Two Hunts, Traced Beat by Beat.
A framework that cannot be shown working is a taxonomy. These are two complete hunts against the Federal Reference Agency — one that starts from a written hypothesis and one that starts from contact — recorded in the framework’s own identifiers, 79 beats between them, including the beats where it went wrong.
Both cases are modeled, not reported. They run against the Federal Reference Agency, a composite estate assembled from public doctrine and the published agency archetypes. Nothing here describes an event at a named agency, and no number on these pages is a measurement anybody earned. What is real is the machinery: every control, technique, terrain layer, product and requirement a beat cites resolves against the published data, and a citation that does not resolve fails the build.
A Record Written in the Framework’s Own Identifiers.
These are not narratives with citations bolted on afterwards. Each beat is a typed record, and every identifier in it is validated against the published data before the site will build.
A record, not a narrative
Every beat is a typed record that cites the machinery it exercised: the cycle step it sat in, the campaign phase, the form of maneuver, the techniques, the governing controls, the terrain touched, the role that acted, the products consumed and produced, and the authority it ran under. The identifiers are links because a claim you can follow is a claim you can check.
The reference agency, never a real one
Both cases run against the Federal Reference Agency — a composite estate built from public doctrine and the published agency archetypes. No beat depicts an event at a named agency, and no figure here is an incident anybody suffered.
What each beat did not settle
Every beat carries a required field saying what it failed to establish. It is the most important field in the model: real defensive work is mostly the accumulation of things you have ruled out, and a hunt narrative in which every step confirms the last is marketing.
Failures point at the doctrine
Both cases depict things going wrong. Where they do, the beat points at the framework’s own published prediction of that failure — a control’s stated failure mode, a cycle step’s, a maneuver’s. A novel failure the doctrine never anticipated would be a finding about the doctrine, not a story beat.
One Starts from a Question. One Starts from Contact.
The difference is not volume or urgency. It is where the hunt enters the loop, and everything else — which forms of maneuver it can use, what its authority costs, what a good outcome even looks like — follows from that.
Two changes landed on the same ground in one change window: a record-read path moved behind a new API gateway, and a partner federation was added to the identity plane. Neither was an incident and neither generated an alert. What they did was invalidate a denied path that last cycle’s headline map finding depended on — a denial asserted from a configuration export and never once reconciled against telemetry. The cycle commissioned a hunt against a hypothesis rather than against an adversary, ran it across the nineteen days from commissioning to brief, and found nobody. What it produced instead is a bounded statement of cleared ground, one control failure it was not looking for, and a precise account of the three avenues nobody in this program has searched in four cycles.
What started it: No alert. A terrain change plus an assumption somebody was willing to write down: that a denied path nobody had tested was still holding after the ground on both sides of it moved.
- Read the case
- PCIR-12
- PCIR-11
- PCIR-05
- PCIR-14
- PCIR-16
A decoy record in the financial and personally-identifiable data partition was read at 02:14 by a machine identity belonging to the bulk-data service, and the alert sat in the general triage queue until the day shift opened it five and a half hours later. What followed was not a hunt in the sense the proactive case uses the word: the hypothesis was written after the first observation, the loop was entered at Maneuver with the three preceding steps skipped, and the dominant form turned out to be isolation rather than counterattack — because the only revocation path available for the compromised identity also degraded a public service with a statutory obligation behind it. The case turns on the same decision taken three times under three different authorities: observe, and buy intelligence at the price of continued exposure, or evict, and act on an estate you have not finished mapping. The second time, nobody got to take it: a platform engineer reset the credential in good faith and out of sequence, and thirty-five minutes later a dormant partner identity nobody had been watching resumed collection somewhere else.
What started it: A decoy record read at 02:14 by a machine identity — contact, arriving as one high-confidence alert into a queue that had no way to treat it differently from a failed login.
- Read the case
- PCIR-09
- PCIR-13
- PCIR-19
- PCIR-20
- PCIR-22
What Makes a Hunt Proactive Is Not Enthusiasm.
“Proactive” and “reactive” are used loosely enough in this industry to mean nothing. Every field below is decidable, and both cases are asserted against it — a case that drifts into the other posture’s shape fails the build rather than quietly becoming the same story twice.
Proactive hunt
Enters at frame or map · Phases 0, I · shaping
- What drives it
- An intelligence requirement, a terrain change, or an assumption somebody is willing to write down and then try to falsify. Never an alert — a hunt that starts from an alert is a triage queue with a better name.
- What it typically produces
- A negative result with a stated bound, plus one or two control findings that have nothing to do with the hypothesis. The control findings are the ordinary yield; the negative is the deliverable.
- How its authority behaves
- Most of what a proactive hunt does is observation, and observation needs no authority. The escalations it does incur are for collection that crosses a boundary — a partner federation, a supplier tenancy, a privacy holding — and they are escalations nobody is under pressure about, which makes them the cheapest possible place to measure approval latency.
- How it characteristically fails
- It drifts toward whatever telemetry is pleasant to query, produces a confident-sounding nothing, and files it as coverage. The hunt that finds nothing and does not say what it searched is indistinguishable from the hunt that was never run.
Reactive hunt
Enters at maneuver or fuse · Phases II, III, IV · contact, consolidation
- What drives it
- Contact. A detection, a decoy interaction, a partner notification, or a report from outside the agency. The hypothesis is written after the first observation rather than before it, and that ordering is the whole difference.
- What it typically produces
- A scoped intrusion, an eviction sequence, and a dwell reconstruction. Its negative results are narrower and more urgent: which hosts are NOT in scope is the finding that lets containment stop somewhere.
- How its authority behaves
- Almost everything it does touches production, so the pre-authorized set is what decides its tempo. Every action outside that set is priced in minutes of adversary dwell, and the sum of those minutes is the case against a narrow set.
- How it characteristically fails
- It closes the ticket. Eviction is declared on the absence of new alerts, the avenue is never verified closed, and the indicators never become detections — so the next occurrence costs the same manual effort as the first.
Counted off the Beats, Not Asserted.
Every value in this table is computed from the two cases as they stand. If an edit ever pushed one case into the other’s shape, the row that measures it would say so here rather than staying quietly wrong.
| Measured | Proactive hunt | Reactive hunt |
|---|---|---|
| What started itThe sharpest distinction, and the one every other row follows from. | No alert. A terrain change plus an assumption somebody was willing to write down: that a denied path nobody had tested was still holding after the ground on both sides of it moved. | A decoy record read at 02:14 by a machine identity — contact, arriving as one high-confidence alert into a queue that had no way to treat it differently from a failed login. |
| Where it enters the loopA hunt that enters at Maneuver has skipped the three steps that would have told it what it was looking at. Sometimes correctly — contact does not wait. | Map | Maneuver |
| Phases traversedProactive work is Phase 0 and I. Reactive work is where the campaign phases were written for. | 0 → I | II → III → IV |
| Leading form of maneuverCounted from the beats, not declared. If the two ever converge, one of the cases has drifted into the other’s shape. | M1 Screen / Guard | M8 Isolation / Retrograde |
| Where the maneuver sitsShaping forms are emplaced on ground of your choosing on your own timeline. Contact forms trade something for time. | shaping | contact |
| Beats, of which in the hunt bandThe surrounding cycle work is in both cases on purpose. Conflating the band with the hunt is how a program comes to believe hunting is a standalone activity. | 40, of which 26 | 39, of which 25 |
| Elapsed, first beat to lastMeasured between beat clocks. The difference here is most of what "tempo" means in practice. | 32d 22h 50m | 8d 12h 46m |
| Authority taxThe same measurement in both cases. Under contact it is priced in adversary dwell; out of contact it is nearly free, which is why it is worth measuring out of contact first. | 20h 40m over 2 | 8h 3m over 6 |
| Terrain layers touchedA hunt that touches two layers is a query. The spread is the honest measure of how much estate a case implicates. | 8 of 10 | 7 of 10 |
| Dominant forms of maneuverForms used at least half as often as the leader. A threshold rather than a top-three, because “the top three” reports three forms for a case that only ever seriously used one. | M1 Screen / Guard — 10 beatsM7 Counterattack — 9 beats | M8 Isolation / Retrograde — 9 beatsM7 Counterattack — 8 beatsM6 Delay — 5 beats |
| Where its requirements came fromBoth cases take the question and the decision verbatim from the published requirement library rather than restating them, so neither can end up answering a slightly different question than the cycle set. | 5 requirements, resolved from the published library.PCIR-12 · PCIR-11 · PCIR-05 · PCIR-14 · PCIR-16 | 5 requirements, resolved from the published library.PCIR-09 · PCIR-13 · PCIR-19 · PCIR-20 · PCIR-22 |
| Controls exercised, and the overlapCounted from the beats. The shared set is the intersection of the two citation indexes — computed, not curated, which is why it is worth anything as evidence that the spine is common. | 39 controls, of which 31 are also exercised by the other case.Reached only by this case: FC-1, FC-2, FO-3, FO-6, LC-1, LC-2, LC-4, TM-6. | 36 controls, of which 31 are also exercised by the other case.Reached only by this case: FO-1, FO-2, RC-1, RC-3, TM-2. |
| The temporal-advantage lineThe framework’s only effectiveness measure, and the one both cases decline to report as met. Located by metric name rather than by position, so a reordered scoreboard cannot silently swap the row. | Not computedThe ratio needs a measured defender decision loop, and a cycle with no contact produces none. Reporting the threshold as met on an empty numerator was refused at Assess. | Defender loop 11h 38m; ratio not computedThe numerator is measured between beat clocks — decoy interaction to the first containment action that removed something. The denominator needs an adversary objective time, which requires the dwell reconstruction that was destroyed on day zero. |
| Failures the case owns up toEach one points at a failure mode the manual already publishes. A novel failure the doctrine never anticipated would be a finding about the doctrine rather than a story beat. | 4 at case level, 4 carried on individual beatsPredicted by 4 distinct published sources. | 5 at case level, 9 carried on individual beatsPredicted by 3 distinct published sources. |
What started it
The sharpest distinction, and the one every other row follows from.
- Proactive hunt
- No alert. A terrain change plus an assumption somebody was willing to write down: that a denied path nobody had tested was still holding after the ground on both sides of it moved.
- Reactive hunt
- A decoy record read at 02:14 by a machine identity — contact, arriving as one high-confidence alert into a queue that had no way to treat it differently from a failed login.
Where it enters the loop
A hunt that enters at Maneuver has skipped the three steps that would have told it what it was looking at. Sometimes correctly — contact does not wait.
- Proactive hunt
- Map
- Reactive hunt
- Maneuver
Phases traversed
Proactive work is Phase 0 and I. Reactive work is where the campaign phases were written for.
- Proactive hunt
- 0 → I
- Reactive hunt
- II → III → IV
Leading form of maneuver
Counted from the beats, not declared. If the two ever converge, one of the cases has drifted into the other’s shape.
- Proactive hunt
- M1 Screen / Guard
- Reactive hunt
- M8 Isolation / Retrograde
Where the maneuver sits
Shaping forms are emplaced on ground of your choosing on your own timeline. Contact forms trade something for time.
- Proactive hunt
- shaping
- Reactive hunt
- contact
Beats, of which in the hunt band
The surrounding cycle work is in both cases on purpose. Conflating the band with the hunt is how a program comes to believe hunting is a standalone activity.
- Proactive hunt
- 40, of which 26
- Reactive hunt
- 39, of which 25
Elapsed, first beat to last
Measured between beat clocks. The difference here is most of what "tempo" means in practice.
- Proactive hunt
- 32d 22h 50m
- Reactive hunt
- 8d 12h 46m
Authority tax
The same measurement in both cases. Under contact it is priced in adversary dwell; out of contact it is nearly free, which is why it is worth measuring out of contact first.
- Proactive hunt
- 20h 40m over 2
- Reactive hunt
- 8h 3m over 6
Terrain layers touched
A hunt that touches two layers is a query. The spread is the honest measure of how much estate a case implicates.
- Proactive hunt
- 8 of 10
- Reactive hunt
- 7 of 10
Dominant forms of maneuver
Forms used at least half as often as the leader. A threshold rather than a top-three, because “the top three” reports three forms for a case that only ever seriously used one.
- Proactive hunt
- M1 Screen / Guard — 10 beatsM7 Counterattack — 9 beats
- Reactive hunt
- M8 Isolation / Retrograde — 9 beatsM7 Counterattack — 8 beatsM6 Delay — 5 beats
Where its requirements came from
Both cases take the question and the decision verbatim from the published requirement library rather than restating them, so neither can end up answering a slightly different question than the cycle set.
Controls exercised, and the overlap
Counted from the beats. The shared set is the intersection of the two citation indexes — computed, not curated, which is why it is worth anything as evidence that the spine is common.
- Proactive hunt
- 39 controls, of which 31 are also exercised by the other case.Reached only by this case: FC-1, FC-2, FO-3, FO-6, LC-1, LC-2, LC-4, TM-6.
- Reactive hunt
- 36 controls, of which 31 are also exercised by the other case.Reached only by this case: FO-1, FO-2, RC-1, RC-3, TM-2.
The temporal-advantage line
The framework’s only effectiveness measure, and the one both cases decline to report as met. Located by metric name rather than by position, so a reordered scoreboard cannot silently swap the row.
- Proactive hunt
- Not computedThe ratio needs a measured defender decision loop, and a cycle with no contact produces none. Reporting the threshold as met on an empty numerator was refused at Assess.
- Reactive hunt
- Defender loop 11h 38m; ratio not computedThe numerator is measured between beat clocks — decoy interaction to the first containment action that removed something. The denominator needs an adversary objective time, which requires the dwell reconstruction that was destroyed on day zero.
Failures the case owns up to
Each one points at a failure mode the manual already publishes. A novel failure the doctrine never anticipated would be a finding about the doctrine rather than a story beat.
- Proactive hunt
- 4 at case level, 4 carried on individual beatsPredicted by 4 distinct published sources.
- Reactive hunt
- 5 at case level, 9 carried on individual beatsPredicted by 3 distinct published sources.
The shared spine. The two cases have no terrain, no adversary and no mission service in common, and they still land on 31 of the same controls: CE-1, CE-2, CE-3, CE-4, CE-5, CE-6, CE-7, CG-1, CG-2, CG-3, CG-4, CG-5, FO-5, KT-2, KT-3, KT-4, KT-5, LC-3, SM-2, SM-3, SM-4, SM-5, SM-6, TA-1, TA-2, TA-3, TA-4, TA-5, TM-1, TM-5, TM-7. That intersection is computed from the two citation indexes rather than curated, which is the only reason it is worth anything: nobody chose it to make a point, and if an edit to either case dropped one of them the list would shorten here on its own.
What Each Case Admits, Side by Side.
Read down one column and it is a list of things that went wrong. Read across and it is something more useful: the proactive failures are all failures of accounting — coverage nobody measured, ground nobody recorded as unsearched. The reactive ones are failures of preparation — an order nobody wrote, a degradation nobody rehearsed, an authority nobody assigned. Neither set is a failure of effort.
Proactive hunt
4 at case level · 4 on individual beats
- The deception grid’s silence was one draft away from becoming evidencePredicted by M5 Ambush — how it fails
- Two avenues had been carried forward unexamined for four cyclesPredicted by M7 Counterattack — how it fails
- A pre-authorized action was escalated anyway, and cost nineteen hoursPredicted by Maneuver — failure mode
- The reachability result the cycle opened with rested on one untested denialPredicted by Map — failure mode
Reactive hunt
5 at case level · 9 on individual beats
- The estate’s best detection spent five and a half hours in the ordinary queuePredicted by M5 Ambush — how it fails
- A credential was reset in good faith, out of sequence, and it bought the adversary a second positionPredicted by M7 Counterattack — how it fails
- The retrograde had never been rehearsed, so containment became an outage on a filing deadlinePredicted by M8 Isolation / Retrograde — how it fails
- The decision that mattered most waited three and a half hours for an authority nobody had assignedPredicted by M8 Isolation / Retrograde — how it fails
- Isolation cost the forensic record, and the forensic record was the input to everything after itPredicted by M8 Isolation / Retrograde — how it fails
The Argument These Two Cases Exist to Make.
One case can demonstrate a framework. Only a pair can demonstrate that the framework discriminates— that it says different things about different situations rather than describing everything equally well, which is the failure mode of every taxonomy that has ever been mistaken for a method.
A single worked example proves almost nothing. Any framework flexible enough to be applied at all can be applied once, and the resulting document will read as though the framework did work it did not do. The test of a model is whether it separates cases that are genuinely different — and if it does, the separation has to be visible in the model’s own vocabulary rather than in the tone of the writing.
That is what the table above is for, and it is why the rows are computed rather than written. The two cases enter the loop at different steps, traverse disjoint sets of campaign phases, lead with different forms of maneuver, put the weight of that maneuver in different bands, and answer requirements drawn from different parts of the published library. None of that was declared by either author. All of it is counted off the beats, and if an edit ever pushed one case into the other’s shape, these rows would converge in public instead of the pair quietly becoming the same story twice.
The second thing the pair shows is harder to see from one case and is the more useful half. Underneath two engagements with nothing situational in common — a hypothesis against a denied path in an empty estate, and a machine identity reading a crown-jewel partition at two in the morning — sits a common spine of 31 controls. Terrain currency, requirement discipline, rules of engagement, coverage computation and the cycle record are exercised by both, because they are not incident-shaped: they are the things that decide how well an agency does at whatever arrives. A program that reads only the reactive case will invest in response. A program that reads both will notice that most of what determined the reactive outcome was decided in some earlier cycle, by people who were not under contact and did not know they were making a decision about this night.
The third is the one the pair is least comfortable making. Both cases report an effectiveness measure they could not compute, and both report it as a gap rather than filling it in. The proactive case cannot produce a temporal-advantage ratio because a cycle with no contact has no defender decision loop to measure. The reactive case has the numerator and lost the denominator, because the containment destroyed the record the dwell reconstruction needed. Two cases, two blank scoreboard lines, two different causes — and a framework whose headline measure is unreportable in both of the situations it was built for. That is a finding about the framework, it belongs here rather than in a footnote, and the honest version of a worked example is one that surfaces it instead of choosing a metric that would have come out green.
Observe or Evict — The Decision That Most Reliably Gets Made by Accident.
Every minute of continued observation buys extent and costs exposure. Because there is no general answer, the trade gets settled by whoever moves first — which in practice means it is settled by the person with the fastest available action rather than the person accountable for the consequence.
Observe
Buy extent, spend exposure
- What it buys
- Extent. Continued observation is the only way to find the positions an adversary holds and has not used — the dormant account, the second egress, the persistence on the host nobody has looked at. An eviction executed against the positions you have found removes the adversary from those, and from nowhere else.
- What it costs
- Everything that happens while you watch. If the adversary is collecting, observation is paid for in records; if they are staging, it is paid for in the difference between contesting a foothold and contesting an estate. The cost is real, it is continuous, and it is borne by people who are not in the room.
- When it is the right side
- The extent is genuinely unknown, the ongoing damage is bounded and measurable, and the observation has a written stop condition with an owner. All three, not two: an observation window with no stop condition does not end, it is abandoned when somebody loses their nerve.
- How choosing it goes wrong
- It becomes the default because it requires no decision. Nobody has to authorize continuing to watch, so watching is what happens while the authorization to act is being sought — and the window is then reported afterwards as a deliberate collection posture rather than as the latency it was.
- The tell
- Nobody can say what the window is buying. Ask what specifically would be learned in the next hour and what would be done differently on learning it; if the answer is a hope rather than a hypothesis, the window ended some time ago and nobody noticed.
Evict
Stop the cost, spend your collection
- What it buys
- The end of the ongoing cost, on the ground you can see. Every hour of confirmed collection that does not happen is the clearest possible return, and it is the only one that is legible to the people the agency answers to.
- What it costs
- Your remaining collection, and the adversary’s ignorance of what you can see. An eviction executed on partial understanding tips them: the positions you had not found are now positions held by someone who knows they are being hunted, and the next intrusion is run by an adversary who has learned your detection surface.
- When it is the right side
- The ongoing damage is unbounded or unmeasurable, or the corpus at risk is one the agency has no right to spend — personally identifiable information and controlled unclassified information are not currency, and buying intelligence with them is not a trade the agency is entitled to make.
- How choosing it goes wrong
- It happens in fragments. The fastest available action is taken first because it is available, the sequence is derived afterwards from what has already been done, and the estate the remaining actions land on is one the adversary has already left.
- The tell
- Actions are being taken by whoever has the console open. If two people can name a different "first action", there is no sequence, and the eviction has already begun out of order whether or not anybody has pressed anything yet.
The Stop Condition Is What Makes a Window a Decision
Without one, an observation window does not end — it is abandoned when somebody loses their nerve, and is then reported afterwards as a deliberate collection posture rather than as the latency it was.
| Field | What it has to answer | A window that will not end says | A window that is a decision says |
|---|---|---|---|
| The observable | What specific thing, if seen, ends the window immediately? | If it gets worse. | Any read against a prefix outside the decoy set, in either of the two sources that carry prefix reads. |
| The horizon | When does the window end if the observable never appears? | Until we understand it. | Four hours, at which point the window closes and the decision is retaken rather than extended by default. |
| The owner | Who ends it, and who can end it if that person is unreachable? | The incident commander. | The Authorizing Official, or the named deputy after fifteen minutes of no answer, with the deputy named before contact rather than found during it. |
| The bounded cost | What is being spent per hour, in units somebody outside the response would recognize? | Some risk. | Reads against one live prefix at an observed rate, enumerated hourly so the total is a number at the end rather than an impression. |
| The prepared action | What happens the instant the window closes, already staged? | We contain. | Sequence block one — four actions, one owner each, staged and ready to execute inside ten minutes of the call. |
The observable
- What it has to answer
- What specific thing, if seen, ends the window immediately?
- A window that will not end says
- If it gets worse.
- A window that is a decision says
- Any read against a prefix outside the decoy set, in either of the two sources that carry prefix reads.
The horizon
- What it has to answer
- When does the window end if the observable never appears?
- A window that will not end says
- Until we understand it.
- A window that is a decision says
- Four hours, at which point the window closes and the decision is retaken rather than extended by default.
The owner
- What it has to answer
- Who ends it, and who can end it if that person is unreachable?
- A window that will not end says
- The incident commander.
- A window that is a decision says
- The Authorizing Official, or the named deputy after fifteen minutes of no answer, with the deputy named before contact rather than found during it.
The bounded cost
- What it has to answer
- What is being spent per hour, in units somebody outside the response would recognize?
- A window that will not end says
- Some risk.
- A window that is a decision says
- Reads against one live prefix at an observed rate, enumerated hourly so the total is a number at the end rather than an impression.
The prepared action
- What it has to answer
- What happens the instant the window closes, already staged?
- A window that will not end says
- We contain.
- A window that is a decision says
- Sequence block one — four actions, one owner each, staged and ready to execute inside ten minutes of the call.
The Eviction Sequence
A sequence is not a list of actions. The distinguishing property is that every entry carries what it costs in tipping, so the order can be argued about before contact instead of discovered during it. The forms available once contact has happened are M5 Ambush, M6 Delay, M7 Counterattack, M8 Isolation / Retrograde.
| Part | Why the sequence needs it | A list of actions says | A sequence says |
|---|---|---|---|
| Order | The first action is the one that tells the adversary you are there. Everything after it lands on an estate that knows. Order is therefore the only property of an eviction that cannot be recovered by working faster. | Contain the affected hosts, reset credentials, review logs. | Block one at T+0: revoke sessions, sever the segment, disable both identities, capture volatile state — four actions inside ten minutes because any of them alone warns. |
| Tipping cost | Some actions are silent and some are loud, and nobody can reason about ordering without knowing which is which. This is the field that turns an argument about sequence into a comparison. | Priority: high. | Rotating the service secret is loud — the session dies within ninety seconds and the adversary knows why. Pulling the access log is silent. Loud actions go in one block or not at all. |
| Owner | An action with no named owner is executed by whoever has the console, which is how an eviction goes out of order without anybody deciding to break it. | Platform team. | Named individual per action, with a named alternate, and an explicit instruction that nobody executes ahead of their position. |
| Blocks | Actions that must land together have to be marked as one thing, because a block executed serially is a sequence of warnings rather than a simultaneous removal. | Do these in order. | Four actions marked as block one, all inside ten minutes, with the block itself owned by one person who calls the start. |
| Preconditions | Preservation and scoping have to sit in front of the destructive actions, or the record they would have produced is destroyed by the response rather than by the adversary. | Capture evidence where possible. | Volatile capture on every in-scope workload, and the platform autoscaler paused, before any isolation action executes. Both are preconditions of block one, not follow-up tasks. |
| The stated gap | A sequence covers the positions that have been found. Saying so on the first line is what stops it being read as a guarantee of completeness. | Full eradication plan. | This sequence covers two identities and five workloads. It cannot order actions against a position nobody has located. |
Order
- Why the sequence needs it
- The first action is the one that tells the adversary you are there. Everything after it lands on an estate that knows. Order is therefore the only property of an eviction that cannot be recovered by working faster.
- A list of actions says
- Contain the affected hosts, reset credentials, review logs.
- A sequence says
- Block one at T+0: revoke sessions, sever the segment, disable both identities, capture volatile state — four actions inside ten minutes because any of them alone warns.
Tipping cost
- Why the sequence needs it
- Some actions are silent and some are loud, and nobody can reason about ordering without knowing which is which. This is the field that turns an argument about sequence into a comparison.
- A list of actions says
- Priority: high.
- A sequence says
- Rotating the service secret is loud — the session dies within ninety seconds and the adversary knows why. Pulling the access log is silent. Loud actions go in one block or not at all.
Owner
- Why the sequence needs it
- An action with no named owner is executed by whoever has the console, which is how an eviction goes out of order without anybody deciding to break it.
- A list of actions says
- Platform team.
- A sequence says
- Named individual per action, with a named alternate, and an explicit instruction that nobody executes ahead of their position.
Blocks
- Why the sequence needs it
- Actions that must land together have to be marked as one thing, because a block executed serially is a sequence of warnings rather than a simultaneous removal.
- A list of actions says
- Do these in order.
- A sequence says
- Four actions marked as block one, all inside ten minutes, with the block itself owned by one person who calls the start.
Preconditions
- Why the sequence needs it
- Preservation and scoping have to sit in front of the destructive actions, or the record they would have produced is destroyed by the response rather than by the adversary.
- A list of actions says
- Capture evidence where possible.
- A sequence says
- Volatile capture on every in-scope workload, and the platform autoscaler paused, before any isolation action executes. Both are preconditions of block one, not follow-up tasks.
The stated gap
- Why the sequence needs it
- A sequence covers the positions that have been found. Saying so on the first line is what stops it being read as a guarantee of completeness.
- A list of actions says
- Full eradication plan.
- A sequence says
- This sequence covers two identities and five workloads. It cannot order actions against a position nobody has located.
Preservation Comes Before Containment, or It Does Not Happen
Containment destroys the forensic record as a side effect and never as a decision. Severing a segment drops the volatile state on the far side of it; isolating a host stops the process that would have been dumped; and in a cloud estate the platform will recycle an ephemeral workload on its own schedule whether or not an incident is running. None of those is a choice anybody makes, which is exactly why the ordering has to be written down in advance: nobody deliberately destroys evidence, and it gets destroyed in most incidents anyway.
The cost is not confined to the investigation, and treating it as an investigator’s concern is how it gets deprioritized. The dwell reconstruction is the input to the adversary dwell estimate, which is the denominator of temporal advantage; it is also the evidence behind at least two of the preconditions any honest restoration gate will set. Lose the record on day zero and the scoreboard line is blank, the restoration gate is unmeetable, and the standing dwell estimate cannot be revised — three consequences, all of them arriving weeks later, none of them attributable at the time to the four hours nobody spent capturing memory.
The practical form is a precondition, not a priority. Volatile capture across the in-scope population, and a documented pause on whatever the platform does automatically, sit in front of block one of the sequence. If that ordering costs containment time, the trade is stated and taken deliberately — which is a different thing from discovering afterwards that the two workloads the intrusion most likely originated on were recycled while everyone was watching the identity plane.
The statutory constraint runs the other way and has to be held at the same time. An agency with a filing deadline cannot simply take the service down, and cannot hold it down while an investigation completes. That is not an argument against preservation; it is the reason preservation must be fast, prepared and automatic, because it is the only version of it that survives being squeezed between an adversary and a statute.
The Authority Ladder
Keyed to the field the timelines actually record, so the ladder cannot fall out of step with the cases. The governing controls are resolved from the published catalog rather than named in prose.
| Rung | What belongs at this level | What the level costs | Governed by |
|---|---|---|---|
| Pre-authorized | Actions whose cost is bounded and whose value decays in minutes. Host isolation on confirmation, credential reset, session revocation, egress blocking on named infrastructure. The test is not how dangerous the action is — it is whether the damage of taking it wrongly is smaller than the damage of a two-hour wait. | Nothing in tempo, and a real cost in judgment: a wide set devolves decisions to whoever is on shift at 03:00, so it has to arrive with a sequence attached or it becomes permission to act on the fastest available thing. | |
| Standing rules of engagement | Work the role holds at its own level without a specific authorization — observation, collection inside the boundary, terrain correction, analysis. Most of a response sits here and it is the rung nobody argues about, which is why it is also the rung where out-of-scope actions get normalized. | Nothing directly. Its failure mode is silent: an action taken repeatedly under standing authority that was never actually inside it becomes precedent, and precedent is discovered at the next assessment rather than at the time. | |
| Escalated to the Authorizing Official | Anything that degrades a mission service, crosses the agency boundary, or spends something the security program does not own — a statutory availability commitment, a contractual relationship, a partner’s trust. These are correctly above the line, and the argument is never about whether they should be escalated. | Measured in minutes of adversary time, and the cost is almost entirely avoidable. The wait is rarely the decision; it is finding out who may make it, on what criteria, at that hour. Writing the criteria down in advance converts a three-hour wait into a ten-minute one without moving the line at all. | |
| Taken as an exception | Action outside the standing authority, recorded as such at the time. The rung exists so that an operator who has to act can act — and so that the record afterwards says "this was outside the set" rather than quietly widening the set to fit what happened. | Governance cost rather than tempo cost, and it is worth paying. An exception recorded honestly is a finding about the set; an exception absorbed silently is how a rules-of-engagement document drifts into a description of past behavior. | |
| No authority required | Analysis, assessment, framing and decision-recording — beats that take no action on the estate. Kept as a distinct rung rather than folded into standing authority so that the authority profile of a case reports the actions and not the thinking. | Nothing, and it is the rung most often mislabeled. Work recorded here that actually touched something is how an authority profile comes to look cleaner than the response was. |
Pre-authorized
- What belongs at this level
- Actions whose cost is bounded and whose value decays in minutes. Host isolation on confirmation, credential reset, session revocation, egress blocking on named infrastructure. The test is not how dangerous the action is — it is whether the damage of taking it wrongly is smaller than the damage of a two-hour wait.
- What the level costs
- Nothing in tempo, and a real cost in judgment: a wide set devolves decisions to whoever is on shift at 03:00, so it has to arrive with a sequence attached or it becomes permission to act on the fastest available thing.
Standing rules of engagement
- What belongs at this level
- Work the role holds at its own level without a specific authorization — observation, collection inside the boundary, terrain correction, analysis. Most of a response sits here and it is the rung nobody argues about, which is why it is also the rung where out-of-scope actions get normalized.
- What the level costs
- Nothing directly. Its failure mode is silent: an action taken repeatedly under standing authority that was never actually inside it becomes precedent, and precedent is discovered at the next assessment rather than at the time.
Escalated to the Authorizing Official
- What belongs at this level
- Anything that degrades a mission service, crosses the agency boundary, or spends something the security program does not own — a statutory availability commitment, a contractual relationship, a partner’s trust. These are correctly above the line, and the argument is never about whether they should be escalated.
- What the level costs
- Measured in minutes of adversary time, and the cost is almost entirely avoidable. The wait is rarely the decision; it is finding out who may make it, on what criteria, at that hour. Writing the criteria down in advance converts a three-hour wait into a ten-minute one without moving the line at all.
Taken as an exception
- What belongs at this level
- Action outside the standing authority, recorded as such at the time. The rung exists so that an operator who has to act can act — and so that the record afterwards says "this was outside the set" rather than quietly widening the set to fit what happened.
- What the level costs
- Governance cost rather than tempo cost, and it is worth paying. An exception recorded honestly is a finding about the set; an exception absorbed silently is how a rules-of-engagement document drifts into a description of past behavior.
No authority required
- What belongs at this level
- Analysis, assessment, framing and decision-recording — beats that take no action on the estate. Kept as a distinct rung rather than folded into standing authority so that the authority profile of a case reports the actions and not the thinking.
- What the level costs
- Nothing, and it is the rung most often mislabeled. Work recorded here that actually touched something is how an authority profile comes to look cleaner than the response was.
The Same Constraint as the Hunt Failures: Each Points at a Published Mode.
Six of the seven are exercised somewhere in the reactive case, which is not a coincidence — the case was written against the agency’s own coverage baseline, and a baseline that grades isolation and delay thin predicts most of this list.
The eviction runs in whatever order the actions became available.
Two people on the bridge would name a different first action, and the sequence in the report was written after the incident from what was actually done.
Write the sequence before contact, with a tipping cost and a named owner against every action, and mark the actions that must land inside the same block. A set of pre-authorized fires with no ordering attached reads as permission to take the fastest one.
“Eviction is unsequenced, so the first action warns the adversary and the remaining actions land on an estate they have already left for a position you have not found.”
The degraded mode is exercised for the first time during the incident.
A dependency nobody had declared surfaces within minutes of the degradation, and it surfaces as a user-visible error rather than as a line on a dependency map.
Rehearse the degradation on a schedule and treat the findings as the point of the exercise. A rehearsal with no findings was a demonstration, and a degraded mode that exists only as a configuration flag and a paragraph has never been tested against the consumers it will take with it.
“Degraded mode was never rehearsed, so degradation becomes an unplanned outage and the organization learns which dependencies were undeclared during the incident.”
The action is available and the authority to take it is not.
The longest interval in the incident timeline is an escalation, and most of that interval was spent establishing who could decide rather than deciding.
Write the decision criteria for service-affecting containment into the scheme of maneuver, with a named deputy and an out-of-hours path. The line does not move; what moves is the time it takes to find out where the line is.
“The severing action is technically available but nobody is authorized to take it, so it is escalated through three layers while the exfiltration completes.”
A statutory service is degraded against a floor that does not exist.
The availability floor is written during the incident, and the number chosen comfortably describes what has already happened.
Declare the floor as a mission judgment, signed by the service owner, outside contact. A floor authored during a breach is authored by the breach, and the security program cannot set it alone because it does not own the statutory obligation.
“A statutory service is degraded without reference to the floor.”
Containment is taken before preservation, and the dwell reconstruction dies with it.
The dwell figure in the closing brief is a range bounded by a log retention setting, or is quietly carried forward from the previous cycle unchanged.
Move preservation in front of block one as a precondition, and document a pause on whatever the platform recycles automatically. Both are cheap in advance and unavailable during.
“Isolation destroys the forensic record, and the dwell reconstruction — the input to every consolidation activity that follows — cannot be produced.”
The service comes back because the pressure to restore beat the evidence.
Restoration preconditions exist and two of them are waived on a signature, or the preconditions were authored the same morning by the people under pressure to restore.
Author the preconditions outside contact, and check that each one can be met by a capability the agency actually operates. A precondition requiring evidence the estate cannot produce is not a gate, it is a waiver with extra steps.
“Services are restored without preconditions, so the estate comes back into a compromise that was contained rather than removed, and the second incident is the same as the first.”
The contact is closed instead of exploited.
No production detection can be named from the last incident, and the avenue is recorded as closed with no statement of how the closure was established.
Close the incident on the detection and on a tested closure, not on the report. The exploitation form exists for this and is the one most often skipped, because the pressure at that moment is entirely toward getting everybody back to their day job.
“Indicators are harvested into a spreadsheet and never converted into detections, so the next occurrence is found by the same manual effort.”
Before Contact, or It Will Not Exist During It
- A phase declaration with a scope. "Phase III" against the estate and "Phase III" against one service open very different fire sets, and the difference has to be stated at the moment of declaration rather than inferred afterwards from what people did.
- A pre-authorized set the shift can read from where it works, with an ordering attached. A wide set with no sequence is permission to act on the fastest available thing.
- An eviction sequence, written and rehearsed, covering the positions found — with the gap stated on its first line so it is not read as a guarantee of completeness.
- A stated availability floor for every service the response could plausibly degrade, signed by the mission owner rather than by the security program.
- A preservation precondition in front of the first destructive action, including a documented pause on whatever the platform recycles on its own schedule.
- A named decision-maker for service-affecting containment, a named deputy, and an out-of-hours path to both. The wait is almost never the decision.
Before the Response May Be Called Finished
- A restoration decision recorded against preconditions, with any waived precondition named individually and carrying a risk owner and an expiry.
- A dwell reconstruction, or an explicit statement of why one could not be produced and what would have to change for the next one to be possible.
- Detections authored from the contact and marked untested until they have fired on telemetry they were not derived from.
- The exploited avenue closed, and the closure recorded as tested or as asserted — never in a field that cannot tell the two apart.
- Every authority latency in the timeline measured and reported as adversary time, including the ones that turned out not to matter.
- An honest statement of which positions the response covered and which it could not have found, so the next cycle inherits a scope rather than a reassurance.
The limit. A response has failed irrecoverably when the service is back, the ticket is closed, and nobody can say whether the adversary was evicted or merely interrupted — because the evidence that would distinguish the two was destroyed by the containment, and the only remaining argument for eviction is the absence of new alerts from sensors that never saw the intrusion in the first place.
If You Cannot Say What Would Kill It, It Is Not a Hypothesis.
The test is mechanical rather than tonal: before collecting anything, state the observation that would falsify the claim. Skip that and the collection decides what it found, which is how a hunt converges on whatever the analyst already expected.
| Part | The test it has to pass | Fails the test | Passes it |
|---|---|---|---|
| The claim | A statement about the estate that could be true or false, naming the terrain and the actor position it is about. | There may be undetected lateral movement in the mission tier. | A non-mission-staff identity has traversed the new gateway to the sensitive-records read path at least once in the last ninety days. |
| The falsifier | The observation that would have to exist if the claim were true — written down before collection, in the source it would appear in. | We would probably see something odd in the logs. | The gateway access log would carry a caller principal outside the mission-staff directory, or the data platform audit would carry a read whose caller cannot be resolved to one. |
| The window | The interval the claim is about, checked against the retention of the source that would falsify it — at Frame, not on the day of the query. | Recently. | Ninety days, against a gateway access log with a fourteen-day horizon. The mismatch is the finding; discovering it after collection is a self-inflicted one. |
| The population | Scope is drawn from the overlay, not from whatever the tooling can currently see. A denominator set by agent coverage flatters every result computed on it. | All endpoints. | State the population and the reachable share of it separately. Cover most of a class, report on all of it, and the question has quietly changed underneath the answer. |
| The decision | The requirement it serves, and what changes on each answer. A hunt that changes nothing either way is an audit. | To increase assurance. | Whether the portal trust boundary stands as drawn in the next authorization package, or is re-scoped before it is signed. |
| The retirement test | What would have to be true for this ground to stop being hunted. A condition, not a date, and it inherits the window. | Ongoing monitoring. | Cleared to the fourteen-day horizon; the clearance goes stale fourteen days after the last search and the avenue returns to the backlog. |
The claim
- The test it has to pass
- A statement about the estate that could be true or false, naming the terrain and the actor position it is about.
- Fails the test
- There may be undetected lateral movement in the mission tier.
- Passes it
- A non-mission-staff identity has traversed the new gateway to the sensitive-records read path at least once in the last ninety days.
The falsifier
- The test it has to pass
- The observation that would have to exist if the claim were true — written down before collection, in the source it would appear in.
- Fails the test
- We would probably see something odd in the logs.
- Passes it
- The gateway access log would carry a caller principal outside the mission-staff directory, or the data platform audit would carry a read whose caller cannot be resolved to one.
The window
- The test it has to pass
- The interval the claim is about, checked against the retention of the source that would falsify it — at Frame, not on the day of the query.
- Fails the test
- Recently.
- Passes it
- Ninety days, against a gateway access log with a fourteen-day horizon. The mismatch is the finding; discovering it after collection is a self-inflicted one.
The population
- The test it has to pass
- Scope is drawn from the overlay, not from whatever the tooling can currently see. A denominator set by agent coverage flatters every result computed on it.
- Fails the test
- All endpoints.
- Passes it
- State the population and the reachable share of it separately. Cover most of a class, report on all of it, and the question has quietly changed underneath the answer.
The decision
- The test it has to pass
- The requirement it serves, and what changes on each answer. A hunt that changes nothing either way is an audit.
- Fails the test
- To increase assurance.
- Passes it
- Whether the portal trust boundary stands as drawn in the next authorization package, or is re-scoped before it is signed.
The retirement test
- The test it has to pass
- What would have to be true for this ground to stop being hunted. A condition, not a date, and it inherits the window.
- Fails the test
- Ongoing monitoring.
- Passes it
- Cleared to the fourteen-day horizon; the clearance goes stale fourteen days after the last search and the avenue returns to the backlog.
A Hunt That Finds Nothing Has Produced a Result.
Which result depends entirely on what was written down. That sentence is the whole discipline, and the reason this section exists at the same depth as the cases themselves.
A hunt that finds nothing has produced a result. Which result depends entirely on what was written down: searched this ground, in these sources, over this window, at this fidelity, and did not find the thing that would have been there. That sentence is evidence. "The hunt found nothing" is not, and the distance between the two is the whole discipline.
The reason to record it is arithmetic rather than moral. An estate has a finite set of enumerated avenues. A hunt clears some of them to a stated bound; the next cycle starts from that record and spends its effort on the ground nobody has walked. Without the record, every cycle re-derives its own scope from whatever is on the analyst’s mind, which in practice means the same handful of comfortable data sources are searched repeatedly and the awkward ones — supplier access, maintenance routes, the enterprise-to-operational crossing — are never searched at all. The framework publishes exactly this as a failure of the counterattack form: coverage is anecdotal, and two sources are never searched.
A program that reports only the hunts that found something is not being modest. It is reporting a biased sample and then reasoning from it. Its dwell estimate is built from the intrusions it detected, which is the population least representative of dwell. Its hunt-effectiveness figure is computed over the hunts that produced findings, which is a hit rate over a denominator that has been quietly redefined. And its leadership learns that a hunt with no finding was wasted effort, which is the lesson most likely to end the practice — because most hunts, in a healthy estate, find nothing, and a team that is punished for that will eventually stop looking anywhere it might.
The uncomfortable corollary is that a negative result is only worth as much as its bound. A clearance with no window, no population and no fidelity statement is more dangerous than no clearance at all, because it will be cited. The right posture toward a hunt that found nothing is neither relief nor apology: it is to state precisely how much ground it cleared, for how long, and what it could not have seen — and then to put an expiry on it, because ground does not stay cleared.
| Field | What it has to answer | A weak record says | A usable record says | Why it is load-bearing |
|---|---|---|---|---|
| Scope | What ground was searched? | The mission tier. | Six of the nine enumerated avenues in full, two partially, and the enterprise-to-operational crossing not at all — recorded as not searched rather than omitted. | Cited by the next cycle as ground it does not have to re-hunt. Without it the record clears nothing in particular, and the same three avenues get searched every cycle while the other six never do. |
| Window | Over what interval, and bounded by which source? | The last quarter. | Fourteen days at the gateway, ninety at the identity provider, four hundred at the data platform. The claim is fourteen days, because the gateway is the only source that binds a caller to the record path. | No negative reaches back further than the least durable source under it. Naming the source that set that limit is what allows a reader to argue the limit was itself the result. |
| Fidelity | What would the search have missed even inside the window? | Complete. | Complete for caller principals outside the mission-staff directory; blind to an adversary operating inside a service principal the case system legitimately uses. | Coverage and fidelity are different. A query that ran across the whole population but could not distinguish a partner identity behaving like a partner identity has full coverage and no discriminating power, and only the second one matters. |
| Falsifier | What would have been visible had the hypothesis been true? | We found no indicators of compromise. | One access-log row with a caller principal outside the directory would have falsified it. The query returned 41,200 rows and none of them was that row. | This is the field that makes the negative auditable. Without it, a reader cannot tell whether the hunt looked in the place the evidence would have been. |
| Expiry | When does this clearance go stale? | Reviewed annually. | Stale fourteen days after the last search, tied to the horizon that produced it, at which point the avenue returns to the hunt backlog automatically. | Ground cleared once stays cleared in the record and stops being true almost immediately. An expiry is what puts the avenue back on the backlog rather than leaving it permanently green. |
| Owner | Who signed it, and who countersigned? | The hunt team. | Signed by the hunt lead, countersigned by governance into the cycle record. | A negative result is a claim someone can be wrong about in public. Anonymous clearance is the same as no clearance, and it is the version that gets quoted three cycles later by someone who was not there. |
Scope
- What it has to answer
- What ground was searched?
- A weak record says
- The mission tier.
- A usable record says
- Six of the nine enumerated avenues in full, two partially, and the enterprise-to-operational crossing not at all — recorded as not searched rather than omitted.
- Why it is load-bearing
- Cited by the next cycle as ground it does not have to re-hunt. Without it the record clears nothing in particular, and the same three avenues get searched every cycle while the other six never do.
Window
- What it has to answer
- Over what interval, and bounded by which source?
- A weak record says
- The last quarter.
- A usable record says
- Fourteen days at the gateway, ninety at the identity provider, four hundred at the data platform. The claim is fourteen days, because the gateway is the only source that binds a caller to the record path.
- Why it is load-bearing
- No negative reaches back further than the least durable source under it. Naming the source that set that limit is what allows a reader to argue the limit was itself the result.
Fidelity
- What it has to answer
- What would the search have missed even inside the window?
- A weak record says
- Complete.
- A usable record says
- Complete for caller principals outside the mission-staff directory; blind to an adversary operating inside a service principal the case system legitimately uses.
- Why it is load-bearing
- Coverage and fidelity are different. A query that ran across the whole population but could not distinguish a partner identity behaving like a partner identity has full coverage and no discriminating power, and only the second one matters.
Falsifier
- What it has to answer
- What would have been visible had the hypothesis been true?
- A weak record says
- We found no indicators of compromise.
- A usable record says
- One access-log row with a caller principal outside the directory would have falsified it. The query returned 41,200 rows and none of them was that row.
- Why it is load-bearing
- This is the field that makes the negative auditable. Without it, a reader cannot tell whether the hunt looked in the place the evidence would have been.
Expiry
- What it has to answer
- When does this clearance go stale?
- A weak record says
- Reviewed annually.
- A usable record says
- Stale fourteen days after the last search, tied to the horizon that produced it, at which point the avenue returns to the hunt backlog automatically.
- Why it is load-bearing
- Ground cleared once stays cleared in the record and stops being true almost immediately. An expiry is what puts the avenue back on the backlog rather than leaving it permanently green.
Owner
- What it has to answer
- Who signed it, and who countersigned?
- A weak record says
- The hunt team.
- A usable record says
- Signed by the hunt lead, countersigned by governance into the cycle record.
- Why it is load-bearing
- A negative result is a claim someone can be wrong about in public. Anonymous clearance is the same as no clearance, and it is the version that gets quoted three cycles later by someone who was not there.
The Four Bounds a Clearance Has to Carry
A clearance with no window, no population and no fidelity statement is more dangerous than no clearance at all — because it will be cited.
Left unanswered: The negative silently becomes a claim about all of history, and the interval an opportunist would actually have used — the days right after a change — is usually the interval that fell off the end.
Left unanswered: Coverage is computed over the elements that had data, which is the same defect the Assess step publishes as a failure mode. Unmeasured elements are reported as clean, and clean is the one thing they are not.
Left unanswered: The record claims discrimination it does not have. This is where hunting inside a service principal, or inside a legitimate reporting job, hides — the search ran, the search was complete, and the search could not have seen it.
Left unanswered: Silence from a sensor sited off the avenue is silence about the sensor. Reading it as silence about the adversary raises confidence on no evidence at all, and the framework publishes it as a named failure of deception specifically because it is so easy to do by accident.
Not One of These Is a Surprise; the Manual Names Every One of Them in Advance.
That constraint is deliberate. A novel failure mode invented here would be a finding about the doctrine rather than a piece of guidance, and it should be raised as one.
Silence is read as absence.
A hunt record cites a sensor that returned nothing without saying where the sensor sits. Confidence rises and no evidence was added.
Reconcile siting against the current avenue list before a null result may be cited. A sensor that is not on the avenue the hypothesis names has produced no information about that avenue.
“Silence read as success”
The hunt is scoped to the telemetry that is easy to query.
Across three cycles the same three sources appear in every hunt record and two named avenues appear in none.
Make coverage accounting an exit condition of the hunt rather than a closing artifact, and compute it over the enumerated avenue list rather than over the avenues searched.
“What was hunted is never accounted for, so coverage is anecdotal and the same three data sources are searched every cycle while two others are never searched at all.”
The negative is discarded rather than recorded.
The same ground is hunted every cycle with no record that it was cleared last time.
Write the negative into the cycle record as a finding with a scope, a window, a fidelity statement and an expiry. Absence of evidence is evidence about coverage even when it is not evidence about the adversary.
“Negative hunt results are discarded.”
The hunt runs on a calendar rather than on a hypothesis.
The hunt backlog is a schedule. Each entry names a data source and a month, and none of them names a claim that could turn out to be false.
Require a written falsifier before collection opens. A hunt whose falsifier cannot be stated is sampling, and sampling an estate this size returns whatever the analyst already expected.
“Hunting the calendar”
Findings never become detections.
The hunt is re-run manually next quarter against the same adversary behavior, and nobody can name a production detection authored from the last one.
Close the hunt on the detection, not on the report. The exploitation form exists for this and is the form most often skipped, because the pressure at that moment is entirely toward closing the ticket.
“Findings never become detections, which means the hunt is re-run manually next quarter for the same adversary behavior.”
Dwell is estimated from the hunts that found something.
The estimate is flattering, and its basis is a small number of closed cases.
State the bias rather than correcting for it silently. The cases where dwell is measurable are the cases that were detected, which is the population least representative of dwell.
“Dwell is estimated from the incidents where dwell was measurable.”
The limit. A hunt has failed irrecoverably when it ran, cost real analyst weeks, found nothing, and left behind no statement of what ground it cleared — because the ground will be hunted again next cycle by someone who has no way of knowing that.
What Has to Be True Before a Hunt Starts, and Before It May Be Called Finished.
Both lists are short on purpose. Every item is something a program can check without a meeting, and every one of them is skipped by somebody every cycle.
Before It Starts
- A written hypothesis with a falsifier, a window and a population. Without one the activity is sampling and should be called that.
- A requirement the hypothesis serves, with a decision attached that changes on the answer. A hunt that changes nothing either way is an audit and should be scheduled as one.
- Retention checked against the window, before collection rather than after. This is the single check most often skipped and it is the one that bounds the whole result.
- The pre-authorized set readable from where the hunt team works. An operator who cannot find the rules of engagement will ask, and asking is measured in hours.
- An avenue list current enough to compute coverage against. Coverage over a stale avenue list is coverage of last cycle’s estate.
Before It Is Finished
- A coverage account: which avenues were searched, in which sources, over which window, at what fidelity — and which were not searched, named individually.
- A result, positive or negative, written with the bound attached rather than in a footnote.
- Every finding that is not about the hypothesis routed to an owner. Most of what a hunt produces is incidental, and the incidental findings are where the control failures live.
- Detections authored for anything the hunt had to find by hand, and recorded as untested until they have fired.
- An expiry on the clearance, tied to the horizon that produced it.
- The intelligence requirement retired, or explicitly carried forward with the reason it survived.