just a blocklist entry. | SM-6, CE-5 |
M10.02 | Avenue Closure Verification | TX | IV,V | Verify by test that the avenue actually used is closed — not that a change was made. | The used avenue fails a deliberate re-test. | SM-6, CE-4, EN-2 |
M10.03 | Terrain Overlay Update | TX | V | Update the terrain overlay with what contact revealed, including everything the map got wrong. | The overlay reflects the estate as contact proved it to be. | TM-1, TM-6, EN-2 |
M10.04 | Intelligence Requirement Revision | TX | V | Revise the priority intelligence requirements from what the engagement showed you could not see. | Requirements change after contact rather than persisting by inertia. | CE-2, CE-6, EN-2 |
M10.05 | Community Reporting | TX | V | Report to CISA and sector partners so the next agency starts from your contact. | Findings are shared within the stated reporting window. | CE-7, CG-5, EN-6 |
M10.06 | Doctrine and Catalog Update | TX | V | Fold what was learned back into the maneuver catalog, the control set and the rules of engagement. | Each engagement changes the doctrine that governs the next. | SM-1, CG-3 |
M10.07 | Supply Chain Lesson Propagation | T9 | V | Feed what a supplier incident taught you back into acquisition and into the terrain register, so the next contract starts from it. | Supplier incidents change the acquisition record, not only the ticket. | LC-1, CG-5, TM-1 |
M11 · 11 techniques
| ID | Technique | Ground | Phases | What it does | Success indicator | Assessed by |
|---|---|---|---|---|---|---|
M11.01 | Recovery Objective Declaration | T4 | 0 | Declare, per mission service, how quickly it must return and how much data loss is survivable — before an incident forces the answer. | Every mission service has a stated recovery objective its owner has signed. | RC-1, FO-5, FO-7 |
M11.02 | Isolated Recovery Environment | T5 | 0,IV | Hold the means of recovery outside the blast radius of the production identity plane, so compromise cannot reach what rebuilds you. | Recovery is possible after total compromise of production identity. | RC-2, KT-2 |
M11.03 | Golden Image and Rebuild Path | T2 | 0,IV | Maintain a trusted, tested build path so rebuilding is a procedure rather than an improvisation under pressure. | A decisive system can be rebuilt from trusted media within its recovery objective. | RC-3, DV-5 |
M11.04 | Identity Plane Reconstitution | T1 | IV | Rehearse rebuilding the identity plane itself, the one system every other recovery depends on. | The identity plane can be re-established without trusting the compromised one. | RC-3, KT-1, ID-1 |
M11.05 | Recovery Data Integrity Verification | T5 | IV | Prove restored data is what it was before contact, rather than restoring the adversary's edits along with it. | Restored records are verified against an independent integrity record. | RC-4 |
M11.06 | Service Restoration Sequencing | T4 | IV,V | Restore in a declared order that respects dependency and statutory priority, so the first service back is the one that must be. | Restoration follows the declared sequence under exercise conditions. | RC-1, RC-5, FO-5, FO-7 |
M11.07 | Reconstitution Exercise | TX | 0,V | Exercise recovery against a real failure scenario on a stated cadence, because an untested recovery plan is a document. | Every recovery objective has been demonstrated within its stated period. | RC-5, CE-1 |
M11.08 | Key Personnel Continuity | T7 | 0,V | Name the roles without which recovery cannot proceed, and make sure none of them is one person deep. | Every recovery-critical role has a rehearsed alternate. | WF-1, RC-5 |
M11.09 | Alternate Facility Activation | T8 | IV,V | Be able to run the mission from somewhere else, and prove it by doing so rather than by documenting it. | The alternate facility has carried the mission within its stated period. | FC-4, RC-1, RC-5 |
M11.10 | Supplier-Independent Rebuild | T9 | IV | Ensure recovery does not depend on the availability or the integrity of the supplier who may be the reason you are recovering. | A decisive system can be rebuilt without supplier assistance. | LC-5, RC-3 |
M11.11 | Mailbox and Message Restoration | T4 | IV,V | Restore mailboxes and messages removed during eviction or lost in the incident, verified against an integrity record, before returning the service to use. | Legitimate messages removed during response are restored and verified. | RC-4, EN-5, RC-3 |