MATRIX

Maneuver Matrix

All 154 techniques across 11 forms of defensive maneuver, with the terrain each sits on, its campaign phasing, a falsifiable success indicator, and the controls that assess it.

ASOM-Fed v6.1 · Unclassified / Illustrative · agency-agnostic reference framework · built from public sources only

154 techniques occupying 77 terrain×form cells. The interactive matrix presents the same data as a scoreable board.

M1 · 15 techniques

IDTechniqueGroundPhasesWhat it doesSuccess indicatorAssessed by
M1.01External Attack Surface EnumerationT30,IContinuously enumerate everything the agency exposes to the internet, from the outside in, on the same cadence an adversary would.New exposure appears in the terrain register before it appears in an alert.TM-1, TM-6, KT-3
M1.02Shadow and Forgotten Asset DiscoveryT30Reconcile discovered internet-facing assets against the authoritative inventory and drive the difference to zero.The unreconciled-asset count trends to zero and stays there.TM-1, TM-6, TM-7, FO-3, DV-1
M1.03Certificate and Domain WatchT30,IWatch certificate transparency and registration feeds for lookalike domains and unsanctioned certificates issued in the agency name.Impersonation infrastructure is identified while it is still being staged.TM-1, KT-3
M1.04Perimeter Canary TokensT50,ISeed uniquely identifying tokens in externally reachable surfaces so that reconnaissance touching them is unambiguous.A token fires before any production system records the actor.KT-3, CE-2
M1.05Authentication Geography BaselineT10,IIBaseline where, when and from what the population legitimately authenticates, so deviation is measurable rather than anecdotal.Account-takeover precursors are detected on deviation, not on damage.CE-2, TA-1
M1.06Credential Exposure MonitoringT10,IMonitor public and criminal sources for agency credentials, session artifacts and tokens offered for sale or dumped.Exposed credentials are invalidated before they are used against the estate.CE-2, TA-4
M1.07Partner and Advisory IntakeTX0,IOperate a named, timed intake path for CISA, sector and law-enforcement reporting that ends in a decision rather than a mailbox.Every advisory reaches a disposition within its stated intake window.CE-2, CG-4
M1.08Public Service Abuse TelemetryT40,IIInstrument public-facing services for abuse patterns — enumeration, scripted submission, credential stuffing — distinct from application errors.Abuse is distinguished from load, and named, before it becomes an incident.CE-2, TA-1, EN-1
M1.09Supply Chain and Vendor WatchTX0Track the security posture and incident disclosures of vendors and integrators whose products sit on key terrain.A vendor compromise reaches the terrain owner before it reaches the news.TM-7, CG-5
M1.10Named-Campaign Indicator WatchTX0,IMaintain standing collection against the specific campaigns the intelligence requirements name, not against indicators in general.Every priority intelligence requirement has live collection against it.CE-2, CE-3
M1.11Operational Technology Asset DiscoveryT60Discover control-system assets passively, because active scanning of a safety-instrumented network is itself an availability risk.The OT inventory is built without a scan-induced outage.TM-1, TM-2, FO-4
M1.12Workforce Credential Exposure MonitoringT70,IWatch the outside world for agency credentials and staff identities appearing where they should not, on the same cadence you watch the network perimeter.Exposed staff credentials are found and revoked before they are used.WF-1, WF-2, TM-6
M1.13Physical Access Anomaly DetectionT80,IIRead badge and access-control telemetry as an intelligence source rather than an audit artifact, and correlate it with logical access.Impossible-travel and after-hours physical anomalies raise a finding.FC-1, FC-2, CE-3
M1.14Supplier Exposure MonitoringT90,IMonitor the suppliers and components that reach into the estate for breach disclosure, advisory and exposure, because their compromise is your compromise.A supplier incident reaches the agency from monitoring, not from the news.LC-1, LC-2, TM-6, FO-6
M1.15Device Estate DiscoveryT20Discover devices reaching the estate from the identity plane outward rather than from the management console, because the console can only report what it already manages.Devices authenticating to the estate but absent from the inventory trend to zero.TM-1, TM-6, DV-1

M2 · 18 techniques

IDTechniqueGroundPhasesWhat it doesSuccess indicatorAssessed by
M2.01Trust Zone ArchitectureT30Define trust zones that reflect real boundaries and assurance differences, and record which elements sit in which.Every element on the terrain resolves to exactly one declared zone.TM-4, TM-5
M2.02Policy Enforcement Point PlacementT30Place an enforcement point at every zone boundary so that crossing is a decision, not a route.No path reaches a higher-trust zone without transiting an enforcement point.TM-4, KT-2, ID-5
M2.03Crown-Jewel EnclaveT50,IIsolate the decisive data behind its own enforcement point, with its own authorization policy and its own telemetry.Reaching the data layer requires defeating controls nothing else shares.KT-1, KT-2
M2.04Independent Control RedundancyTX0Ensure the controls guarding key terrain fail independently — no shared agent, identity, console or vendor across a protection floor.No single control, credential or vendor failure exposes a decisive point.KT-2, KT-5
M2.05Endpoint Detection and Response CoverageT20Achieve and prove sensor coverage across the managed fleet, with unmanaged devices treated as a measured gap rather than an assumption.Coverage is reconciled to the inventory, not to the console.TM-2, TM-6, DV-1, DV-3
M2.06Device Posture GatingT20,IMake device health a precondition of access, so a compromised or non-compliant endpoint cannot spend a valid credential.Failing posture denies access rather than raising a ticket.KT-2, SM-2, DV-2
M2.07Web Application ProtectionT40Front public applications with request-level inspection tuned to the application, not to a generic ruleset.Application-layer attacks are stopped at the edge and counted.KT-2, SM-2
M2.08API Authorization EnforcementT40Enforce per-call authorization at an API gateway rather than trusting network position or a shared key.No API path authorizes on network location alone.KT-2, SM-2
M2.09Data-at-Rest Encryption and Key SeparationT50Encrypt decisive data with keys held outside the system that reads it, so storage compromise is not data compromise.Exfiltrating storage does not yield readable records.KT-2, TM-3, FO-2
M2.10Egress Data Loss PreventionT50,IIIInspect and constrain outbound movement of the record types the campaign exists to protect.Bulk movement of protected records is blocked or alerted at egress.KT-2, KT-5
M2.11Workload Hardening BaselineT20Hold servers, images and containers to a declared baseline, and treat drift from it as a finding.Baseline drift is detected on a stated cadence and dispositioned.TM-6, CG-4, DV-4
M2.12Secrets ManagementT40Remove long-lived secrets from code, images and configuration into brokered, rotated, audited storage.No decisive system authenticates with a static embedded secret.KT-2, SM-3, ID-2
M2.13Backup Isolation and ImmutabilityT50,IVHold recovery data outside the blast radius of the production identity plane and make it immutable for its retention window.Recovery is possible after full compromise of production identity.KT-2, SM-5
M2.14Control Failure DetectionTX0Detect when a control stops working — sensor silent, policy unapplied, agent removed — as a security event in its own right.A silent control is detected in hours, not at the next assessment.SM-3, SM-6, CE-6, DV-3
M2.15Safety Instrumented Layer IntegrityT60Keep the safety layer independent of the control layer, so a compromise of operations cannot defeat the function that prevents harm.Safety functions hold when the control network is assumed hostile.KT-2, FO-4
M2.16Role-Based Privilege MinimizationT70Give each role the least authority its work requires, so a compromised person yields the least ground.No role holds authority its documented duties do not require.WF-2, WF-3
M2.17Facility Defense in DepthT80Layer physical controls so that defeating one barrier does not deliver the floor, the rack or the media inside it.Reaching a decisive asset physically requires defeating three independent controls.FC-2, FC-1
M2.18Component Provenance VerificationT90Know what is inside what you deploy, and verify it came from who it claims, before it runs on your ground.Every deployed component resolves to a verified origin and a current inventory.LC-2, LC-4

M3 · 20 techniques

IDTechniqueGroundPhasesWhat it doesSuccess indicatorAssessed by
M3.01Phishing-Resistant AuthenticationT10,IMove the population to authenticators that cannot be relayed or replayed by a proxy.Credential phishing yields no usable authentication.KT-2, SM-2, ID-2, ID-3
M3.02Conditional Access Policy EngineT10,IConcentrate access decisions in one policy decision point that sees identity, device, network and behavior together.Access decisions are made in one place and are inspectable.KT-1, SM-2, ID-1
M3.03Continuous AuthorizationT10,IIRe-evaluate authorization during a session on changed signal, rather than only at sign-in.A session that becomes risky is downgraded mid-flight.SM-2, TA-4, ID-5
M3.04Just-in-Time PrivilegeT10,IGrant privilege for a bounded task and window, with the grant itself recorded as an event.Standing privileged sessions approach zero.KT-2, SM-2
M3.05Privileged Access WorkstationsT20,IRequire administration of decisive systems from dedicated, hardened, separately governed endpoints.No decisive system is administered from a general-purpose desktop.KT-2, TM-2, DV-2
M3.06Machine and Service Identity GovernanceT10Give non-human identities owners, expiry and scope on the same terms as human ones.Every service account has a named owner and an expiry date.TM-7, SM-3, ID-2
M3.07Standing Privilege EliminationT10,ISystematically remove permanent administrative rights, replacing them with request-and-grant paths.Permanent privileged entitlements trend to a declared floor.KT-2, SM-3
M3.08Identity Lifecycle EnforcementT10Bind joiner, mover and leaver events to authoritative sources so access follows the person, not the ticket.Departure removes access within the stated interval, provably.SM-3, TM-6
M3.09External-User Identity AssuranceT10,IApply proportionate identity assurance to public and partner users of mission services without denying access to the public.Account takeover of external users falls while service access holds.KT-2, SM-2, ID-3
M3.10Device-Bound CredentialsT20,IBind credentials cryptographically to hardware so that stolen material cannot be spent elsewhere.Exported credential material is unusable off its device.KT-2, SM-2, ID-2, DV-2
M3.11Session and Token Revocation PathT10,IIIMaintain a tested path to invalidate sessions and tokens estate-wide within a stated interval.Revocation completes inside the interval the rules of engagement assume.TA-4, TA-1, ID-4
M3.12Authorization Policy as CodeT10Express access policy as reviewed, version-controlled, testable code rather than console state.Policy change is reviewable and revertible like any other change.SM-2, SM-3, ID-5
M3.13Federation Trust Boundary ControlT10,IEnumerate every federated trust into the estate, own each one, and constrain what it may assert.Every inbound trust has an owner, a scope and a suspension path.TM-5, CG-5, ID-1
M3.14Entitlement RecertificationT10Review entitlements on a cadence against actual use, and remove what is not used.Unused entitlements are removed rather than recertified.SM-3, CG-4
M3.15Break-Glass Account ControlT10,IVHold emergency accounts under split control with alerting on any use, so the last resort is not the soft target.Break-glass use is always deliberate and always noticed.KT-2, CG-3
M3.16Token Replay ProtectionT10,IIBind issued tokens to sender and context so a captured token cannot be replayed from elsewhere.Replayed tokens fail outside their issuing context.SM-2, KT-5, ID-4
M3.17Authentication Anomaly ScoringT10,IIScore authentication against the behavioral baseline and feed the score back into the policy decision point.Anomalous authentication changes the access decision automatically.CE-2, SM-2, ID-3
M3.18Identity Provider Tamper DetectionT10,IIITreat the identity provider as decisive terrain: alert on federation, policy, key and admin changes independently of the provider itself.Changes to the identity plane are detected out-of-band.KT-1, CE-2, ID-1, ID-5
M3.19Human-to-Account BindingT70,IBind every privileged account to a named, current, cleared human, so an orphaned credential has nowhere to hide.No privileged account exists without a named accountable holder.WF-2, WF-5
M3.20Supplier Identity FederationT90,IBring supplier access under the agency's own identity plane rather than standing local accounts the agency cannot see or revoke.Supplier access is revocable by the agency in one action.LC-3, WF-2

M4 · 17 techniques

IDTechniqueGroundPhasesWhat it doesSuccess indicatorAssessed by
M4.01MicrosegmentationT30,IReduce reachability between workloads to what is declared, so lateral movement requires defeating policy rather than finding a route.Reachable-neighbor counts fall against a declared target.TM-4, KT-5
M4.02East-West Deny by DefaultT30,IMake the default answer between segments "no", with exceptions declared, owned and expiring.New east-west paths exist only where they are declared.TM-5, KT-5
M4.03Egress Filtering and Allow-ListingT30,IConstrain outbound destinations so command channels must use paths you inspect.Outbound connections resolve to an allow-listed destination or fail.KT-5, TM-5
M4.04DNS Control and SinkholingT30,IRoute resolution through controlled resolvers, log it, and sinkhole known-bad and newly registered domains.Resolution to staged infrastructure fails and alerts.KT-5, CE-2
M4.05Application Allow-ListingT20,IConstrain what may execute on decisive endpoints to what is approved and signed.Unapproved executables do not run on decisive endpoints.KT-2, TM-2, DV-4
M4.06Administrative Path RestrictionT30,IConfine administrative protocols to declared corridors from declared sources.Administrative access from outside the corridor fails and alerts.TM-5, KT-2
M4.07Cloud Boundary EnforcementT30Enforce account, VPC and role boundaries in the cloud with the same rigor as network segments on the ground.Cross-account reachability matches the declared design exactly.TM-4, TM-5
M4.08Instrumented Corridor DesignT3I,IIDeliberately leave the paths you want an adversary to take, and instrument them heavily.Observed lateral attempts land in instrumented segments.KT-5, CE-2
M4.09Removable Media ControlT20Constrain and log removable media on endpoints holding or reaching decisive data.Media use on decisive endpoints is either denied or recorded.KT-2, TM-2, DV-5
M4.10Bastion and Jump-Host EnforcementT30,IForce privileged access to decisive systems through recorded, brokered hosts.Privileged sessions to decisive systems are recorded without exception.KT-2, CG-3
M4.11Protocol and Port RestrictionT30Permit only the protocols the design requires, and treat the rest as a canalization opportunity.Non-design protocols are denied at the boundary and counted.TM-5, KT-5
M4.12Denied-Path Register EnforcementT30Maintain the explicit register of paths that must never exist, and test continuously that they do not.Every denied path is tested on a stated cadence and holds.TM-5, SM-6
M4.13Operational Technology SegregationT60,ISeparate control-system networks from the enterprise with an enforced, inspectable boundary rather than a documented intention.No route exists from an office endpoint to a controller without transiting an enforcement point.TM-4, KT-5, FO-4
M4.14Control Protocol ConstraintT60,IPermit only the industrial protocols and function codes the process requires, and deny engineering commands from outside the corridor.Write and program commands originate only from declared engineering stations.KT-5, FO-4
M4.15Physical Zone SegregationT80,IDivide facilities into zones whose boundaries are enforced and logged, so physical movement is as canalised as network movement.Movement between physical zones is enforced and recorded.FC-2, FC-1
M4.16Maintenance Access ConstraintT8I,IIForce vendor and remote maintenance onto a supervised, time-boxed path instead of standing access into the estate.No maintenance path is available outside an approved, supervised window.FC-3, LC-3
M4.17Supplier Access CanalisationT9I,IIRoute every supplier into a defined broker rather than directly onto mission systems, so their traffic crosses ground you instrument.No supplier reaches a mission system except through the brokered path.LC-3, TM-5

M5 · 13 techniques

IDTechniqueGroundPhasesWhat it doesSuccess indicatorAssessed by
M5.01Decoy Records in the Data LayerT5I,IISeed the record stores with realistic decoy records whose only purpose is to be accessed by someone who should not.Access to a decoy produces a high-confidence detection with no false-positive tail.KT-2, CE-2, SM-7
M5.02Honeytokens in Document StoresT5I,IIPlace tokenized documents in collaboration and file estate where staged collection would find them.Staging for exfiltration is detected during collection, not after.CE-2, TA-1, SM-7
M5.03Decoy CredentialsT1I,IISeed credential stores, memory and configuration with credentials that are valid-looking and monitored but powerless.Credential harvesting is detected on use of a planted credential.CE-2, KT-4, FO-1, SM-7, ID-2
M5.04Honeypot Services in CorridorsT3I,IIPlace responsive services in the lateral corridors so that scanning and movement produce contact rather than silence.Lateral reconnaissance produces an alert on first contact.KT-5, CE-2, SM-7
M5.05Canary Files on EndpointsT2I,IIDistribute monitored files across the endpoint fleet to detect mass encryption and mass collection early.Mass file operations are detected within the first affected hosts.CE-2, TA-1, SM-7
M5.06Decoy Service EndpointsT4I,IIPublish plausible but unused API and administrative endpoints that only enumeration would find.Enumeration of the application surface produces contact.CE-2, KT-3, SM-7
M5.07Identity-Plane DeceptionT1I,IIPlant privileged-looking accounts and group memberships that no legitimate process ever touches.Directory reconnaissance is detected at the enumeration stage.CE-2, KT-4, SM-7
M5.08Decoy Cloud ResourcesT4I,IIStand up monitored buckets, roles and secrets that legitimate workloads never call.Cloud credential abuse is detected on first exploratory call.CE-2, KT-4, SM-7
M5.09Deception Alert RoutingTXI,IIIRoute deception alerts on a separate, high-trust path that bypasses ordinary triage queues.Deception alerts reach a decision-maker without queueing.CE-3, TA-4, SM-7, EN-1
M5.10Deception Coverage MeasurementT50,IMeasure what share of the data layer is actually seeded, and treat the unseeded remainder as a gap.Deception coverage is a reported number, not an impression.CE-4, SM-6, SM-7
M5.11Control Network DeceptionT6I,IIPlace decoy controllers and engineering workstations on the control network, where legitimate traffic is narrow and predictable.Any interaction with a decoy controller is unambiguous.CE-2, FO-4, SM-7
M5.12Phishing Deception and ReportingT70,IExercise the workforce against realistic lures and treat the reporting rate, not the click rate, as the measure that matters.Reporting rate exceeds click rate and the first report arrives within minutes.WF-3, CE-2, SM-7
M5.13Physical DeceptionT8ISeed facilities with tokens whose only plausible use is by someone who should not have them — dropped media, decoy badges, decoy racks.Physical decoy interaction produces findings with no false-positive tail.FC-1, CE-3, SM-7

M6 · 10 techniques

IDTechniqueGroundPhasesWhat it doesSuccess indicatorAssessed by
M6.01Adaptive Rate LimitingT4II,IIISlow request rates as risk rises, so automation loses its advantage while humans keep service.Automated abuse degrades while legitimate service holds.TA-5, SM-2
M6.02Step-Up Authentication on AnomalyT1II,IIIDemand stronger proof at the moment behavior deviates, rather than uniformly at sign-in.Anomalous sessions must re-prove before continuing.SM-2, TA-4, ID-3
M6.03Bulk Export ThrottlingT5II,IIICap the rate and volume of bulk retrieval so a successful intrusion cannot become a successful exfiltration in one pass.Bulk collection takes long enough to be detected and stopped.KT-2, TA-5
M6.04Session Duration Reduction Under AlertT1II,IIIShorten session and token lifetimes automatically while the estate is in contact.Session lifetimes contract on phase change without an outage.TA-4, CG-2, ID-4
M6.05Approval Gates on High-Impact ActionsTXII,IIIRequire a second, human authorization for the small set of actions that would be decisive if abused.Decisive actions cannot be completed by one compromised identity.CG-3, TA-4, EN-4
M6.06Tarpitting and Response DelayT3IIIntroduce deliberate latency on suspicious paths, so an adversary spends time you are spending on decision.Adversary tempo drops below defender decision tempo.TA-1, TA-5
M6.07Progressive LockoutT1IIEscalate friction against an identity under attack without handing an attacker a denial-of-service lever.Guessing is defeated without locking the population out.SM-2, TA-5
M6.08Change and Deploy Freeze Under ContactT4IIISuspend routine change into decisive systems while in contact, so the adversary cannot hide in the noise of normal deployment.Change into decisive systems stops on phase declaration.CG-2, TA-5
M6.09Query Complexity LimitsT4II,IIIBound the cost and breadth of a single query against mission data stores.No single query can enumerate the corpus.KT-2, TA-5
M6.10Update Staging and SoakT9II,IIIHold vendor updates in a staging ring long enough to observe them, trading a little currency for the ability to not deploy a compromised build estate-wide.No supplier update reaches the whole estate without a stated soak period.LC-4, LC-2

M7 · 17 techniques

IDTechniqueGroundPhasesWhat it doesSuccess indicatorAssessed by
M7.01Hypothesis-Driven HuntingTXII,IIIHunt against stated hypotheses drawn from the intelligence requirements, not against whatever the queue surfaced.Every hunt traces to a priority intelligence requirement.CE-2, CE-3
M7.02Fusion-Fed Hunt BacklogTXII,IIIConvert fused assessments into a ranked, worked hunt backlog with explicit confidence on each entry.Fusion output becomes hunt work rather than a report.CE-3, CE-5, EN-1
M7.03Automated Containment PlaybooksTXIIIEncode containment as tested automation so the decision, not the execution, is the slow step.Containment executes in seconds once the decision is made.TA-4, SM-5, EN-4
M7.04Host Isolation on ConfirmationT2IIISever a host from the network on confirmed compromise while preserving it for analysis.Confirmed hosts are isolated inside the stated interval.TA-4, TA-1, SM-4
M7.05Credential Reset SweepT1IIIExecute a scoped, ordered reset of credentials and tokens across the compromised blast radius.The reset completes without leaving a re-entry credential.TA-4, SM-5
M7.06Build Pipeline Integrity HuntT4IIIHunt the build pipeline specifically, because poisoning it envelops everything downstream.Pipeline integrity is verified rather than assumed after contact.KT-1, SM-6
M7.07Persistence SweepT2III,IVSweep systematically for persistence across identity, endpoint, cloud and application layers before declaring eradication.Eradication is declared on evidence across every layer.SM-6, CG-4, EN-5
M7.08Lateral Path AuditT3II,IIIRecompute what the adversary could reach from where they stand, and close the paths ahead of them.Reachability from the foothold is reduced during the engagement.KT-4, KT-5
M7.09Detection Engineering from HuntTXIII,VConvert every hunt finding into a durable detection with an owner and a test.No hunt finding is left as tribal knowledge.SM-6, CE-5
M7.10Purple-Team ValidationTX0,VTest whether each emplaced maneuver actually performs, using the cell success indicator as the pass condition.Every claimed maneuver has been demonstrated, not asserted.SM-6, CE-4
M7.11Eviction SequencingTXIIIPlan eviction as a single sequenced action, so the adversary cannot re-enter through what is evicted last.Eviction happens once, not in rounds.SM-5, TA-3, EN-5
M7.12Adversary Dwell ReconstructionTXIII,IVReconstruct how long the adversary held the ground, so temporal advantage is computed rather than estimated.Dwell is measured from evidence for every engagement.TA-2, CE-6, EN-2
M7.13Hunt Coverage AccountingTXVTrack which terrain has been hunted, how recently, and against which hypotheses.Unhunted terrain is visible and dispositioned.CE-4, CE-6
M7.14Process Anomaly HuntingT6II,IIIHunt for deviation in the physical process itself, not only in the network, because a competent adversary will look correct on the wire.Process behavior outside its engineering envelope is investigated as a security event.CE-2, FO-4
M7.15Insider Risk InvestigationT7IIIRun a defined, rights-respecting process to resolve an insider indication, rather than improvising one under pressure.Insider indications reach a documented disposition within a stated period.WF-4, CG-4
M7.16Supply Chain Compromise HuntingT9IIIHunt for the specific behaviors a compromised supplier or component would produce, on the assumption that it is already inside.Supplier-origin behaviors are hunted on a stated cadence, not only on advisory.LC-2, LC-4, CE-2
M7.17Malicious Message EvictionT4IIIRemove a delivered malicious message from every mailbox it reached, including forwards and delegated copies, rather than only from the originally reported one.A reported message is removed estate-wide, not only where it was reported.EN-5, TA-4, DV-3

M8 · 17 techniques

IDTechniqueGroundPhasesWhat it doesSuccess indicatorAssessed by
M8.01Automated Segment SeveringT3IIIHold a tested capability to sever a segment or zone on decision, without an unplanned outage of everything else.A zone can be severed inside the interval the plan assumes.TA-4, SM-5, EN-4
M8.02Estate-Wide Session RevocationT1IIIInvalidate every session and token across the estate as one action when the identity plane is in doubt.Estate-wide revocation is exercised and timed, not theoretical.TA-4, SM-5, ID-4
M8.03Read-Only Service DegradationT4III,IVDegrade mission services to read-only or queued operation rather than exposing or losing the corpus.Service degrades gracefully instead of failing open or dark.SM-5, TA-5
M8.04Fail-Secure Default PostureTX0,IIIEnsure that when a control fails, the estate denies rather than permits — including under load and during recovery.Control failure denies access rather than bypassing the control.KT-2, CG-3
M8.05Federation Trust SuspensionT1IIISuspend an inbound federated trust independently, without dismantling the identity plane around it.A compromised trust is suspended without an estate outage.TM-5, TA-4
M8.06Cloud Account QuarantineT4IIIQuarantine a cloud account or subscription — revoking roles and cutting peering — as one rehearsed action.A cloud account is isolated inside the stated interval.TA-4, TM-4
M8.07Egress BlackholeT3IIICut outbound reachability for a defined scope to stop exfiltration and command channels while analysis continues.Exfiltration stops without severing the whole estate.KT-5, TA-4
M8.08Statutory Availability FloorTXIII,IVDeclare in advance which mission functions may never be taken offline, and design containment around them.Containment never breaches the declared availability floor.CG-1, CG-3
M8.09Contained Forensic PreservationT5III,IVPreserve evidence in a way that survives containment and recovery, on storage the adversary could not reach.Evidence survives the response intact and admissible.KT-2, CE-6, EN-3
M8.10Third-Party Connection CutoutT3IIICut a specific partner or vendor connection on decision without taking down the shared boundary.A single external connection can be cut in isolation.TM-5, CG-5
M8.11Restoration PreconditionsTXIVDefine what must be true before anything comes back — no restoration on hope.Nothing is restored until its preconditions are evidenced.SM-5, CG-4, EN-5
M8.12Degradation RehearsalTX0,IVRehearse degradation and severing on the real estate, because an untested retrograde is a plan, not a capability.Every severing action has been exercised within its stated period.SM-6, CE-1
M8.13Safe-State IsolationT6IIISever the control network to a defined safe state that preserves the physical process, rather than a network state that abandons it.Isolation leaves the process safe, not merely disconnected.SM-5, FO-4, RC-1
M8.14Rapid Offboarding and RevocationT7III,IVRemove all access from a departing or suspended person in one action, in a time measured against the tempo an insider needs.Full revocation completes within the stated tempo, evidenced by exercise.WF-5, TA-1, DV-5
M8.15Facility IsolationT8IIIBe able to sever a building or floor from the estate without severing the mission, and know in advance what that costs.A facility can be isolated on a rehearsed procedure without an unplanned outage.FC-2, FC-4, SM-5
M8.16Supplier SeveranceT9III,IVBe able to cut a supplier's access immediately and continue the mission, because the alternative is negotiating with an intrusion.A supplier can be severed within a stated period without halting the mission.LC-5, SM-5
M8.17Device Decommissioning and SanitizationT20,VRemove a retired, lost or reassigned device from the estate's trust and sanitize its media within a period derived from what its retained trust could do.No device holds estate trust without a current accountable holder.DV-5, WF-5, TM-7

M9 · 9 techniques

IDTechniqueGroundPhasesWhat it doesSuccess indicatorAssessed by
M9.01Advisory-Driven Pre-BlockingTX0,IBlock infrastructure named in partner reporting before it is used against you, on a stated clock.Named infrastructure is blocked within the intake window.CE-2, TA-4
M9.02Targeted Emergency PatchingT40,IPatch out of cycle when intelligence — not the calendar — says a specific weakness is being used now.Actively exploited weaknesses are closed ahead of the routine cycle.CE-5, CG-4
M9.03Staged Infrastructure DenialT30,IDeny resolution and reachability to infrastructure observed staging against the sector, not only against you.Sector-staged infrastructure never reaches an avenue of approach.KT-3, CE-2
M9.04Sector Intelligence ExchangeTX0,VContribute and consume in the sector and federal exchanges so pre-emption is possible at all.The agency both receives and contributes actionable reporting.CE-7, CG-5, EN-6
M9.05Pre-Emptive Credential InvalidationT10,IInvalidate credentials on exposure intelligence, before misuse, accepting the friction.Exposed credentials are dead before they are tried.TA-4, CE-2
M9.06Vendor Compromise ResponseTX0,IHold a rehearsed path to constrain a compromised vendor or integrator connection on disclosure.A vendor disclosure produces a constraint, not a meeting.CG-5, TM-5
M9.07Exploited-Vulnerability Catalog EnforcementT40Treat authoritative known-exploited catalogs as a directive with an owner and a due date on the terrain register.Catalog entries are closed on their due dates, with exceptions owned.CE-5, CG-4
M9.08Workforce Threat BriefingT70,ITell the workforce what is actually being attempted against agencies like yours, so recognition happens before the click.Briefings cite current campaigns and reach the roles those campaigns target.WF-3, CE-2
M9.09Supplier Advisory Pre-emptionT90,IAct on supplier and component advisories before exploitation reaches you, including by staging the update or constraining the access.Advisories affecting named suppliers are dispositioned within the stated window.LC-1, LC-4, CE-2

M10 · 7 techniques

IDTechniqueGroundPhasesWhat it doesSuccess indicatorAssessed by
M10.01Indicator-to-Detection ConversionTXIV,VConvert every indicator observed in contact into a durable, tested detection rather than a one-time block.Contact leaves behind detection, not just a blocklist entry.SM-6, CE-5
M10.02Avenue Closure VerificationTXIV,VVerify by test that the avenue actually used is closed — not that a change was made.The used avenue fails a deliberate re-test.SM-6, CE-4, EN-2
M10.03Terrain Overlay UpdateTXVUpdate the terrain overlay with what contact revealed, including everything the map got wrong.The overlay reflects the estate as contact proved it to be.TM-1, TM-6, EN-2
M10.04Intelligence Requirement RevisionTXVRevise the priority intelligence requirements from what the engagement showed you could not see.Requirements change after contact rather than persisting by inertia.CE-2, CE-6, EN-2
M10.05Community ReportingTXVReport to CISA and sector partners so the next agency starts from your contact.Findings are shared within the stated reporting window.CE-7, CG-5, EN-6
M10.06Doctrine and Catalog UpdateTXVFold what was learned back into the maneuver catalog, the control set and the rules of engagement.Each engagement changes the doctrine that governs the next.SM-1, CG-3
M10.07Supply Chain Lesson PropagationT9VFeed what a supplier incident taught you back into acquisition and into the terrain register, so the next contract starts from it.Supplier incidents change the acquisition record, not only the ticket.LC-1, CG-5, TM-1

M11 · 11 techniques

IDTechniqueGroundPhasesWhat it doesSuccess indicatorAssessed by
M11.01Recovery Objective DeclarationT40Declare, per mission service, how quickly it must return and how much data loss is survivable — before an incident forces the answer.Every mission service has a stated recovery objective its owner has signed.RC-1, FO-5, FO-7
M11.02Isolated Recovery EnvironmentT50,IVHold the means of recovery outside the blast radius of the production identity plane, so compromise cannot reach what rebuilds you.Recovery is possible after total compromise of production identity.RC-2, KT-2
M11.03Golden Image and Rebuild PathT20,IVMaintain a trusted, tested build path so rebuilding is a procedure rather than an improvisation under pressure.A decisive system can be rebuilt from trusted media within its recovery objective.RC-3, DV-5
M11.04Identity Plane ReconstitutionT1IVRehearse rebuilding the identity plane itself, the one system every other recovery depends on.The identity plane can be re-established without trusting the compromised one.RC-3, KT-1, ID-1
M11.05Recovery Data Integrity VerificationT5IVProve restored data is what it was before contact, rather than restoring the adversary's edits along with it.Restored records are verified against an independent integrity record.RC-4
M11.06Service Restoration SequencingT4IV,VRestore in a declared order that respects dependency and statutory priority, so the first service back is the one that must be.Restoration follows the declared sequence under exercise conditions.RC-1, RC-5, FO-5, FO-7
M11.07Reconstitution ExerciseTX0,VExercise recovery against a real failure scenario on a stated cadence, because an untested recovery plan is a document.Every recovery objective has been demonstrated within its stated period.RC-5, CE-1
M11.08Key Personnel ContinuityT70,VName the roles without which recovery cannot proceed, and make sure none of them is one person deep.Every recovery-critical role has a rehearsed alternate.WF-1, RC-5
M11.09Alternate Facility ActivationT8IV,VBe able to run the mission from somewhere else, and prove it by doing so rather than by documenting it.The alternate facility has carried the mission within its stated period.FC-4, RC-1, RC-5
M11.10Supplier-Independent RebuildT9IVEnsure recovery does not depend on the availability or the integrity of the supplier who may be the reason you are recovering.A decisive system can be rebuilt without supplier assistance.LC-5, RC-3
M11.11Mailbox and Message RestorationT4IV,VRestore mailboxes and messages removed during eviction or lost in the incident, verified against an integrity record, before returning the service to use.Legitimate messages removed during response are restored and verified.RC-4, EN-5, RC-3