ASOM-Fedv6.1Open the explorer
Worked case · Proactive hunt

The hunt that found nothing, and what that was worth

Two changes landed on the same ground in one change window: a record-read path moved behind a new API gateway, and a partner federation was added to the identity plane. Neither was an incident and neither generated an alert. What they did was invalidate a denied path that last cycle’s headline map finding depended on — a denial asserted from a configuration export and never once reconciled against telemetry. The cycle commissioned a hunt against a hypothesis rather than against an adversary, ran it across the nineteen days from commissioning to brief, and found nobody. What it produced instead is a bounded statement of cleared ground, one control failure it was not looking for, and a precise account of the three avenues nobody in this program has searched in four cycles.

40Beats26 inside the hunt band, 14 the cycle work around it
32d 22h 50mFirst beat to lastThe hunt band itself ran 17d 4h 20m
20h 40mAuthority taxSpent waiting on 2 escalations to the Authorizing Official
39Controls exercisedAlongside 27 techniques across 8 terrain layers

Everything here is modeled against the Federal Reference Agency. This is not a report of an event at a named agency. The estate is a composite drawn from public doctrine and the published agency archetypes; the beats are authored. What is not authored is the machinery — every control, technique, terrain layer, product and requirement below resolves against the published data, and a citation that does not resolve fails the build.

Where It Starts

The Trigger, and the Ground It Starts On.

A proactive hunt may legitimately enter the loop at frame or map, and where it enters decides almost everything after — which forms are available, what its authority costs, and what a good outcome even looks like.

What Started It

The trigger

Trigger
No alert. A terrain change plus an assumption somebody was willing to write down: that a denied path nobody had tested was still holding after the ground on both sides of it moved.
Where it enters the loop
map — a proactive hunt may legitimately enter at frame or map.
Phases traversed
0 Shape (33)I Deter (7)

The Ground in Play

Federal Reference Agency slots

  • Public Service Portal
  • Case Filing System
  • Case Processing System
  • CI/CD Pipeline
  • ICAM / PDP
  • Sensitive Mission Records
  • Mission-Staff Workstations
Terrain touched
8 of 10 layers. Never touched: T6 Operational Technology, T7 Workforce — which is usually the more interesting list.
The Requirements

What the Hunt Was Actually Asked.

Every requirement carries the decision that changes on the answer. One that changes nothing either way is an audit, and should be scheduled as one rather than run as a hunt.

PCIR-12

The decision it changes: Whether the portal’s trust boundary stands as drawn in the next authorization package, or is re-scoped before that package is signed.

PCIR-11

The decision it changes: Whether the next segmentation obstacle is emplaced at the east–west boundary or at the egress boundary. One can be funded and staffed this cycle.

PCIR-05

The decision it changes: Whether this cycle’s main effort is terrain currency rather than any form of maneuver at all — you cannot array a scheme against ground you have not mapped.

PCIR-14

The decision it changes: Whether to fund a hunt campaign aimed specifically at the blind interval, or to carry the current estimate into the running estimate as stated.

PCIR-16

The decision it changes: Whether to re-site the deception grid onto the avenues that reachability analysis says are live, or to leave it in place and read the silence as evidence of absence.

The Shape of It

Which Forms Were Used, and Where the Work Actually Sat.

Each figure is counted off the beats rather than declared. A case that claims one posture and spends its beats in the other’s band is describing something other than what it says it is.

Forms of Maneuver Exercised

M3
Envelopment3 beats · shaping

Make identity, not network location, the decisive plane — surround the adversary with policy.

M10
Exploitation & Pursuit2 beats · consolidation

Convert contact into durable advantage rather than closing the ticket.

M4
Obstacle / Canalization2 beats · shaping

Force the adversary onto ground you own and watch.

M5
Ambush2 beats · contact

Trade space for information and time, and impose cost.

M2
Defense in Depth1 beat · shaping

Ensure no single failure is decisive.

Where the Beats Sat

  • 01 Frame 3 beats, 0 in the hunt band.
  • 02 Map 7 beats, 0 in the hunt band.
  • 03 Array 3 beats, 1 in the hunt band.
  • 04 Maneuver 21 beats, 21 in the hunt band.
  • 05 Fuse 3 beats, 3 in the hunt band.
  • 06 Assess 3 beats, 1 in the hunt band.

Maneuver Bands

  • shaping16 beats.
  • contact11 beats.
  • consolidation2 beats.

Authority

20h 40m spent waiting on 2 escalations. Under contact that is priced in adversary dwell; out of contact it is nearly free, which is why it is worth measuring out of contact first.

Exhibit 1

The Operating Loop, with This Case’s Beats Counted onto It

01FrameScreen02MapCyber Preparation of the Environment03ArrayDesign the scheme04ManeuverExecute05FuseAnalyze06AssessProduceRe-frame · the loop turns faster than the adversary adapts
  1. Frame

    Screen · Analytic Design step 1

  2. Map

    Cyber Preparation of the Environment — the IPB analog

  3. Array

    Design the scheme

  4. Maneuver

    Execute

  5. Fuse

    Analyze · Integrate

  6. Assess

    Produce · re-frame

↺ Re-frame — the loop turns faster than the adversary adapts

Where Its Weight Fell

Beats per step, counted from the timeline. The case enters at Map and puts most of its weight on Maneuver.

Which Campaign Phases It Crossed

The loop turns inside a phase; the phase changes when the Authorizing Official declares it. The two clocks are separate on purpose, and a case that crosses phases is showing both of them.

The diagram is the framework’s own and is unchanged; a case study has no business editing it, and a second copy that could drift would be worse than no drawing. What a case is entitled to add is where its own weight fell, and that is counted underneath in text so it survives a phone — the diagram’s labels are sized against a 1000-unit viewBox and would land near 4px at 390px.
The Honesty Check

Checked Against the Same Agency’s Coverage Baseline.

The most tempting error available to a worked example is depicting the agency doing something the same site elsewhere says it cannot do. So this is a computation rather than a promise: of the 27 techniques these beats cite, the published baseline grades 13 absent — 48.1%. Follow any of them into the record above and check that it is depicted improvised, degraded or failing.

Grades are read from the coverage baseline for the Federal Reference Agency at render time, not copied here — so if the baseline moves, this section moves with it. A technique graded absent that is nonetheless depicted working smoothly would be a defect in the case study, and this is how a reader finds one.

The Record

40 beats, in order.

Every beat carries what it did not establish, because that is most of what real defensive work produces. Beats with a heavier left edge sit inside the hunt band; the rest are the cycle work that made the hunt possible, and separating them is how a program avoids believing hunting is a standalone activity.

  1. D-14 16:40

    Beat 1, The CI/CD Pipeline cut the Case Processing System’s record-read path over to a new API gateway. External attack-surface enumeration picked up the new hostname the same evening, and terrain currency raised it as a material change rather than leaving it for the next scheduled overlay rebuild.

    What it did not establish

    That the new gateway changed what was reachable. Enumeration says a host exists and answers; it says nothing about what stands behind it. The overlay entry was created with its adjacencies blank, and blank adjacencies are the state in which an element is on a list rather than on a map.

    Outcome

    One new element on the overlay, owner recorded as the platform group that ran the cutover, adjacency unknown and flagged as unknown.

    Confidence — high

    The change record and the gateway configuration carry the same cutover timestamp, and external enumeration observed the new hostname answering within four hours of it.

    Authority

    Standing ROE

    Form — M1 Screen / Guard
    Controls
  2. D-13 10:15

    Beat 2, A federation trust to a mission partner was added to the ICAM / PDP in the same change window, giving 22 partner identities a path to the Case Filing System. The connection register was updated with the trust and the claimed authenticator assurance.

    What it did not establish

    What the partner’s identity assurance actually is. The trust was recorded as configured; the assurance behind it was taken from the partner’s own attestation, which imports their weakest authenticator into this agency’s policy engine on their word.

    Outcome

    One new permitted edge on the register, and a second element — the partner tenancy — that this agency can see the boundary of and not the inside of.

    Confidence — moderate

    The trust configuration is directly observable. The assurance behind it is a statement in a partner agreement and has never been tested from this side.

  3. D-12 09:05

    Beat 3, Discovered internet-facing assets were reconciled against the authoritative inventory. Eleven of thirteen new entries resolved to the migration. Two did not resolve to anything, sitting in a cloud subscription outside the declared tenancy boundary.

    What it did not establish

    Whether the two unresolved entries are ours. The reconciliation established that nobody in the platform group claims them, which is a statement about the register rather than about ownership, and they were carried forward as an open item rather than closed either way.

    Outcome

    Overlay refreshed against the migration. Unreconciled-asset count moved from zero to two, and was reported as two rather than as “substantially reconciled”.

  4. D-11 14:20

    Beat 4, A key-assumptions check over last cycle’s reachability result asked what the result required to be true. It required one denial — public tier to mission tier, east–west, at the boundary the new gateway now sits astride — and that denial had no telemetry reconciliation recorded against it since before the migration.

    What it did not establish

    That the path is now permitted. It established only that nothing had tested it, which is a statement about the evidence and not about the corridor. The corridor might have been fine the whole time; nobody could say so from the register.

    Outcome

    The load-bearing denial was reclassified as untested. Under the framework’s own rule an untested denial is treated as permitted for reachability purposes, which invalidated last cycle’s headline map finding without anyone observing a packet.

    Confidence — high

    The connection register itself records the date of the last telemetry reconciliation against each denial. For this one the field was empty.

    This is a failure the manual already predictsMap — failure mode

    Denied paths are asserted from configuration and never tested.

    • The denial was asserted from a firewall policy export at the time the register was built, and the register records assertions and reconciliations in the same column.
    • Flow telemetry for that segment exists, and nobody had been assigned to compare the two since the segment’s owner changed teams.
    • The reachability result that depended on it was the previous cycle’s best finding, which made it the least likely thing in the register to be re-examined.
    Authority

    No authority required

    Form

    None — an analytic beat, instantiating no maneuver.

    Controls
    Requirement
  5. D-10 11:00

    Beat 5, The lateral-path audit was re-run with the untested denial treated as permitted. From a self-registered Public Service Portal identity it found a two-hop route to the Case Processing System record-read path, through the new gateway, that no denied-path entry covered.

    What it did not establish

    Whether anyone has ever traversed it. A permitted path is a possibility. The register cannot distinguish a possibility from a use, and the whole hunt exists because of that gap — not because of the path.

    Outcome

    Reachability result recorded as: crown-jewel read path reachable from the public identity tier on permitted paths, shortest route two hops. The result changed the map without any adversary being involved.

    Confidence — moderate

    Walked over exported policy and route tables rather than from a live position. Two of the cloud route tables were exported a day apart, so the graph is internally consistent to within a day.

  6. D-10 15:30

    Beat 6, Certificate and domain watch was folded into a re-enumeration of the avenues of approach to the crown-jewel record set. Nine avenues were listed; the gateway route was added as the shortest of them.

    What it did not establish

    Anything about the physical, maintenance and supplier routes. Three of the nine were copied forward from the previous cycle unchanged because nothing had obviously moved on them — and carrying an avenue forward is an assumption that nobody wrote down as one at the time.

    Outcome

    Nine avenues on the list, six of them re-derived this cycle and three inherited. The inheritance was not marked.

  7. D-9 10:45

    Beat 7, Most-likely and most-dangerous courses of action were redrawn against the new gateway. The most dangerous routes through a federated partner identity to the record path; the most likely routes through a self-registered portal account and abuses the gateway’s authorization gap rather than any credential.

    What it did not establish

    That either course of action is being executed. A course of action is a plan attributed to an adversary. This cycle produced no observation to attach to either, and the pair is a planning device rather than an assessment.

    Outcome

    Two courses of action that differ materially — one turns on identity assurance the agency cannot see, the other on an authorization decision the agency owns entirely.

    Authority

    No authority required

    Form

    None — an analytic beat, instantiating no maneuver.

    Controls
  8. D-3 09:30

    Beat 8, Frame opened on the previous cycle’s brief. The intent paragraph was revised to name the sensitive-records read path as the thing that must hold and public-facing search latency as the thing that may be degraded to hold it. Phase was held at 0, cadence set at 21 days, temporal-advantage threshold restated.

    What it did not establish

    Whether holding at Phase 0 was right. The phase was held because nothing in the last brief argued for moving it, which is a defensible reason and is not the same as evidence. The decision was recorded as a deliberate no-change so that it could later be argued with.

    Outcome

    A signed intent that names something it is willing to lose, a 21-day cadence on a calendar other people can see, and a threshold set before anyone knew what the cycle would find.

  9. D-3 11:10

    Beat 9, Five requirements were adopted for the cycle. The portal-reachability requirement was assigned to the hunt lead by name, with the SOC duty analyst as collector of record for the gateway pull. The dwell-basis requirement was carried forward from the previous cycle with the reason it survived.

    What it did not establish

    That the requirements are answerable with the collection the agency holds. Retention was not checked against any of them at Frame. That omission is what bounded the eventual result, and it cost nothing to make and could not be undone later.

    Outcome

    Five requirements, each with a named individual owner and a decision attached. One of them was already two cycles old.

    Authority

    No authority required

    Form

    None — an analytic beat, instantiating no maneuver.

    Controls
    Requirement
  10. D0 09:00

    Beat 10, The Authorizing Official designated the hunt against the portal-identity-to-records path as the cycle’s main effort, citing the crown-jewel record set as the decisive point it defends. Two competing candidates — a segmentation program and a recertification backlog — were named as supporting efforts and explicitly not resourced this cycle.

    What it did not establish

    That the hunt would find anything. The designation rests on a reachability result and an untested denial, which together are a reason to look and not a reason to expect. Nothing in the record predicted a finding, which is why the negative was survivable when it arrived.

    Outcome

    One main effort, one sentence of justification citing a decisive point, and two named efforts that were told they were not it.

  11. D0 11:20

    Beat 11, Rules of engagement for the hunt were set. Pre-authorized: read-only collection across identity, gateway, data-platform and flow telemetry, including the partner federation’s sign-in log; emplacement of decoys on any corridor already on the avenue list. Reserved to the Authorizing Official: any session revocation against a live portal identity, and any change inside the release freeze window.

    What it did not establish

    Where the operators would actually read it. The record was published to the governance repository and linked from the cycle brief. Nobody tested whether the hunt team could find it from the query console at the moment they needed it, and three days later somebody could not.

    Outcome

    A pre-authorized set wide enough that almost everything the hunt subsequently did was inside it — a fact that did not survive contact with the way it was published.

    Authority

    Standing ROE

    Form

    None — an analytic beat, instantiating no maneuver.

    Controls
  12. D+1 09:40

    Beat 12, The hypothesis was written in falsifiable form before any collection ran: a non-mission-staff identity has traversed the new gateway to the record-read path at least once in the last 90 days. The falsifier was written with it — the gateway access log would carry a caller principal outside the mission-staff directory, or the data-platform audit would carry a read whose caller cannot be resolved to one.

    What it did not establish

    Nothing at all, and that is what it is for. A hypothesis establishes only what would count as evidence. Writing it before collection is what stops the collection from deciding afterwards what it had found.

    Outcome

    One claim, one falsifier, one window, one population — and a window of 90 days that nobody had yet checked against any retention setting.

    Confidence — low

    Nothing had been observed. The confidence attaches to the collection’s ability to answer the question, not to the claim, and at this point the collection had not been inventoried.

  13. D+1 14:15

    Beat 13, The four sources the falsifier needs were inventoried with their actual retention: gateway access log 14 days, identity provider sign-in 90 days, data-platform audit 400 days, VPC flow 14 days. Public service abuse telemetry supplied the request-volume baseline the gateway query would be read against.

    What it did not establish

    That 14 days is enough. It established the horizon. Whether the horizon covers the interval that matters is a different question, and it was not asked until the arithmetic was done four days later — by which time the hunt had already been scoped as a 90-day question.

    Outcome

    Four sources, one of which — the only one that binds a caller to the record path — has a horizon shorter than the age of the change that prompted the hunt.

    Confidence — high

    Retention settings read from each platform’s own configuration rather than from the logging standard, which describes what was intended.

  14. D+2 08:50

    Beat 14, An authentication-geography baseline was pulled across the full 90-day identity window, to establish what the population looked like before the federation was added and what it looked like after.

    What it did not establish

    That an anomalous partner sign-in would have been visible. The baseline describes a population. A single federated partner identity behaving exactly like a partner identity sits inside that population by construction, and no percentile of it would have moved.

    Outcome

    A baseline that shifted measurably on the day the federation was added, and not since. Useful as context, useless as a discriminator.

    Authority

    Pre-authorized

    Form — M1 Screen / Guard
    Controls
  15. D+2 10:30

    Beat 15, Every mission-staff and partner identity with entitlement on the Case Processing System was checked against credential-exposure collection for the preceding twelve months. Six hits, all on personal addresses in unrelated third-party breaches, none of them reusable against a phishing-resistant authenticator.

    What it did not establish

    That no credential is exposed. Exposure collection sees what has been published. The credential worth having is the one still being sold privately, and no feed this agency holds would show it — so the six hits bound the answer at “nothing public”, not at “nothing”.

    Outcome

    Negative for the hypothesis. Six low-consequence hits routed to workforce readiness rather than to the hunt.

    Authority

    Pre-authorized

    Form — M1 Screen / Guard
    Controls
  16. D+2 13:30

    Beat 16, Every request through the new gateway to the record-read path was pulled for the full 14-day horizon and resolved to a caller principal — 41,200 calls. All resolved either to the mission-staff directory or to the two service principals the case system runs as. Not one row matched the falsifier.

    What it did not establish

    Anything about the interval between the cutover and the start of the horizon. The days immediately after a change are when a fresh authorization gap is most exposed and least noticed, and that is precisely the interval this query cannot see.

    Outcome

    Negative within the horizon, and the bound recorded on the same line as the result rather than in a footnote where it would be quoted without it.

    Confidence — moderate

    Complete within the source’s horizon, with every caller resolved rather than sampled. Moderate rather than high because the horizon, not the query, is the limitation.

  17. D+3 09:00D+2 13:55 — approval requested by the hunt leadD+3 09:00 — approval received, action unchanged

    Beat 17, Before pulling the partner federation’s sign-in log, the hunt lead raised an approval request and stopped work on that thread. The pull had been inside the pre-authorized set since the rules of engagement were published three days earlier. The approval came back 19 hours and 5 minutes later, unchanged, with a question from the Authorizing Official asking why it had been asked.

    What it did not establish

    What the delay cost. In this cycle it cost nineteen hours of a hunt with no adversary in it, which is close to nothing. The same nineteen hours under contact is the entire argument for having a pre-authorized set, and a cycle with no contact produces no way to price it.

    Outcome

    Recorded as an authority exception even though the action was inside the standing set — the exception is the asking, not the doing, and counting it is the only way the pattern becomes visible.

    This is a failure the manual already predictsManeuver — failure mode

    A pre-authorized action is escalated anyway.

    • The rules-of-engagement record lived in the governance repository, not beside the query console, so the hunt lead could not check it at 13:55 and asked instead.
    • The pre-authorized set had been widened three days earlier and never rehearsed. A set the shift cannot recite is a set the shift will not rely on.
    • The request was raised late on a Friday afternoon. A deputy approver was named in the record the hunt lead could not find.
    Authority

    Escalated to the AO1145 minutes waiting on the decision

    Form — M7 Counterattack
    Controls
  18. D+3 11:20

    Beat 18, Ninety days of federated partner sign-ins were pulled: 1,340 authentications from all 22 partner identities. None reached the gateway. All were bound to device-posture claims the partner asserts and this agency does not verify.

    What it did not establish

    That the partner identities are trustworthy. It established where they went, not what assurance stands behind them. The requirement’s decision does not turn on the second question, which is why the hunt stopped here and raised it as a separate finding rather than expanding.

    Outcome

    Negative for the hypothesis on the identity route. One finding raised against the partner agreement’s assurance clause, owned by governance rather than by the hunt.

    Confidence — moderate

    Complete across the identity provider’s 90-day horizon. The partner-side authenticator claims are self-asserted and were not corroborated.

    Authority

    Pre-authorized

    Form — M3 Envelopment
    Controls
    Requirement
  19. D+3 15:10

    Beat 19, Named-campaign indicator watch was re-run against the gateway product and the agency’s public hostnames across 90 days of sector and government reporting. No campaign names either.

    What it did not establish

    That no campaign is pointed at this estate. Absence from reporting is a statement about what has been published and attributed. The interval between an intrusion and its first public attribution is measured in months, so this negative is about the reporting community and not about the adversary.

    Outcome

    Negative, and explicitly labeled as a negative about attribution rather than about presence.

    Authority

    Pre-authorized

    Form — M1 Screen / Guard
    Controls
  20. D+4 10:05

    Beat 20, Four hundred days of data-platform audit were searched for reads of the Sensitive Mission Records set by any principal outside the data-access governance boundary. Eleven hits, all resolving to a quarterly reporting job whose service principal sits outside the boundary by design.

    What it did not establish

    That the reporting job is safe. The search resolved the hits and stopped. Why a job with standing read on the crown-jewel set authenticates with a static secret was not asked here — it went to the backlog as a separate finding, because answering it inside the hunt would have widened the hunt into a different investigation.

    Outcome

    Negative for the hypothesis, on the only source whose horizon covers the whole question. One incidental finding, which is the ordinary yield of a hunt.

    Confidence — high

    The data-platform audit log has a 400-day horizon and covers every read, so this is the one source in the account whose window exceeds the hypothesis window.

    Authority

    Pre-authorized

    Form — M2 Defense in Depth
    Controls
    Terrain
    Requirement
  21. D+4 15:40

    Beat 21, The two service principals the gateway calls resolved to owners. One had a named owner who had moved teams eight months earlier; the other had none, and had been created during the migration.

    What it did not establish

    Whether the unowned principal is used by anything current. Ownership and use are different questions. Only the first was answerable inside the hunt window, and answering the first is what made the second worth asking.

    Outcome

    Two ownership findings on the identity layer, neither of them evidence of an adversary and both of them the kind of ground an adversary would want.

    Authority

    Pre-authorized

    Form — M3 Envelopment
    Controls
  22. D+5 09:15

    Beat 22, The deception grid had not fired in 96 days. The first draft of the hunt record wrote that up as a negative result supporting the hypothesis’ rejection. A coverage measurement run against the current avenue list showed that four of the fourteen decoys sit on corridors the avenue analysis no longer lists, and that none sits on the gateway corridor the hypothesis names.

    What it did not establish

    That nothing walked the corridor. Silence from a grid that is not on the corridor is silence about the grid. The draft that read it as silence about the adversary would have raised the assessment’s confidence on no evidence whatsoever, which is worse than adding nothing.

    Outcome

    The negative was withdrawn before it reached the record. The grid’s silence was reclassified as uninformative, and re-siting went onto the cycle’s work rather than onto the backlog.

    Confidence — high

    Grid inventory compared element by element against the avenue list dated four days earlier. Both artifacts are current and the comparison is arithmetic.

    This is a failure the manual already predictsM5 Ambush — how it fails

    Coverage is never measured, so the grid drifts into the layers that were easy to instrument and away from the ones the threat courses of action actually run through.

    • The grid was sited two cycles ago against an avenue list that has since been re-derived twice, and nothing re-checks siting when the avenue list changes.
    • Decoy telemetry is reported as a count of interactions, which is zero whether the grid is perfectly sited or entirely misplaced.
    • The hunt record template accepted a null result from a named sensor without asking where the sensor was.
    Authority

    Pre-authorized

    Form — M5 Ambush
    Controls
    Requirement
  23. D+5 14:40

    Beat 23, Advisory intake was reviewed for the gateway product since the cutover. One advisory — a pre-authentication path traversal — had arrived and been dispositioned nine days before the hunt opened. The artifact registry records the patched build as deployed.

    What it did not establish

    That the version running is the version the registry records. The check compared the registry against the advisory. Nobody queried a running instance, and in this estate those two have disagreed before, in the direction of the registry being optimistic.

    Outcome

    Negative on the advisory route, with the caveat recorded as a caveat rather than dropped for being minor.

    Authority

    Pre-authorized

    Form — M1 Screen / Guard
    Controls
  24. D+6 14:00

    Beat 24, Three decoy service endpoints were emplaced on the gateway corridor, resembling the record-read path closely enough to be worth trying and holding nothing. Alert routing was tested with a synthetic trigger: 4 minutes from interaction to a human acknowledging it.

    What it did not establish

    Anything about the past, and not much about the worst case. A decoy emplaced on the sixth day is evidence from the sixth day onward, and the hunt’s question is about the ninety days before it. The routing test ran at 14:00 on a Tuesday, which is the easiest hour of the week to answer a page.

    Outcome

    Grid coverage against the current avenue list moved from 10 of 14 decoys on live avenues to 13 of 17. Implementation state recorded as operational at the point of emplacement rather than at the next reconciliation.

  25. D+7 10:00

    Beat 25, A devil’s-advocate pass — run by someone who had not executed any of the collection — asked which of the nine avenues the hunt had not touched. The answer was the maintenance route and the supplier route, both inherited unchanged at the avenue re-enumeration. Neither had been searched in the previous three cycles either.

    What it did not establish

    That the two routes are clear. It established that nobody had looked, which is a finding about the program rather than about the estate. The looking happened afterwards, and it found the only positive result the cycle produced.

    Outcome

    Scope widened by two avenues on the seventh day of a nineteen-day hunt, at the cost of the two days of analyst time that had been reserved for writing up.

    Confidence — high

    Three cycles of hunt records were read directly. Neither avenue appears in any of them, which is a matter of record rather than of recollection.

    This is a failure the manual already predictsM7 Counterattack — how it fails

    What was hunted is never accounted for, so coverage is anecdotal and the same three data sources are searched every cycle while two others are never searched at all.

    • Hunt coverage was accounted for at the end of a hunt rather than planned against the avenue list at the start, so nothing forced the comparison until the write-up.
    • The avenue list carried no marker distinguishing avenues re-derived this cycle from avenues copied forward, so the inherited three were invisible as inherited.
    • The maintenance and supplier routes are owned by facilities and procurement respectively, and neither owner reads a hunt backlog.
    Authority

    No authority required

    Form

    None — an analytic beat, instantiating no maneuver.

    Controls
  26. D+7 15:00

    Beat 26, The four suppliers with access to the case-processing estate were checked for disclosed compromise since the previous cycle. None had disclosed one. The check surfaced that the register’s access column for the migration contractor had not been touched since the cutover milestone.

    What it did not establish

    That the suppliers are uncompromised. It establishes that none has disclosed a compromise. The contract clause requires disclosure within 72 hours of the supplier knowing, not of it happening, and the gap between those two is where every supply-chain case in the sector has lived.

    Outcome

    Negative on disclosure, and one stale register field that sent the hunt down the supplier route the next morning.

    Authority

    Pre-authorized

    Form — M1 Screen / Guard
  27. D+8 11:45

    Beat 27, The supplier that ran the gateway migration still held brokered administrative access to the gateway’s configuration plane, granted for the cutover window and never expired — 61 days of standing access, with four sessions after the cutover. All four reconcile to change tickets raised by the agency.

    What it did not establish

    That the access was misused. Every session reconciles to a ticket. What this establishes is that the constraint failed, not that the supplier did, and those are different findings with different owners and very different consequences for the supplier.

    Outcome

    The hunt’s only positive finding, and it is a control failure rather than an adversary. Routed to the supplier-access constraint owner the same afternoon.

    Confidence — high

    The brokering system’s own session records, cross-read against the contract milestone dates held in procurement. Two independent systems, and they agree.

  28. D+9 09:30

    Beat 28, Physical access anomaly review ran over the quarter for the space holding the gateway’s management plane. Three badge events fell outside work-order windows; all three reconcile to a fire-alarm test with a signed escort record.

    What it did not establish

    Whether an escorted visitor did anything at a console. Badge records place a person in a room. They do not place their hands on a keyboard, and no console session log covers that room — which makes this negative a statement about presence and not about action.

    Outcome

    Negative on the maintenance route, with the fidelity limit stated on the same line so it cannot be quoted without it.

  29. D+11 10:20

    Beat 29, The observable horizon was reconstructed per source to establish how far back any negative result in this estate could reach at all: 14 days at the gateway, 14 at flow, 90 at identity, 400 at the data platform. The agency’s carried dwell estimate is 34 days, built entirely from closed cases.

    What it did not establish

    A dwell estimate. It established the ceiling on any dwell claim, which is not the claim. An estimate of 34 days sitting on top of a 14-day horizon at the only source that binds a caller to the objective is an estimate the collection cannot support in either direction.

    Outcome

    The carried estimate was left unchanged and its basis restated with the horizon mismatch attached. The requirement it serves was carried forward for a third cycle, with the reason written down.

    Confidence — moderate

    The horizons are configuration facts. What they imply about dwell is an inference, and it is an inference about what could be seen rather than about what happened.

  30. D+12 14:00

    Beat 30, A persistence sweep ran across the Mission-Staff Workstations with standing access to the case system: 240 of the 330 devices on the overlay carry an endpoint agent capable of the sweep. Nothing was found on the 240.

    What it did not establish

    Anything about the 90 unmanaged and contractor devices that authenticate to the same service. They carry no agent, so the sweep could not run on them. Their absence from the result is a coverage gap and was recorded as unmeasured rather than folded into a clean number.

    Outcome

    Negative across the population the sweep could reach, over a denominator taken from the terrain overlay rather than from the endpoint console — which would have reported 100%.

    Confidence — moderate

    Complete across the agent-carrying population, which is 73% of the population that matters. The remaining 27% is not evidence in either direction.

    Authority

    Pre-authorized

    Form — M7 Counterattack
    Controls
    Terrain
  31. D+14 09:00

    Beat 31, The coverage account was written: for each of the nine enumerated avenues, which sources were searched, over which window, at what fidelity, and what would have been visible had the hypothesis been true. Six avenues fully searched, two partially, one — the enterprise-to-operational crossing — not searched at all.

    What it did not establish

    That the ground searched is clear beyond its window. Every line in the account carries a horizon. Outside the horizon the account says nothing, which is deliberately different from saying clear, and the template refuses to render the two the same way.

    Outcome

    A coverage figure with the avenue list as its denominator. Computed against the avenues searched instead, the same hunt would have reported 100%.

  32. D+15 10:00

    Beat 32, Analysis of competing hypotheses was run over four hypotheses, including one in which the activity is not hostile and one in which an adversary operates inside the reporting job’s service principal and is therefore indistinguishable from it. The fourth survived on the evidence — nothing disconfirmed it — and nothing supported it either.

    What it did not establish

    That the path has never been used. The assessment is bounded by the shortest horizon in its own account, and a claim about ninety days cannot be made from fourteen days of the only evidence that binds a caller to the objective.

    Outcome

    The requirement was answered: no chain from a self-registered identity was exercised in the observable window, and the chain nonetheless exists on permitted paths. The requirement’s second branch applied — hold the boundary as drawn and record the denials carrying it — and the recording found that the number of denials carrying it was one.

    Confidence — moderate

    Four independent sources, each complete within its own horizon, none covering the interval between the cutover and the start of the gateway horizon. Moderate rather than high specifically because that uncovered interval is the one an opportunist would have used.

  33. D+15 15:20

    Beat 33, Two detections were authored from the queries the hunt had run by hand: any caller principal outside the mission-staff directory on the gateway record path, and any brokered supplier session on the gateway configuration plane outside a change window.

    What it did not establish

    That either detection works. Neither has fired. A detection that has never fired is untested rather than quiet, and both were recorded in that state rather than counted as coverage.

    Outcome

    Two production detections, both marked unvalidated, and a signpost attached to each saying what firing would mean.

  34. D+16 11:00

    Beat 34, On the fused assessment — a permitted chain that exists, a supplier constraint that failed, and a deception grid that had been sited off the live avenues for two cycles — the Authorizing Official declared Phase I against the case-processing scope, out of band. The declaration widened the hardening and deception effort and did not widen the fire set.

    What it did not establish

    That an adversary is present. Phase I is a statement about cost imposed on an adversary, not about contact with one. Declaring it on a negative result is this case’s most easily misread decision, and the declaration says so in its own text for exactly that reason.

    Outcome

    A phase change driven by terrain findings rather than by an alert, with cadence tightened from 21 days to 14 and the pre-authorized set left where it was.

    Authority

    Standing ROE

    Form

    None — an analytic beat, instantiating no maneuver.

    Controls
  35. D+17 10:30

    Beat 35, The untested denial was made a tested one. An explicit deny was added at the gateway for callers outside the mission-staff directory and the two case service principals, and the denial was then reconciled against seven days of flow telemetry before being recorded as denied.

    What it did not establish

    That the register is correct anywhere else. One denial was tested. The register holds 214, and 213 of them are in exactly the state this one was in on the day the assumptions check found it.

    Outcome

    One permitted path closed and evidenced. Reachability from the public identity tier to the record path recomputed as denied, this time on telemetry rather than on configuration.

  36. D+17 15:00D+17 13:25 — request raised inside the release freeze windowD+17 15:00 — revocation executed

    Beat 36, The migration contractor’s standing access to the gateway configuration plane was revoked and re-issued as time-bounded brokered access per work order. Because the revocation landed inside the release freeze window it needed the Authorizing Official; the decision took 1 hour 35 minutes, which is what an escalation costs when the approver knows the question is coming.

    What it did not establish

    Whether the same pattern exists on the other thirty suppliers. One register entry was corrected. The reconciliation against procurement records that would find the rest went to the backlog with a date and, at cycle close, no owner.

    Outcome

    Standing supplier access to a decisive point removed 61 days after it should have expired, and a second escalation whose latency is worth having next to the first one.

    Authority

    Escalated to the AO95 minutes waiting on the decision

    Form — M4 Obstacle / Canalization
    Controls
  37. D+18 09:20

    Beat 37, The overlay was updated from the hunt rather than from the calendar: the gateway’s adjacencies filled in, the supplier’s access edge corrected, the two unowned service principals recorded with the owner the review assigned them, and the three inherited avenues marked as inherited.

    What it did not establish

    That the overlay is current anywhere the hunt did not go. The elements the hunt touched are current as of today. Everything else carries the age it had at the start of the cycle, and the overlay’s reported staleness was left at that age rather than at the age of its newest entry.

    Outcome

    Four corrections, one new marker on the avenue list, and a staleness figure that did not improve because three elements being fresh does not make an overlay fresh.

  38. D+18 14:00

    Beat 38, The negative result was written into the cycle record as a first-class finding carrying six fields: scope, window, fidelity, falsifier, expiry and owner. Signed by the hunt lead, countersigned by governance. The expiry is tied to the gateway’s horizon — fourteen days after the last search, the clearance is stale and the avenue returns to the hunt backlog.

    What it did not establish

    That the ground stays cleared. It does not, and the record says when it stops. The one thing the field prevents is the failure this whole practice exists to prevent: a clearance quoted in three cycles’ time by someone who was not there and cannot see its bound.

    Outcome

    A negative result another analyst can audit, disagree with, and — for fourteen days — decline to repeat.

    Confidence — high

    The record is a transcription of the coverage account and the fused assessment, both of which are themselves sourced. Nothing in it is a summary judgment.

    Authority

    No authority required

    Form

    None — an analytic beat, instantiating no maneuver.

    Controls
  39. D+19 11:00

    Beat 39, The brief led with the negative and its bound, not with the supplier finding. Temporal advantage was reported as not computed: a cycle with no contact produces no defender decision loop, and reporting the threshold as met on an empty numerator was refused in the drafting.

    What it did not establish

    Whether this program is winning. Its only effectiveness measure needs contact to produce a number, and this cycle had none. The honest entry is a gap, and a gap is what an oversight reader will ask about — which is the correct outcome and the reason it is tempting to fill in.

    Outcome

    A distributed brief whose headline is a bounded negative, whose scoreboard line is blank, and whose backlog is re-ranked with the untested-denial reconciliation above eleven higher-volume items.

  40. D+19 15:30

    Beat 40, The reachability requirement retired on a recorded result plus a boundary statement in the authorization package. The deception requirement retired on the re-siting. The dwell-basis requirement was carried forward for a third cycle. Two new requirements were raised: supplier standing-access reconciliation, and gateway log retention against the hypothesis windows the hunt program actually asks.

    What it did not establish

    That the carried-forward requirement will be answered next cycle. It has now survived two cycle boundaries. The record notes that a third would make it a standing wish rather than a priority, which is a note written to be uncomfortable to read next Frame.

    Outcome

    Two requirements retired on their stated conditions, one carried with a reason and a warning, two raised from findings that had nothing to do with the hypothesis.

    Authority

    No authority required

    Form — M10 Exploitation & Pursuit
    Controls
Where It Went Wrong

Each of These Is a Failure the Manual Already Predicts.

A case study in which nothing goes wrong is a brochure. Each failure below points at the framework’s own published prediction of it — inventing a novel failure the doctrine never anticipated would be a finding about the doctrine rather than a story beat.

The deception grid’s silence was one draft away from becoming evidence

What happened

Ninety-six days of silence from the deception grid was written into the first draft of the hunt record as a negative result supporting the hypothesis’ rejection. It was not. Four of the fourteen decoys sat on corridors the avenue analysis had stopped listing two cycles earlier, and none sat on the corridor the hypothesis names. Had the draft stood, the assessment’s confidence would have risen on a sensor that was not pointed at the question.

Predicted byM5 Ambush — how it fails

Coverage is never measured, so the grid drifts into the layers that were easy to instrument and away from the ones the threat courses of action actually run through.

What changed as a result

Coverage measurement now runs before a null result from the grid may be cited, and the hunt record template refuses a negative from any sensor whose siting has not been reconciled against the current avenue list in the same cycle. Three decoys were emplaced on the gateway corridor during the hunt. What has not changed is the trigger: nothing re-checks siting when the avenue list is re-derived, so this will recur the next time the map moves and nobody re-reads the grid.

Two avenues had been carried forward unexamined for four cycles

What happened

Three of the nine avenues were copied forward at the map refresh because nothing had obviously moved on them, and the copying was not marked. Two of those three — the maintenance route and the supplier route — had not been searched in any of the previous three cycles either. Neither was in this hunt’s scope. Both were added on the seventh day only because a devil’s-advocate pass asked what had not been searched, and the hunt’s single positive finding was sitting on one of them.

Predicted byM7 Counterattack — how it fails

What was hunted is never accounted for, so coverage is anecdotal and the same three data sources are searched every cycle while two others are never searched at all.

What changed as a result

Hunt coverage accounting moved from a closing artifact to an exit condition, computed against the enumerated avenue list rather than against the avenues searched, and the avenue list now marks which entries were re-derived this cycle and which were inherited. The deeper cause is untouched: the maintenance and supplier routes are owned by facilities and by procurement, and neither owner reads a hunt backlog.

A pre-authorized action was escalated anyway, and cost nineteen hours

What happened

The hunt lead stopped work and requested approval to pull the partner federation’s sign-in log. The pull had been inside the pre-authorized set for three days. The approval returned unchanged after 19 hours and 5 minutes, which is 92% of this cycle’s entire authority tax spent on an action nobody needed to approve.

Predicted byManeuver — failure mode

A pre-authorized action is escalated anyway.

What changed as a result

The pre-authorized set is now rendered in the hunt console beside the query editor, with the named approver and deputy next to it, rather than living only in the governance repository. Whether that works is a next-cycle question — it has not been tested out of hours, and the framework is explicit that a set the shift cannot recite is a set the shift will not rely on.

The reachability result the cycle opened with rested on one untested denial

What happened

Last cycle’s headline map finding — that the crown-jewel read path was not reachable from the public identity tier — depended on a single denied path, asserted from a firewall policy export and never reconciled against flow telemetry. The register records assertions and reconciliations in the same column, so nothing distinguished the two. The finding was the previous cycle’s best work, which made it the least likely entry in the register to be re-examined.

Predicted byMap — failure mode

Denied paths are asserted from configuration and never tested.

What changed as a result

That one denial is now tested and evidenced against seven days of flow telemetry, and the register has been given a separate reconciliation-date field so an assertion can no longer be mistaken for a test. The other 213 entries are in exactly the state this one was in. The reconciliation is on the backlog with a date and, at cycle close, no owner.

4 individual beats also carry a pointer to a published failure mode, marked in the record above.

What It Measured

Including the Thresholds It Missed.

8 measures: 2 met, 4 missed and 2 that could not be computed at all — counted off the table rather than typed above it. Every metric carries the method that produced it, because a metric with no method is a claim, and a case that reports only the thresholds it met is reporting a biased sample and then reasoning from it.

MeasureValueAgainst its own thresholdHow it was computedWhat that means
Avenues searched, against the enumerated avenue list6 of 9 in full, 2 partially, 1 not at allNot metCounted from the coverage account against the avenue-of-approach list current at the time of writing. The denominator is the avenue list, not the list of avenues the hunt happened to touch — computed the second way the same hunt reports 100%.The stated exit condition was that every enumerated avenue be searched or explicitly deferred with a reason. The enterprise-to-operational crossing was neither, and is recorded as not searched.
Interval the negative result cannot reach1d 20h 50mNot metDerived from three inputs: the cutover timestamp on the first beat, the retro-hunt timestamp on the gateway beat, and the gateway access log’s 14-day retention. Not asserted anywhere — subtracted.The threshold set with the hypothesis was full coverage of the interval since the change that prompted it. Missing the opening interval of a new authorization surface is missing the most exposed part of the window, and the miss was fixed at Frame by not checking retention against the question.
Authority tax20h 40m across 2 escalationsNot metSummed over the beats whose authority is recorded as escalated, using the same function the site computes it with for any case. Both escalations carry a decision time and an effective time.One of the two escalations was against an action already inside the pre-authorized set. Under contact that one is the whole argument for the set; here it cost nineteen hours of a hunt nobody was racing.
Hunt band elapsed, against the declared cycle cadence17d 4h 20m against a 21-day cadenceMetMeasured between the first and last in-band beat. The cadence is the one declared at Frame, before anyone knew what the hunt would find.It fitted, and it fitted only because the write-up absorbed the two days the scope widening cost. The band sits inside a case that runs 32d 22h 50m from the terrain change that started it to the brief that closed it — the hunt is the short part.
Persistence sweep population240 of 330 devices (73%)Not metThe denominator is every device with standing access to the case system, taken from the terrain overlay. Taken from the endpoint console instead — the count of devices carrying an agent — the same sweep reports 100%.The 90 devices outside the sweep are recorded as unmeasured. Unmeasured is a worse finding than poorly covered, and it is the one that gets quietly excluded.
Temporal advantageNot computedNot computedThe ratio needs a measured defender decision loop, and a cycle with no contact produces none. Reporting the threshold as met on an empty numerator was refused at Assess.This is the correct entry for a proactive cycle and it is the one most often filled in anyway, because a blank scoreboard line invites a question and a green one does not.
Positive findings1 control finding, 0 adversary findingsNot computedCounted from the beats whose outcome records a positive result. The program deliberately sets no threshold on this figure: a target for positive findings is an incentive to produce them.The single positive — standing supplier access that outlived its work order — was found on an avenue the hunt had not planned to search.
Detections authored from the hunt2, neither of which has firedMetCounted from the indicators and signposts produced at Fuse. Firing is not counted toward the figure, because a detection that has never fired is untested rather than working.The threshold is at least one production detection per hunt, on the principle that a hunt nobody can automate any part of will be re-run by hand forever.

Avenues searched, against the enumerated avenue list

Value
6 of 9 in full, 2 partially, 1 not at all
Against its own threshold
Not met
How it was computed
Counted from the coverage account against the avenue-of-approach list current at the time of writing. The denominator is the avenue list, not the list of avenues the hunt happened to touch — computed the second way the same hunt reports 100%.
What that means
The stated exit condition was that every enumerated avenue be searched or explicitly deferred with a reason. The enterprise-to-operational crossing was neither, and is recorded as not searched.

Interval the negative result cannot reach

Value
1d 20h 50m
Against its own threshold
Not met
How it was computed
Derived from three inputs: the cutover timestamp on the first beat, the retro-hunt timestamp on the gateway beat, and the gateway access log’s 14-day retention. Not asserted anywhere — subtracted.
What that means
The threshold set with the hypothesis was full coverage of the interval since the change that prompted it. Missing the opening interval of a new authorization surface is missing the most exposed part of the window, and the miss was fixed at Frame by not checking retention against the question.

Authority tax

Value
20h 40m across 2 escalations
Against its own threshold
Not met
How it was computed
Summed over the beats whose authority is recorded as escalated, using the same function the site computes it with for any case. Both escalations carry a decision time and an effective time.
What that means
One of the two escalations was against an action already inside the pre-authorized set. Under contact that one is the whole argument for the set; here it cost nineteen hours of a hunt nobody was racing.

Hunt band elapsed, against the declared cycle cadence

Value
17d 4h 20m against a 21-day cadence
Against its own threshold
Met
How it was computed
Measured between the first and last in-band beat. The cadence is the one declared at Frame, before anyone knew what the hunt would find.
What that means
It fitted, and it fitted only because the write-up absorbed the two days the scope widening cost. The band sits inside a case that runs 32d 22h 50m from the terrain change that started it to the brief that closed it — the hunt is the short part.

Persistence sweep population

Value
240 of 330 devices (73%)
Against its own threshold
Not met
How it was computed
The denominator is every device with standing access to the case system, taken from the terrain overlay. Taken from the endpoint console instead — the count of devices carrying an agent — the same sweep reports 100%.
What that means
The 90 devices outside the sweep are recorded as unmeasured. Unmeasured is a worse finding than poorly covered, and it is the one that gets quietly excluded.

Temporal advantage

Value
Not computed
Against its own threshold
Not computed
How it was computed
The ratio needs a measured defender decision loop, and a cycle with no contact produces none. Reporting the threshold as met on an empty numerator was refused at Assess.
What that means
This is the correct entry for a proactive cycle and it is the one most often filled in anyway, because a blank scoreboard line invites a question and a green one does not.

Positive findings

Value
1 control finding, 0 adversary findings
Against its own threshold
Not computed
How it was computed
Counted from the beats whose outcome records a positive result. The program deliberately sets no threshold on this figure: a target for positive findings is an incentive to produce them.
What that means
The single positive — standing supplier access that outlived its work order — was found on an avenue the hunt had not planned to search.

Detections authored from the hunt

Value
2, neither of which has fired
Against its own threshold
Met
How it was computed
Counted from the indicators and signposts produced at Fuse. Firing is not counted toward the figure, because a detection that has never fired is untested rather than working.
What that means
The threshold is at least one production detection per hunt, on the principle that a hunt nobody can automate any part of will be re-run by hand forever.
Who Acted

Counted, Not Characterized.

Exactly one role acts on each beat. Shared action is not action, and a case in which everybody contributes to everything cannot be used to argue for a staffing model.

RoleBeats ledBeats supportedWhat the role owns
Hunt teamHUNT1513Counterattack. Works the hypotheses that Fuse raises.
Cyber Threat Intelligence cellCTI129Frame, Map and Fuse. The intelligence requirements, the threat courses of action, and the confidence levels.
Platform and product ownersPLAT710Their own terrain. Obstacles get emplaced on their ground, so they site them.
Authorizing Official / CISOAO36Intent, risk acceptance, and the scheme itself.
Governance / RMF / ISSOISSO211Translating cycle outputs into FISMA and RMF artifacts, and owning the rules of engagement.
SOC / Defensive OperationsSOC111Maneuver. Executes fires and emplaces obstacles inside the standing rules of engagement.

Hunt team

HUNT

Beats led
15
Beats supported
13
What the role owns
Counterattack. Works the hypotheses that Fuse raises.

Cyber Threat Intelligence cell

CTI

Beats led
12
Beats supported
9
What the role owns
Frame, Map and Fuse. The intelligence requirements, the threat courses of action, and the confidence levels.

Platform and product owners

PLAT

Beats led
7
Beats supported
10
What the role owns
Their own terrain. Obstacles get emplaced on their ground, so they site them.

Authorizing Official / CISO

AO

Beats led
3
Beats supported
6
What the role owns
Intent, risk acceptance, and the scheme itself.

Governance / RMF / ISSO

ISSO

Beats led
2
Beats supported
11
What the role owns
Translating cycle outputs into FISMA and RMF artifacts, and owning the rules of engagement.

SOC / Defensive Operations

SOC

Beats led
1
Beats supported
11
What the role owns
Maneuver. Executes fires and emplaces obstacles inside the standing rules of engagement.
What It Consumed and Produced

The Artifacts, with the Beats on Each Side of Them.

A product with no consumer is overhead. Reading down this table is the fastest way to see which artifacts were load-bearing in this case and which were written because the process said to.

ArtifactWhat it isProduced atConsumed at
Defensive intent paragraphOne signed paragraph stating what the defense exists to protect, what may be degraded to protect it, and the acceptable risk. The commander’s-intent analog, and the citation every downstream designation rests on.
Priority Cyber Intelligence RequirementsThree to seven questions the cycle will try to answer, each naming the decision it informs, the collection source expected to answer it, and an individual owner.
Phase declarationThe declared campaign phase and the scope it is declared against. Sets cadence, dominant forms of maneuver, and how wide the pre-authorization set runs.
Cycle cadence and calendarThe declared length of a cycle, its close date, and the refresh intervals that inherit from it. Makes “per cycle” a measurable unit rather than a figure of speech.
Temporal advantage thresholdThe number the cycle will be judged against: defender decision loop versus adversary dwell, stated with units before the cycle runs.
Cyber Terrain OverlayThe positional map of the estate: every element with a defensive layer, a defensive weight, a named accountable owner and its adjacencies. Not an asset inventory — an inventory enumerates, an overlay positions.
Trust zones and the connection registerThe zone boundaries and the permitted- and denied-path register — the graph reachability is actually walked over, reconciled against observed flow telemetry rather than against intended configuration.
Decisive point registerThe elements whose control confers decisive advantage — each carrying the evidence that raised it above merely important, and the protection floor it owes as a result.
Avenue-of-approach analysisThe enumerated routes an adversary could take toward each decisive point, including physical, supplier and maintenance routes, with unassessed routes recorded as intelligence gaps rather than as absence of risk.
Adversary reachability assessmentThe formal result: from each entry point, which decisive points are reachable over the permitted-path graph. The framework’s hardest single finding, and the headline of the brief when it changes.
Barrier sufficiency registerThe specific barriers holding the line where reachability is prevented, each with a named enforcing owner. What the reachability result depends on, made explicit so its erosion is visible.
Threat course-of-action sketchTwo courses of action, most likely and most dangerous, drawn against the decisive points already designated. Each is a route across ground the estate really has, not a category of threat.
Scheme of maneuverOne graphic and one narrative: which forms of maneuver are sited where, in what sequence. The assignment record behind it carries the element, the avenue and the implementation state for every move.
Main effort designationThe single designated main effort for the cycle, and the sentence citing the decisive point that justifies it. The answer to which work wins when two things need the same engineer.
Rules of engagementWhich defensive actions may be taken by whom without escalation, which need the Authorizing Official, and what is prohibited outright. The cyber analog of engagement authority, and the single largest determinant of tempo.
Pre-authorized response setThe specific containment and response actions the SOC may execute at machine speed, bounded by the statutory availability floor. Directly measurable: it shortens the decision segment of the defender loop.
Change recordEvery defensive action carried out, stamped twice — at the decision and at the effect. A thin, unglamorous table, and the one the headline metric is computed from.
Implementation state recordPlanned, partial or operational, per maneuver assignment. The mechanism that stops intended work being counted as deployed protection.
Authority exception logActions taken outside the standing rules of engagement, with who approved them and why. Exceptions are not failures; unrecorded exceptions are.
Defender decision loop measurementDetect to decide to contain, measured per incident from the change record’s timestamps and reported as a distribution rather than as a mean.
Fused assessmentWhat the cycle’s intelligence requirements returned: each answer graded for confidence and showing its working, and each requirement left unanswered recorded against the collection gap responsible.
Adversary dwell estimateThe estimated time an adversary could operate undetected in this estate, with its basis stated — measured dwell, sector reporting, or partner intelligence — and its bias acknowledged.
Cyber Running EstimateThe living situational picture the SOC, hunt and intelligence cell share: current posture, current assessments and their confidence, open requirements, and what has moved since the last look.
Indicators and signpostsFor each surviving hypothesis, the observable events that would confirm or kill it, handed to collection. The mechanism that makes this cycle’s analysis into next cycle’s requirements.
Hunt results, including negative resultsWhat was hunted, how, and what was not found. Negative results are the half most often discarded, and they are the half that says what has actually been cleared.
Coverage and residual risk resultCoverage and residual risk computed over the whole overlay population, weighted by consequence, discounted by implementation state and corrected by validated effectiveness — with the denominator stated.
Temporal advantage resultDefender decision loop against adversary dwell, reported as a ratio against the threshold set at Frame, with the result written as a word: met, or not met. The framework’s single honest scoreboard.
Remediation backlogThe ranked list of what to fix, ordered by residual risk, main-effort weighting, and decisive-point floor breaches — which sit above higher-volume, lower-weight work regardless of count.
Findings disposition recordEvery finding with an outcome: remediate with an owner and a date, accept with a named accepter and an expiry, or transfer with the party named. “Under review” is not a disposition.
Cycle record and trendThe closed record of the cycle — posture, loop measurement, conclusions and their confidence, backlog state at close — and the trend across cycles that makes a second cycle worth more than a first.
Cycle briefThe published product: terrain, reachability, main effort, temporal advantage, coverage, trend, and the top-ranked backlog items — each confidence-tagged. Also the evidence that feeds the next intent.
Statutory availability floorThe mission services whose availability is set by statute or regulation, and the floor below which degradation stops being a defensive choice. Bounds what may be pre-authorized and what may be degraded under contact.
Privacy and controlled-information terrain registerWhere privacy holdings and controlled unclassified information sit, the authorities under which they are held, and the boundaries their handling requires — expressed as denied paths, not as policy statements.
Tenancy and inheritance boundary recordWhat is inherited from a provider and what remains the agency’s, drawn from provider authorization packages and responsibility matrices, so inherited mitigation is counted once and correctly.
Privileged human registerWhich individuals hold which high-consequence access, reconciled against the identity system rather than against the last access review spreadsheet.
Facility terrain registerWhere elements physically are, which personnel populations are associated with each site, and which facilities carry mission services.
Maintenance access recordWho may perform maintenance in which zone, under what escort and in what window — including supplier maintenance, which is where standing physical access usually hides.
Supplier terrain registerSuppliers as external actors on the overlay, with the access each holds, the paths that access implies, and the contract behind it.
Component provenance recordWhere components came from, from inventories, build manifests and supplier attestations — and which components have an origin that cannot be verified.
Supplier access constraint recordHow supplier access is brokered, time-bounded and constrained — and the prohibition on standing supplier access to designated decisive points.

Defensive intent paragraph

What it is
One signed paragraph stating what the defense exists to protect, what may be degraded to protect it, and the acceptable risk. The commander’s-intent analog, and the citation every downstream designation rests on.
Produced at

Priority Cyber Intelligence Requirements

What it is
Three to seven questions the cycle will try to answer, each naming the decision it informs, the collection source expected to answer it, and an individual owner.
Produced at

Phase declaration

What it is
The declared campaign phase and the scope it is declared against. Sets cadence, dominant forms of maneuver, and how wide the pre-authorization set runs.
Consumed at

Cycle cadence and calendar

What it is
The declared length of a cycle, its close date, and the refresh intervals that inherit from it. Makes “per cycle” a measurable unit rather than a figure of speech.
Produced at
Consumed at

Temporal advantage threshold

What it is
The number the cycle will be judged against: defender decision loop versus adversary dwell, stated with units before the cycle runs.
Produced at
Consumed at

Cyber Terrain Overlay

What it is
The positional map of the estate: every element with a defensive layer, a defensive weight, a named accountable owner and its adjacencies. Not an asset inventory — an inventory enumerates, an overlay positions.

Trust zones and the connection register

What it is
The zone boundaries and the permitted- and denied-path register — the graph reachability is actually walked over, reconciled against observed flow telemetry rather than against intended configuration.
Produced at

Decisive point register

What it is
The elements whose control confers decisive advantage — each carrying the evidence that raised it above merely important, and the protection floor it owes as a result.
Produced at
Consumed at

Avenue-of-approach analysis

What it is
The enumerated routes an adversary could take toward each decisive point, including physical, supplier and maintenance routes, with unassessed routes recorded as intelligence gaps rather than as absence of risk.
Produced at

Adversary reachability assessment

What it is
The formal result: from each entry point, which decisive points are reachable over the permitted-path graph. The framework’s hardest single finding, and the headline of the brief when it changes.
Produced at

Barrier sufficiency register

What it is
The specific barriers holding the line where reachability is prevented, each with a named enforcing owner. What the reachability result depends on, made explicit so its erosion is visible.
Produced at
Consumed at

Threat course-of-action sketch

What it is
Two courses of action, most likely and most dangerous, drawn against the decisive points already designated. Each is a route across ground the estate really has, not a category of threat.
Produced at

Scheme of maneuver

What it is
One graphic and one narrative: which forms of maneuver are sited where, in what sequence. The assignment record behind it carries the element, the avenue and the implementation state for every move.
Produced at
Consumed at

Main effort designation

What it is
The single designated main effort for the cycle, and the sentence citing the decisive point that justifies it. The answer to which work wins when two things need the same engineer.
Produced at
Consumed at

Rules of engagement

What it is
Which defensive actions may be taken by whom without escalation, which need the Authorizing Official, and what is prohibited outright. The cyber analog of engagement authority, and the single largest determinant of tempo.
Produced at
Consumed at

Pre-authorized response set

What it is
The specific containment and response actions the SOC may execute at machine speed, bounded by the statutory availability floor. Directly measurable: it shortens the decision segment of the defender loop.
Produced at
Consumed at

Change record

What it is
Every defensive action carried out, stamped twice — at the decision and at the effect. A thin, unglamorous table, and the one the headline metric is computed from.
Consumed at

Implementation state record

What it is
Planned, partial or operational, per maneuver assignment. The mechanism that stops intended work being counted as deployed protection.
Consumed at

Authority exception log

What it is
Actions taken outside the standing rules of engagement, with who approved them and why. Exceptions are not failures; unrecorded exceptions are.
Consumed at

Defender decision loop measurement

What it is
Detect to decide to contain, measured per incident from the change record’s timestamps and reported as a distribution rather than as a mean.
Produced at
Consumed at

Fused assessment

What it is
What the cycle’s intelligence requirements returned: each answer graded for confidence and showing its working, and each requirement left unanswered recorded against the collection gap responsible.
Produced at

Adversary dwell estimate

What it is
The estimated time an adversary could operate undetected in this estate, with its basis stated — measured dwell, sector reporting, or partner intelligence — and its bias acknowledged.
Produced at
Consumed at

Cyber Running Estimate

What it is
The living situational picture the SOC, hunt and intelligence cell share: current posture, current assessments and their confidence, open requirements, and what has moved since the last look.
Produced at
Consumed at

Indicators and signposts

What it is
For each surviving hypothesis, the observable events that would confirm or kill it, handed to collection. The mechanism that makes this cycle’s analysis into next cycle’s requirements.
Produced at

Hunt results, including negative results

What it is
What was hunted, how, and what was not found. Negative results are the half most often discarded, and they are the half that says what has actually been cleared.

Coverage and residual risk result

What it is
Coverage and residual risk computed over the whole overlay population, weighted by consequence, discounted by implementation state and corrected by validated effectiveness — with the denominator stated.
Produced at

Temporal advantage result

What it is
Defender decision loop against adversary dwell, reported as a ratio against the threshold set at Frame, with the result written as a word: met, or not met. The framework’s single honest scoreboard.
Produced at
Consumed at

Remediation backlog

What it is
The ranked list of what to fix, ordered by residual risk, main-effort weighting, and decisive-point floor breaches — which sit above higher-volume, lower-weight work regardless of count.
Produced at
Consumed at

Findings disposition record

What it is
Every finding with an outcome: remediate with an owner and a date, accept with a named accepter and an expiry, or transfer with the party named. “Under review” is not a disposition.
Produced at
Consumed at

Cycle record and trend

What it is
The closed record of the cycle — posture, loop measurement, conclusions and their confidence, backlog state at close — and the trend across cycles that makes a second cycle worth more than a first.

Cycle brief

What it is
The published product: terrain, reachability, main effort, temporal advantage, coverage, trend, and the top-ranked backlog items — each confidence-tagged. Also the evidence that feeds the next intent.
Produced at
Consumed at

Statutory availability floor

What it is
The mission services whose availability is set by statute or regulation, and the floor below which degradation stops being a defensive choice. Bounds what may be pre-authorized and what may be degraded under contact.
Produced at

Privacy and controlled-information terrain register

What it is
Where privacy holdings and controlled unclassified information sit, the authorities under which they are held, and the boundaries their handling requires — expressed as denied paths, not as policy statements.
Produced at
Consumed at

Tenancy and inheritance boundary record

What it is
What is inherited from a provider and what remains the agency’s, drawn from provider authorization packages and responsibility matrices, so inherited mitigation is counted once and correctly.
Produced at
Consumed at

Privileged human register

What it is
Which individuals hold which high-consequence access, reconciled against the identity system rather than against the last access review spreadsheet.
Produced at
Consumed at

Facility terrain register

What it is
Where elements physically are, which personnel populations are associated with each site, and which facilities carry mission services.
Produced at
Consumed at

Maintenance access record

What it is
Who may perform maintenance in which zone, under what escort and in what window — including supplier maintenance, which is where standing physical access usually hides.
Produced at
Consumed at

Supplier terrain register

What it is
Suppliers as external actors on the overlay, with the access each holds, the paths that access implies, and the contract behind it.
Produced at

Component provenance record

What it is
Where components came from, from inventories, build manifests and supplier attestations — and which components have an origin that cannot be verified.
Produced at
Consumed at

Supplier access constraint record

What it is
How supplier access is brokered, time-bounded and constrained — and the prohibition on standing supplier access to designated decisive points.
Produced at
Everything It Cited

The Whole Citation Index, Resolved.

Each identifier links to its own entry in the reference manual, and each carries the beats it appears in. This is the section that makes the case checkable rather than merely readable.

Controls (39)

Techniques (27)

Terrain (8)

What This Is Not Evidence Of

Stated Here so It Cannot Be Over-Read.

One worked case is one worked case. The limits below are the claims a reader might reasonably draw from it that it does not actually support.

The other case runs the opposite posture: The intrusion that made the agency choose between watching and stoppingreactive hunt, 39 beats. The two are meant to be read against each other, and the contrast between them is computed rather than asserted.