The hunt that found nothing, and what that was worth
Two changes landed on the same ground in one change window: a record-read path moved behind a new API gateway, and a partner federation was added to the identity plane. Neither was an incident and neither generated an alert. What they did was invalidate a denied path that last cycle’s headline map finding depended on — a denial asserted from a configuration export and never once reconciled against telemetry. The cycle commissioned a hunt against a hypothesis rather than against an adversary, ran it across the nineteen days from commissioning to brief, and found nobody. What it produced instead is a bounded statement of cleared ground, one control failure it was not looking for, and a precise account of the three avenues nobody in this program has searched in four cycles.
Everything here is modeled against the Federal Reference Agency. This is not a report of an event at a named agency. The estate is a composite drawn from public doctrine and the published agency archetypes; the beats are authored. What is not authored is the machinery — every control, technique, terrain layer, product and requirement below resolves against the published data, and a citation that does not resolve fails the build.
The Trigger, and the Ground It Starts On.
A proactive hunt may legitimately enter the loop at frame or map, and where it enters decides almost everything after — which forms are available, what its authority costs, and what a good outcome even looks like.
What Started It
The trigger
- Trigger
- No alert. A terrain change plus an assumption somebody was willing to write down: that a denied path nobody had tested was still holding after the ground on both sides of it moved.
- Where it enters the loop
- map — a proactive hunt may legitimately enter at frame or map.
- Phases traversed
- 0 Shape (33) → I Deter (7)
The Ground in Play
Federal Reference Agency slots
- Public Service Portal
- Case Filing System
- Case Processing System
- CI/CD Pipeline
- ICAM / PDP
- Sensitive Mission Records
- Mission-Staff Workstations
- Terrain touched
- 8 of 10 layers. Never touched: T6 Operational Technology, T7 Workforce — which is usually the more interesting list.
What the Hunt Was Actually Asked.
Every requirement carries the decision that changes on the answer. One that changes nothing either way is an audit, and should be scheduled as one rather than run as a hunt.
The decision it changes: Whether the portal’s trust boundary stands as drawn in the next authorization package, or is re-scoped before that package is signed.
The decision it changes: Whether the next segmentation obstacle is emplaced at the east–west boundary or at the egress boundary. One can be funded and staffed this cycle.
The decision it changes: Whether this cycle’s main effort is terrain currency rather than any form of maneuver at all — you cannot array a scheme against ground you have not mapped.
The decision it changes: Whether to fund a hunt campaign aimed specifically at the blind interval, or to carry the current estimate into the running estimate as stated.
The decision it changes: Whether to re-site the deception grid onto the avenues that reachability analysis says are live, or to leave it in place and read the silence as evidence of absence.
Which Forms Were Used, and Where the Work Actually Sat.
Each figure is counted off the beats rather than declared. A case that claims one posture and spends its beats in the other’s band is describing something other than what it says it is.
Forms of Maneuver Exercised
Gain early warning and buy reaction time before the adversary touches key terrain.
Seize the initiative and evict before the adversary reaches the objective.
Make identity, not network location, the decisive plane — surround the adversary with policy.
Convert contact into durable advantage rather than closing the ticket.
Where the Beats Sat
- 01 Frame — 3 beats, 0 in the hunt band.
- 02 Map — 7 beats, 0 in the hunt band.
- 03 Array — 3 beats, 1 in the hunt band.
- 04 Maneuver — 21 beats, 21 in the hunt band.
- 05 Fuse — 3 beats, 3 in the hunt band.
- 06 Assess — 3 beats, 1 in the hunt band.
Maneuver Bands
- shaping — 16 beats.
- contact — 11 beats.
- consolidation — 2 beats.
Authority
20h 40m spent waiting on 2 escalations. Under contact that is priced in adversary dwell; out of contact it is nearly free, which is why it is worth measuring out of contact first.
- Beat 17 · D+3 09:00 — 1145 minutes waiting on the decision.
- Beat 36 · D+17 15:00 — 95 minutes waiting on the decision.
The Operating Loop, with This Case’s Beats Counted onto It
Frame
Screen · Analytic Design step 1
Map
Cyber Preparation of the Environment — the IPB analog
Array
Design the scheme
Maneuver
Execute
Fuse
Analyze · Integrate
Assess
Produce · re-frame
↺ Re-frame — the loop turns faster than the adversary adapts
Where Its Weight Fell
Beats per step, counted from the timeline. The case enters at Map and puts most of its weight on Maneuver.
Which Campaign Phases It Crossed
The loop turns inside a phase; the phase changes when the Authorizing Official declares it. The two clocks are separate on purpose, and a case that crosses phases is showing both of them.
- Phase 0 · Shape33 beatsSet conditions
- Phase I · Deter7 beatsRaise adversary cost
Checked Against the Same Agency’s Coverage Baseline.
The most tempting error available to a worked example is depicting the agency doing something the same site elsewhere says it cannot do. So this is a computation rather than a promise: of the 27 techniques these beats cite, the published baseline grades 13 absent — 48.1%. Follow any of them into the record above and check that it is depicted improvised, degraded or failing.
- Absent · 13
- Partial · 12
- Full · 2
- M1.06Credential Exposure MonitoringBaseline: Absent · cited by 1 beat
- M1.13Physical Access Anomaly DetectionBaseline: Absent · cited by 1 beat
- M1.14Supplier Exposure MonitoringBaseline: Absent · cited by 1 beat
- M10.04Intelligence Requirement RevisionBaseline: Absent · cited by 1 beat
- M4.17Supplier Access CanalisationBaseline: Absent · cited by 1 beat
- M5.06Decoy Service EndpointsBaseline: Absent · cited by 1 beat
- M5.10Deception Coverage MeasurementBaseline: Absent · cited by 1 beat
- M7.02Fusion-Fed Hunt BacklogBaseline: Absent · cited by 1 beat
- M7.08Lateral Path AuditBaseline: Absent · cited by 2 beats
- M7.09Detection Engineering from HuntBaseline: Absent · cited by 1 beat
- M7.12Adversary Dwell ReconstructionBaseline: Absent · cited by 1 beat
- M7.13Hunt Coverage AccountingBaseline: Absent · cited by 1 beat
- M7.16Supply Chain Compromise HuntingBaseline: Absent · cited by 1 beat
- M1.02Shadow and Forgotten Asset DiscoveryBaseline: Partial · cited by 1 beat
- M1.03Certificate and Domain WatchBaseline: Partial · cited by 1 beat
- M1.05Authentication Geography BaselineBaseline: Partial · cited by 1 beat
- M1.08Public Service Abuse TelemetryBaseline: Partial · cited by 1 beat
- M1.10Named-Campaign Indicator WatchBaseline: Partial · cited by 1 beat
- M10.03Terrain Overlay UpdateBaseline: Partial · cited by 1 beat
- M2.10Egress Data Loss PreventionBaseline: Partial · cited by 1 beat
- M3.06Machine and Service Identity GovernanceBaseline: Partial · cited by 1 beat
- M3.13Federation Trust Boundary ControlBaseline: Partial · cited by 2 beats
- M4.12Denied-Path Register EnforcementBaseline: Partial · cited by 1 beat
- M7.01Hypothesis-Driven HuntingBaseline: Partial · cited by 1 beat
- M7.07Persistence SweepBaseline: Partial · cited by 1 beat
- M1.01External Attack Surface EnumerationBaseline: Full · cited by 1 beat
- M1.07Partner and Advisory IntakeBaseline: Full · cited by 1 beat
Grades are read from the coverage baseline for the Federal Reference Agency at render time, not copied here — so if the baseline moves, this section moves with it. A technique graded absent that is nonetheless depicted working smoothly would be a defect in the case study, and this is how a reader finds one.
40 beats, in order.
Every beat carries what it did not establish, because that is most of what real defensive work produces. Beats with a heavier left edge sit inside the hunt band; the rest are the cycle work that made the hunt possible, and separating them is how a program avoids believing hunting is a standalone activity.
- D-14 16:40
Beat 1, The CI/CD Pipeline cut the Case Processing System’s record-read path over to a new API gateway. External attack-surface enumeration picked up the new hostname the same evening, and terrain currency raised it as a material change rather than leaving it for the next scheduled overlay rebuild.
What it did not establishThat the new gateway changed what was reachable. Enumeration says a host exists and answers; it says nothing about what stands behind it. The overlay entry was created with its adjacencies blank, and blank adjacencies are the state in which an element is on a list rather than on a map.
OutcomeOne new element on the overlay, owner recorded as the platform group that ran the cutover, adjacency unknown and flagged as unknown.
Confidence — highThe change record and the gateway configuration carry the same cutover timestamp, and external enumeration observed the new hostname answering within four hours of it.
AuthorityStanding ROE
Form — M1 Screen / GuardConsumedProduced - D-13 10:15
Beat 2, A federation trust to a mission partner was added to the ICAM / PDP in the same change window, giving 22 partner identities a path to the Case Filing System. The connection register was updated with the trust and the claimed authenticator assurance.
What it did not establishWhat the partner’s identity assurance actually is. The trust was recorded as configured; the assurance behind it was taken from the partner’s own attestation, which imports their weakest authenticator into this agency’s policy engine on their word.
OutcomeOne new permitted edge on the register, and a second element — the partner tenancy — that this agency can see the boundary of and not the inside of.
Confidence — moderateThe trust configuration is directly observable. The assurance behind it is a statement in a partner agreement and has never been tested from this side.
AuthorityStanding ROE
Form — M3 EnvelopmentTerrain - D-12 09:05
Beat 3, Discovered internet-facing assets were reconciled against the authoritative inventory. Eleven of thirteen new entries resolved to the migration. Two did not resolve to anything, sitting in a cloud subscription outside the declared tenancy boundary.
What it did not establishWhether the two unresolved entries are ours. The reconciliation established that nobody in the platform group claims them, which is a statement about the register rather than about ownership, and they were carried forward as an open item rather than closed either way.
OutcomeOverlay refreshed against the migration. Unreconciled-asset count moved from zero to two, and was reported as two rather than as “substantially reconciled”.
AuthorityStanding ROE
Form — M1 Screen / GuardProducedRequirement - D-11 14:20
Beat 4, A key-assumptions check over last cycle’s reachability result asked what the result required to be true. It required one denial — public tier to mission tier, east–west, at the boundary the new gateway now sits astride — and that denial had no telemetry reconciliation recorded against it since before the migration.
What it did not establishThat the path is now permitted. It established only that nothing had tested it, which is a statement about the evidence and not about the corridor. The corridor might have been fine the whole time; nobody could say so from the register.
OutcomeThe load-bearing denial was reclassified as untested. Under the framework’s own rule an untested denial is treated as permitted for reachability purposes, which invalidated last cycle’s headline map finding without anyone observing a packet.
Confidence — highThe connection register itself records the date of the last telemetry reconciliation against each denial. For this one the field was empty.
This is a failure the manual already predicts — Map — failure mode“Denied paths are asserted from configuration and never tested.”
- The denial was asserted from a firewall policy export at the time the register was built, and the register records assertions and reconciliations in the same column.
- Flow telemetry for that segment exists, and nobody had been assigned to compare the two since the segment’s owner changed teams.
- The reachability result that depended on it was the previous cycle’s best finding, which made it the least likely thing in the register to be re-examined.
AuthorityNo authority required
FormNone — an analytic beat, instantiating no maneuver.
TerrainConsumedRequirement - D-10 11:00
Beat 5, The lateral-path audit was re-run with the untested denial treated as permitted. From a self-registered Public Service Portal identity it found a two-hop route to the Case Processing System record-read path, through the new gateway, that no denied-path entry covered.
What it did not establishWhether anyone has ever traversed it. A permitted path is a possibility. The register cannot distinguish a possibility from a use, and the whole hunt exists because of that gap — not because of the path.
OutcomeReachability result recorded as: crown-jewel read path reachable from the public identity tier on permitted paths, shortest route two hops. The result changed the map without any adversary being involved.
Confidence — moderateWalked over exported policy and route tables rather than from a live position. Two of the cloud route tables were exported a day apart, so the graph is internally consistent to within a day.
AuthorityStanding ROE
Form — M7 CounterattackRequirement - D-10 15:30
Beat 6, Certificate and domain watch was folded into a re-enumeration of the avenues of approach to the crown-jewel record set. Nine avenues were listed; the gateway route was added as the shortest of them.
What it did not establishAnything about the physical, maintenance and supplier routes. Three of the nine were copied forward from the previous cycle unchanged because nothing had obviously moved on them — and carrying an avenue forward is an assumption that nobody wrote down as one at the time.
OutcomeNine avenues on the list, six of them re-derived this cycle and three inherited. The inheritance was not marked.
AuthorityStanding ROE
Form — M1 Screen / GuardTerrainProduced - D-9 10:45
Beat 7, Most-likely and most-dangerous courses of action were redrawn against the new gateway. The most dangerous routes through a federated partner identity to the record path; the most likely routes through a self-registered portal account and abuses the gateway’s authorization gap rather than any credential.
What it did not establishThat either course of action is being executed. A course of action is a plan attributed to an adversary. This cycle produced no observation to attach to either, and the pair is a planning device rather than an assessment.
OutcomeTwo courses of action that differ materially — one turns on identity assurance the agency cannot see, the other on an authorization decision the agency owns entirely.
AuthorityNo authority required
FormNone — an analytic beat, instantiating no maneuver.
Produced - D-3 09:30
Beat 8, Frame opened on the previous cycle’s brief. The intent paragraph was revised to name the sensitive-records read path as the thing that must hold and public-facing search latency as the thing that may be degraded to hold it. Phase was held at 0, cadence set at 21 days, temporal-advantage threshold restated.
What it did not establishWhether holding at Phase 0 was right. The phase was held because nothing in the last brief argued for moving it, which is a defensible reason and is not the same as evidence. The decision was recorded as a deliberate no-change so that it could later be argued with.
OutcomeA signed intent that names something it is willing to lose, a 21-day cadence on a calendar other people can see, and a threshold set before anyone knew what the cycle would find.
AuthorityNo authority required
FormNone — an analytic beat, instantiating no maneuver.
Terrain - D-3 11:10
Beat 9, Five requirements were adopted for the cycle. The portal-reachability requirement was assigned to the hunt lead by name, with the SOC duty analyst as collector of record for the gateway pull. The dwell-basis requirement was carried forward from the previous cycle with the reason it survived.
What it did not establishThat the requirements are answerable with the collection the agency holds. Retention was not checked against any of them at Frame. That omission is what bounded the eventual result, and it cost nothing to make and could not be undone later.
OutcomeFive requirements, each with a named individual owner and a decision attached. One of them was already two cycles old.
AuthorityNo authority required
FormNone — an analytic beat, instantiating no maneuver.
ControlsRequirement - D0 09:00
Beat 10, The Authorizing Official designated the hunt against the portal-identity-to-records path as the cycle’s main effort, citing the crown-jewel record set as the decisive point it defends. Two competing candidates — a segmentation program and a recertification backlog — were named as supporting efforts and explicitly not resourced this cycle.
What it did not establishThat the hunt would find anything. The designation rests on a reachability result and an untested denial, which together are a reason to look and not a reason to expect. Nothing in the record predicted a finding, which is why the negative was survivable when it arrived.
OutcomeOne main effort, one sentence of justification citing a decisive point, and two named efforts that were told they were not it.
AuthorityStanding ROE
FormNone — an analytic beat, instantiating no maneuver.
Consumed - D0 11:20
Beat 11, Rules of engagement for the hunt were set. Pre-authorized: read-only collection across identity, gateway, data-platform and flow telemetry, including the partner federation’s sign-in log; emplacement of decoys on any corridor already on the avenue list. Reserved to the Authorizing Official: any session revocation against a live portal identity, and any change inside the release freeze window.
What it did not establishWhere the operators would actually read it. The record was published to the governance repository and linked from the cycle brief. Nobody tested whether the hunt team could find it from the query console at the moment they needed it, and three days later somebody could not.
OutcomeA pre-authorized set wide enough that almost everything the hunt subsequently did was inside it — a fact that did not survive contact with the way it was published.
AuthorityStanding ROE
FormNone — an analytic beat, instantiating no maneuver.
Terrain - D+1 09:40
Beat 12, The hypothesis was written in falsifiable form before any collection ran: a non-mission-staff identity has traversed the new gateway to the record-read path at least once in the last 90 days. The falsifier was written with it — the gateway access log would carry a caller principal outside the mission-staff directory, or the data-platform audit would carry a read whose caller cannot be resolved to one.
What it did not establishNothing at all, and that is what it is for. A hypothesis establishes only what would count as evidence. Writing it before collection is what stops the collection from deciding afterwards what it had found.
OutcomeOne claim, one falsifier, one window, one population — and a window of 90 days that nobody had yet checked against any retention setting.
Confidence — lowNothing had been observed. The confidence attaches to the collection’s ability to answer the question, not to the claim, and at this point the collection had not been inventoried.
AuthorityNo authority required
Form — M7 CounterattackConsumedRequirement - D+1 14:15
Beat 13, The four sources the falsifier needs were inventoried with their actual retention: gateway access log 14 days, identity provider sign-in 90 days, data-platform audit 400 days, VPC flow 14 days. Public service abuse telemetry supplied the request-volume baseline the gateway query would be read against.
What it did not establishThat 14 days is enough. It established the horizon. Whether the horizon covers the interval that matters is a different question, and it was not asked until the arithmetic was done four days later — by which time the hunt had already been scoped as a 90-day question.
OutcomeFour sources, one of which — the only one that binds a caller to the record path — has a horizon shorter than the age of the change that prompted the hunt.
Confidence — highRetention settings read from each platform’s own configuration rather than from the logging standard, which describes what was intended.
AuthorityPre-authorized
Form — M1 Screen / GuardConsumed - D+2 08:50
Beat 14, An authentication-geography baseline was pulled across the full 90-day identity window, to establish what the population looked like before the federation was added and what it looked like after.
What it did not establishThat an anomalous partner sign-in would have been visible. The baseline describes a population. A single federated partner identity behaving exactly like a partner identity sits inside that population by construction, and no percentile of it would have moved.
OutcomeA baseline that shifted measurably on the day the federation was added, and not since. Useful as context, useless as a discriminator.
AuthorityPre-authorized
Form — M1 Screen / GuardTerrain - D+2 10:30
Beat 15, Every mission-staff and partner identity with entitlement on the Case Processing System was checked against credential-exposure collection for the preceding twelve months. Six hits, all on personal addresses in unrelated third-party breaches, none of them reusable against a phishing-resistant authenticator.
What it did not establishThat no credential is exposed. Exposure collection sees what has been published. The credential worth having is the one still being sold privately, and no feed this agency holds would show it — so the six hits bound the answer at “nothing public”, not at “nothing”.
OutcomeNegative for the hypothesis. Six low-consequence hits routed to workforce readiness rather than to the hunt.
AuthorityPre-authorized
Form — M1 Screen / GuardTerrainConsumed - D+2 13:30
Beat 16, Every request through the new gateway to the record-read path was pulled for the full 14-day horizon and resolved to a caller principal — 41,200 calls. All resolved either to the mission-staff directory or to the two service principals the case system runs as. Not one row matched the falsifier.
What it did not establishAnything about the interval between the cutover and the start of the horizon. The days immediately after a change are when a fresh authorization gap is most exposed and least noticed, and that is precisely the interval this query cannot see.
OutcomeNegative within the horizon, and the bound recorded on the same line as the result rather than in a footnote where it would be quoted without it.
Confidence — moderateComplete within the source’s horizon, with every caller resolved rather than sampled. Moderate rather than high because the horizon, not the query, is the limitation.
AuthorityPre-authorized
Form — M7 CounterattackRequirement - D+3 09:00D+2 13:55 — approval requested by the hunt leadD+3 09:00 — approval received, action unchanged
Beat 17, Before pulling the partner federation’s sign-in log, the hunt lead raised an approval request and stopped work on that thread. The pull had been inside the pre-authorized set since the rules of engagement were published three days earlier. The approval came back 19 hours and 5 minutes later, unchanged, with a question from the Authorizing Official asking why it had been asked.
What it did not establishWhat the delay cost. In this cycle it cost nineteen hours of a hunt with no adversary in it, which is close to nothing. The same nineteen hours under contact is the entire argument for having a pre-authorized set, and a cycle with no contact produces no way to price it.
OutcomeRecorded as an authority exception even though the action was inside the standing set — the exception is the asking, not the doing, and counting it is the only way the pattern becomes visible.
This is a failure the manual already predicts — Maneuver — failure mode“A pre-authorized action is escalated anyway.”
- The rules-of-engagement record lived in the governance repository, not beside the query console, so the hunt lead could not check it at 13:55 and asked instead.
- The pre-authorized set had been widened three days earlier and never rehearsed. A set the shift cannot recite is a set the shift will not rely on.
- The request was raised late on a Friday afternoon. A deputy approver was named in the record the hunt lead could not find.
AuthorityEscalated to the AO — 1145 minutes waiting on the decision
Form — M7 CounterattackTerrain - D+3 11:20
Beat 18, Ninety days of federated partner sign-ins were pulled: 1,340 authentications from all 22 partner identities. None reached the gateway. All were bound to device-posture claims the partner asserts and this agency does not verify.
What it did not establishThat the partner identities are trustworthy. It established where they went, not what assurance stands behind them. The requirement’s decision does not turn on the second question, which is why the hunt stopped here and raised it as a separate finding rather than expanding.
OutcomeNegative for the hypothesis on the identity route. One finding raised against the partner agreement’s assurance clause, owned by governance rather than by the hunt.
Confidence — moderateComplete across the identity provider’s 90-day horizon. The partner-side authenticator claims are self-asserted and were not corroborated.
AuthorityPre-authorized
Form — M3 EnvelopmentTerrainRequirement - D+3 15:10
Beat 19, Named-campaign indicator watch was re-run against the gateway product and the agency’s public hostnames across 90 days of sector and government reporting. No campaign names either.
What it did not establishThat no campaign is pointed at this estate. Absence from reporting is a statement about what has been published and attributed. The interval between an intrusion and its first public attribution is measured in months, so this negative is about the reporting community and not about the adversary.
OutcomeNegative, and explicitly labeled as a negative about attribution rather than about presence.
AuthorityPre-authorized
Form — M1 Screen / GuardTerrain - D+4 10:05
Beat 20, Four hundred days of data-platform audit were searched for reads of the Sensitive Mission Records set by any principal outside the data-access governance boundary. Eleven hits, all resolving to a quarterly reporting job whose service principal sits outside the boundary by design.
What it did not establishThat the reporting job is safe. The search resolved the hits and stopped. Why a job with standing read on the crown-jewel set authenticates with a static secret was not asked here — it went to the backlog as a separate finding, because answering it inside the hunt would have widened the hunt into a different investigation.
OutcomeNegative for the hypothesis, on the only source whose horizon covers the whole question. One incidental finding, which is the ordinary yield of a hunt.
Confidence — highThe data-platform audit log has a 400-day horizon and covers every read, so this is the one source in the account whose window exceeds the hypothesis window.
AuthorityPre-authorized
Form — M2 Defense in DepthTerrainRequirement - D+4 15:40
Beat 21, The two service principals the gateway calls resolved to owners. One had a named owner who had moved teams eight months earlier; the other had none, and had been created during the migration.
What it did not establishWhether the unowned principal is used by anything current. Ownership and use are different questions. Only the first was answerable inside the hunt window, and answering the first is what made the second worth asking.
OutcomeTwo ownership findings on the identity layer, neither of them evidence of an adversary and both of them the kind of ground an adversary would want.
AuthorityPre-authorized
Form — M3 EnvelopmentTerrainConsumed - D+5 09:15
Beat 22, The deception grid had not fired in 96 days. The first draft of the hunt record wrote that up as a negative result supporting the hypothesis’ rejection. A coverage measurement run against the current avenue list showed that four of the fourteen decoys sit on corridors the avenue analysis no longer lists, and that none sits on the gateway corridor the hypothesis names.
What it did not establishThat nothing walked the corridor. Silence from a grid that is not on the corridor is silence about the grid. The draft that read it as silence about the adversary would have raised the assessment’s confidence on no evidence whatsoever, which is worse than adding nothing.
OutcomeThe negative was withdrawn before it reached the record. The grid’s silence was reclassified as uninformative, and re-siting went onto the cycle’s work rather than onto the backlog.
Confidence — highGrid inventory compared element by element against the avenue list dated four days earlier. Both artifacts are current and the comparison is arithmetic.
This is a failure the manual already predicts — M5 Ambush — how it fails“Coverage is never measured, so the grid drifts into the layers that were easy to instrument and away from the ones the threat courses of action actually run through.”
- The grid was sited two cycles ago against an avenue list that has since been re-derived twice, and nothing re-checks siting when the avenue list changes.
- Decoy telemetry is reported as a count of interactions, which is zero whether the grid is perfectly sited or entirely misplaced.
- The hunt record template accepted a null result from a named sensor without asking where the sensor was.
AuthorityPre-authorized
TerrainConsumedRequirement - D+5 14:40
Beat 23, Advisory intake was reviewed for the gateway product since the cutover. One advisory — a pre-authentication path traversal — had arrived and been dispositioned nine days before the hunt opened. The artifact registry records the patched build as deployed.
What it did not establishThat the version running is the version the registry records. The check compared the registry against the advisory. Nobody queried a running instance, and in this estate those two have disagreed before, in the direction of the registry being optimistic.
OutcomeNegative on the advisory route, with the caveat recorded as a caveat rather than dropped for being minor.
AuthorityPre-authorized
Form — M1 Screen / GuardTerrainConsumed - D+6 14:00
Beat 24, Three decoy service endpoints were emplaced on the gateway corridor, resembling the record-read path closely enough to be worth trying and holding nothing. Alert routing was tested with a synthetic trigger: 4 minutes from interaction to a human acknowledging it.
What it did not establishAnything about the past, and not much about the worst case. A decoy emplaced on the sixth day is evidence from the sixth day onward, and the hunt’s question is about the ninety days before it. The routing test ran at 14:00 on a Tuesday, which is the easiest hour of the week to answer a page.
OutcomeGrid coverage against the current avenue list moved from 10 of 14 decoys on live avenues to 13 of 17. Implementation state recorded as operational at the point of emplacement rather than at the next reconciliation.
AuthorityPre-authorized
ConsumedRequirement - D+7 10:00
Beat 25, A devil’s-advocate pass — run by someone who had not executed any of the collection — asked which of the nine avenues the hunt had not touched. The answer was the maintenance route and the supplier route, both inherited unchanged at the avenue re-enumeration. Neither had been searched in the previous three cycles either.
What it did not establishThat the two routes are clear. It established that nobody had looked, which is a finding about the program rather than about the estate. The looking happened afterwards, and it found the only positive result the cycle produced.
OutcomeScope widened by two avenues on the seventh day of a nineteen-day hunt, at the cost of the two days of analyst time that had been reserved for writing up.
Confidence — highThree cycles of hunt records were read directly. Neither avenue appears in any of them, which is a matter of record rather than of recollection.
This is a failure the manual already predicts — M7 Counterattack — how it fails“What was hunted is never accounted for, so coverage is anecdotal and the same three data sources are searched every cycle while two others are never searched at all.”
- Hunt coverage was accounted for at the end of a hunt rather than planned against the avenue list at the start, so nothing forced the comparison until the write-up.
- The avenue list carried no marker distinguishing avenues re-derived this cycle from avenues copied forward, so the inherited three were invisible as inherited.
- The maintenance and supplier routes are owned by facilities and procurement respectively, and neither owner reads a hunt backlog.
AuthorityNo authority required
FormNone — an analytic beat, instantiating no maneuver.
- D+7 15:00
Beat 26, The four suppliers with access to the case-processing estate were checked for disclosed compromise since the previous cycle. None had disclosed one. The check surfaced that the register’s access column for the migration contractor had not been touched since the cutover milestone.
What it did not establishThat the suppliers are uncompromised. It establishes that none has disclosed a compromise. The contract clause requires disclosure within 72 hours of the supplier knowing, not of it happening, and the gap between those two is where every supply-chain case in the sector has lived.
OutcomeNegative on disclosure, and one stale register field that sent the hunt down the supplier route the next morning.
AuthorityPre-authorized
Form — M1 Screen / GuardTerrainConsumed - D+8 11:45
Beat 27, The supplier that ran the gateway migration still held brokered administrative access to the gateway’s configuration plane, granted for the cutover window and never expired — 61 days of standing access, with four sessions after the cutover. All four reconcile to change tickets raised by the agency.
What it did not establishThat the access was misused. Every session reconciles to a ticket. What this establishes is that the constraint failed, not that the supplier did, and those are different findings with different owners and very different consequences for the supplier.
OutcomeThe hunt’s only positive finding, and it is a control failure rather than an adversary. Routed to the supplier-access constraint owner the same afternoon.
Confidence — highThe brokering system’s own session records, cross-read against the contract milestone dates held in procurement. Two independent systems, and they agree.
AuthorityPre-authorized
Form — M7 Counterattack - D+9 09:30
Beat 28, Physical access anomaly review ran over the quarter for the space holding the gateway’s management plane. Three badge events fell outside work-order windows; all three reconcile to a fire-alarm test with a signed escort record.
What it did not establishWhether an escorted visitor did anything at a console. Badge records place a person in a room. They do not place their hands on a keyboard, and no console session log covers that room — which makes this negative a statement about presence and not about action.
OutcomeNegative on the maintenance route, with the fidelity limit stated on the same line so it cannot be quoted without it.
AuthorityPre-authorized
Form — M1 Screen / GuardTerrain - D+11 10:20
Beat 29, The observable horizon was reconstructed per source to establish how far back any negative result in this estate could reach at all: 14 days at the gateway, 14 at flow, 90 at identity, 400 at the data platform. The agency’s carried dwell estimate is 34 days, built entirely from closed cases.
What it did not establishA dwell estimate. It established the ceiling on any dwell claim, which is not the claim. An estimate of 34 days sitting on top of a 14-day horizon at the only source that binds a caller to the objective is an estimate the collection cannot support in either direction.
OutcomeThe carried estimate was left unchanged and its basis restated with the horizon mismatch attached. The requirement it serves was carried forward for a third cycle, with the reason written down.
Confidence — moderateThe horizons are configuration facts. What they imply about dwell is an inference, and it is an inference about what could be seen rather than about what happened.
AuthorityPre-authorized
Form — M7 CounterattackTerrainRequirement - D+12 14:00
Beat 30, A persistence sweep ran across the Mission-Staff Workstations with standing access to the case system: 240 of the 330 devices on the overlay carry an endpoint agent capable of the sweep. Nothing was found on the 240.
What it did not establishAnything about the 90 unmanaged and contractor devices that authenticate to the same service. They carry no agent, so the sweep could not run on them. Their absence from the result is a coverage gap and was recorded as unmeasured rather than folded into a clean number.
OutcomeNegative across the population the sweep could reach, over a denominator taken from the terrain overlay rather than from the endpoint console — which would have reported 100%.
Confidence — moderateComplete across the agent-carrying population, which is 73% of the population that matters. The remaining 27% is not evidence in either direction.
AuthorityPre-authorized
Form — M7 CounterattackTerrainConsumed - D+14 09:00
Beat 31, The coverage account was written: for each of the nine enumerated avenues, which sources were searched, over which window, at what fidelity, and what would have been visible had the hypothesis been true. Six avenues fully searched, two partially, one — the enterprise-to-operational crossing — not searched at all.
What it did not establishThat the ground searched is clear beyond its window. Every line in the account carries a horizon. Outside the horizon the account says nothing, which is deliberately different from saying clear, and the template refuses to render the two the same way.
OutcomeA coverage figure with the avenue list as its denominator. Computed against the avenues searched instead, the same hunt would have reported 100%.
AuthorityPre-authorized
Form — M7 CounterattackTerrainRequirement - D+15 10:00
Beat 32, Analysis of competing hypotheses was run over four hypotheses, including one in which the activity is not hostile and one in which an adversary operates inside the reporting job’s service principal and is therefore indistinguishable from it. The fourth survived on the evidence — nothing disconfirmed it — and nothing supported it either.
What it did not establishThat the path has never been used. The assessment is bounded by the shortest horizon in its own account, and a claim about ninety days cannot be made from fourteen days of the only evidence that binds a caller to the objective.
OutcomeThe requirement was answered: no chain from a self-registered identity was exercised in the observable window, and the chain nonetheless exists on permitted paths. The requirement’s second branch applied — hold the boundary as drawn and record the denials carrying it — and the recording found that the number of denials carrying it was one.
Confidence — moderateFour independent sources, each complete within its own horizon, none covering the interval between the cutover and the start of the gateway horizon. Moderate rather than high specifically because that uncovered interval is the one an opportunist would have used.
AuthorityNo authority required
FormNone — an analytic beat, instantiating no maneuver.
ConsumedRequirement - D+15 15:20
Beat 33, Two detections were authored from the queries the hunt had run by hand: any caller principal outside the mission-staff directory on the gateway record path, and any brokered supplier session on the gateway configuration plane outside a change window.
What it did not establishThat either detection works. Neither has fired. A detection that has never fired is untested rather than quiet, and both were recorded in that state rather than counted as coverage.
OutcomeTwo production detections, both marked unvalidated, and a signpost attached to each saying what firing would mean.
AuthorityPre-authorized
Form — M7 CounterattackTerrainProduced - D+16 11:00
Beat 34, On the fused assessment — a permitted chain that exists, a supplier constraint that failed, and a deception grid that had been sited off the live avenues for two cycles — the Authorizing Official declared Phase I against the case-processing scope, out of band. The declaration widened the hardening and deception effort and did not widen the fire set.
What it did not establishThat an adversary is present. Phase I is a statement about cost imposed on an adversary, not about contact with one. Declaring it on a negative result is this case’s most easily misread decision, and the declaration says so in its own text for exactly that reason.
OutcomeA phase change driven by terrain findings rather than by an alert, with cadence tightened from 21 days to 14 and the pre-authorized set left where it was.
AuthorityStanding ROE
FormNone — an analytic beat, instantiating no maneuver.
TerrainProduced - D+17 10:30
Beat 35, The untested denial was made a tested one. An explicit deny was added at the gateway for callers outside the mission-staff directory and the two case service principals, and the denial was then reconciled against seven days of flow telemetry before being recorded as denied.
What it did not establishThat the register is correct anywhere else. One denial was tested. The register holds 214, and 213 of them are in exactly the state this one was in on the day the assumptions check found it.
OutcomeOne permitted path closed and evidenced. Reachability from the public identity tier to the record path recomputed as denied, this time on telemetry rather than on configuration.
AuthorityStanding ROE
Form — M4 Obstacle / CanalizationRequirement - D+17 15:00D+17 13:25 — request raised inside the release freeze windowD+17 15:00 — revocation executed
Beat 36, The migration contractor’s standing access to the gateway configuration plane was revoked and re-issued as time-bounded brokered access per work order. Because the revocation landed inside the release freeze window it needed the Authorizing Official; the decision took 1 hour 35 minutes, which is what an escalation costs when the approver knows the question is coming.
What it did not establishWhether the same pattern exists on the other thirty suppliers. One register entry was corrected. The reconciliation against procurement records that would find the rest went to the backlog with a date and, at cycle close, no owner.
OutcomeStanding supplier access to a decisive point removed 61 days after it should have expired, and a second escalation whose latency is worth having next to the first one.
AuthorityEscalated to the AO — 95 minutes waiting on the decision
Form — M4 Obstacle / CanalizationTerrain - D+18 09:20
Beat 37, The overlay was updated from the hunt rather than from the calendar: the gateway’s adjacencies filled in, the supplier’s access edge corrected, the two unowned service principals recorded with the owner the review assigned them, and the three inherited avenues marked as inherited.
What it did not establishThat the overlay is current anywhere the hunt did not go. The elements the hunt touched are current as of today. Everything else carries the age it had at the start of the cycle, and the overlay’s reported staleness was left at that age rather than at the age of its newest entry.
OutcomeFour corrections, one new marker on the avenue list, and a staleness figure that did not improve because three elements being fresh does not make an overlay fresh.
AuthorityStanding ROE
Form — M10 Exploitation & PursuitProduced - D+18 14:00
Beat 38, The negative result was written into the cycle record as a first-class finding carrying six fields: scope, window, fidelity, falsifier, expiry and owner. Signed by the hunt lead, countersigned by governance. The expiry is tied to the gateway’s horizon — fourteen days after the last search, the clearance is stale and the avenue returns to the hunt backlog.
What it did not establishThat the ground stays cleared. It does not, and the record says when it stops. The one thing the field prevents is the failure this whole practice exists to prevent: a clearance quoted in three cycles’ time by someone who was not there and cannot see its bound.
OutcomeA negative result another analyst can audit, disagree with, and — for fourteen days — decline to repeat.
Confidence — highThe record is a transcription of the coverage account and the fused assessment, both of which are themselves sourced. Nothing in it is a summary judgment.
AuthorityNo authority required
FormNone — an analytic beat, instantiating no maneuver.
Terrain - D+19 11:00
Beat 39, The brief led with the negative and its bound, not with the supplier finding. Temporal advantage was reported as not computed: a cycle with no contact produces no defender decision loop, and reporting the threshold as met on an empty numerator was refused in the drafting.
What it did not establishWhether this program is winning. Its only effectiveness measure needs contact to produce a number, and this cycle had none. The honest entry is a gap, and a gap is what an oversight reader will ask about — which is the correct outcome and the reason it is tempting to fill in.
OutcomeA distributed brief whose headline is a bounded negative, whose scoreboard line is blank, and whose backlog is re-ranked with the untested-denial reconciliation above eleven higher-volume items.
AuthorityNo authority required
FormNone — an analytic beat, instantiating no maneuver.
TerrainConsumed - D+19 15:30
Beat 40, The reachability requirement retired on a recorded result plus a boundary statement in the authorization package. The deception requirement retired on the re-siting. The dwell-basis requirement was carried forward for a third cycle. Two new requirements were raised: supplier standing-access reconciliation, and gateway log retention against the hypothesis windows the hunt program actually asks.
What it did not establishThat the carried-forward requirement will be answered next cycle. It has now survived two cycle boundaries. The record notes that a third would make it a standing wish rather than a priority, which is a note written to be uncomfortable to read next Frame.
OutcomeTwo requirements retired on their stated conditions, one carried with a reason and a warning, two raised from findings that had nothing to do with the hypothesis.
AuthorityNo authority required
Form — M10 Exploitation & PursuitTerrainProduced
Each of These Is a Failure the Manual Already Predicts.
A case study in which nothing goes wrong is a brochure. Each failure below points at the framework’s own published prediction of it — inventing a novel failure the doctrine never anticipated would be a finding about the doctrine rather than a story beat.
The deception grid’s silence was one draft away from becoming evidence
Ninety-six days of silence from the deception grid was written into the first draft of the hunt record as a negative result supporting the hypothesis’ rejection. It was not. Four of the fourteen decoys sat on corridors the avenue analysis had stopped listing two cycles earlier, and none sat on the corridor the hypothesis names. Had the draft stood, the assessment’s confidence would have risen on a sensor that was not pointed at the question.
“Coverage is never measured, so the grid drifts into the layers that were easy to instrument and away from the ones the threat courses of action actually run through.”
Coverage measurement now runs before a null result from the grid may be cited, and the hunt record template refuses a negative from any sensor whose siting has not been reconciled against the current avenue list in the same cycle. Three decoys were emplaced on the gateway corridor during the hunt. What has not changed is the trigger: nothing re-checks siting when the avenue list is re-derived, so this will recur the next time the map moves and nobody re-reads the grid.
Two avenues had been carried forward unexamined for four cycles
Three of the nine avenues were copied forward at the map refresh because nothing had obviously moved on them, and the copying was not marked. Two of those three — the maintenance route and the supplier route — had not been searched in any of the previous three cycles either. Neither was in this hunt’s scope. Both were added on the seventh day only because a devil’s-advocate pass asked what had not been searched, and the hunt’s single positive finding was sitting on one of them.
“What was hunted is never accounted for, so coverage is anecdotal and the same three data sources are searched every cycle while two others are never searched at all.”
Hunt coverage accounting moved from a closing artifact to an exit condition, computed against the enumerated avenue list rather than against the avenues searched, and the avenue list now marks which entries were re-derived this cycle and which were inherited. The deeper cause is untouched: the maintenance and supplier routes are owned by facilities and by procurement, and neither owner reads a hunt backlog.
A pre-authorized action was escalated anyway, and cost nineteen hours
The hunt lead stopped work and requested approval to pull the partner federation’s sign-in log. The pull had been inside the pre-authorized set for three days. The approval returned unchanged after 19 hours and 5 minutes, which is 92% of this cycle’s entire authority tax spent on an action nobody needed to approve.
“A pre-authorized action is escalated anyway.”
The pre-authorized set is now rendered in the hunt console beside the query editor, with the named approver and deputy next to it, rather than living only in the governance repository. Whether that works is a next-cycle question — it has not been tested out of hours, and the framework is explicit that a set the shift cannot recite is a set the shift will not rely on.
The reachability result the cycle opened with rested on one untested denial
Last cycle’s headline map finding — that the crown-jewel read path was not reachable from the public identity tier — depended on a single denied path, asserted from a firewall policy export and never reconciled against flow telemetry. The register records assertions and reconciliations in the same column, so nothing distinguished the two. The finding was the previous cycle’s best work, which made it the least likely entry in the register to be re-examined.
“Denied paths are asserted from configuration and never tested.”
That one denial is now tested and evidenced against seven days of flow telemetry, and the register has been given a separate reconciliation-date field so an assertion can no longer be mistaken for a test. The other 213 entries are in exactly the state this one was in. The reconciliation is on the backlog with a date and, at cycle close, no owner.
4 individual beats also carry a pointer to a published failure mode, marked in the record above.
Including the Thresholds It Missed.
8 measures: 2 met, 4 missed and 2 that could not be computed at all — counted off the table rather than typed above it. Every metric carries the method that produced it, because a metric with no method is a claim, and a case that reports only the thresholds it met is reporting a biased sample and then reasoning from it.
| Measure | Value | Against its own threshold | How it was computed | What that means |
|---|---|---|---|---|
| Avenues searched, against the enumerated avenue list | 6 of 9 in full, 2 partially, 1 not at all | Not met | Counted from the coverage account against the avenue-of-approach list current at the time of writing. The denominator is the avenue list, not the list of avenues the hunt happened to touch — computed the second way the same hunt reports 100%. | The stated exit condition was that every enumerated avenue be searched or explicitly deferred with a reason. The enterprise-to-operational crossing was neither, and is recorded as not searched. |
| Interval the negative result cannot reach | 1d 20h 50m | Not met | Derived from three inputs: the cutover timestamp on the first beat, the retro-hunt timestamp on the gateway beat, and the gateway access log’s 14-day retention. Not asserted anywhere — subtracted. | The threshold set with the hypothesis was full coverage of the interval since the change that prompted it. Missing the opening interval of a new authorization surface is missing the most exposed part of the window, and the miss was fixed at Frame by not checking retention against the question. |
| Authority tax | 20h 40m across 2 escalations | Not met | Summed over the beats whose authority is recorded as escalated, using the same function the site computes it with for any case. Both escalations carry a decision time and an effective time. | One of the two escalations was against an action already inside the pre-authorized set. Under contact that one is the whole argument for the set; here it cost nineteen hours of a hunt nobody was racing. |
| Hunt band elapsed, against the declared cycle cadence | 17d 4h 20m against a 21-day cadence | Met | Measured between the first and last in-band beat. The cadence is the one declared at Frame, before anyone knew what the hunt would find. | It fitted, and it fitted only because the write-up absorbed the two days the scope widening cost. The band sits inside a case that runs 32d 22h 50m from the terrain change that started it to the brief that closed it — the hunt is the short part. |
| Persistence sweep population | 240 of 330 devices (73%) | Not met | The denominator is every device with standing access to the case system, taken from the terrain overlay. Taken from the endpoint console instead — the count of devices carrying an agent — the same sweep reports 100%. | The 90 devices outside the sweep are recorded as unmeasured. Unmeasured is a worse finding than poorly covered, and it is the one that gets quietly excluded. |
| Temporal advantage | Not computed | Not computed | The ratio needs a measured defender decision loop, and a cycle with no contact produces none. Reporting the threshold as met on an empty numerator was refused at Assess. | This is the correct entry for a proactive cycle and it is the one most often filled in anyway, because a blank scoreboard line invites a question and a green one does not. |
| Positive findings | 1 control finding, 0 adversary findings | Not computed | Counted from the beats whose outcome records a positive result. The program deliberately sets no threshold on this figure: a target for positive findings is an incentive to produce them. | The single positive — standing supplier access that outlived its work order — was found on an avenue the hunt had not planned to search. |
| Detections authored from the hunt | 2, neither of which has fired | Met | Counted from the indicators and signposts produced at Fuse. Firing is not counted toward the figure, because a detection that has never fired is untested rather than working. | The threshold is at least one production detection per hunt, on the principle that a hunt nobody can automate any part of will be re-run by hand forever. |
Avenues searched, against the enumerated avenue list
- Value
- 6 of 9 in full, 2 partially, 1 not at all
- Against its own threshold
- Not met
- How it was computed
- Counted from the coverage account against the avenue-of-approach list current at the time of writing. The denominator is the avenue list, not the list of avenues the hunt happened to touch — computed the second way the same hunt reports 100%.
- What that means
- The stated exit condition was that every enumerated avenue be searched or explicitly deferred with a reason. The enterprise-to-operational crossing was neither, and is recorded as not searched.
Interval the negative result cannot reach
- Value
- 1d 20h 50m
- Against its own threshold
- Not met
- How it was computed
- Derived from three inputs: the cutover timestamp on the first beat, the retro-hunt timestamp on the gateway beat, and the gateway access log’s 14-day retention. Not asserted anywhere — subtracted.
- What that means
- The threshold set with the hypothesis was full coverage of the interval since the change that prompted it. Missing the opening interval of a new authorization surface is missing the most exposed part of the window, and the miss was fixed at Frame by not checking retention against the question.
Authority tax
- Value
- 20h 40m across 2 escalations
- Against its own threshold
- Not met
- How it was computed
- Summed over the beats whose authority is recorded as escalated, using the same function the site computes it with for any case. Both escalations carry a decision time and an effective time.
- What that means
- One of the two escalations was against an action already inside the pre-authorized set. Under contact that one is the whole argument for the set; here it cost nineteen hours of a hunt nobody was racing.
Hunt band elapsed, against the declared cycle cadence
- Value
- 17d 4h 20m against a 21-day cadence
- Against its own threshold
- Met
- How it was computed
- Measured between the first and last in-band beat. The cadence is the one declared at Frame, before anyone knew what the hunt would find.
- What that means
- It fitted, and it fitted only because the write-up absorbed the two days the scope widening cost. The band sits inside a case that runs 32d 22h 50m from the terrain change that started it to the brief that closed it — the hunt is the short part.
Persistence sweep population
- Value
- 240 of 330 devices (73%)
- Against its own threshold
- Not met
- How it was computed
- The denominator is every device with standing access to the case system, taken from the terrain overlay. Taken from the endpoint console instead — the count of devices carrying an agent — the same sweep reports 100%.
- What that means
- The 90 devices outside the sweep are recorded as unmeasured. Unmeasured is a worse finding than poorly covered, and it is the one that gets quietly excluded.
Temporal advantage
- Value
- Not computed
- Against its own threshold
- Not computed
- How it was computed
- The ratio needs a measured defender decision loop, and a cycle with no contact produces none. Reporting the threshold as met on an empty numerator was refused at Assess.
- What that means
- This is the correct entry for a proactive cycle and it is the one most often filled in anyway, because a blank scoreboard line invites a question and a green one does not.
Positive findings
- Value
- 1 control finding, 0 adversary findings
- Against its own threshold
- Not computed
- How it was computed
- Counted from the beats whose outcome records a positive result. The program deliberately sets no threshold on this figure: a target for positive findings is an incentive to produce them.
- What that means
- The single positive — standing supplier access that outlived its work order — was found on an avenue the hunt had not planned to search.
Detections authored from the hunt
- Value
- 2, neither of which has fired
- Against its own threshold
- Met
- How it was computed
- Counted from the indicators and signposts produced at Fuse. Firing is not counted toward the figure, because a detection that has never fired is untested rather than working.
- What that means
- The threshold is at least one production detection per hunt, on the principle that a hunt nobody can automate any part of will be re-run by hand forever.
Counted, Not Characterized.
Exactly one role acts on each beat. Shared action is not action, and a case in which everybody contributes to everything cannot be used to argue for a staffing model.
| Role | Beats led | Beats supported | What the role owns |
|---|---|---|---|
| Hunt teamHUNT | 15 | 13 | Counterattack. Works the hypotheses that Fuse raises. |
| Cyber Threat Intelligence cellCTI | 12 | 9 | Frame, Map and Fuse. The intelligence requirements, the threat courses of action, and the confidence levels. |
| Platform and product ownersPLAT | 7 | 10 | Their own terrain. Obstacles get emplaced on their ground, so they site them. |
| Authorizing Official / CISOAO | 3 | 6 | Intent, risk acceptance, and the scheme itself. |
| Governance / RMF / ISSOISSO | 2 | 11 | Translating cycle outputs into FISMA and RMF artifacts, and owning the rules of engagement. |
| SOC / Defensive OperationsSOC | 1 | 11 | Maneuver. Executes fires and emplaces obstacles inside the standing rules of engagement. |
Hunt team
HUNT
- Beats led
- 15
- Beats supported
- 13
- What the role owns
- Counterattack. Works the hypotheses that Fuse raises.
Cyber Threat Intelligence cell
CTI
- Beats led
- 12
- Beats supported
- 9
- What the role owns
- Frame, Map and Fuse. The intelligence requirements, the threat courses of action, and the confidence levels.
Platform and product owners
PLAT
- Beats led
- 7
- Beats supported
- 10
- What the role owns
- Their own terrain. Obstacles get emplaced on their ground, so they site them.
Authorizing Official / CISO
AO
- Beats led
- 3
- Beats supported
- 6
- What the role owns
- Intent, risk acceptance, and the scheme itself.
Governance / RMF / ISSO
ISSO
- Beats led
- 2
- Beats supported
- 11
- What the role owns
- Translating cycle outputs into FISMA and RMF artifacts, and owning the rules of engagement.
SOC / Defensive Operations
SOC
- Beats led
- 1
- Beats supported
- 11
- What the role owns
- Maneuver. Executes fires and emplaces obstacles inside the standing rules of engagement.
The Artifacts, with the Beats on Each Side of Them.
A product with no consumer is overhead. Reading down this table is the fastest way to see which artifacts were load-bearing in this case and which were written because the process said to.
| Artifact | What it is | Produced at | Consumed at |
|---|---|---|---|
| Defensive intent paragraph | One signed paragraph stating what the defense exists to protect, what may be degraded to protect it, and the acceptable risk. The commander’s-intent analog, and the citation every downstream designation rests on. | ||
| Priority Cyber Intelligence Requirements | Three to seven questions the cycle will try to answer, each naming the decision it informs, the collection source expected to answer it, and an individual owner. | ||
| Phase declaration | The declared campaign phase and the scope it is declared against. Sets cadence, dominant forms of maneuver, and how wide the pre-authorization set runs. | — | |
| Cycle cadence and calendar | The declared length of a cycle, its close date, and the refresh intervals that inherit from it. Makes “per cycle” a measurable unit rather than a figure of speech. | — | |
| Temporal advantage threshold | The number the cycle will be judged against: defender decision loop versus adversary dwell, stated with units before the cycle runs. | — | |
| Cyber Terrain Overlay | The positional map of the estate: every element with a defensive layer, a defensive weight, a named accountable owner and its adjacencies. Not an asset inventory — an inventory enumerates, an overlay positions. | ||
| Trust zones and the connection register | The zone boundaries and the permitted- and denied-path register — the graph reachability is actually walked over, reconciled against observed flow telemetry rather than against intended configuration. | ||
| Decisive point register | The elements whose control confers decisive advantage — each carrying the evidence that raised it above merely important, and the protection floor it owes as a result. | — | |
| Avenue-of-approach analysis | The enumerated routes an adversary could take toward each decisive point, including physical, supplier and maintenance routes, with unassessed routes recorded as intelligence gaps rather than as absence of risk. | ||
| Adversary reachability assessment | The formal result: from each entry point, which decisive points are reachable over the permitted-path graph. The framework’s hardest single finding, and the headline of the brief when it changes. | ||
| Barrier sufficiency register | The specific barriers holding the line where reachability is prevented, each with a named enforcing owner. What the reachability result depends on, made explicit so its erosion is visible. | — | |
| Threat course-of-action sketch | Two courses of action, most likely and most dangerous, drawn against the decisive points already designated. Each is a route across ground the estate really has, not a category of threat. | ||
| Scheme of maneuver | One graphic and one narrative: which forms of maneuver are sited where, in what sequence. The assignment record behind it carries the element, the avenue and the implementation state for every move. | ||
| Main effort designation | The single designated main effort for the cycle, and the sentence citing the decisive point that justifies it. The answer to which work wins when two things need the same engineer. | — | |
| Rules of engagement | Which defensive actions may be taken by whom without escalation, which need the Authorizing Official, and what is prohibited outright. The cyber analog of engagement authority, and the single largest determinant of tempo. | ||
| Pre-authorized response set | The specific containment and response actions the SOC may execute at machine speed, bounded by the statutory availability floor. Directly measurable: it shortens the decision segment of the defender loop. | ||
| Change record | Every defensive action carried out, stamped twice — at the decision and at the effect. A thin, unglamorous table, and the one the headline metric is computed from. | ||
| Implementation state record | Planned, partial or operational, per maneuver assignment. The mechanism that stops intended work being counted as deployed protection. | — | |
| Authority exception log | Actions taken outside the standing rules of engagement, with who approved them and why. Exceptions are not failures; unrecorded exceptions are. | — | |
| Defender decision loop measurement | Detect to decide to contain, measured per incident from the change record’s timestamps and reported as a distribution rather than as a mean. | — | |
| Fused assessment | What the cycle’s intelligence requirements returned: each answer graded for confidence and showing its working, and each requirement left unanswered recorded against the collection gap responsible. | ||
| Adversary dwell estimate | The estimated time an adversary could operate undetected in this estate, with its basis stated — measured dwell, sector reporting, or partner intelligence — and its bias acknowledged. | ||
| Cyber Running Estimate | The living situational picture the SOC, hunt and intelligence cell share: current posture, current assessments and their confidence, open requirements, and what has moved since the last look. | ||
| Indicators and signposts | For each surviving hypothesis, the observable events that would confirm or kill it, handed to collection. The mechanism that makes this cycle’s analysis into next cycle’s requirements. | ||
| Hunt results, including negative results | What was hunted, how, and what was not found. Negative results are the half most often discarded, and they are the half that says what has actually been cleared. | ||
| Coverage and residual risk result | Coverage and residual risk computed over the whole overlay population, weighted by consequence, discounted by implementation state and corrected by validated effectiveness — with the denominator stated. | — | |
| Temporal advantage result | Defender decision loop against adversary dwell, reported as a ratio against the threshold set at Frame, with the result written as a word: met, or not met. The framework’s single honest scoreboard. | — | |
| Remediation backlog | The ranked list of what to fix, ordered by residual risk, main-effort weighting, and decisive-point floor breaches — which sit above higher-volume, lower-weight work regardless of count. | — | |
| Findings disposition record | Every finding with an outcome: remediate with an owner and a date, accept with a named accepter and an expiry, or transfer with the party named. “Under review” is not a disposition. | ||
| Cycle record and trend | The closed record of the cycle — posture, loop measurement, conclusions and their confidence, backlog state at close — and the trend across cycles that makes a second cycle worth more than a first. | ||
| Cycle brief | The published product: terrain, reachability, main effort, temporal advantage, coverage, trend, and the top-ranked backlog items — each confidence-tagged. Also the evidence that feeds the next intent. | ||
| Statutory availability floor | The mission services whose availability is set by statute or regulation, and the floor below which degradation stops being a defensive choice. Bounds what may be pre-authorized and what may be degraded under contact. | — | |
| Privacy and controlled-information terrain register | Where privacy holdings and controlled unclassified information sit, the authorities under which they are held, and the boundaries their handling requires — expressed as denied paths, not as policy statements. | — | |
| Tenancy and inheritance boundary record | What is inherited from a provider and what remains the agency’s, drawn from provider authorization packages and responsibility matrices, so inherited mitigation is counted once and correctly. | — | |
| Privileged human register | Which individuals hold which high-consequence access, reconciled against the identity system rather than against the last access review spreadsheet. | — | |
| Facility terrain register | Where elements physically are, which personnel populations are associated with each site, and which facilities carry mission services. | — | |
| Maintenance access record | Who may perform maintenance in which zone, under what escort and in what window — including supplier maintenance, which is where standing physical access usually hides. | — | |
| Supplier terrain register | Suppliers as external actors on the overlay, with the access each holds, the paths that access implies, and the contract behind it. | — | |
| Component provenance record | Where components came from, from inventories, build manifests and supplier attestations — and which components have an origin that cannot be verified. | — | |
| Supplier access constraint record | How supplier access is brokered, time-bounded and constrained — and the prohibition on standing supplier access to designated decisive points. | — |
Defensive intent paragraph
- What it is
- One signed paragraph stating what the defense exists to protect, what may be degraded to protect it, and the acceptable risk. The commander’s-intent analog, and the citation every downstream designation rests on.
- Produced at
- Consumed at
Priority Cyber Intelligence Requirements
- What it is
- Three to seven questions the cycle will try to answer, each naming the decision it informs, the collection source expected to answer it, and an individual owner.
- Produced at
- Consumed at
Phase declaration
- What it is
- The declared campaign phase and the scope it is declared against. Sets cadence, dominant forms of maneuver, and how wide the pre-authorization set runs.
- Produced at
- Consumed at
- —
Cycle cadence and calendar
- What it is
- The declared length of a cycle, its close date, and the refresh intervals that inherit from it. Makes “per cycle” a measurable unit rather than a figure of speech.
- Produced at
- Consumed at
- —
Temporal advantage threshold
- What it is
- The number the cycle will be judged against: defender decision loop versus adversary dwell, stated with units before the cycle runs.
- Produced at
- Consumed at
- —
Cyber Terrain Overlay
- What it is
- The positional map of the estate: every element with a defensive layer, a defensive weight, a named accountable owner and its adjacencies. Not an asset inventory — an inventory enumerates, an overlay positions.
- Produced at
Trust zones and the connection register
- What it is
- The zone boundaries and the permitted- and denied-path register — the graph reachability is actually walked over, reconciled against observed flow telemetry rather than against intended configuration.
- Produced at
Decisive point register
- What it is
- The elements whose control confers decisive advantage — each carrying the evidence that raised it above merely important, and the protection floor it owes as a result.
- Produced at
- —
- Consumed at
Avenue-of-approach analysis
- What it is
- The enumerated routes an adversary could take toward each decisive point, including physical, supplier and maintenance routes, with unassessed routes recorded as intelligence gaps rather than as absence of risk.
- Produced at
Adversary reachability assessment
- What it is
- The formal result: from each entry point, which decisive points are reachable over the permitted-path graph. The framework’s hardest single finding, and the headline of the brief when it changes.
- Produced at
Barrier sufficiency register
- What it is
- The specific barriers holding the line where reachability is prevented, each with a named enforcing owner. What the reachability result depends on, made explicit so its erosion is visible.
- Produced at
- —
- Consumed at
Threat course-of-action sketch
- What it is
- Two courses of action, most likely and most dangerous, drawn against the decisive points already designated. Each is a route across ground the estate really has, not a category of threat.
- Produced at
- Consumed at
Scheme of maneuver
- What it is
- One graphic and one narrative: which forms of maneuver are sited where, in what sequence. The assignment record behind it carries the element, the avenue and the implementation state for every move.
- Produced at
- Consumed at
Main effort designation
- What it is
- The single designated main effort for the cycle, and the sentence citing the decisive point that justifies it. The answer to which work wins when two things need the same engineer.
- Produced at
- Consumed at
- —
Rules of engagement
- What it is
- Which defensive actions may be taken by whom without escalation, which need the Authorizing Official, and what is prohibited outright. The cyber analog of engagement authority, and the single largest determinant of tempo.
- Produced at
- Consumed at
Pre-authorized response set
- What it is
- The specific containment and response actions the SOC may execute at machine speed, bounded by the statutory availability floor. Directly measurable: it shortens the decision segment of the defender loop.
- Produced at
- Consumed at
Change record
- What it is
- Every defensive action carried out, stamped twice — at the decision and at the effect. A thin, unglamorous table, and the one the headline metric is computed from.
- Consumed at
Implementation state record
- What it is
- Planned, partial or operational, per maneuver assignment. The mechanism that stops intended work being counted as deployed protection.
- Produced at
- Consumed at
- —
Authority exception log
- What it is
- Actions taken outside the standing rules of engagement, with who approved them and why. Exceptions are not failures; unrecorded exceptions are.
- Produced at
- Consumed at
- —
Defender decision loop measurement
- What it is
- Detect to decide to contain, measured per incident from the change record’s timestamps and reported as a distribution rather than as a mean.
- Produced at
- —
- Consumed at
Fused assessment
- What it is
- What the cycle’s intelligence requirements returned: each answer graded for confidence and showing its working, and each requirement left unanswered recorded against the collection gap responsible.
- Produced at
Adversary dwell estimate
- What it is
- The estimated time an adversary could operate undetected in this estate, with its basis stated — measured dwell, sector reporting, or partner intelligence — and its bias acknowledged.
- Produced at
- Consumed at
Cyber Running Estimate
- What it is
- The living situational picture the SOC, hunt and intelligence cell share: current posture, current assessments and their confidence, open requirements, and what has moved since the last look.
- Produced at
- Consumed at
Indicators and signposts
- What it is
- For each surviving hypothesis, the observable events that would confirm or kill it, handed to collection. The mechanism that makes this cycle’s analysis into next cycle’s requirements.
- Produced at
- Consumed at
Hunt results, including negative results
- What it is
- What was hunted, how, and what was not found. Negative results are the half most often discarded, and they are the half that says what has actually been cleared.
- Produced at
Coverage and residual risk result
- What it is
- Coverage and residual risk computed over the whole overlay population, weighted by consequence, discounted by implementation state and corrected by validated effectiveness — with the denominator stated.
- Produced at
- —
- Consumed at
Temporal advantage result
- What it is
- Defender decision loop against adversary dwell, reported as a ratio against the threshold set at Frame, with the result written as a word: met, or not met. The framework’s single honest scoreboard.
- Produced at
- Consumed at
- —
Remediation backlog
- What it is
- The ranked list of what to fix, ordered by residual risk, main-effort weighting, and decisive-point floor breaches — which sit above higher-volume, lower-weight work regardless of count.
- Produced at
- Consumed at
- —
Findings disposition record
- What it is
- Every finding with an outcome: remediate with an owner and a date, accept with a named accepter and an expiry, or transfer with the party named. “Under review” is not a disposition.
- Produced at
- Consumed at
Cycle record and trend
- What it is
- The closed record of the cycle — posture, loop measurement, conclusions and their confidence, backlog state at close — and the trend across cycles that makes a second cycle worth more than a first.
- Produced at
- Consumed at
Cycle brief
- What it is
- The published product: terrain, reachability, main effort, temporal advantage, coverage, trend, and the top-ranked backlog items — each confidence-tagged. Also the evidence that feeds the next intent.
- Produced at
- Consumed at
Statutory availability floor
- What it is
- The mission services whose availability is set by statute or regulation, and the floor below which degradation stops being a defensive choice. Bounds what may be pre-authorized and what may be degraded under contact.
- Produced at
- —
- Consumed at
Privacy and controlled-information terrain register
- What it is
- Where privacy holdings and controlled unclassified information sit, the authorities under which they are held, and the boundaries their handling requires — expressed as denied paths, not as policy statements.
- Produced at
- —
- Consumed at
Tenancy and inheritance boundary record
- What it is
- What is inherited from a provider and what remains the agency’s, drawn from provider authorization packages and responsibility matrices, so inherited mitigation is counted once and correctly.
- Produced at
- —
- Consumed at
Privileged human register
- What it is
- Which individuals hold which high-consequence access, reconciled against the identity system rather than against the last access review spreadsheet.
- Produced at
- —
- Consumed at
Facility terrain register
- What it is
- Where elements physically are, which personnel populations are associated with each site, and which facilities carry mission services.
- Produced at
- —
- Consumed at
Maintenance access record
- What it is
- Who may perform maintenance in which zone, under what escort and in what window — including supplier maintenance, which is where standing physical access usually hides.
- Produced at
- —
- Consumed at
Supplier terrain register
- What it is
- Suppliers as external actors on the overlay, with the access each holds, the paths that access implies, and the contract behind it.
- Produced at
- —
- Consumed at
Component provenance record
- What it is
- Where components came from, from inventories, build manifests and supplier attestations — and which components have an origin that cannot be verified.
- Produced at
- —
- Consumed at
Supplier access constraint record
- What it is
- How supplier access is brokered, time-bounded and constrained — and the prohibition on standing supplier access to designated decisive points.
- Produced at
- —
- Consumed at
The Whole Citation Index, Resolved.
Each identifier links to its own entry in the reference manual, and each carries the beats it appears in. This is the section that makes the case checkable rather than merely readable.
Controls (39)
Techniques (27)
Terrain (8)
Stated Here so It Cannot Be Over-Read.
One worked case is one worked case. The limits below are the claims a reader might reasonably draw from it that it does not actually support.
- Not evidence that the estate is clean. One hypothesis was tested against one path, and the strongest thing the result can say is bounded by the shortest retention horizon in its own account.
- Not evidence that proactive hunting pays. One hunt in one cycle produced one control finding and no adversary. Whether that is a good return needs a denominator across many cycles that this case does not have and does not pretend to.
- Not a detection-engineering result. Two detections were authored and neither has fired, so nothing here says they work — only that the manual queries behind them now exist as code.
- Not transferable to an estate without flow telemetry on the segments whose denials it asserts. Almost everything the hunt was able to conclude, it concluded because that telemetry existed; an agency without it would have reached the same conclusions with no evidence behind them.
- Not evidence about the unmanaged and contractor device population. Ninety of the 330 devices in scope could not be swept and are recorded as unmeasured, which is not the same as clear and must not be read as it.
- Not a tempo claim. No contact means no defender decision loop, so this case says nothing about whether the program is fast. Its two authority latencies are indicative and were measured under no pressure at all.
- Not a template for a hunt under contact. The pace, the authority profile and the willingness to spend seven days before widening scope are all affordances of an empty estate, and none of them survives an adversary being on it.
- Not, in the end, evidence about the adversary. Everything this case establishes is about the defender: what is reachable, what is collected, how far back, who may act without asking, and how much of the ground nobody has looked at.
The other case runs the opposite posture: The intrusion that made the agency choose between watching and stopping — reactive hunt, 39 beats. The two are meant to be read against each other, and the contrast between them is computed rather than asserted.