ASOM-Fedv6.1Open the explorer
Worked case · Reactive hunt

The intrusion that made the agency choose between watching and stopping

A decoy record in the financial and personally-identifiable data partition was read at 02:14 by a machine identity belonging to the bulk-data service, and the alert sat in the general triage queue until the day shift opened it five and a half hours later. What followed was not a hunt in the sense the proactive case uses the word: the hypothesis was written after the first observation, the loop was entered at Maneuver with the three preceding steps skipped, and the dominant form turned out to be isolation rather than counterattack — because the only revocation path available for the compromised identity also degraded a public service with a statutory obligation behind it. The case turns on the same decision taken three times under three different authorities: observe, and buy intelligence at the price of continued exposure, or evict, and act on an estate you have not finished mapping. The second time, nobody got to take it: a platform engineer reset the credential in good faith and out of sequence, and thirty-five minutes later a dormant partner identity nobody had been watching resumed collection somewhere else.

39Beats25 inside the hunt band, 14 the cycle work around it
8d 12h 46mFirst beat to lastThe hunt band itself ran 3d 7h 49m
8h 3mAuthority taxSpent waiting on 6 escalations to the Authorizing Official
36Controls exercisedAlongside 29 techniques across 7 terrain layers

Everything here is modeled against the Federal Reference Agency. This is not a report of an event at a named agency. The estate is a composite drawn from public doctrine and the published agency archetypes; the beats are authored. What is not authored is the machinery — every control, technique, terrain layer, product and requirement below resolves against the published data, and a citation that does not resolve fails the build.

Where It Starts

The Trigger, and the Ground It Starts On.

A reactive hunt may legitimately enter the loop at maneuver or fuse, and where it enters decides almost everything after — which forms are available, what its authority costs, and what a good outcome even looks like.

What Started It

The trigger

Trigger
A decoy record read at 02:14 by a machine identity — contact, arriving as one high-confidence alert into a queue that had no way to treat it differently from a failed login.
Where it enters the loop
maneuver — a reactive hunt may legitimately enter at maneuver or fuse.
Phases traversed
II Seize Initiative (11)III Dominate (21)IV Stabilize (7)

The Ground in Play

Federal Reference Agency slots

  • Public Data / Open API
  • PII Store / Financial Data
  • Case Filing System
  • ICAM / PDP
  • Mission-Staff Workstations
  • Secondary Portal / Secondary Mission System
Terrain touched
7 of 10 layers. Never touched: T6 Operational Technology, T7 Workforce, T8 Facilities — which is usually the more interesting list.
The Requirements

What the Hunt Was Actually Asked.

Every requirement carries the decision that changes on the answer. One that changes nothing either way is an audit, and should be scheduled as one rather than run as a hunt.

PCIR-09

The decision it changes: Whether to tighten the governance boundary this cycle — which will break at least one reporting workflow the mission depends on — or accept it and instrument the out-of-boundary reads.

PCIR-13

The decision it changes: Whether the next tempo investment goes to detection engineering or to widening the pre-authorized set. They buy different halves of the same interval, and buying the wrong half changes nothing.

PCIR-19

The decision it changes: Whether to transition from Dominate to Stabilize, or hold the phase and keep the wider authorities open at the cost of continued disruption.

PCIR-20

The decision it changes: Whether containment proceeds as designed, or is re-sequenced to preserve evidence and bound exposure — and whether the privacy function is brought in now rather than at the end.

PCIR-22

The decision it changes: Whether to pre-authorize the service-degrading action with explicit bounds, or to build an out-of-hours escalation path with a stated ceiling on time-to-decision.

The Shape of It

Which Forms Were Used, and Where the Work Actually Sat.

Each figure is counted off the beats rather than declared. A case that claims one posture and spends its beats in the other’s band is describing something other than what it says it is.

Forms of Maneuver Exercised

M8
Isolation / Retrograde9 beats · contact
M7
Counterattack8 beats · contact
M6
Delay5 beats · contact

Buy decision time and prevent the adversary culminating on the objective.

M5
Ambush3 beats · contact

Trade space for information and time, and impose cost.

M10
Exploitation & Pursuit2 beats · consolidation

Convert contact into durable advantage rather than closing the ticket.

M1
Screen / Guard1 beat · shaping

Gain early warning and buy reaction time before the adversary touches key terrain.

M3
Envelopment1 beat · shaping

Make identity, not network location, the decisive plane — surround the adversary with policy.

Where the Beats Sat

  • 01 Frame 3 beats, 0 in the hunt band.
  • 02 Map 1 beat, 0 in the hunt band.
  • 03 Array 1 beat, 0 in the hunt band.
  • 04 Maneuver 29 beats, 23 in the hunt band.
  • 05 Fuse 4 beats, 2 in the hunt band.
  • 06 Assess 1 beat, 0 in the hunt band.

Maneuver Bands

  • contact25 beats.
  • consolidation2 beats.
  • shaping2 beats.

Authority

8h 3m spent waiting on 6 escalations. Under contact that is priced in adversary dwell; out of contact it is nearly free, which is why it is worth measuring out of contact first.

Exhibit 1

The Operating Loop, with This Case’s Beats Counted onto It

01FrameScreen02MapCyber Preparation of the Environment03ArrayDesign the scheme04ManeuverExecute05FuseAnalyze06AssessProduceRe-frame · the loop turns faster than the adversary adapts
  1. Frame

    Screen · Analytic Design step 1

  2. Map

    Cyber Preparation of the Environment — the IPB analog

  3. Array

    Design the scheme

  4. Maneuver

    Execute

  5. Fuse

    Analyze · Integrate

  6. Assess

    Produce · re-frame

↺ Re-frame — the loop turns faster than the adversary adapts

Where Its Weight Fell

Beats per step, counted from the timeline. The case enters at Maneuver and puts most of its weight on Maneuver.

Which Campaign Phases It Crossed

The loop turns inside a phase; the phase changes when the Authorizing Official declares it. The two clocks are separate on purpose, and a case that crosses phases is showing both of them.

The diagram is the framework’s own and is unchanged; a case study has no business editing it, and a second copy that could drift would be worse than no drawing. What a case is entitled to add is where its own weight fell, and that is counted underneath in text so it survives a phone — the diagram’s labels are sized against a 1000-unit viewBox and would land near 4px at 390px.
The Honesty Check

Checked Against the Same Agency’s Coverage Baseline.

The most tempting error available to a worked example is depicting the agency doing something the same site elsewhere says it cannot do. So this is a computation rather than a promise: of the 29 techniques these beats cite, the published baseline grades 16 absent — 55.2%. Follow any of them into the record above and check that it is depicted improvised, degraded or failing.

Grades are read from the coverage baseline for the Federal Reference Agency at render time, not copied here — so if the baseline moves, this section moves with it. A technique graded absent that is nonetheless depicted working smoothly would be a defect in the case study, and this is how a reader finds one.

The Record

39 beats, in order.

Every beat carries what it did not establish, because that is most of what real defensive work produces. Beats with a heavier left edge sit inside the hunt band; the rest are the cycle work that made the hunt possible, and separating them is how a program avoids believing hunting is a standalone activity.

  1. D0 02:14

    Beat 1, A decoy record seeded in the PII Store / Financial Data partition was read by a caller inside the bulk-data platform. Four decoys had been maintained on that one layer for eleven months; this was the first interaction any of them had ever produced.

    What it did not establish

    Who read it. A decoy interaction establishes that something touched ground no legitimate process has a reason to touch, and nothing whatsoever about the identity, the intent or the position behind the read.

    Outcome

    One alert raised at medium severity and routed into the general triage queue, where it joined the night’s other 214 items.

    Authority

    Standing ROE

    Form — M5 Ambush
    Controls
    Terrain
    Requirement
  2. D0 07:52

    Beat 2, The day-shift analyst opened the item five hours and thirty-eight minutes after it fired. There was no dedicated route for deception telemetry — the grid emitted into the same pipeline as every other sensor, at a severity assigned by the source’s default, and the queue was worked in arrival order.

    What it did not establish

    Whether a dedicated route would have been answered faster at 02:14. The agency runs a two-person night shift against a queue that does not distinguish a decoy from a failed login, and the routing gap and the staffing floor are two separate findings that this beat cannot separate.

    Outcome

    The single highest-confidence detection the estate is capable of producing was worked in arrival order, and the interval was recorded rather than rounded.

    Confidence — high

    Both timestamps come from the same alerting platform: the deception source emitted at 02:14 and the first analyst action on the item is recorded at 07:52. Nothing about the interval is reconstructed.

    This is a failure the manual already predictsM5 Ambush — how it fails

    Decoy hits are routed to the same queue as everything else, which discards the only property that made them worth emplacing.

    • Deception alert routing was never built as a separate path. The grid was emplaced as a detection project and its output inherited the default severity of the platform that carried it.
    • The night shift works a mixed queue in arrival order, so an item’s position depends on when it arrived rather than on what would follow from it being true.
    • Nobody had ever measured time-to-human on a decoy interaction, because until this night the grid had never produced one to measure.
    Authority

    Standing ROE

    Form — M5 Ambush
    Controls
  3. D0 08:31

    Beat 3, The hunt lead wrote the hypothesis after the observation rather than before it, which is the ordering that makes this a reactive hunt: an identity that is not a mission-staff human has read from the crown-jewel partition, and if that is true the same identity will appear in the object-store access log against non-decoy prefixes.

    What it did not establish

    Anything about scope. A hypothesis written thirty-nine minutes after a decoy fires is a direction to search in, and this one deliberately named a falsifier before collection opened so that the search could come back empty and mean something.

    Outcome

    One written claim, one named falsifier, and a collection list of three sources — the object-store access log, the identity provider token issuance record, and the bulk-export service’s own audit trail.

    Authority

    No authority required

    Form — M7 Counterattack
    Controls
    Requirement
  4. D0 09:10

    Beat 4, The read was attributed to a machine identity belonging to the Public Data / Open API bulk-export service. The lateral path audit was done by hand against raw flow records — the agency has no path-audit tooling — and it took thirty-one minutes to establish that this identity has a standing route to the whole partition, not only to the published extract.

    What it did not establish

    Whether the machine identity was itself the adversary or was being driven by something upstream of it. A service principal reading its own data path looks identical whether the caller is the service or is somebody holding the service’s secret.

    Outcome

    The caller named, the route confirmed as standing and unconstrained, and a second question opened that the telemetry as sited cannot answer.

    Confidence — moderate

    The caller principal resolves cleanly in three logs. What it was doing on behalf of does not resolve at all, because the bulk-export service does not propagate an on-behalf-of claim into its data-layer calls.

  5. D0 09:40

    Beat 5, The Authorizing Official held the declaration at Phase II rather than jumping to Phase III, and shifted the cycle cadence from twenty-one days to a four-hour contact tempo. The intent paragraph was rewritten in one sentence: preserve the record set, and do not take the filing path down to do it.

    What it did not establish

    Whether Phase II was the right declaration. It was the declaration that kept the wider fire set closed for another four hours, and the case cannot say what the wider set would have bought during them because it was not open.

    Outcome

    A phase held, a cadence changed, and an intent paragraph that named the constraint the whole rest of the cycle turned on.

    Authority

    Standing ROE

    Form

    None — an analytic beat, instantiating no maneuver.

    Controls
  6. D0 10:05requested 09:39decided 10:05

    Beat 6, The first observe-or-evict decision, made explicitly and recorded as such. The hunt lead recommended isolating the machine identity immediately. The Authorizing Official decided to hold and observe for a bounded four hours, on the reasoning that isolating the only identity currently visible would tip whatever was behind it before its extent was known — and wrote a stop condition: any read against a non-decoy prefix ends the window at once.

    What it did not establish

    Whether observation was worth its price. The window ran for three hours and fifteen minutes before its stop condition fired, and what it bought — the shape of the collection pattern — is real but cannot be weighed against what continued reading cost, because the reads inside the window were never enumerated.

    Outcome

    A bounded observation window with a written stop condition, a named decision-maker, and twenty-six minutes of latency to reach him during the working day.

    Confidence — moderate

    The judgment rests on one read against one decoy and a route that is standing rather than newly created. Nothing at this point distinguished an adversary from a misconfigured job.

    Authority

    Escalated to the AO26 minutes waiting on the decision

    Form

    None — an analytic beat, instantiating no maneuver.

    Requirement
  7. D0 10:40

    Beat 7, Adaptive rate limiting was applied to the bulk-export path under the pre-authorized set. The discriminating control — a throttle scoped to a single caller — does not exist in this estate, so the limit was applied to the endpoint, which means to every consumer of it: eleven external bulk subscribers, two internal reporting jobs, and the adversary.

    What it did not establish

    Whether the adversary was slowed at all. Their observed request rate had been running at roughly a third of the new ceiling for as long as the log reaches, so the limit sat above their behavior and below everybody else’s.

    Outcome

    Two subscriber complaints inside forty minutes, a measurable drop in legitimate throughput, and no measurable change in the caller the limit was imposed for.

    This is a failure the manual already predictsM6 Delay — how it fails

    Delay is applied to the population rather than to the anomaly, because the discriminator was never built. The adversary is slowed by the same proportion as everyone else, which is no relative advantage at all.

    • Per-caller export throttling was never implemented, so the only throttle available operates on the endpoint rather than on the identity.
    • The rate ceiling was derived from load testing rather than from observed adversary behavior, so it was set above the rate the adversary was actually using.
    • The pre-authorized set names the action but not the population it may be applied to, which left the choice of blast radius to an operator at 10:40 with no stated bound.
    Authority

    Pre-authorized

    Form — M6 Delay
    Controls
  8. D0 11:15

    Beat 8, Step-up authentication on anomaly was triggered against the affected scope. It reached every human session in the mission tier and none of the machine identities, because a service principal holding a client secret has no second factor to step up to and the policy engine skips it rather than denying it.

    What it did not establish

    Whether the human population in scope was clean. Forty-one staff re-authenticated successfully, which says they could satisfy the challenge and says nothing about whether any of their tokens had already been taken.

    Outcome

    A delay measure that landed entirely on the population that was not under suspicion, recorded as no effect rather than as a control exercised.

    Authority

    Pre-authorized

    Form — M6 Delay
    Controls
  9. D0 11:48

    Beat 9, Session duration under alert was cut from eight hours to thirty minutes across the mission tier. The bulk-export service principal holds a twenty-four-hour token that the reduction policy does not govern, so the measure shortened every session except the one it was imposed against.

    What it did not establish

    How long the adversary’s current token had left to run. Token issuance time was available; the lifetime configured at issuance was not recorded anywhere the responders could read during contact, and it was reconstructed two days later.

    Outcome

    Human session lifetime cut by a factor of sixteen, machine session lifetime unchanged, and a helpdesk load that arrived within the hour.

    Authority

    Pre-authorized

    Form — M6 Delay
    Controls
  10. D0 12:30

    Beat 10, The team established, by trying it, that the machine identity’s issued token cannot be revoked independently of the service: the only supported revocation invalidates every token the bulk-export service holds and requires the service to restart to re-acquire one. Revoking the adversary’s access and degrading the public data service were, in this estate, the same action.

    What it did not establish

    Whether that coupling is a platform constraint or a configuration one. The finding was recorded against the service, not against the platform, and the distinction was carried forward unresolved because nobody had time to test it under contact.

    Outcome

    The single technical fact that shaped every subsequent decision: there was no quiet eviction available on this identity, only a loud one.

    Confidence — high

    Established by attempting it in the pre-production tenancy rather than by reading the documentation, which described a revocation path the platform has not supported since the last major version.

    Authority

    Pre-authorized

    Form — M3 Envelopment
    Controls
    Requirement
  11. D0 13:20

    Beat 11, The observation window’s stop condition fired at three hours fifteen. The caller read from a live PII prefix, not a decoy one — 41 objects, ordered by key, at a rate that had not changed since the window opened. The fused assessment named it deliberate staged collection at high confidence, and named the two hypotheses it could not yet separate: a compromised secret, or a compromised host holding one.

    What it did not establish

    Which of the two competing hypotheses was true, or whether either excluded a third the fusion had not thought of. The assessment stated both and did not collapse them, which is what stopped the eviction plan from being written against one of them an hour later.

    Outcome

    Contact confirmed on evidence rather than on inference, the observation window closed by its own written condition, and two hypotheses carried forward rather than one.

    Confidence — high

    Two independent sources agree: the object-store access log carries the prefix reads, and the data platform’s own audit trail carries the same object keys under the same principal within the same minute.

    Authority

    No authority required

    Form

    None — an analytic beat, instantiating no maneuver.

    Controls
    Requirement
  12. D0 13:35

    Beat 12, Phase III was declared against the Public Data / Open API scope on the strength of the fused assessment, fifteen minutes after the stop condition fired. The declaration was scoped to that service rather than to the estate, which kept the Case Filing System outside the fire set — a decision that turned out to matter eleven hours later, and not in the way it was intended.

    What it did not establish

    That the scope of the declaration matched the scope of the intrusion. The declaration was drawn around the service the evidence named, and the evidence at that hour reached exactly one identity.

    Outcome

    A phase declared eleven hours and twenty-one minutes after first contact, and a tempo threshold set for the first time in this cycle at thirty minutes from detection to containment action.

    Authority

    Standing ROE

    Form

    None — an analytic beat, instantiating no maneuver.

    Controls
  13. D0 13:45

    Beat 13, The wider pre-authorized fire set was opened: host isolation on confirmation, credential reset, egress blocking on named infrastructure and estate-wide session revocation moved from AO decisions to operator decisions. Three actions stayed above the line — degrading a public statutory service, suspending a federation, and cutting a third-party connection.

    What it did not establish

    Whether the line was drawn in the right place. It was drawn where the scheme had drawn it in Phase 0, unchanged, and every one of the three actions held above it was needed within the next twenty-six hours.

    Outcome

    Four classes of action devolved to the shift, three retained, and a rules-of-engagement version stamp that the responders could read from the console for the first time in the incident.

    Authority

    Standing ROE

    Form

    None — an analytic beat, instantiating no maneuver.

    Controls
    Requirement
  14. D0 13:52

    Beat 14, The Mission-Staff Workstation that had most recently held an interactive session with the export service was isolated at the endpoint agent, seven minutes after the fire set opened and thirty-two seconds after the operator decided to. This was the only action in the entire incident that took less time to execute than to describe.

    What it did not establish

    That the isolated host was the origin. It was the host the correlation reached first, and it was isolated because isolation is cheap and reversible, not because the evidence had settled on it.

    Outcome

    One host isolated inside the declared thirty-minute threshold, with the first genuinely fast containment action of the cycle recorded against it.

    Authority

    Pre-authorized

    Form — M7 Counterattack
    Controls
    Terrain
    Requirement
  15. D0 14:06

    Beat 15, A platform engineer watching the same bridge, acting in good faith and reading the newly-opened fire set as permission, rotated the bulk-export service principal’s client secret. Credential reset was inside the set. What was not inside anything was an order — there was no eviction sequence, because the agency has never written one, so the fastest available action was taken first rather than in a position in a plan.

    What it did not establish

    Whether a sequence would have held. The counterfactual is unavailable: nobody can say that an eviction plan written in advance would have survived an engineer with the access, the authority and eleven hours of adrenaline.

    Outcome

    The adversary’s active session died within ninety seconds. Eleven minutes later a second identity that nobody had been watching authenticated from a partner federation and resumed collection on a different egress path.

    This is a failure the manual already predictsM7 Counterattack — how it fails

    Eviction is unsequenced, so the first action warns the adversary and the remaining actions land on an estate they have already left for a position you have not found.

    • No eviction sequence existed to be out of order with. The pre-authorized set enumerates actions and says nothing about their ordering, which reads as permission to take any of them at any time.
    • The fire set was opened to the shift twenty-one minutes earlier with no accompanying statement of what was to be done first, and an opened authority with no plan attached is an invitation to act on the fastest thing.
    • The engineer was not on the hunt bridge and had no visibility of the two competing hypotheses, so the tipping cost of a credential rotation was not visible from where the decision was made.
    Authority

    Taken as an exception

    Form — M7 Counterattack
    Controls
    Requirement
  16. D0 14:41

    Beat 16, The new authentication was resolved against the authentication geography baseline: a dormant partner-federation identity, last used one hundred and thirty-one days earlier, authenticating from an autonomous system the baseline had never seen for that account, thirty-five minutes after the credential rotation.

    What it did not establish

    How long the second identity had been available to the adversary. It was dormant, not new — the account had existed and been entitled throughout, so its appearance says when it was used and nothing about when it was obtained.

    Outcome

    A second position identified, an intrusion that was demonstrably wider than the evidence had reached, and the first hard indication that the eviction had begun before the mapping had finished.

    Confidence — moderate

    The authentication is anomalous against a ninety-day geography baseline that covers partner identities thinly — twenty-two accounts, most of which sign in a handful of times a month, which is a small denominator to call anomalous against.

    Authority

    Pre-authorized

    Form — M1 Screen / Guard
    Controls
    Requirement
  17. D0 14:52

    Beat 17, The connection register was corrected under contact. It carried the partner federation as a permitted edge to the Case Filing System only; the entitlement actually reaching the bulk-data platform had been granted eight months earlier through a group nesting that the register does not model.

    What it did not establish

    How many other permitted edges the register understates for the same reason. One nesting was found because it was in the path of an active intrusion; nothing was done to enumerate the rest, and the register was corrected for this edge alone.

    Outcome

    One corrected edge, one newly-recorded finding that the register models direct grants and not inherited ones, and no change to the register’s reported completeness.

    Authority

    Standing ROE

    Form

    None — an analytic beat, instantiating no maneuver.

  18. D0 15:10requested 14:32in force 15:10

    Beat 18, A change and deploy freeze was imposed across the mission tier so that the estate the responders were reasoning about would stop moving underneath them. It needed the Authorizing Official because it slips releases, and it waited thirty-eight minutes for him — during which two unrelated deployments completed and had to be re-examined afterwards.

    What it did not establish

    Whether the two deployments that landed during the wait were clean. They were reviewed and nothing was found, which is a statement about a review that had four minutes of attention on a day when nobody had four minutes.

    Outcome

    The estate stopped moving thirty-eight minutes later than it was asked to, and two changes landed inside the gap.

    Authority

    Escalated to the AO38 minutes waiting on the decision

    Form — M6 Delay
    Controls
  19. D0 16:34requested 14:58in force 16:34

    Beat 19, Suspension of the partner federation trust was requested seventeen minutes after the second identity was found, and took effect ninety-six minutes later. The action is technically a single configuration change; the delay was entirely in reaching a decision-maker whose criteria for making it had never been written down, so the decision was reasoned from first principles at the moment it was least affordable to do so.

    What it did not establish

    What the partner’s other twenty-one identities were doing during the wait. Their activity was collected and has still not been analyzed at the time of writing, because the analytic effort went to the intrusion rather than to the population around it.

    Outcome

    The second identity’s route closed at 16:34. Collection on the alternate egress path continued throughout the ninety-six minutes and is recorded as having done so.

    Authority

    Escalated to the AO96 minutes waiting on the decision

    Form — M8 Isolation / Retrograde
    Requirement
  20. D0 17:20

    Beat 20, The exfiltration destination was a commercial object-store tenancy that the open-data service also legitimately publishes to. A blanket blackhole would have taken down the agency’s own publication path, so the block was written against a single bucket path by hand — forty minutes of rule-writing to do what the pre-authorized set assumes is one action.

    What it did not establish

    Whether the adversary held a second destination. The block closed the path that had been observed; nothing in the estate would have shown a destination that had not yet been used.

    Outcome

    One egress path closed with the agency’s own publication left standing, at the cost of forty minutes of the incident’s scarcest hour.

    Authority

    Pre-authorized

    Form — M8 Isolation / Retrograde
    Controls
  21. D0 18:05

    Beat 21, Volatile capture and disk imaging were taken on the workloads in scope, four hours after the first containment action. Three of five were captured. The other two were ephemeral compute that the platform’s own autoscaler had recycled at 15:40 and 16:12 — after contact was confirmed, and while everyone was watching the identity plane.

    What it did not establish

    What was on the two recycled workloads. They are gone, and the record notes that they are gone rather than reasoning about what they probably held, because a reconstruction of a destroyed host is an assumption with a timestamp on it.

    Outcome

    A partial evidentiary record, chain of custody intact on what survives, and the input to every consolidation activity downstream reduced to three fifths of its scope.

    Confidence — low

    Preservation covers three of the five workloads in scope, and the two that are missing are the two the intrusion most likely originated on. What survives is a partial record whose gaps are not randomly distributed.

    This is a failure the manual already predictsM8 Isolation / Retrograde — how it fails

    Isolation destroys the forensic record, and the dwell reconstruction — the input to every consolidation activity that follows — cannot be produced.

    • The isolation playbook has no preservation step in front of it, so preservation happened when somebody thought of it rather than as a precondition of containing anything.
    • Ephemeral compute recycles on a platform schedule that no incident action pauses, and nobody in the response had the authority or the knowledge to pause it.
    • The two lost workloads were in scope from 13:20 and were not captured until 18:05, an interval in which nothing prevented the platform from doing exactly what it is configured to do.
    Authority

    Standing ROE

    Form — M8 Isolation / Retrograde
    Controls
    Requirement
  22. D0 19:30

    Beat 22, The record sets inside the affected scope were resolved against the privacy terrain: two of the four prefixes the caller had reached hold personally identifiable information, one holds controlled unclassified information under a handling caveat, and one is the published open-data extract and holds neither.

    What it did not establish

    How many records were actually read. The object-store access log records the prefixes touched and the request counts, not the object bodies, so the exposure is bounded by what could have been read rather than by what was.

    Outcome

    Three of four prefixes classified as reportable if read, an upper bound on exposure stated as an upper bound, and a notification clock that started from the classification rather than from the containment.

    Authority

    No authority required

    Form

    None — an analytic beat, instantiating no maneuver.

    Terrain
    Requirement
  23. D0 20:40

    Beat 23, The second observe-or-evict decision, and the one that went the other way. The hunt lead asked to leave the remaining collection path open overnight to see whether a third position surfaced. The Authorizing Official refused inside four minutes and gave the reason in one sentence: the corpus is personally identifiable information, and an agency does not buy intelligence with other people’s records.

    What it did not establish

    Whether a third position existed. It was not looked for from this direction, and the persistence sweep two days later could not have found a position that was dormant and untouched throughout it.

    Outcome

    Observation ended by decision rather than by exhaustion, with the reason recorded in the incident log in the decision-maker’s own words and available to be argued with afterwards.

    Authority

    Standing ROE

    Form

    None — an analytic beat, instantiating no maneuver.

    Requirement
  24. D+1 00:15requested D0 20:41in force D+1 00:15

    Beat 24, Because there was no way to revoke the machine identity without restarting the service, containment and degradation were the same act. The Public Data / Open API was dropped to a cached read-only snapshot. The request went up at 20:41 and the action landed at 00:15 — three hours and thirty-four minutes, most of it spent establishing who was permitted to authorize degrading a service with a published availability commitment, because that had never been written down.

    What it did not establish

    What was read during the wait. The egress block held from 17:20, so the destination was closed; whether a second destination was in use during those three and a half hours is exactly the question the case cannot answer, and it is the reason the wait is expensive rather than merely slow.

    Outcome

    The service degraded as intended and took the Case Filing System’s status lookup with it — an undeclared dependency on the same API, discovered at 00:19 by a citizen-facing error rather than by a dependency map.

    This is a failure the manual already predictsM8 Isolation / Retrograde — how it fails

    Degraded mode was never rehearsed, so degradation becomes an unplanned outage and the organization learns which dependencies were undeclared during the incident.

    • The degraded mode had never been exercised. It existed as a configuration flag and a paragraph, and the paragraph did not know about the filing status lookup.
    • Dependency declaration is voluntary in this estate and is done by the consuming team, so a consumer that never declared its dependency is invisible to the producer’s degradation plan.
    • The decision took three and a half hours because the authority to make it had not been assigned in advance, which meant the first thirty minutes of the outage were spent on a question that a single line in the scheme of maneuver would have answered.
    Authority

    Escalated to the AO214 minutes waiting on the decision

    Form — M8 Isolation / Retrograde
    Requirement
  25. D+1 03:35

    Beat 25, The statutory availability floor was written at 03:35 on the second day of an incident, by the Authorizing Official, into the incident log — because it did not exist before then. Three hours and twenty minutes of filing-status unavailability had already elapsed on a statutory filing deadline day, against a floor that was being defined after the fact to describe what had already happened.

    What it did not establish

    What the floor should have been. What was written at 03:35 is a floor that the events of that night comfortably satisfy, and the record marks it as provisional and requiring a mission owner’s signature outside contact, precisely because a floor authored during a breach is authored by the breach.

    Outcome

    A floor on the record, an exception recorded against the authority under which the degradation had already been taken, and a finding raised against the absence rather than against the people improvising around it.

    This is a failure the manual already predictsManeuver — failure mode

    A statutory service is degraded without reference to the floor.

    • No availability floor had ever been declared for the filing path, so there was no number to degrade against and no threshold at which the degradation should have been escalated further.
    • The floor is a mission judgment and had been left to the security program, which does not own the statutory obligation and could not have set it alone.
    • The dependency between the data API and the filing status lookup meant the floor that mattered belonged to a service nobody had declared Phase III against.
    Authority

    Taken as an exception

    Form — M8 Isolation / Retrograde
    Requirement
  26. D+1 03:55

    Beat 26, The filing status lookup was repointed at a static cache and came back at 03:55. It had failed rather than degraded because the fail-secure default is set to deny — the correct setting, which in this instance converted a stale-data problem into an outage, and the record says so in that order rather than treating the default as the fault.

    What it did not establish

    Whether fail-secure is the right default for this particular call. A status lookup returning a stale answer is arguably safer than one returning an error, and the case notes the question without answering it because it is a mission judgment and not a security one.

    Outcome

    Filing status restored on cached data after three hours and forty minutes, and a design question raised that the incident is not the right forum to settle.

    Authority

    Pre-authorized

    Form — M8 Isolation / Retrograde
    Controls
  27. D+1 10:15

    Beat 27, An approval gate was inserted in front of configuration changes to the bulk-export path, on the reasoning that an estate under contact should not be reconfigured without a second pair of eyes. By cycle close it had fired eleven times and approved eleven, at a median of ninety seconds.

    What it did not establish

    Whether any of the eleven should have been refused. A gate that approves everything supplies no evidence either way, which is the property that makes it indistinguishable from no gate at all except in the latency it adds.

    Outcome

    Eleven approvals, no refusals, ninety seconds of median latency per change, and a control that was reported at cycle close as friction rather than as maneuver.

    This is a failure the manual already predictsM6 Delay — how it fails

    The approval gate degrades into a rubber stamp. A high-impact action that always gets approved within ninety seconds has added latency and removed nothing.

    • The gate was inserted without a refusal criterion, so the approver had nothing to test a request against beyond whether it looked reasonable at the time.
    • The approver was drawn from the same team making the requests, which makes refusal a social act rather than a procedural one.
    • No measurement of the gate was planned, so the eleven-of-eleven figure exists only because somebody counted it retrospectively while writing the cycle record.
    Authority

    Standing ROE

    Form — M6 Delay
    Controls
  28. D+1 11:00

    Beat 28, The eviction sequence was written for the first time, on a whiteboard, thirty-two hours and forty-six minutes after contact: twenty-six actions, each with a named owner, a stated tipping cost and a position in an order, with the four actions that must land within the same ten minutes marked as a single block.

    What it did not establish

    That the sequence was complete. It covers the two identities that were found; a sequence cannot order actions against a position nobody has located, and the document says so on its own first line.

    Outcome

    A sequence that will exist before the next contact, and the plain observation that writing it took under two hours and could have been done in any of the previous eleven cycles.

    Confidence — moderate

    The sequence is built on a scope that is three fifths evidenced and two fifths inferred, because two of the five workloads were recycled before capture. Its ordering is sound; its completeness inherits that gap.

  29. D+1 12:20

    Beat 29, Estate-wide session revocation was executed as block one of the sequence: 14,900 sessions invalidated in four minutes. Three service accounts could not be revoked without restarting the services behind them and were left live under continuous watch, with the exception recorded against each rather than against the action as a whole.

    What it did not establish

    Whether the three exempted service accounts were clean. They were watched, which detects use and does not establish absence, and they are named individually in the cycle record so that the residual attaches to something specific.

    Outcome

    Near-complete revocation in four minutes, three named exceptions carried openly, and a helpdesk volume that peaked at eleven times normal for ninety minutes.

    Authority

    Pre-authorized

    Form — M8 Isolation / Retrograde
    Controls
    Requirement
  30. D+1 13:05

    Beat 30, The automated containment playbook ran the credential reset across the sixty-one identities the sequence named. It completed fifty-seven and stopped on four: two owned by a supplier under a contract that requires notice, one bound to a scheduled job with a secret stored outside the vault, and one whose owner had separated and whose account had not been closed.

    What it did not establish

    Why the separated account survived. It was raised to the workforce owner as a finding and had not been answered by cycle close, so the case records an open question rather than the cause it would be convenient to assume.

    Outcome

    Fifty-seven of sixty-one reset automatically, four escalated by hand with a named reason each, and one incidental finding about the separation pipeline that had nothing to do with the intrusion.

  31. D+1 15:40requested 14:53in force 15:40

    Beat 31, The standing network connection to the partner tenancy was cut, forty-seven minutes after it was requested. The delay was contractual rather than technical: the connection carries a notice obligation, and the forty-seven minutes were spent establishing that an active intrusion satisfies the emergency clause.

    What it did not establish

    Whether the emergency clause is durable. Counsel read it in the moment and agreed; nothing has since been changed in the agreement or in the runbook, so the same forty-seven minutes are available to be spent again.

    Outcome

    The connection cut, the partner notified under the emergency clause, and the reading of the clause recorded so the next incident does not have to re-derive it.

    Authority

    Escalated to the AO47 minutes waiting on the decision

    Form — M8 Isolation / Retrograde
    Controls
  32. D+2 09:15

    Beat 32, A persistence sweep was run across the workload fleet against the eleven mechanisms the sequence named. It covered 412 of 540 workloads. The remaining 128 are ephemeral compute that recycles faster than the sweep completes, and they are recorded as unmeasured rather than as clear.

    What it did not establish

    That persistence was absent from the 128. A sweep that cannot reach a population says nothing about it, and the temptation with an ephemeral fleet is to argue that recycling is itself eradication — which is true only for persistence that does not survive a rebuild.

    Outcome

    Two artifacts found on one host, both consistent with the first identity and neither with the second, and 24% of the fleet reported as unmeasured in the same sentence as the result.

    Confidence — moderate

    The sweep is complete across the persistent fleet and structurally blind to the ephemeral one, and the ephemeral fleet is where two of the five in-scope workloads lived.

  33. D+2 15:00

    Beat 33, Phase IV was declared on the Public Data / Open API scope: eradicate, verify, and preserve availability through the recovery. The declaration was made on the absence of new indicators for twenty-six hours, which the record explicitly labels as the weakest of the three grounds it could have been made on.

    What it did not establish

    That the intrusion was over. Twenty-six hours of quiet is consistent with eviction and equally consistent with an adversary who has gone quiet, and the declaration names both readings instead of choosing the flattering one.

    Outcome

    A phase declared on a stated and admittedly weak basis, with the basis written into the declaration so that a later reader can weigh it.

    Authority

    Standing ROE

    Form

    None — an analytic beat, instantiating no maneuver.

    Controls
  34. D+3 10:00requested 08:58signed 10:00

    Beat 34, Restoration preconditions were written — also for the first time — as five conditions the service had to satisfy before returning to full read-write. Three were met. Two were not: the dwell reconstruction could not be produced, and the integrity of the published open-data snapshots could not be verified against an independent record because no independent record is kept. The service was restored anyway, on the Authorizing Official’s signature, with both gaps named in the decision.

    What it did not establish

    That the estate came back clean. Three preconditions were satisfied and two were waived, and the difference between "restored on evidence" and "restored on a signature covering the missing evidence" is the entire content of this beat.

    Outcome

    Full service restored on day three with two of five preconditions formally waived, each waiver carrying a named risk owner and an expiry.

    This is a failure the manual already predictsM8 Isolation / Retrograde — how it fails

    Services are restored without preconditions, so the estate comes back into a compromise that was contained rather than removed, and the second incident is the same as the first.

    • The preconditions did not exist before the incident, so they were authored by the people under pressure to restore, which is the worst possible authorship for a gate.
    • Two of the five could never have been met, because the evidence they require — a dwell reconstruction and an independent integrity record — is produced by capabilities this estate does not operate.
    • The pressure to restore was statutory and real, and no mechanism existed to price the residual of restoring early against the cost of staying down, so the trade was made on judgment alone.
    Authority

    Escalated to the AO62 minutes waiting on the decision

    Form — M8 Isolation / Retrograde
    Requirement
  35. D+3 16:20

    Beat 35, The dwell reconstruction was attempted and abandoned. First evidenced access sits at the fourteen-day edge of the object-store access log, which means the true first access is at or before it and cannot be placed. The identity provider retains ninety days and shows the partner account dormant for one hundred and thirty-one, which brackets the second position and not the first.

    What it did not establish

    When the adversary actually arrived. The honest statement is a range whose lower bound is a log retention setting and whose upper bound is the decoy read, and the difference between them is thirty-two days that nobody can narrow.

    Outcome

    Dwell reported as a range between 14 and 46 days with the bound attributed to retention, and the agency’s standing dwell estimate left unchanged rather than revised on a number this weak.

    Confidence — low

    Two of the five in-scope workloads were destroyed before capture and the object-store access log reaches back fourteen days. The earliest evidenced access is a floor imposed by retention, not a finding about the adversary.

  36. D+5 11:00

    Beat 36, Seven detections were authored from the incident’s indicators. Four fired correctly against replayed telemetry. Two produced volumes that could not be triaged by a two-person night shift and were held back rather than shipped noisy. One could not be written at all: the discriminating signal is the on-behalf-of claim that the bulk-export service does not propagate.

    What it did not establish

    That the four shipped detections work. They fired against replayed telemetry from this incident, which is the sample they were derived from, and a detection validated only against the intrusion that produced it is untested rather than proven.

    Outcome

    Four detections in production and marked untested, two held back with a stated reason, and one recorded as a telemetry gap rather than as a detection failure.

  37. D+6 14:00

    Beat 37, The avenue was closed by policy: application consent grants on mission-staff accounts now require administrative approval, and the bulk-export identity was re-scoped from the whole partition to the published extract. Verification that the avenue is actually closed was not performed, because the test requires consenting a live application against production identity policy and nobody was willing to do that eight days after an intrusion.

    What it did not establish

    That the avenue is closed. The configuration says it is; nothing has tested it; and the register entry that records the closure looks exactly like the two hundred and thirteen other entries in it that were also never tested.

    Outcome

    Two changes applied, the closure recorded as asserted rather than as verified, and a verification task raised with a date and no owner.

    This is a failure the manual already predictsMap — failure mode

    Denied paths are asserted from configuration and never tested.

    • Testing the closure requires exercising a consent flow in production, and no safe method for doing so exists in this estate.
    • The denied-path register has one column for a path being denied and no column for how that denial was established, so an assertion and a test are recorded identically.
    • The verification task was raised at the end of an eight-day incident into a backlog with no owner assigned, which is the state in which tasks age rather than complete.
  38. D+7 10:30

    Beat 38, Deception coverage was measured for the first time, prompted entirely by the grid having finally produced something. Four decoys, all on the data layer, none on the identity plane and none on the corridor the second position used. A dedicated alert route was built so that a future decoy interaction pages a human directly instead of entering the general queue.

    What it did not establish

    Whether the grid would catch the same intrusion again. The one decoy that fired was on the objective, and a decoy on the objective fires after an adversary has reached it — the coverage measurement makes that visible and the re-siting to fix it has not been done.

    Outcome

    A measured coverage figure of one layer in ten, a routing gap closed in an afternoon after eleven months, and a re-siting plan raised into the backlog.

  39. D+8 15:00

    Beat 39, The cycle record was written with the authority tax as its headline rather than the containment. Six escalations, summed from the beats that waited, against a set of pre-authorized fires that covered four of the ten actions the incident actually needed. The brief led with the three-and-a-half-hour wait on the degradation decision, not with the four-minute host isolation.

    What it did not establish

    Whether the program is faster than the adversary. The temporal-advantage ratio needs a measured adversary objective time, and the dwell reconstruction that would supply it was destroyed on day zero — so the numerator exists, the denominator does not, and the scoreboard line is a gap.

    Outcome

    A record whose headline is a latency rather than a success, a backlog re-ranked with the eviction sequence and the availability floor above eleven higher-volume items, and one scoreboard line left deliberately blank.

Where It Went Wrong

Each of These Is a Failure the Manual Already Predicts.

A case study in which nothing goes wrong is a brochure. Each failure below points at the framework’s own published prediction of it — inventing a novel failure the doctrine never anticipated would be a finding about the doctrine rather than a story beat.

The estate’s best detection spent five and a half hours in the ordinary queue

What happened

The deception grid produced its first interaction in eleven months and it was routed into the general triage queue at the source platform’s default severity, where it was worked in arrival order behind 214 other items. A decoy interaction has no false-positive budget — legitimate processes have no reason to touch a decoy — and that property is the entire reason the grid was funded. Routing it into a mixed queue converted the one detection the estate can trust without tuning into an ordinary ticket, and the five hours and thirty-eight minutes it waited are the single largest recoverable interval anywhere in this timeline.

Predicted byM5 Ambush — how it fails

Decoy hits are routed to the same queue as everything else, which discards the only property that made them worth emplacing.

What changed as a result

A dedicated route now pages a named human directly on any deception-source event, built in one afternoon on day seven, and deception coverage is measured for the first time — four decoys across one of ten layers. What has not changed is the night-shift floor: the route now reaches two people at 02:14 instead of nobody, and whether two people can act on it at that hour has not been tested.

A credential was reset in good faith, out of sequence, and it bought the adversary a second position

What happened

Twenty-one minutes after the wider fire set was opened to the shift, a platform engineer rotated the bulk-export service principal’s client secret. The action was inside the pre-authorized set and the engineer was entitled to take it. What did not exist was an order: the agency has never written an eviction sequence, so the set enumerates actions and says nothing about which one goes first or what each costs in tipping. The adversary’s session died within ninety seconds and a dormant partner-federation identity authenticated thirty-five minutes later on a different egress path — a position nobody had been watching, on an account last used one hundred and thirty-one days earlier.

Predicted byM7 Counterattack — how it fails

Eviction is unsequenced, so the first action warns the adversary and the remaining actions land on an estate they have already left for a position you have not found.

What changed as a result

An eviction sequence now exists: twenty-six actions, each with an owner, a tipping cost and a position, with the four that must land inside the same ten minutes marked as one block. It was written in under two hours on day one, which is the uncomfortable part of the finding — nothing prevented it being written in any of the eleven previous cycles. It has not been rehearsed, and a sequence that has never been walked through is a document rather than a capability.

The retrograde had never been rehearsed, so containment became an outage on a filing deadline

What happened

Because the compromised machine identity could not be revoked without restarting the service that held it, containment and degradation were the same act. The read-only degradation had existed for two years as a configuration flag and a paragraph and had never once been exercised. When it was applied at 00:15 it took the Case Filing System’s status lookup with it — an undeclared dependency on the same API — and citizens on a statutory filing deadline day received errors for three hours and forty minutes. The dependency was discovered by a member of the public before it was discovered by the agency.

Predicted byM8 Isolation / Retrograde — how it fails

Degraded mode was never rehearsed, so degradation becomes an unplanned outage and the organization learns which dependencies were undeclared during the incident.

What changed as a result

A degradation rehearsal is now on the backlog with a date, and the filing status lookup has been repointed at a cache permanently rather than for the duration. The deeper cause is untouched: dependency declaration in this estate is voluntary and is done by the consuming team, so the producer’s degradation plan is only ever as complete as the consumers chose to make it, and nothing about that has changed.

The decision that mattered most waited three and a half hours for an authority nobody had assigned

What happened

Degrading a public service with a published availability commitment was above the line in the rules of engagement, correctly. What was not written anywhere was who could authorize crossing that line, on what criteria, at what hour. The request went up at 20:41 and the action landed at 00:15, and most of those three hours and thirty-four minutes were spent establishing the answer to a question that one line in the scheme of maneuver would have settled in advance. It is the single longest wait in the case and it accounts for a large share of the whole authority tax — and the interval was spent, from the adversary’s point of view, with the collection path still open.

Predicted byM8 Isolation / Retrograde — how it fails

The severing action is technically available but nobody is authorized to take it, so it is escalated through three layers while the exfiltration completes.

What changed as a result

The Authorizing Official’s decision criteria for service-affecting containment are now written into the scheme of maneuver with a named deputy and an out-of-hours path, and a statutory availability floor exists on paper for the filing service. Both were authored during or immediately after the incident, which means both are provisional: a floor written at 03:35 by the person who has just degraded the service is a floor that describes what happened rather than what should be permitted.

Isolation cost the forensic record, and the forensic record was the input to everything after it

What happened

Volatile capture was taken four hours after the first containment action, and by then the platform’s own autoscaler had recycled two of the five in-scope workloads — the two the intrusion most likely originated on. Nothing in the response paused the autoscaler, because no one in the response had the authority or the knowledge to pause it and the isolation playbook has no preservation step in front of it. The consequence is not confined to the investigation: the dwell reconstruction could not be produced, which left the temporal-advantage scoreboard line blank, left two restoration preconditions permanently unmeetable, and left the agency’s standing dwell estimate unrevised.

Predicted byM8 Isolation / Retrograde — how it fails

Isolation destroys the forensic record, and the dwell reconstruction — the input to every consolidation activity that follows — cannot be produced.

What changed as a result

Preservation has been moved to the front of the isolation playbook as a precondition rather than a following step, and the autoscaler now has a documented incident pause. Neither has been exercised. The retention side is unfixed and expensive: the object-store access log still reaches fourteen days, which is shorter than any dwell this agency has ever reconstructed, and extending it is a budget decision that sits with a team the incident did not involve.

9 individual beats also carry a pointer to a published failure mode, marked in the record above.

What It Measured

Including the Thresholds It Missed.

10 measures: 1 met, 7 missed and 2 that could not be computed at all — counted off the table rather than typed above it. Every metric carries the method that produced it, because a metric with no method is a claim, and a case that reports only the thresholds it met is reporting a biased sample and then reasoning from it.

MeasureValueAgainst its own thresholdHow it was computedWhat that means
Decoy interaction to first defensive action8h 26m against a 60-minute thresholdNot metSubtracted between two beat clocks: the decoy read that opened the case, and the first fire that imposed anything on the adversary. Measured from the interaction rather than from the analyst opening the ticket, because the second measurement deletes the queue from the figure.Of that interval, 5h 38m was spent in the general triage queue before any human saw the item. The threshold was set for a deception-grid interaction specifically, on the reasoning that a decoy hit has no false-positive budget to spend.
Time the estate’s highest-confidence detection spent unread5h 38mNot metThe interval between the deception source emitting and the first analyst action on the item, both timestamps taken from the same alerting platform rather than reconstructed from anyone’s recollection.The grid had produced no interaction in eleven months, so no time-to-human had ever been measured on it. The first measurement of a control is often the first time anyone learns it was not wired to anything.
Authority tax8h 3m across 6 escalationsNot metSummed over the beats whose authority is recorded as escalated, using the same function the site computes it with for either case. Every escalated beat carries a request time and an effective time, so each contribution can be checked individually.The longest single wait — the decision to degrade the public data service — was 3h 34m, which is 44% of the whole tax. Under contact this is not administrative overhead; it is adversary time, and the case declines to describe it as anything else.
Actions needed that were inside the pre-authorized set4 of 10Not metCounted from the beats: every action taken against the adversary, classified by the authority it was actually taken under, against the pre-authorized set as it stood when contact began.Six actions needed either the Authorizing Official or an exception. The framework’s argument for a wide pre-authorized set is priced here in minutes of continued collection rather than in convenience.
Statutory filing-status availabilityUnavailable for 3h 40m on a filing-deadline dayNot metMeasured between the beat where the degradation took effect and the beat where the status lookup was repointed at a cache. The dependency that caused it was undeclared, so the outage is attributable to the degradation rather than to the intrusion.No availability floor existed to measure against. One was written at 03:35 the same night, which means the figure is being reported against a threshold that was authored after the event it describes.
Cost of evicting out of sequenceSecond position surfaced 35m after the first eviction actionNot metSubtracted between the beat recording the unsequenced credential rotation and the beat recording the second identity authenticating. Both timestamps come from the identity provider rather than from the response bridge.The interval is evidence that the reset was noticed, not proof that it caused the move. A dormant account activating thirty-five minutes after a rotation is the strongest correlation available and it is still a correlation.
Adversary dwell before detectionNot established; bracketed between 14d and 46 daysNot computedAttempted from the object-store access log and the identity provider record, and abandoned. The earliest evidenced access sits at the log’s 14-day retention edge, which is a property of the logging configuration rather than a finding about the adversary.The unresolved interval is 32d wide. Two of the five in-scope workloads were recycled by the platform before capture, and they are the two the intrusion most likely originated on.
Temporal advantageDefender loop 11h 38m; ratio not computedNot computedThe numerator is measured between beat clocks — decoy interaction to the first containment action that removed something. The denominator needs an adversary objective time, which requires the dwell reconstruction that was destroyed on day zero.Reporting the ratio as met on a numerator alone was refused at Assess. A scoreboard line that reads as a gap invites a question, which is the correct outcome and the reason it is tempting to fill in.
Detections authored from the incident7 authored, 4 shipped and untested, 1 inexpressibleMetCounted from the indicators produced at Fuse. Firing against replayed telemetry from this incident is not counted as validation, because a detection tested only on the sample it was derived from is untested.The threshold was at least one production detection per contact, on the principle that an intrusion nobody can automate any part of will be worked by hand again next time.
Persistence sweep population412 of 540 workloads (76%)Not metThe denominator is the workload fleet from the terrain overlay. Taken from the endpoint console instead — the count of workloads carrying an agent that survived long enough to answer — the same sweep reports 100%.The 128 ephemeral workloads outside the sweep are recorded as unmeasured. It is tempting to argue that recycling is itself eradication; that is true only for persistence that does not survive a rebuild.

Decoy interaction to first defensive action

Value
8h 26m against a 60-minute threshold
Against its own threshold
Not met
How it was computed
Subtracted between two beat clocks: the decoy read that opened the case, and the first fire that imposed anything on the adversary. Measured from the interaction rather than from the analyst opening the ticket, because the second measurement deletes the queue from the figure.
What that means
Of that interval, 5h 38m was spent in the general triage queue before any human saw the item. The threshold was set for a deception-grid interaction specifically, on the reasoning that a decoy hit has no false-positive budget to spend.

Time the estate’s highest-confidence detection spent unread

Value
5h 38m
Against its own threshold
Not met
How it was computed
The interval between the deception source emitting and the first analyst action on the item, both timestamps taken from the same alerting platform rather than reconstructed from anyone’s recollection.
What that means
The grid had produced no interaction in eleven months, so no time-to-human had ever been measured on it. The first measurement of a control is often the first time anyone learns it was not wired to anything.

Authority tax

Value
8h 3m across 6 escalations
Against its own threshold
Not met
How it was computed
Summed over the beats whose authority is recorded as escalated, using the same function the site computes it with for either case. Every escalated beat carries a request time and an effective time, so each contribution can be checked individually.
What that means
The longest single wait — the decision to degrade the public data service — was 3h 34m, which is 44% of the whole tax. Under contact this is not administrative overhead; it is adversary time, and the case declines to describe it as anything else.

Actions needed that were inside the pre-authorized set

Value
4 of 10
Against its own threshold
Not met
How it was computed
Counted from the beats: every action taken against the adversary, classified by the authority it was actually taken under, against the pre-authorized set as it stood when contact began.
What that means
Six actions needed either the Authorizing Official or an exception. The framework’s argument for a wide pre-authorized set is priced here in minutes of continued collection rather than in convenience.

Statutory filing-status availability

Value
Unavailable for 3h 40m on a filing-deadline day
Against its own threshold
Not met
How it was computed
Measured between the beat where the degradation took effect and the beat where the status lookup was repointed at a cache. The dependency that caused it was undeclared, so the outage is attributable to the degradation rather than to the intrusion.
What that means
No availability floor existed to measure against. One was written at 03:35 the same night, which means the figure is being reported against a threshold that was authored after the event it describes.

Cost of evicting out of sequence

Value
Second position surfaced 35m after the first eviction action
Against its own threshold
Not met
How it was computed
Subtracted between the beat recording the unsequenced credential rotation and the beat recording the second identity authenticating. Both timestamps come from the identity provider rather than from the response bridge.
What that means
The interval is evidence that the reset was noticed, not proof that it caused the move. A dormant account activating thirty-five minutes after a rotation is the strongest correlation available and it is still a correlation.

Adversary dwell before detection

Value
Not established; bracketed between 14d and 46 days
Against its own threshold
Not computed
How it was computed
Attempted from the object-store access log and the identity provider record, and abandoned. The earliest evidenced access sits at the log’s 14-day retention edge, which is a property of the logging configuration rather than a finding about the adversary.
What that means
The unresolved interval is 32d wide. Two of the five in-scope workloads were recycled by the platform before capture, and they are the two the intrusion most likely originated on.

Temporal advantage

Value
Defender loop 11h 38m; ratio not computed
Against its own threshold
Not computed
How it was computed
The numerator is measured between beat clocks — decoy interaction to the first containment action that removed something. The denominator needs an adversary objective time, which requires the dwell reconstruction that was destroyed on day zero.
What that means
Reporting the ratio as met on a numerator alone was refused at Assess. A scoreboard line that reads as a gap invites a question, which is the correct outcome and the reason it is tempting to fill in.

Detections authored from the incident

Value
7 authored, 4 shipped and untested, 1 inexpressible
Against its own threshold
Met
How it was computed
Counted from the indicators produced at Fuse. Firing against replayed telemetry from this incident is not counted as validation, because a detection tested only on the sample it was derived from is untested.
What that means
The threshold was at least one production detection per contact, on the principle that an intrusion nobody can automate any part of will be worked by hand again next time.

Persistence sweep population

Value
412 of 540 workloads (76%)
Against its own threshold
Not met
How it was computed
The denominator is the workload fleet from the terrain overlay. Taken from the endpoint console instead — the count of workloads carrying an agent that survived long enough to answer — the same sweep reports 100%.
What that means
The 128 ephemeral workloads outside the sweep are recorded as unmeasured. It is tempting to argue that recycling is itself eradication; that is true only for persistence that does not survive a rebuild.
Who Acted

Counted, Not Characterized.

Exactly one role acts on each beat. Shared action is not action, and a case in which everybody contributes to everything cannot be used to argue for a staffing model.

RoleBeats ledBeats supportedWhat the role owns
Platform and product ownersPLAT1210Their own terrain. Obstacles get emplaced on their ground, so they site them.
SOC / Defensive OperationsSOC815Maneuver. Executes fires and emplaces obstacles inside the standing rules of engagement.
Authorizing Official / CISOAO78Intent, risk acceptance, and the scheme itself.
Governance / RMF / ISSOISSO513Translating cycle outputs into FISMA and RMF artifacts, and owning the rules of engagement.
Hunt teamHUNT412Counterattack. Works the hypotheses that Fuse raises.
Cyber Threat Intelligence cellCTI37Frame, Map and Fuse. The intelligence requirements, the threat courses of action, and the confidence levels.

Platform and product owners

PLAT

Beats led
12
Beats supported
10
What the role owns
Their own terrain. Obstacles get emplaced on their ground, so they site them.

SOC / Defensive Operations

SOC

Beats led
8
Beats supported
15
What the role owns
Maneuver. Executes fires and emplaces obstacles inside the standing rules of engagement.

Authorizing Official / CISO

AO

Beats led
7
Beats supported
8
What the role owns
Intent, risk acceptance, and the scheme itself.

Governance / RMF / ISSO

ISSO

Beats led
5
Beats supported
13
What the role owns
Translating cycle outputs into FISMA and RMF artifacts, and owning the rules of engagement.

Hunt team

HUNT

Beats led
4
Beats supported
12
What the role owns
Counterattack. Works the hypotheses that Fuse raises.

Cyber Threat Intelligence cell

CTI

Beats led
3
Beats supported
7
What the role owns
Frame, Map and Fuse. The intelligence requirements, the threat courses of action, and the confidence levels.
What It Consumed and Produced

The Artifacts, with the Beats on Each Side of Them.

A product with no consumer is overhead. Reading down this table is the fastest way to see which artifacts were load-bearing in this case and which were written because the process said to.

ArtifactWhat it isProduced atConsumed at
Defensive intent paragraphOne signed paragraph stating what the defense exists to protect, what may be degraded to protect it, and the acceptable risk. The commander’s-intent analog, and the citation every downstream designation rests on.
Phase declarationThe declared campaign phase and the scope it is declared against. Sets cadence, dominant forms of maneuver, and how wide the pre-authorization set runs.
Cycle cadence and calendarThe declared length of a cycle, its close date, and the refresh intervals that inherit from it. Makes “per cycle” a measurable unit rather than a figure of speech.
Temporal advantage thresholdThe number the cycle will be judged against: defender decision loop versus adversary dwell, stated with units before the cycle runs.
Cyber Terrain OverlayThe positional map of the estate: every element with a defensive layer, a defensive weight, a named accountable owner and its adjacencies. Not an asset inventory — an inventory enumerates, an overlay positions.
Trust zones and the connection registerThe zone boundaries and the permitted- and denied-path register — the graph reachability is actually walked over, reconciled against observed flow telemetry rather than against intended configuration.
Avenue-of-approach analysisThe enumerated routes an adversary could take toward each decisive point, including physical, supplier and maintenance routes, with unassessed routes recorded as intelligence gaps rather than as absence of risk.
Threat course-of-action sketchTwo courses of action, most likely and most dangerous, drawn against the decisive points already designated. Each is a route across ground the estate really has, not a category of threat.
Scheme of maneuverOne graphic and one narrative: which forms of maneuver are sited where, in what sequence. The assignment record behind it carries the element, the avenue and the implementation state for every move.
Branch and sequel planThe branches answer the most-dangerous course of action; the sequels answer success. Every one names the authority it needs, and any expected to run inside the decision window is pre-authorized when it is written.
Rules of engagementWhich defensive actions may be taken by whom without escalation, which need the Authorizing Official, and what is prohibited outright. The cyber analog of engagement authority, and the single largest determinant of tempo.
Pre-authorized response setThe specific containment and response actions the SOC may execute at machine speed, bounded by the statutory availability floor. Directly measurable: it shortens the decision segment of the defender loop.
Change recordEvery defensive action carried out, stamped twice — at the decision and at the effect. A thin, unglamorous table, and the one the headline metric is computed from.
Implementation state recordPlanned, partial or operational, per maneuver assignment. The mechanism that stops intended work being counted as deployed protection.
Authority exception logActions taken outside the standing rules of engagement, with who approved them and why. Exceptions are not failures; unrecorded exceptions are.
Defender decision loop measurementDetect to decide to contain, measured per incident from the change record’s timestamps and reported as a distribution rather than as a mean.
Fused assessmentWhat the cycle’s intelligence requirements returned: each answer graded for confidence and showing its working, and each requirement left unanswered recorded against the collection gap responsible.
Adversary dwell estimateThe estimated time an adversary could operate undetected in this estate, with its basis stated — measured dwell, sector reporting, or partner intelligence — and its bias acknowledged.
Maneuver effectiveness validation recordWhether the moves claiming operational status produced the effect the catalog assumed — from exercise results, control testing, and observed incident performance.
Indicators and signpostsFor each surviving hypothesis, the observable events that would confirm or kill it, handed to collection. The mechanism that makes this cycle’s analysis into next cycle’s requirements.
Hunt results, including negative resultsWhat was hunted, how, and what was not found. Negative results are the half most often discarded, and they are the half that says what has actually been cleared.
Coverage and residual risk resultCoverage and residual risk computed over the whole overlay population, weighted by consequence, discounted by implementation state and corrected by validated effectiveness — with the denominator stated.
Temporal advantage resultDefender decision loop against adversary dwell, reported as a ratio against the threshold set at Frame, with the result written as a word: met, or not met. The framework’s single honest scoreboard.
Remediation backlogThe ranked list of what to fix, ordered by residual risk, main-effort weighting, and decisive-point floor breaches — which sit above higher-volume, lower-weight work regardless of count.
Findings disposition recordEvery finding with an outcome: remediate with an owner and a date, accept with a named accepter and an expiry, or transfer with the party named. “Under review” is not a disposition.
Cycle record and trendThe closed record of the cycle — posture, loop measurement, conclusions and their confidence, backlog state at close — and the trend across cycles that makes a second cycle worth more than a first.
Cycle briefThe published product: terrain, reachability, main effort, temporal advantage, coverage, trend, and the top-ranked backlog items — each confidence-tagged. Also the evidence that feeds the next intent.
Recovery objectives registerA declared recovery time and recovery point objective per mission service, agreed with the service owner and constrained by statutory deadlines rather than by what is currently achievable.
Statutory availability floorThe mission services whose availability is set by statute or regulation, and the floor below which degradation stops being a defensive choice. Bounds what may be pre-authorized and what may be degraded under contact.
Privacy and controlled-information terrain registerWhere privacy holdings and controlled unclassified information sit, the authorities under which they are held, and the boundaries their handling requires — expressed as denied paths, not as policy statements.
Supplier terrain registerSuppliers as external actors on the overlay, with the access each holds, the paths that access implies, and the contract behind it.

Defensive intent paragraph

What it is
One signed paragraph stating what the defense exists to protect, what may be degraded to protect it, and the acceptable risk. The commander’s-intent analog, and the citation every downstream designation rests on.
Produced at

Phase declaration

What it is
The declared campaign phase and the scope it is declared against. Sets cadence, dominant forms of maneuver, and how wide the pre-authorization set runs.
Consumed at

Cycle cadence and calendar

What it is
The declared length of a cycle, its close date, and the refresh intervals that inherit from it. Makes “per cycle” a measurable unit rather than a figure of speech.
Produced at
Consumed at

Temporal advantage threshold

What it is
The number the cycle will be judged against: defender decision loop versus adversary dwell, stated with units before the cycle runs.
Produced at
Consumed at

Cyber Terrain Overlay

What it is
The positional map of the estate: every element with a defensive layer, a defensive weight, a named accountable owner and its adjacencies. Not an asset inventory — an inventory enumerates, an overlay positions.
Produced at
Consumed at

Trust zones and the connection register

What it is
The zone boundaries and the permitted- and denied-path register — the graph reachability is actually walked over, reconciled against observed flow telemetry rather than against intended configuration.
Produced at

Avenue-of-approach analysis

What it is
The enumerated routes an adversary could take toward each decisive point, including physical, supplier and maintenance routes, with unassessed routes recorded as intelligence gaps rather than as absence of risk.
Produced at

Threat course-of-action sketch

What it is
Two courses of action, most likely and most dangerous, drawn against the decisive points already designated. Each is a route across ground the estate really has, not a category of threat.
Produced at

Scheme of maneuver

What it is
One graphic and one narrative: which forms of maneuver are sited where, in what sequence. The assignment record behind it carries the element, the avenue and the implementation state for every move.
Produced at
Consumed at

Branch and sequel plan

What it is
The branches answer the most-dangerous course of action; the sequels answer success. Every one names the authority it needs, and any expected to run inside the decision window is pre-authorized when it is written.
Produced at

Rules of engagement

What it is
Which defensive actions may be taken by whom without escalation, which need the Authorizing Official, and what is prohibited outright. The cyber analog of engagement authority, and the single largest determinant of tempo.
Produced at

Pre-authorized response set

What it is
The specific containment and response actions the SOC may execute at machine speed, bounded by the statutory availability floor. Directly measurable: it shortens the decision segment of the defender loop.
Produced at

Change record

What it is
Every defensive action carried out, stamped twice — at the decision and at the effect. A thin, unglamorous table, and the one the headline metric is computed from.

Implementation state record

What it is
Planned, partial or operational, per maneuver assignment. The mechanism that stops intended work being counted as deployed protection.

Authority exception log

What it is
Actions taken outside the standing rules of engagement, with who approved them and why. Exceptions are not failures; unrecorded exceptions are.
Consumed at

Defender decision loop measurement

What it is
Detect to decide to contain, measured per incident from the change record’s timestamps and reported as a distribution rather than as a mean.
Consumed at

Fused assessment

What it is
What the cycle’s intelligence requirements returned: each answer graded for confidence and showing its working, and each requirement left unanswered recorded against the collection gap responsible.

Adversary dwell estimate

What it is
The estimated time an adversary could operate undetected in this estate, with its basis stated — measured dwell, sector reporting, or partner intelligence — and its bias acknowledged.
Produced at
Consumed at

Maneuver effectiveness validation record

What it is
Whether the moves claiming operational status produced the effect the catalog assumed — from exercise results, control testing, and observed incident performance.
Produced at
Consumed at

Indicators and signposts

What it is
For each surviving hypothesis, the observable events that would confirm or kill it, handed to collection. The mechanism that makes this cycle’s analysis into next cycle’s requirements.

Hunt results, including negative results

What it is
What was hunted, how, and what was not found. Negative results are the half most often discarded, and they are the half that says what has actually been cleared.

Coverage and residual risk result

What it is
Coverage and residual risk computed over the whole overlay population, weighted by consequence, discounted by implementation state and corrected by validated effectiveness — with the denominator stated.
Produced at
Consumed at

Temporal advantage result

What it is
Defender decision loop against adversary dwell, reported as a ratio against the threshold set at Frame, with the result written as a word: met, or not met. The framework’s single honest scoreboard.
Produced at
Consumed at

Remediation backlog

What it is
The ranked list of what to fix, ordered by residual risk, main-effort weighting, and decisive-point floor breaches — which sit above higher-volume, lower-weight work regardless of count.
Produced at
Consumed at

Findings disposition record

What it is
Every finding with an outcome: remediate with an owner and a date, accept with a named accepter and an expiry, or transfer with the party named. “Under review” is not a disposition.
Produced at
Consumed at

Cycle record and trend

What it is
The closed record of the cycle — posture, loop measurement, conclusions and their confidence, backlog state at close — and the trend across cycles that makes a second cycle worth more than a first.
Produced at
Consumed at

Cycle brief

What it is
The published product: terrain, reachability, main effort, temporal advantage, coverage, trend, and the top-ranked backlog items — each confidence-tagged. Also the evidence that feeds the next intent.
Produced at
Consumed at

Recovery objectives register

What it is
A declared recovery time and recovery point objective per mission service, agreed with the service owner and constrained by statutory deadlines rather than by what is currently achievable.
Produced at
Consumed at

Statutory availability floor

What it is
The mission services whose availability is set by statute or regulation, and the floor below which degradation stops being a defensive choice. Bounds what may be pre-authorized and what may be degraded under contact.
Produced at
Consumed at

Privacy and controlled-information terrain register

What it is
Where privacy holdings and controlled unclassified information sit, the authorities under which they are held, and the boundaries their handling requires — expressed as denied paths, not as policy statements.
Produced at
Consumed at

Supplier terrain register

What it is
Suppliers as external actors on the overlay, with the access each holds, the paths that access implies, and the contract behind it.
Produced at
Consumed at
Everything It Cited

The Whole Citation Index, Resolved.

Each identifier links to its own entry in the reference manual, and each carries the beats it appears in. This is the section that makes the case checkable rather than merely readable.

Controls (36)

Techniques (29)

Terrain (7)

What This Is Not Evidence Of

Stated Here so It Cannot Be Over-Read.

One worked case is one worked case. The limits below are the claims a reader might reasonably draw from it that it does not actually support.

The other case runs the opposite posture: The hunt that found nothing, and what that was worthproactive hunt, 40 beats. The two are meant to be read against each other, and the contrast between them is computed rather than asserted.