The intrusion that made the agency choose between watching and stopping
A decoy record in the financial and personally-identifiable data partition was read at 02:14 by a machine identity belonging to the bulk-data service, and the alert sat in the general triage queue until the day shift opened it five and a half hours later. What followed was not a hunt in the sense the proactive case uses the word: the hypothesis was written after the first observation, the loop was entered at Maneuver with the three preceding steps skipped, and the dominant form turned out to be isolation rather than counterattack — because the only revocation path available for the compromised identity also degraded a public service with a statutory obligation behind it. The case turns on the same decision taken three times under three different authorities: observe, and buy intelligence at the price of continued exposure, or evict, and act on an estate you have not finished mapping. The second time, nobody got to take it: a platform engineer reset the credential in good faith and out of sequence, and thirty-five minutes later a dormant partner identity nobody had been watching resumed collection somewhere else.
Everything here is modeled against the Federal Reference Agency. This is not a report of an event at a named agency. The estate is a composite drawn from public doctrine and the published agency archetypes; the beats are authored. What is not authored is the machinery — every control, technique, terrain layer, product and requirement below resolves against the published data, and a citation that does not resolve fails the build.
The Trigger, and the Ground It Starts On.
A reactive hunt may legitimately enter the loop at maneuver or fuse, and where it enters decides almost everything after — which forms are available, what its authority costs, and what a good outcome even looks like.
What Started It
The trigger
- Trigger
- A decoy record read at 02:14 by a machine identity — contact, arriving as one high-confidence alert into a queue that had no way to treat it differently from a failed login.
- Where it enters the loop
- maneuver — a reactive hunt may legitimately enter at maneuver or fuse.
- Phases traversed
- II Seize Initiative (11) → III Dominate (21) → IV Stabilize (7)
The Ground in Play
Federal Reference Agency slots
- Public Data / Open API
- PII Store / Financial Data
- Case Filing System
- ICAM / PDP
- Mission-Staff Workstations
- Secondary Portal / Secondary Mission System
- Terrain touched
- 7 of 10 layers. Never touched: T6 Operational Technology, T7 Workforce, T8 Facilities — which is usually the more interesting list.
What the Hunt Was Actually Asked.
Every requirement carries the decision that changes on the answer. One that changes nothing either way is an audit, and should be scheduled as one rather than run as a hunt.
The decision it changes: Whether to tighten the governance boundary this cycle — which will break at least one reporting workflow the mission depends on — or accept it and instrument the out-of-boundary reads.
The decision it changes: Whether the next tempo investment goes to detection engineering or to widening the pre-authorized set. They buy different halves of the same interval, and buying the wrong half changes nothing.
The decision it changes: Whether to transition from Dominate to Stabilize, or hold the phase and keep the wider authorities open at the cost of continued disruption.
The decision it changes: Whether containment proceeds as designed, or is re-sequenced to preserve evidence and bound exposure — and whether the privacy function is brought in now rather than at the end.
The decision it changes: Whether to pre-authorize the service-degrading action with explicit bounds, or to build an out-of-hours escalation path with a stated ceiling on time-to-decision.
Which Forms Were Used, and Where the Work Actually Sat.
Each figure is counted off the beats rather than declared. A case that claims one posture and spends its beats in the other’s band is describing something other than what it says it is.
Forms of Maneuver Exercised
Give ground deliberately to preserve the force. Degrade gracefully; never fail open.
Seize the initiative and evict before the adversary reaches the objective.
Convert contact into durable advantage rather than closing the ticket.
Gain early warning and buy reaction time before the adversary touches key terrain.
Make identity, not network location, the decisive plane — surround the adversary with policy.
Where the Beats Sat
- 01 Frame — 3 beats, 0 in the hunt band.
- 02 Map — 1 beat, 0 in the hunt band.
- 03 Array — 1 beat, 0 in the hunt band.
- 04 Maneuver — 29 beats, 23 in the hunt band.
- 05 Fuse — 4 beats, 2 in the hunt band.
- 06 Assess — 1 beat, 0 in the hunt band.
Maneuver Bands
- contact — 25 beats.
- consolidation — 2 beats.
- shaping — 2 beats.
Authority
8h 3m spent waiting on 6 escalations. Under contact that is priced in adversary dwell; out of contact it is nearly free, which is why it is worth measuring out of contact first.
- Beat 06 · D0 10:05 — 26 minutes waiting on the decision.
- Beat 18 · D0 15:10 — 38 minutes waiting on the decision.
- Beat 19 · D0 16:34 — 96 minutes waiting on the decision.
- Beat 24 · D+1 00:15 — 214 minutes waiting on the decision.
- Beat 31 · D+1 15:40 — 47 minutes waiting on the decision.
- Beat 34 · D+3 10:00 — 62 minutes waiting on the decision.
The Operating Loop, with This Case’s Beats Counted onto It
Frame
Screen · Analytic Design step 1
Map
Cyber Preparation of the Environment — the IPB analog
Array
Design the scheme
Maneuver
Execute
Fuse
Analyze · Integrate
Assess
Produce · re-frame
↺ Re-frame — the loop turns faster than the adversary adapts
Where Its Weight Fell
Beats per step, counted from the timeline. The case enters at Maneuver and puts most of its weight on Maneuver.
Which Campaign Phases It Crossed
The loop turns inside a phase; the phase changes when the Authorizing Official declares it. The two clocks are separate on purpose, and a case that crosses phases is showing both of them.
- Phase II · Seize Initiative11 beatsContest first contact
- Phase III · Dominate21 beatsDefeat the attempt
- Phase IV · Stabilize7 beatsRestore secure operations
Checked Against the Same Agency’s Coverage Baseline.
The most tempting error available to a worked example is depicting the agency doing something the same site elsewhere says it cannot do. So this is a computation rather than a promise: of the 29 techniques these beats cite, the published baseline grades 16 absent — 55.2%. Follow any of them into the record above and check that it is depicted improvised, degraded or failing.
- Absent · 16
- Partial · 12
- Full · 1
- M10.02Avenue Closure VerificationBaseline: Absent · cited by 1 beat
- M5.09Deception Alert RoutingBaseline: Absent · cited by 2 beats
- M5.10Deception Coverage MeasurementBaseline: Absent · cited by 1 beat
- M6.02Step-Up Authentication on AnomalyBaseline: Absent · cited by 1 beat
- M6.04Session Duration Reduction Under AlertBaseline: Absent · cited by 1 beat
- M6.05Approval Gates on High-Impact ActionsBaseline: Absent · cited by 1 beat
- M6.08Change and Deploy Freeze Under ContactBaseline: Absent · cited by 1 beat
- M7.08Lateral Path AuditBaseline: Absent · cited by 1 beat
- M7.11Eviction SequencingBaseline: Absent · cited by 1 beat
- M7.12Adversary Dwell ReconstructionBaseline: Absent · cited by 1 beat
- M8.03Read-Only Service DegradationBaseline: Absent · cited by 1 beat
- M8.05Federation Trust SuspensionBaseline: Absent · cited by 1 beat
- M8.07Egress BlackholeBaseline: Absent · cited by 1 beat
- M8.08Statutory Availability FloorBaseline: Absent · cited by 1 beat
- M8.10Third-Party Connection CutoutBaseline: Absent · cited by 1 beat
- M8.11Restoration PreconditionsBaseline: Absent · cited by 1 beat
- M1.05Authentication Geography BaselineBaseline: Partial · cited by 1 beat
- M10.01Indicator-to-Detection ConversionBaseline: Partial · cited by 1 beat
- M3.11Session and Token Revocation PathBaseline: Partial · cited by 1 beat
- M5.01Decoy Records in the Data LayerBaseline: Partial · cited by 1 beat
- M6.01Adaptive Rate LimitingBaseline: Partial · cited by 1 beat
- M7.01Hypothesis-Driven HuntingBaseline: Partial · cited by 1 beat
- M7.03Automated Containment PlaybooksBaseline: Partial · cited by 1 beat
- M7.05Credential Reset SweepBaseline: Partial · cited by 1 beat
- M7.07Persistence SweepBaseline: Partial · cited by 1 beat
- M8.02Estate-Wide Session RevocationBaseline: Partial · cited by 1 beat
- M8.04Fail-Secure Default PostureBaseline: Partial · cited by 1 beat
- M8.09Contained Forensic PreservationBaseline: Partial · cited by 1 beat
- M7.04Host Isolation on ConfirmationBaseline: Full · cited by 1 beat
Grades are read from the coverage baseline for the Federal Reference Agency at render time, not copied here — so if the baseline moves, this section moves with it. A technique graded absent that is nonetheless depicted working smoothly would be a defect in the case study, and this is how a reader finds one.
39 beats, in order.
Every beat carries what it did not establish, because that is most of what real defensive work produces. Beats with a heavier left edge sit inside the hunt band; the rest are the cycle work that made the hunt possible, and separating them is how a program avoids believing hunting is a standalone activity.
- D0 02:14
Beat 1, A decoy record seeded in the PII Store / Financial Data partition was read by a caller inside the bulk-data platform. Four decoys had been maintained on that one layer for eleven months; this was the first interaction any of them had ever produced.
What it did not establishWho read it. A decoy interaction establishes that something touched ground no legitimate process has a reason to touch, and nothing whatsoever about the identity, the intent or the position behind the read.
OutcomeOne alert raised at medium severity and routed into the general triage queue, where it joined the night’s other 214 items.
- D0 07:52
Beat 2, The day-shift analyst opened the item five hours and thirty-eight minutes after it fired. There was no dedicated route for deception telemetry — the grid emitted into the same pipeline as every other sensor, at a severity assigned by the source’s default, and the queue was worked in arrival order.
What it did not establishWhether a dedicated route would have been answered faster at 02:14. The agency runs a two-person night shift against a queue that does not distinguish a decoy from a failed login, and the routing gap and the staffing floor are two separate findings that this beat cannot separate.
OutcomeThe single highest-confidence detection the estate is capable of producing was worked in arrival order, and the interval was recorded rather than rounded.
Confidence — highBoth timestamps come from the same alerting platform: the deception source emitted at 02:14 and the first analyst action on the item is recorded at 07:52. Nothing about the interval is reconstructed.
This is a failure the manual already predicts — M5 Ambush — how it fails“Decoy hits are routed to the same queue as everything else, which discards the only property that made them worth emplacing.”
- Deception alert routing was never built as a separate path. The grid was emplaced as a detection project and its output inherited the default severity of the platform that carried it.
- The night shift works a mixed queue in arrival order, so an item’s position depends on when it arrived rather than on what would follow from it being true.
- Nobody had ever measured time-to-human on a decoy interaction, because until this night the grid had never produced one to measure.
AuthorityStanding ROE
TerrainConsumed - D0 08:31
Beat 3, The hunt lead wrote the hypothesis after the observation rather than before it, which is the ordering that makes this a reactive hunt: an identity that is not a mission-staff human has read from the crown-jewel partition, and if that is true the same identity will appear in the object-store access log against non-decoy prefixes.
What it did not establishAnything about scope. A hypothesis written thirty-nine minutes after a decoy fires is a direction to search in, and this one deliberately named a falsifier before collection opened so that the search could come back empty and mean something.
OutcomeOne written claim, one named falsifier, and a collection list of three sources — the object-store access log, the identity provider token issuance record, and the bulk-export service’s own audit trail.
AuthorityNo authority required
Form — M7 CounterattackTerrainRequirement - D0 09:10
Beat 4, The read was attributed to a machine identity belonging to the Public Data / Open API bulk-export service. The lateral path audit was done by hand against raw flow records — the agency has no path-audit tooling — and it took thirty-one minutes to establish that this identity has a standing route to the whole partition, not only to the published extract.
What it did not establishWhether the machine identity was itself the adversary or was being driven by something upstream of it. A service principal reading its own data path looks identical whether the caller is the service or is somebody holding the service’s secret.
OutcomeThe caller named, the route confirmed as standing and unconstrained, and a second question opened that the telemetry as sited cannot answer.
Confidence — moderateThe caller principal resolves cleanly in three logs. What it was doing on behalf of does not resolve at all, because the bulk-export service does not propagate an on-behalf-of claim into its data-layer calls.
AuthorityPre-authorized
Form — M7 CounterattackTerrainRequirement - D0 09:40
Beat 5, The Authorizing Official held the declaration at Phase II rather than jumping to Phase III, and shifted the cycle cadence from twenty-one days to a four-hour contact tempo. The intent paragraph was rewritten in one sentence: preserve the record set, and do not take the filing path down to do it.
What it did not establishWhether Phase II was the right declaration. It was the declaration that kept the wider fire set closed for another four hours, and the case cannot say what the wider set would have bought during them because it was not open.
OutcomeA phase held, a cadence changed, and an intent paragraph that named the constraint the whole rest of the cycle turned on.
AuthorityStanding ROE
FormNone — an analytic beat, instantiating no maneuver.
Terrain - D0 10:05requested 09:39decided 10:05
Beat 6, The first observe-or-evict decision, made explicitly and recorded as such. The hunt lead recommended isolating the machine identity immediately. The Authorizing Official decided to hold and observe for a bounded four hours, on the reasoning that isolating the only identity currently visible would tip whatever was behind it before its extent was known — and wrote a stop condition: any read against a non-decoy prefix ends the window at once.
What it did not establishWhether observation was worth its price. The window ran for three hours and fifteen minutes before its stop condition fired, and what it bought — the shape of the collection pattern — is real but cannot be weighed against what continued reading cost, because the reads inside the window were never enumerated.
OutcomeA bounded observation window with a written stop condition, a named decision-maker, and twenty-six minutes of latency to reach him during the working day.
Confidence — moderateThe judgment rests on one read against one decoy and a route that is standing rather than newly created. Nothing at this point distinguished an adversary from a misconfigured job.
AuthorityEscalated to the AO — 26 minutes waiting on the decision
FormNone — an analytic beat, instantiating no maneuver.
TerrainRequirement - D0 10:40
Beat 7, Adaptive rate limiting was applied to the bulk-export path under the pre-authorized set. The discriminating control — a throttle scoped to a single caller — does not exist in this estate, so the limit was applied to the endpoint, which means to every consumer of it: eleven external bulk subscribers, two internal reporting jobs, and the adversary.
What it did not establishWhether the adversary was slowed at all. Their observed request rate had been running at roughly a third of the new ceiling for as long as the log reaches, so the limit sat above their behavior and below everybody else’s.
OutcomeTwo subscriber complaints inside forty minutes, a measurable drop in legitimate throughput, and no measurable change in the caller the limit was imposed for.
This is a failure the manual already predicts — M6 Delay — how it fails“Delay is applied to the population rather than to the anomaly, because the discriminator was never built. The adversary is slowed by the same proportion as everyone else, which is no relative advantage at all.”
- Per-caller export throttling was never implemented, so the only throttle available operates on the endpoint rather than on the identity.
- The rate ceiling was derived from load testing rather than from observed adversary behavior, so it was set above the rate the adversary was actually using.
- The pre-authorized set names the action but not the population it may be applied to, which left the choice of blast radius to an operator at 10:40 with no stated bound.
AuthorityPre-authorized
ConsumedProduced - D0 11:15
Beat 8, Step-up authentication on anomaly was triggered against the affected scope. It reached every human session in the mission tier and none of the machine identities, because a service principal holding a client secret has no second factor to step up to and the policy engine skips it rather than denying it.
What it did not establishWhether the human population in scope was clean. Forty-one staff re-authenticated successfully, which says they could satisfy the challenge and says nothing about whether any of their tokens had already been taken.
OutcomeA delay measure that landed entirely on the population that was not under suspicion, recorded as no effect rather than as a control exercised.
AuthorityPre-authorized
TerrainConsumed - D0 11:48
Beat 9, Session duration under alert was cut from eight hours to thirty minutes across the mission tier. The bulk-export service principal holds a twenty-four-hour token that the reduction policy does not govern, so the measure shortened every session except the one it was imposed against.
What it did not establishHow long the adversary’s current token had left to run. Token issuance time was available; the lifetime configured at issuance was not recorded anywhere the responders could read during contact, and it was reconstructed two days later.
OutcomeHuman session lifetime cut by a factor of sixteen, machine session lifetime unchanged, and a helpdesk load that arrived within the hour.
AuthorityPre-authorized
TerrainConsumedProduced - D0 12:30
Beat 10, The team established, by trying it, that the machine identity’s issued token cannot be revoked independently of the service: the only supported revocation invalidates every token the bulk-export service holds and requires the service to restart to re-acquire one. Revoking the adversary’s access and degrading the public data service were, in this estate, the same action.
What it did not establishWhether that coupling is a platform constraint or a configuration one. The finding was recorded against the service, not against the platform, and the distinction was carried forward unresolved because nobody had time to test it under contact.
OutcomeThe single technical fact that shaped every subsequent decision: there was no quiet eviction available on this identity, only a loud one.
Confidence — highEstablished by attempting it in the pre-production tenancy rather than by reading the documentation, which described a revocation path the platform has not supported since the last major version.
AuthorityPre-authorized
Form — M3 EnvelopmentTerrainConsumedProducedRequirement - D0 13:20
Beat 11, The observation window’s stop condition fired at three hours fifteen. The caller read from a live PII prefix, not a decoy one — 41 objects, ordered by key, at a rate that had not changed since the window opened. The fused assessment named it deliberate staged collection at high confidence, and named the two hypotheses it could not yet separate: a compromised secret, or a compromised host holding one.
What it did not establishWhich of the two competing hypotheses was true, or whether either excluded a third the fusion had not thought of. The assessment stated both and did not collapse them, which is what stopped the eviction plan from being written against one of them an hour later.
OutcomeContact confirmed on evidence rather than on inference, the observation window closed by its own written condition, and two hypotheses carried forward rather than one.
Confidence — highTwo independent sources agree: the object-store access log carries the prefix reads, and the data platform’s own audit trail carries the same object keys under the same principal within the same minute.
AuthorityNo authority required
FormNone — an analytic beat, instantiating no maneuver.
TerrainRequirement - D0 13:35
Beat 12, Phase III was declared against the Public Data / Open API scope on the strength of the fused assessment, fifteen minutes after the stop condition fired. The declaration was scoped to that service rather than to the estate, which kept the Case Filing System outside the fire set — a decision that turned out to matter eleven hours later, and not in the way it was intended.
What it did not establishThat the scope of the declaration matched the scope of the intrusion. The declaration was drawn around the service the evidence named, and the evidence at that hour reached exactly one identity.
OutcomeA phase declared eleven hours and twenty-one minutes after first contact, and a tempo threshold set for the first time in this cycle at thirty minutes from detection to containment action.
AuthorityStanding ROE
FormNone — an analytic beat, instantiating no maneuver.
Terrain - D0 13:45
Beat 13, The wider pre-authorized fire set was opened: host isolation on confirmation, credential reset, egress blocking on named infrastructure and estate-wide session revocation moved from AO decisions to operator decisions. Three actions stayed above the line — degrading a public statutory service, suspending a federation, and cutting a third-party connection.
What it did not establishWhether the line was drawn in the right place. It was drawn where the scheme had drawn it in Phase 0, unchanged, and every one of the three actions held above it was needed within the next twenty-six hours.
OutcomeFour classes of action devolved to the shift, three retained, and a rules-of-engagement version stamp that the responders could read from the console for the first time in the incident.
AuthorityStanding ROE
FormNone — an analytic beat, instantiating no maneuver.
TerrainRequirement - D0 13:52
Beat 14, The Mission-Staff Workstation that had most recently held an interactive session with the export service was isolated at the endpoint agent, seven minutes after the fire set opened and thirty-two seconds after the operator decided to. This was the only action in the entire incident that took less time to execute than to describe.
What it did not establishThat the isolated host was the origin. It was the host the correlation reached first, and it was isolated because isolation is cheap and reversible, not because the evidence had settled on it.
OutcomeOne host isolated inside the declared thirty-minute threshold, with the first genuinely fast containment action of the cycle recorded against it.
AuthorityPre-authorized
Form — M7 CounterattackTerrainProducedRequirement - D0 14:06
Beat 15, A platform engineer watching the same bridge, acting in good faith and reading the newly-opened fire set as permission, rotated the bulk-export service principal’s client secret. Credential reset was inside the set. What was not inside anything was an order — there was no eviction sequence, because the agency has never written one, so the fastest available action was taken first rather than in a position in a plan.
What it did not establishWhether a sequence would have held. The counterfactual is unavailable: nobody can say that an eviction plan written in advance would have survived an engineer with the access, the authority and eleven hours of adrenaline.
OutcomeThe adversary’s active session died within ninety seconds. Eleven minutes later a second identity that nobody had been watching authenticated from a partner federation and resumed collection on a different egress path.
This is a failure the manual already predicts — M7 Counterattack — how it fails“Eviction is unsequenced, so the first action warns the adversary and the remaining actions land on an estate they have already left for a position you have not found.”
- No eviction sequence existed to be out of order with. The pre-authorized set enumerates actions and says nothing about their ordering, which reads as permission to take any of them at any time.
- The fire set was opened to the shift twenty-one minutes earlier with no accompanying statement of what was to be done first, and an opened authority with no plan attached is an invitation to act on the fastest thing.
- The engineer was not on the hunt bridge and had no visibility of the two competing hypotheses, so the tipping cost of a credential rotation was not visible from where the decision was made.
AuthorityTaken as an exception
Form — M7 CounterattackTerrainConsumedProducedRequirement - D0 14:41
Beat 16, The new authentication was resolved against the authentication geography baseline: a dormant partner-federation identity, last used one hundred and thirty-one days earlier, authenticating from an autonomous system the baseline had never seen for that account, thirty-five minutes after the credential rotation.
What it did not establishHow long the second identity had been available to the adversary. It was dormant, not new — the account had existed and been entitled throughout, so its appearance says when it was used and nothing about when it was obtained.
OutcomeA second position identified, an intrusion that was demonstrably wider than the evidence had reached, and the first hard indication that the eviction had begun before the mapping had finished.
Confidence — moderateThe authentication is anomalous against a ninety-day geography baseline that covers partner identities thinly — twenty-two accounts, most of which sign in a handful of times a month, which is a small denominator to call anomalous against.
AuthorityPre-authorized
Form — M1 Screen / GuardTerrainRequirement - D0 14:52
Beat 17, The connection register was corrected under contact. It carried the partner federation as a permitted edge to the Case Filing System only; the entitlement actually reaching the bulk-data platform had been granted eight months earlier through a group nesting that the register does not model.
What it did not establishHow many other permitted edges the register understates for the same reason. One nesting was found because it was in the path of an active intrusion; nothing was done to enumerate the rest, and the register was corrected for this edge alone.
OutcomeOne corrected edge, one newly-recorded finding that the register models direct grants and not inherited ones, and no change to the register’s reported completeness.
AuthorityStanding ROE
FormNone — an analytic beat, instantiating no maneuver.
Terrain - D0 15:10requested 14:32in force 15:10
Beat 18, A change and deploy freeze was imposed across the mission tier so that the estate the responders were reasoning about would stop moving underneath them. It needed the Authorizing Official because it slips releases, and it waited thirty-eight minutes for him — during which two unrelated deployments completed and had to be re-examined afterwards.
What it did not establishWhether the two deployments that landed during the wait were clean. They were reviewed and nothing was found, which is a statement about a review that had four minutes of attention on a day when nobody had four minutes.
OutcomeThe estate stopped moving thirty-eight minutes later than it was asked to, and two changes landed inside the gap.
AuthorityEscalated to the AO — 38 minutes waiting on the decision
ConsumedProduced - D0 16:34requested 14:58in force 16:34
Beat 19, Suspension of the partner federation trust was requested seventeen minutes after the second identity was found, and took effect ninety-six minutes later. The action is technically a single configuration change; the delay was entirely in reaching a decision-maker whose criteria for making it had never been written down, so the decision was reasoned from first principles at the moment it was least affordable to do so.
What it did not establishWhat the partner’s other twenty-one identities were doing during the wait. Their activity was collected and has still not been analyzed at the time of writing, because the analytic effort went to the intrusion rather than to the population around it.
OutcomeThe second identity’s route closed at 16:34. Collection on the alternate egress path continued throughout the ninety-six minutes and is recorded as having done so.
AuthorityEscalated to the AO — 96 minutes waiting on the decision
Form — M8 Isolation / RetrogradeTerrainProducedRequirement - D0 17:20
Beat 20, The exfiltration destination was a commercial object-store tenancy that the open-data service also legitimately publishes to. A blanket blackhole would have taken down the agency’s own publication path, so the block was written against a single bucket path by hand — forty minutes of rule-writing to do what the pre-authorized set assumes is one action.
What it did not establishWhether the adversary held a second destination. The block closed the path that had been observed; nothing in the estate would have shown a destination that had not yet been used.
OutcomeOne egress path closed with the agency’s own publication left standing, at the cost of forty minutes of the incident’s scarcest hour.
AuthorityPre-authorized
Form — M8 Isolation / RetrogradeTerrainProduced - D0 18:05
Beat 21, Volatile capture and disk imaging were taken on the workloads in scope, four hours after the first containment action. Three of five were captured. The other two were ephemeral compute that the platform’s own autoscaler had recycled at 15:40 and 16:12 — after contact was confirmed, and while everyone was watching the identity plane.
What it did not establishWhat was on the two recycled workloads. They are gone, and the record notes that they are gone rather than reasoning about what they probably held, because a reconstruction of a destroyed host is an assumption with a timestamp on it.
OutcomeA partial evidentiary record, chain of custody intact on what survives, and the input to every consolidation activity downstream reduced to three fifths of its scope.
Confidence — lowPreservation covers three of the five workloads in scope, and the two that are missing are the two the intrusion most likely originated on. What survives is a partial record whose gaps are not randomly distributed.
This is a failure the manual already predicts — M8 Isolation / Retrograde — how it fails“Isolation destroys the forensic record, and the dwell reconstruction — the input to every consolidation activity that follows — cannot be produced.”
- The isolation playbook has no preservation step in front of it, so preservation happened when somebody thought of it rather than as a precondition of containing anything.
- Ephemeral compute recycles on a platform schedule that no incident action pauses, and nobody in the response had the authority or the knowledge to pause it.
- The two lost workloads were in scope from 13:20 and were not captured until 18:05, an interval in which nothing prevented the platform from doing exactly what it is configured to do.
AuthorityStanding ROE
Form — M8 Isolation / RetrogradeTerrainConsumedProducedRequirement - D0 19:30
Beat 22, The record sets inside the affected scope were resolved against the privacy terrain: two of the four prefixes the caller had reached hold personally identifiable information, one holds controlled unclassified information under a handling caveat, and one is the published open-data extract and holds neither.
What it did not establishHow many records were actually read. The object-store access log records the prefixes touched and the request counts, not the object bodies, so the exposure is bounded by what could have been read rather than by what was.
OutcomeThree of four prefixes classified as reportable if read, an upper bound on exposure stated as an upper bound, and a notification clock that started from the classification rather than from the containment.
AuthorityNo authority required
FormNone — an analytic beat, instantiating no maneuver.
TerrainProducedRequirement - D0 20:40
Beat 23, The second observe-or-evict decision, and the one that went the other way. The hunt lead asked to leave the remaining collection path open overnight to see whether a third position surfaced. The Authorizing Official refused inside four minutes and gave the reason in one sentence: the corpus is personally identifiable information, and an agency does not buy intelligence with other people’s records.
What it did not establishWhether a third position existed. It was not looked for from this direction, and the persistence sweep two days later could not have found a position that was dormant and untouched throughout it.
OutcomeObservation ended by decision rather than by exhaustion, with the reason recorded in the incident log in the decision-maker’s own words and available to be argued with afterwards.
AuthorityStanding ROE
FormNone — an analytic beat, instantiating no maneuver.
TerrainRequirement - D+1 00:15requested D0 20:41in force D+1 00:15
Beat 24, Because there was no way to revoke the machine identity without restarting the service, containment and degradation were the same act. The Public Data / Open API was dropped to a cached read-only snapshot. The request went up at 20:41 and the action landed at 00:15 — three hours and thirty-four minutes, most of it spent establishing who was permitted to authorize degrading a service with a published availability commitment, because that had never been written down.
What it did not establishWhat was read during the wait. The egress block held from 17:20, so the destination was closed; whether a second destination was in use during those three and a half hours is exactly the question the case cannot answer, and it is the reason the wait is expensive rather than merely slow.
OutcomeThe service degraded as intended and took the Case Filing System’s status lookup with it — an undeclared dependency on the same API, discovered at 00:19 by a citizen-facing error rather than by a dependency map.
This is a failure the manual already predicts — M8 Isolation / Retrograde — how it fails“Degraded mode was never rehearsed, so degradation becomes an unplanned outage and the organization learns which dependencies were undeclared during the incident.”
- The degraded mode had never been exercised. It existed as a configuration flag and a paragraph, and the paragraph did not know about the filing status lookup.
- Dependency declaration is voluntary in this estate and is done by the consuming team, so a consumer that never declared its dependency is invisible to the producer’s degradation plan.
- The decision took three and a half hours because the authority to make it had not been assigned in advance, which meant the first thirty minutes of the outage were spent on a question that a single line in the scheme of maneuver would have answered.
AuthorityEscalated to the AO — 214 minutes waiting on the decision
Form — M8 Isolation / RetrogradeRequirement - D+1 03:35
Beat 25, The statutory availability floor was written at 03:35 on the second day of an incident, by the Authorizing Official, into the incident log — because it did not exist before then. Three hours and twenty minutes of filing-status unavailability had already elapsed on a statutory filing deadline day, against a floor that was being defined after the fact to describe what had already happened.
What it did not establishWhat the floor should have been. What was written at 03:35 is a floor that the events of that night comfortably satisfy, and the record marks it as provisional and requiring a mission owner’s signature outside contact, precisely because a floor authored during a breach is authored by the breach.
OutcomeA floor on the record, an exception recorded against the authority under which the degradation had already been taken, and a finding raised against the absence rather than against the people improvising around it.
This is a failure the manual already predicts — Maneuver — failure mode“A statutory service is degraded without reference to the floor.”
- No availability floor had ever been declared for the filing path, so there was no number to degrade against and no threshold at which the degradation should have been escalated further.
- The floor is a mission judgment and had been left to the security program, which does not own the statutory obligation and could not have set it alone.
- The dependency between the data API and the filing status lookup meant the floor that mattered belonged to a service nobody had declared Phase III against.
AuthorityTaken as an exception
Form — M8 Isolation / RetrogradeTerrainProducedRequirement - D+1 03:55
Beat 26, The filing status lookup was repointed at a static cache and came back at 03:55. It had failed rather than degraded because the fail-secure default is set to deny — the correct setting, which in this instance converted a stale-data problem into an outage, and the record says so in that order rather than treating the default as the fault.
What it did not establishWhether fail-secure is the right default for this particular call. A status lookup returning a stale answer is arguably safer than one returning an error, and the case notes the question without answering it because it is a mission judgment and not a security one.
OutcomeFiling status restored on cached data after three hours and forty minutes, and a design question raised that the incident is not the right forum to settle.
AuthorityPre-authorized
Form — M8 Isolation / RetrogradeConsumedProduced - D+1 10:15
Beat 27, An approval gate was inserted in front of configuration changes to the bulk-export path, on the reasoning that an estate under contact should not be reconfigured without a second pair of eyes. By cycle close it had fired eleven times and approved eleven, at a median of ninety seconds.
What it did not establishWhether any of the eleven should have been refused. A gate that approves everything supplies no evidence either way, which is the property that makes it indistinguishable from no gate at all except in the latency it adds.
OutcomeEleven approvals, no refusals, ninety seconds of median latency per change, and a control that was reported at cycle close as friction rather than as maneuver.
This is a failure the manual already predicts — M6 Delay — how it fails“The approval gate degrades into a rubber stamp. A high-impact action that always gets approved within ninety seconds has added latency and removed nothing.”
- The gate was inserted without a refusal criterion, so the approver had nothing to test a request against beyond whether it looked reasonable at the time.
- The approver was drawn from the same team making the requests, which makes refusal a social act rather than a procedural one.
- No measurement of the gate was planned, so the eleven-of-eleven figure exists only because somebody counted it retrospectively while writing the cycle record.
AuthorityStanding ROE
TerrainConsumedProduced - D+1 11:00
Beat 28, The eviction sequence was written for the first time, on a whiteboard, thirty-two hours and forty-six minutes after contact: twenty-six actions, each with a named owner, a stated tipping cost and a position in an order, with the four actions that must land within the same ten minutes marked as a single block.
What it did not establishThat the sequence was complete. It covers the two identities that were found; a sequence cannot order actions against a position nobody has located, and the document says so on its own first line.
OutcomeA sequence that will exist before the next contact, and the plain observation that writing it took under two hours and could have been done in any of the previous eleven cycles.
Confidence — moderateThe sequence is built on a scope that is three fifths evidenced and two fifths inferred, because two of the five workloads were recycled before capture. Its ordering is sound; its completeness inherits that gap.
AuthorityStanding ROE
Form — M7 CounterattackTerrainRequirement - D+1 12:20
Beat 29, Estate-wide session revocation was executed as block one of the sequence: 14,900 sessions invalidated in four minutes. Three service accounts could not be revoked without restarting the services behind them and were left live under continuous watch, with the exception recorded against each rather than against the action as a whole.
What it did not establishWhether the three exempted service accounts were clean. They were watched, which detects use and does not establish absence, and they are named individually in the cycle record so that the residual attaches to something specific.
OutcomeNear-complete revocation in four minutes, three named exceptions carried openly, and a helpdesk volume that peaked at eleven times normal for ninety minutes.
AuthorityPre-authorized
Form — M8 Isolation / RetrogradeTerrainProducedRequirement - D+1 13:05
Beat 30, The automated containment playbook ran the credential reset across the sixty-one identities the sequence named. It completed fifty-seven and stopped on four: two owned by a supplier under a contract that requires notice, one bound to a scheduled job with a secret stored outside the vault, and one whose owner had separated and whose account had not been closed.
What it did not establishWhy the separated account survived. It was raised to the workforce owner as a finding and had not been answered by cycle close, so the case records an open question rather than the cause it would be convenient to assume.
OutcomeFifty-seven of sixty-one reset automatically, four escalated by hand with a named reason each, and one incidental finding about the separation pipeline that had nothing to do with the intrusion.
AuthorityPre-authorized
Form — M7 CounterattackTerrainRequirement - D+1 15:40requested 14:53in force 15:40
Beat 31, The standing network connection to the partner tenancy was cut, forty-seven minutes after it was requested. The delay was contractual rather than technical: the connection carries a notice obligation, and the forty-seven minutes were spent establishing that an active intrusion satisfies the emergency clause.
What it did not establishWhether the emergency clause is durable. Counsel read it in the moment and agreed; nothing has since been changed in the agreement or in the runbook, so the same forty-seven minutes are available to be spent again.
OutcomeThe connection cut, the partner notified under the emergency clause, and the reading of the clause recorded so the next incident does not have to re-derive it.
AuthorityEscalated to the AO — 47 minutes waiting on the decision
Form — M8 Isolation / RetrogradeTerrainProduced - D+2 09:15
Beat 32, A persistence sweep was run across the workload fleet against the eleven mechanisms the sequence named. It covered 412 of 540 workloads. The remaining 128 are ephemeral compute that recycles faster than the sweep completes, and they are recorded as unmeasured rather than as clear.
What it did not establishThat persistence was absent from the 128. A sweep that cannot reach a population says nothing about it, and the temptation with an ephemeral fleet is to argue that recycling is itself eradication — which is true only for persistence that does not survive a rebuild.
OutcomeTwo artifacts found on one host, both consistent with the first identity and neither with the second, and 24% of the fleet reported as unmeasured in the same sentence as the result.
Confidence — moderateThe sweep is complete across the persistent fleet and structurally blind to the ephemeral one, and the ephemeral fleet is where two of the five in-scope workloads lived.
AuthorityPre-authorized
Form — M7 CounterattackTerrainRequirement - D+2 15:00
Beat 33, Phase IV was declared on the Public Data / Open API scope: eradicate, verify, and preserve availability through the recovery. The declaration was made on the absence of new indicators for twenty-six hours, which the record explicitly labels as the weakest of the three grounds it could have been made on.
What it did not establishThat the intrusion was over. Twenty-six hours of quiet is consistent with eviction and equally consistent with an adversary who has gone quiet, and the declaration names both readings instead of choosing the flattering one.
OutcomeA phase declared on a stated and admittedly weak basis, with the basis written into the declaration so that a later reader can weigh it.
AuthorityStanding ROE
FormNone — an analytic beat, instantiating no maneuver.
TerrainProduced - D+3 10:00requested 08:58signed 10:00
Beat 34, Restoration preconditions were written — also for the first time — as five conditions the service had to satisfy before returning to full read-write. Three were met. Two were not: the dwell reconstruction could not be produced, and the integrity of the published open-data snapshots could not be verified against an independent record because no independent record is kept. The service was restored anyway, on the Authorizing Official’s signature, with both gaps named in the decision.
What it did not establishThat the estate came back clean. Three preconditions were satisfied and two were waived, and the difference between "restored on evidence" and "restored on a signature covering the missing evidence" is the entire content of this beat.
OutcomeFull service restored on day three with two of five preconditions formally waived, each waiver carrying a named risk owner and an expiry.
This is a failure the manual already predicts — M8 Isolation / Retrograde — how it fails“Services are restored without preconditions, so the estate comes back into a compromise that was contained rather than removed, and the second incident is the same as the first.”
- The preconditions did not exist before the incident, so they were authored by the people under pressure to restore, which is the worst possible authorship for a gate.
- Two of the five could never have been met, because the evidence they require — a dwell reconstruction and an independent integrity record — is produced by capabilities this estate does not operate.
- The pressure to restore was statutory and real, and no mechanism existed to price the residual of restoring early against the cost of staying down, so the trade was made on judgment alone.
AuthorityEscalated to the AO — 62 minutes waiting on the decision
Form — M8 Isolation / RetrogradeRequirement - D+3 16:20
Beat 35, The dwell reconstruction was attempted and abandoned. First evidenced access sits at the fourteen-day edge of the object-store access log, which means the true first access is at or before it and cannot be placed. The identity provider retains ninety days and shows the partner account dormant for one hundred and thirty-one, which brackets the second position and not the first.
What it did not establishWhen the adversary actually arrived. The honest statement is a range whose lower bound is a log retention setting and whose upper bound is the decoy read, and the difference between them is thirty-two days that nobody can narrow.
OutcomeDwell reported as a range between 14 and 46 days with the bound attributed to retention, and the agency’s standing dwell estimate left unchanged rather than revised on a number this weak.
Confidence — lowTwo of the five in-scope workloads were destroyed before capture and the object-store access log reaches back fourteen days. The earliest evidenced access is a floor imposed by retention, not a finding about the adversary.
AuthorityNo authority required
Form — M7 CounterattackTerrainRequirement - D+5 11:00
Beat 36, Seven detections were authored from the incident’s indicators. Four fired correctly against replayed telemetry. Two produced volumes that could not be triaged by a two-person night shift and were held back rather than shipped noisy. One could not be written at all: the discriminating signal is the on-behalf-of claim that the bulk-export service does not propagate.
What it did not establishThat the four shipped detections work. They fired against replayed telemetry from this incident, which is the sample they were derived from, and a detection validated only against the intrusion that produced it is untested rather than proven.
OutcomeFour detections in production and marked untested, two held back with a stated reason, and one recorded as a telemetry gap rather than as a detection failure.
AuthorityStanding ROE
Form — M10 Exploitation & PursuitTerrain - D+6 14:00
Beat 37, The avenue was closed by policy: application consent grants on mission-staff accounts now require administrative approval, and the bulk-export identity was re-scoped from the whole partition to the published extract. Verification that the avenue is actually closed was not performed, because the test requires consenting a live application against production identity policy and nobody was willing to do that eight days after an intrusion.
What it did not establishThat the avenue is closed. The configuration says it is; nothing has tested it; and the register entry that records the closure looks exactly like the two hundred and thirteen other entries in it that were also never tested.
OutcomeTwo changes applied, the closure recorded as asserted rather than as verified, and a verification task raised with a date and no owner.
This is a failure the manual already predicts — Map — failure mode“Denied paths are asserted from configuration and never tested.”
- Testing the closure requires exercising a consent flow in production, and no safe method for doing so exists in this estate.
- The denied-path register has one column for a path being denied and no column for how that denial was established, so an assertion and a test are recorded identically.
- The verification task was raised at the end of an eight-day incident into a backlog with no owner assigned, which is the state in which tasks age rather than complete.
AuthorityStanding ROE
Form — M10 Exploitation & PursuitProducedRequirement - D+7 10:30
Beat 38, Deception coverage was measured for the first time, prompted entirely by the grid having finally produced something. Four decoys, all on the data layer, none on the identity plane and none on the corridor the second position used. A dedicated alert route was built so that a future decoy interaction pages a human directly instead of entering the general queue.
What it did not establishWhether the grid would catch the same intrusion again. The one decoy that fired was on the objective, and a decoy on the objective fires after an adversary has reached it — the coverage measurement makes that visible and the re-siting to fix it has not been done.
OutcomeA measured coverage figure of one layer in ten, a routing gap closed in an afternoon after eleven months, and a re-siting plan raised into the backlog.
AuthorityStanding ROE
TerrainProduced - D+8 15:00
Beat 39, The cycle record was written with the authority tax as its headline rather than the containment. Six escalations, summed from the beats that waited, against a set of pre-authorized fires that covered four of the ten actions the incident actually needed. The brief led with the three-and-a-half-hour wait on the degradation decision, not with the four-minute host isolation.
What it did not establishWhether the program is faster than the adversary. The temporal-advantage ratio needs a measured adversary objective time, and the dwell reconstruction that would supply it was destroyed on day zero — so the numerator exists, the denominator does not, and the scoreboard line is a gap.
OutcomeA record whose headline is a latency rather than a success, a backlog re-ranked with the eviction sequence and the availability floor above eleven higher-volume items, and one scoreboard line left deliberately blank.
AuthorityNo authority required
FormNone — an analytic beat, instantiating no maneuver.
TerrainConsumedProducedRequirement
Each of These Is a Failure the Manual Already Predicts.
A case study in which nothing goes wrong is a brochure. Each failure below points at the framework’s own published prediction of it — inventing a novel failure the doctrine never anticipated would be a finding about the doctrine rather than a story beat.
The estate’s best detection spent five and a half hours in the ordinary queue
The deception grid produced its first interaction in eleven months and it was routed into the general triage queue at the source platform’s default severity, where it was worked in arrival order behind 214 other items. A decoy interaction has no false-positive budget — legitimate processes have no reason to touch a decoy — and that property is the entire reason the grid was funded. Routing it into a mixed queue converted the one detection the estate can trust without tuning into an ordinary ticket, and the five hours and thirty-eight minutes it waited are the single largest recoverable interval anywhere in this timeline.
“Decoy hits are routed to the same queue as everything else, which discards the only property that made them worth emplacing.”
A dedicated route now pages a named human directly on any deception-source event, built in one afternoon on day seven, and deception coverage is measured for the first time — four decoys across one of ten layers. What has not changed is the night-shift floor: the route now reaches two people at 02:14 instead of nobody, and whether two people can act on it at that hour has not been tested.
A credential was reset in good faith, out of sequence, and it bought the adversary a second position
Twenty-one minutes after the wider fire set was opened to the shift, a platform engineer rotated the bulk-export service principal’s client secret. The action was inside the pre-authorized set and the engineer was entitled to take it. What did not exist was an order: the agency has never written an eviction sequence, so the set enumerates actions and says nothing about which one goes first or what each costs in tipping. The adversary’s session died within ninety seconds and a dormant partner-federation identity authenticated thirty-five minutes later on a different egress path — a position nobody had been watching, on an account last used one hundred and thirty-one days earlier.
“Eviction is unsequenced, so the first action warns the adversary and the remaining actions land on an estate they have already left for a position you have not found.”
An eviction sequence now exists: twenty-six actions, each with an owner, a tipping cost and a position, with the four that must land inside the same ten minutes marked as one block. It was written in under two hours on day one, which is the uncomfortable part of the finding — nothing prevented it being written in any of the eleven previous cycles. It has not been rehearsed, and a sequence that has never been walked through is a document rather than a capability.
The retrograde had never been rehearsed, so containment became an outage on a filing deadline
Because the compromised machine identity could not be revoked without restarting the service that held it, containment and degradation were the same act. The read-only degradation had existed for two years as a configuration flag and a paragraph and had never once been exercised. When it was applied at 00:15 it took the Case Filing System’s status lookup with it — an undeclared dependency on the same API — and citizens on a statutory filing deadline day received errors for three hours and forty minutes. The dependency was discovered by a member of the public before it was discovered by the agency.
“Degraded mode was never rehearsed, so degradation becomes an unplanned outage and the organization learns which dependencies were undeclared during the incident.”
A degradation rehearsal is now on the backlog with a date, and the filing status lookup has been repointed at a cache permanently rather than for the duration. The deeper cause is untouched: dependency declaration in this estate is voluntary and is done by the consuming team, so the producer’s degradation plan is only ever as complete as the consumers chose to make it, and nothing about that has changed.
The decision that mattered most waited three and a half hours for an authority nobody had assigned
Degrading a public service with a published availability commitment was above the line in the rules of engagement, correctly. What was not written anywhere was who could authorize crossing that line, on what criteria, at what hour. The request went up at 20:41 and the action landed at 00:15, and most of those three hours and thirty-four minutes were spent establishing the answer to a question that one line in the scheme of maneuver would have settled in advance. It is the single longest wait in the case and it accounts for a large share of the whole authority tax — and the interval was spent, from the adversary’s point of view, with the collection path still open.
“The severing action is technically available but nobody is authorized to take it, so it is escalated through three layers while the exfiltration completes.”
The Authorizing Official’s decision criteria for service-affecting containment are now written into the scheme of maneuver with a named deputy and an out-of-hours path, and a statutory availability floor exists on paper for the filing service. Both were authored during or immediately after the incident, which means both are provisional: a floor written at 03:35 by the person who has just degraded the service is a floor that describes what happened rather than what should be permitted.
Isolation cost the forensic record, and the forensic record was the input to everything after it
Volatile capture was taken four hours after the first containment action, and by then the platform’s own autoscaler had recycled two of the five in-scope workloads — the two the intrusion most likely originated on. Nothing in the response paused the autoscaler, because no one in the response had the authority or the knowledge to pause it and the isolation playbook has no preservation step in front of it. The consequence is not confined to the investigation: the dwell reconstruction could not be produced, which left the temporal-advantage scoreboard line blank, left two restoration preconditions permanently unmeetable, and left the agency’s standing dwell estimate unrevised.
“Isolation destroys the forensic record, and the dwell reconstruction — the input to every consolidation activity that follows — cannot be produced.”
Preservation has been moved to the front of the isolation playbook as a precondition rather than a following step, and the autoscaler now has a documented incident pause. Neither has been exercised. The retention side is unfixed and expensive: the object-store access log still reaches fourteen days, which is shorter than any dwell this agency has ever reconstructed, and extending it is a budget decision that sits with a team the incident did not involve.
9 individual beats also carry a pointer to a published failure mode, marked in the record above.
Including the Thresholds It Missed.
10 measures: 1 met, 7 missed and 2 that could not be computed at all — counted off the table rather than typed above it. Every metric carries the method that produced it, because a metric with no method is a claim, and a case that reports only the thresholds it met is reporting a biased sample and then reasoning from it.
| Measure | Value | Against its own threshold | How it was computed | What that means |
|---|---|---|---|---|
| Decoy interaction to first defensive action | 8h 26m against a 60-minute threshold | Not met | Subtracted between two beat clocks: the decoy read that opened the case, and the first fire that imposed anything on the adversary. Measured from the interaction rather than from the analyst opening the ticket, because the second measurement deletes the queue from the figure. | Of that interval, 5h 38m was spent in the general triage queue before any human saw the item. The threshold was set for a deception-grid interaction specifically, on the reasoning that a decoy hit has no false-positive budget to spend. |
| Time the estate’s highest-confidence detection spent unread | 5h 38m | Not met | The interval between the deception source emitting and the first analyst action on the item, both timestamps taken from the same alerting platform rather than reconstructed from anyone’s recollection. | The grid had produced no interaction in eleven months, so no time-to-human had ever been measured on it. The first measurement of a control is often the first time anyone learns it was not wired to anything. |
| Authority tax | 8h 3m across 6 escalations | Not met | Summed over the beats whose authority is recorded as escalated, using the same function the site computes it with for either case. Every escalated beat carries a request time and an effective time, so each contribution can be checked individually. | The longest single wait — the decision to degrade the public data service — was 3h 34m, which is 44% of the whole tax. Under contact this is not administrative overhead; it is adversary time, and the case declines to describe it as anything else. |
| Actions needed that were inside the pre-authorized set | 4 of 10 | Not met | Counted from the beats: every action taken against the adversary, classified by the authority it was actually taken under, against the pre-authorized set as it stood when contact began. | Six actions needed either the Authorizing Official or an exception. The framework’s argument for a wide pre-authorized set is priced here in minutes of continued collection rather than in convenience. |
| Statutory filing-status availability | Unavailable for 3h 40m on a filing-deadline day | Not met | Measured between the beat where the degradation took effect and the beat where the status lookup was repointed at a cache. The dependency that caused it was undeclared, so the outage is attributable to the degradation rather than to the intrusion. | No availability floor existed to measure against. One was written at 03:35 the same night, which means the figure is being reported against a threshold that was authored after the event it describes. |
| Cost of evicting out of sequence | Second position surfaced 35m after the first eviction action | Not met | Subtracted between the beat recording the unsequenced credential rotation and the beat recording the second identity authenticating. Both timestamps come from the identity provider rather than from the response bridge. | The interval is evidence that the reset was noticed, not proof that it caused the move. A dormant account activating thirty-five minutes after a rotation is the strongest correlation available and it is still a correlation. |
| Adversary dwell before detection | Not established; bracketed between 14d and 46 days | Not computed | Attempted from the object-store access log and the identity provider record, and abandoned. The earliest evidenced access sits at the log’s 14-day retention edge, which is a property of the logging configuration rather than a finding about the adversary. | The unresolved interval is 32d wide. Two of the five in-scope workloads were recycled by the platform before capture, and they are the two the intrusion most likely originated on. |
| Temporal advantage | Defender loop 11h 38m; ratio not computed | Not computed | The numerator is measured between beat clocks — decoy interaction to the first containment action that removed something. The denominator needs an adversary objective time, which requires the dwell reconstruction that was destroyed on day zero. | Reporting the ratio as met on a numerator alone was refused at Assess. A scoreboard line that reads as a gap invites a question, which is the correct outcome and the reason it is tempting to fill in. |
| Detections authored from the incident | 7 authored, 4 shipped and untested, 1 inexpressible | Met | Counted from the indicators produced at Fuse. Firing against replayed telemetry from this incident is not counted as validation, because a detection tested only on the sample it was derived from is untested. | The threshold was at least one production detection per contact, on the principle that an intrusion nobody can automate any part of will be worked by hand again next time. |
| Persistence sweep population | 412 of 540 workloads (76%) | Not met | The denominator is the workload fleet from the terrain overlay. Taken from the endpoint console instead — the count of workloads carrying an agent that survived long enough to answer — the same sweep reports 100%. | The 128 ephemeral workloads outside the sweep are recorded as unmeasured. It is tempting to argue that recycling is itself eradication; that is true only for persistence that does not survive a rebuild. |
Decoy interaction to first defensive action
- Value
- 8h 26m against a 60-minute threshold
- Against its own threshold
- Not met
- How it was computed
- Subtracted between two beat clocks: the decoy read that opened the case, and the first fire that imposed anything on the adversary. Measured from the interaction rather than from the analyst opening the ticket, because the second measurement deletes the queue from the figure.
- What that means
- Of that interval, 5h 38m was spent in the general triage queue before any human saw the item. The threshold was set for a deception-grid interaction specifically, on the reasoning that a decoy hit has no false-positive budget to spend.
Time the estate’s highest-confidence detection spent unread
- Value
- 5h 38m
- Against its own threshold
- Not met
- How it was computed
- The interval between the deception source emitting and the first analyst action on the item, both timestamps taken from the same alerting platform rather than reconstructed from anyone’s recollection.
- What that means
- The grid had produced no interaction in eleven months, so no time-to-human had ever been measured on it. The first measurement of a control is often the first time anyone learns it was not wired to anything.
Authority tax
- Value
- 8h 3m across 6 escalations
- Against its own threshold
- Not met
- How it was computed
- Summed over the beats whose authority is recorded as escalated, using the same function the site computes it with for either case. Every escalated beat carries a request time and an effective time, so each contribution can be checked individually.
- What that means
- The longest single wait — the decision to degrade the public data service — was 3h 34m, which is 44% of the whole tax. Under contact this is not administrative overhead; it is adversary time, and the case declines to describe it as anything else.
Actions needed that were inside the pre-authorized set
- Value
- 4 of 10
- Against its own threshold
- Not met
- How it was computed
- Counted from the beats: every action taken against the adversary, classified by the authority it was actually taken under, against the pre-authorized set as it stood when contact began.
- What that means
- Six actions needed either the Authorizing Official or an exception. The framework’s argument for a wide pre-authorized set is priced here in minutes of continued collection rather than in convenience.
Statutory filing-status availability
- Value
- Unavailable for 3h 40m on a filing-deadline day
- Against its own threshold
- Not met
- How it was computed
- Measured between the beat where the degradation took effect and the beat where the status lookup was repointed at a cache. The dependency that caused it was undeclared, so the outage is attributable to the degradation rather than to the intrusion.
- What that means
- No availability floor existed to measure against. One was written at 03:35 the same night, which means the figure is being reported against a threshold that was authored after the event it describes.
Cost of evicting out of sequence
- Value
- Second position surfaced 35m after the first eviction action
- Against its own threshold
- Not met
- How it was computed
- Subtracted between the beat recording the unsequenced credential rotation and the beat recording the second identity authenticating. Both timestamps come from the identity provider rather than from the response bridge.
- What that means
- The interval is evidence that the reset was noticed, not proof that it caused the move. A dormant account activating thirty-five minutes after a rotation is the strongest correlation available and it is still a correlation.
Adversary dwell before detection
- Value
- Not established; bracketed between 14d and 46 days
- Against its own threshold
- Not computed
- How it was computed
- Attempted from the object-store access log and the identity provider record, and abandoned. The earliest evidenced access sits at the log’s 14-day retention edge, which is a property of the logging configuration rather than a finding about the adversary.
- What that means
- The unresolved interval is 32d wide. Two of the five in-scope workloads were recycled by the platform before capture, and they are the two the intrusion most likely originated on.
Temporal advantage
- Value
- Defender loop 11h 38m; ratio not computed
- Against its own threshold
- Not computed
- How it was computed
- The numerator is measured between beat clocks — decoy interaction to the first containment action that removed something. The denominator needs an adversary objective time, which requires the dwell reconstruction that was destroyed on day zero.
- What that means
- Reporting the ratio as met on a numerator alone was refused at Assess. A scoreboard line that reads as a gap invites a question, which is the correct outcome and the reason it is tempting to fill in.
Detections authored from the incident
- Value
- 7 authored, 4 shipped and untested, 1 inexpressible
- Against its own threshold
- Met
- How it was computed
- Counted from the indicators produced at Fuse. Firing against replayed telemetry from this incident is not counted as validation, because a detection tested only on the sample it was derived from is untested.
- What that means
- The threshold was at least one production detection per contact, on the principle that an intrusion nobody can automate any part of will be worked by hand again next time.
Persistence sweep population
- Value
- 412 of 540 workloads (76%)
- Against its own threshold
- Not met
- How it was computed
- The denominator is the workload fleet from the terrain overlay. Taken from the endpoint console instead — the count of workloads carrying an agent that survived long enough to answer — the same sweep reports 100%.
- What that means
- The 128 ephemeral workloads outside the sweep are recorded as unmeasured. It is tempting to argue that recycling is itself eradication; that is true only for persistence that does not survive a rebuild.
Counted, Not Characterized.
Exactly one role acts on each beat. Shared action is not action, and a case in which everybody contributes to everything cannot be used to argue for a staffing model.
| Role | Beats led | Beats supported | What the role owns |
|---|---|---|---|
| Platform and product ownersPLAT | 12 | 10 | Their own terrain. Obstacles get emplaced on their ground, so they site them. |
| SOC / Defensive OperationsSOC | 8 | 15 | Maneuver. Executes fires and emplaces obstacles inside the standing rules of engagement. |
| Authorizing Official / CISOAO | 7 | 8 | Intent, risk acceptance, and the scheme itself. |
| Governance / RMF / ISSOISSO | 5 | 13 | Translating cycle outputs into FISMA and RMF artifacts, and owning the rules of engagement. |
| Hunt teamHUNT | 4 | 12 | Counterattack. Works the hypotheses that Fuse raises. |
| Cyber Threat Intelligence cellCTI | 3 | 7 | Frame, Map and Fuse. The intelligence requirements, the threat courses of action, and the confidence levels. |
Platform and product owners
PLAT
- Beats led
- 12
- Beats supported
- 10
- What the role owns
- Their own terrain. Obstacles get emplaced on their ground, so they site them.
SOC / Defensive Operations
SOC
- Beats led
- 8
- Beats supported
- 15
- What the role owns
- Maneuver. Executes fires and emplaces obstacles inside the standing rules of engagement.
Authorizing Official / CISO
AO
- Beats led
- 7
- Beats supported
- 8
- What the role owns
- Intent, risk acceptance, and the scheme itself.
Governance / RMF / ISSO
ISSO
- Beats led
- 5
- Beats supported
- 13
- What the role owns
- Translating cycle outputs into FISMA and RMF artifacts, and owning the rules of engagement.
Hunt team
HUNT
- Beats led
- 4
- Beats supported
- 12
- What the role owns
- Counterattack. Works the hypotheses that Fuse raises.
Cyber Threat Intelligence cell
CTI
- Beats led
- 3
- Beats supported
- 7
- What the role owns
- Frame, Map and Fuse. The intelligence requirements, the threat courses of action, and the confidence levels.
The Artifacts, with the Beats on Each Side of Them.
A product with no consumer is overhead. Reading down this table is the fastest way to see which artifacts were load-bearing in this case and which were written because the process said to.
| Artifact | What it is | Produced at | Consumed at |
|---|---|---|---|
| Defensive intent paragraph | One signed paragraph stating what the defense exists to protect, what may be degraded to protect it, and the acceptable risk. The commander’s-intent analog, and the citation every downstream designation rests on. | — | |
| Phase declaration | The declared campaign phase and the scope it is declared against. Sets cadence, dominant forms of maneuver, and how wide the pre-authorization set runs. | ||
| Cycle cadence and calendar | The declared length of a cycle, its close date, and the refresh intervals that inherit from it. Makes “per cycle” a measurable unit rather than a figure of speech. | — | |
| Temporal advantage threshold | The number the cycle will be judged against: defender decision loop versus adversary dwell, stated with units before the cycle runs. | — | |
| Cyber Terrain Overlay | The positional map of the estate: every element with a defensive layer, a defensive weight, a named accountable owner and its adjacencies. Not an asset inventory — an inventory enumerates, an overlay positions. | ||
| Trust zones and the connection register | The zone boundaries and the permitted- and denied-path register — the graph reachability is actually walked over, reconciled against observed flow telemetry rather than against intended configuration. | ||
| Avenue-of-approach analysis | The enumerated routes an adversary could take toward each decisive point, including physical, supplier and maintenance routes, with unassessed routes recorded as intelligence gaps rather than as absence of risk. | — | |
| Threat course-of-action sketch | Two courses of action, most likely and most dangerous, drawn against the decisive points already designated. Each is a route across ground the estate really has, not a category of threat. | — | |
| Scheme of maneuver | One graphic and one narrative: which forms of maneuver are sited where, in what sequence. The assignment record behind it carries the element, the avenue and the implementation state for every move. | — | |
| Branch and sequel plan | The branches answer the most-dangerous course of action; the sequels answer success. Every one names the authority it needs, and any expected to run inside the decision window is pre-authorized when it is written. | — | |
| Rules of engagement | Which defensive actions may be taken by whom without escalation, which need the Authorizing Official, and what is prohibited outright. The cyber analog of engagement authority, and the single largest determinant of tempo. | ||
| Pre-authorized response set | The specific containment and response actions the SOC may execute at machine speed, bounded by the statutory availability floor. Directly measurable: it shortens the decision segment of the defender loop. | ||
| Change record | Every defensive action carried out, stamped twice — at the decision and at the effect. A thin, unglamorous table, and the one the headline metric is computed from. | ||
| Implementation state record | Planned, partial or operational, per maneuver assignment. The mechanism that stops intended work being counted as deployed protection. | ||
| Authority exception log | Actions taken outside the standing rules of engagement, with who approved them and why. Exceptions are not failures; unrecorded exceptions are. | — | |
| Defender decision loop measurement | Detect to decide to contain, measured per incident from the change record’s timestamps and reported as a distribution rather than as a mean. | ||
| Fused assessment | What the cycle’s intelligence requirements returned: each answer graded for confidence and showing its working, and each requirement left unanswered recorded against the collection gap responsible. | ||
| Adversary dwell estimate | The estimated time an adversary could operate undetected in this estate, with its basis stated — measured dwell, sector reporting, or partner intelligence — and its bias acknowledged. | ||
| Maneuver effectiveness validation record | Whether the moves claiming operational status produced the effect the catalog assumed — from exercise results, control testing, and observed incident performance. | — | |
| Indicators and signposts | For each surviving hypothesis, the observable events that would confirm or kill it, handed to collection. The mechanism that makes this cycle’s analysis into next cycle’s requirements. | ||
| Hunt results, including negative results | What was hunted, how, and what was not found. Negative results are the half most often discarded, and they are the half that says what has actually been cleared. | ||
| Coverage and residual risk result | Coverage and residual risk computed over the whole overlay population, weighted by consequence, discounted by implementation state and corrected by validated effectiveness — with the denominator stated. | — | |
| Temporal advantage result | Defender decision loop against adversary dwell, reported as a ratio against the threshold set at Frame, with the result written as a word: met, or not met. The framework’s single honest scoreboard. | — | |
| Remediation backlog | The ranked list of what to fix, ordered by residual risk, main-effort weighting, and decisive-point floor breaches — which sit above higher-volume, lower-weight work regardless of count. | — | |
| Findings disposition record | Every finding with an outcome: remediate with an owner and a date, accept with a named accepter and an expiry, or transfer with the party named. “Under review” is not a disposition. | — | |
| Cycle record and trend | The closed record of the cycle — posture, loop measurement, conclusions and their confidence, backlog state at close — and the trend across cycles that makes a second cycle worth more than a first. | — | |
| Cycle brief | The published product: terrain, reachability, main effort, temporal advantage, coverage, trend, and the top-ranked backlog items — each confidence-tagged. Also the evidence that feeds the next intent. | — | |
| Recovery objectives register | A declared recovery time and recovery point objective per mission service, agreed with the service owner and constrained by statutory deadlines rather than by what is currently achievable. | — | |
| Statutory availability floor | The mission services whose availability is set by statute or regulation, and the floor below which degradation stops being a defensive choice. Bounds what may be pre-authorized and what may be degraded under contact. | — | |
| Privacy and controlled-information terrain register | Where privacy holdings and controlled unclassified information sit, the authorities under which they are held, and the boundaries their handling requires — expressed as denied paths, not as policy statements. | — | |
| Supplier terrain register | Suppliers as external actors on the overlay, with the access each holds, the paths that access implies, and the contract behind it. | — |
Defensive intent paragraph
- What it is
- One signed paragraph stating what the defense exists to protect, what may be degraded to protect it, and the acceptable risk. The commander’s-intent analog, and the citation every downstream designation rests on.
- Produced at
- —
- Consumed at
Phase declaration
- What it is
- The declared campaign phase and the scope it is declared against. Sets cadence, dominant forms of maneuver, and how wide the pre-authorization set runs.
- Produced at
- Consumed at
Cycle cadence and calendar
- What it is
- The declared length of a cycle, its close date, and the refresh intervals that inherit from it. Makes “per cycle” a measurable unit rather than a figure of speech.
- Produced at
- Consumed at
- —
Temporal advantage threshold
- What it is
- The number the cycle will be judged against: defender decision loop versus adversary dwell, stated with units before the cycle runs.
- Produced at
- Consumed at
- —
Cyber Terrain Overlay
- What it is
- The positional map of the estate: every element with a defensive layer, a defensive weight, a named accountable owner and its adjacencies. Not an asset inventory — an inventory enumerates, an overlay positions.
- Produced at
- Consumed at
Trust zones and the connection register
- What it is
- The zone boundaries and the permitted- and denied-path register — the graph reachability is actually walked over, reconciled against observed flow telemetry rather than against intended configuration.
- Produced at
Avenue-of-approach analysis
- What it is
- The enumerated routes an adversary could take toward each decisive point, including physical, supplier and maintenance routes, with unassessed routes recorded as intelligence gaps rather than as absence of risk.
- Produced at
- —
- Consumed at
Threat course-of-action sketch
- What it is
- Two courses of action, most likely and most dangerous, drawn against the decisive points already designated. Each is a route across ground the estate really has, not a category of threat.
- Produced at
- —
- Consumed at
Scheme of maneuver
- What it is
- One graphic and one narrative: which forms of maneuver are sited where, in what sequence. The assignment record behind it carries the element, the avenue and the implementation state for every move.
- Produced at
- —
- Consumed at
Branch and sequel plan
- What it is
- The branches answer the most-dangerous course of action; the sequels answer success. Every one names the authority it needs, and any expected to run inside the decision window is pre-authorized when it is written.
- Produced at
- —
- Consumed at
Rules of engagement
- What it is
- Which defensive actions may be taken by whom without escalation, which need the Authorizing Official, and what is prohibited outright. The cyber analog of engagement authority, and the single largest determinant of tempo.
- Produced at
Pre-authorized response set
- What it is
- The specific containment and response actions the SOC may execute at machine speed, bounded by the statutory availability floor. Directly measurable: it shortens the decision segment of the defender loop.
- Produced at
Change record
- What it is
- Every defensive action carried out, stamped twice — at the decision and at the effect. A thin, unglamorous table, and the one the headline metric is computed from.
- Produced at
- Consumed at
Implementation state record
- What it is
- Planned, partial or operational, per maneuver assignment. The mechanism that stops intended work being counted as deployed protection.
- Consumed at
Authority exception log
- What it is
- Actions taken outside the standing rules of engagement, with who approved them and why. Exceptions are not failures; unrecorded exceptions are.
- Produced at
- Consumed at
- —
Defender decision loop measurement
- What it is
- Detect to decide to contain, measured per incident from the change record’s timestamps and reported as a distribution rather than as a mean.
- Produced at
- Consumed at
Fused assessment
- What it is
- What the cycle’s intelligence requirements returned: each answer graded for confidence and showing its working, and each requirement left unanswered recorded against the collection gap responsible.
- Produced at
Adversary dwell estimate
- What it is
- The estimated time an adversary could operate undetected in this estate, with its basis stated — measured dwell, sector reporting, or partner intelligence — and its bias acknowledged.
- Produced at
- Consumed at
Maneuver effectiveness validation record
- What it is
- Whether the moves claiming operational status produced the effect the catalog assumed — from exercise results, control testing, and observed incident performance.
- Produced at
- Consumed at
- —
Indicators and signposts
- What it is
- For each surviving hypothesis, the observable events that would confirm or kill it, handed to collection. The mechanism that makes this cycle’s analysis into next cycle’s requirements.
- Produced at
Hunt results, including negative results
- What it is
- What was hunted, how, and what was not found. Negative results are the half most often discarded, and they are the half that says what has actually been cleared.
- Produced at
Coverage and residual risk result
- What it is
- Coverage and residual risk computed over the whole overlay population, weighted by consequence, discounted by implementation state and corrected by validated effectiveness — with the denominator stated.
- Produced at
- Consumed at
- —
Temporal advantage result
- What it is
- Defender decision loop against adversary dwell, reported as a ratio against the threshold set at Frame, with the result written as a word: met, or not met. The framework’s single honest scoreboard.
- Produced at
- Consumed at
- —
Remediation backlog
- What it is
- The ranked list of what to fix, ordered by residual risk, main-effort weighting, and decisive-point floor breaches — which sit above higher-volume, lower-weight work regardless of count.
- Produced at
- Consumed at
- —
Findings disposition record
- What it is
- Every finding with an outcome: remediate with an owner and a date, accept with a named accepter and an expiry, or transfer with the party named. “Under review” is not a disposition.
- Produced at
- Consumed at
- —
Cycle record and trend
- What it is
- The closed record of the cycle — posture, loop measurement, conclusions and their confidence, backlog state at close — and the trend across cycles that makes a second cycle worth more than a first.
- Produced at
- Consumed at
- —
Cycle brief
- What it is
- The published product: terrain, reachability, main effort, temporal advantage, coverage, trend, and the top-ranked backlog items — each confidence-tagged. Also the evidence that feeds the next intent.
- Produced at
- Consumed at
- —
Recovery objectives register
- What it is
- A declared recovery time and recovery point objective per mission service, agreed with the service owner and constrained by statutory deadlines rather than by what is currently achievable.
- Produced at
- —
- Consumed at
Statutory availability floor
- What it is
- The mission services whose availability is set by statute or regulation, and the floor below which degradation stops being a defensive choice. Bounds what may be pre-authorized and what may be degraded under contact.
- Produced at
- —
- Consumed at
Privacy and controlled-information terrain register
- What it is
- Where privacy holdings and controlled unclassified information sit, the authorities under which they are held, and the boundaries their handling requires — expressed as denied paths, not as policy statements.
- Produced at
- —
- Consumed at
Supplier terrain register
- What it is
- Suppliers as external actors on the overlay, with the access each holds, the paths that access implies, and the contract behind it.
- Produced at
- —
- Consumed at
The Whole Citation Index, Resolved.
Each identifier links to its own entry in the reference manual, and each carries the beats it appears in. This is the section that makes the case checkable rather than merely readable.
Controls (36)
Techniques (29)
Terrain (7)
Stated Here so It Cannot Be Over-Read.
One worked case is one worked case. The limits below are the claims a reader might reasonably draw from it that it does not actually support.
- Not evidence that the intrusion was evicted. The Phase IV declaration rests on twenty-six hours without new indicators, which is consistent with eviction and equally consistent with an adversary who has gone quiet, and the declaration itself says so.
- Not a dwell figure. The reconstruction was attempted and abandoned against a fourteen-day log horizon and two destroyed workloads, so the case reports a thirty-two-day bracket it cannot narrow rather than the point estimate a reader would prefer.
- Not evidence about the scale of exposure. The access log records prefixes touched and request counts, not object bodies, so everything this case says about what was read is an upper bound on what could have been read.
- Not transferable to an estate that can revoke a machine identity independently of the service holding it. Almost every hard decision in this case follows from that one coupling, and an agency without it faces a materially easier problem than the one described here.
- Not a tempo benchmark. The measured intervals are one contact at one agency, and the authority latencies in particular are properties of who happened to be reachable on a Tuesday afternoon rather than of the authority model in general.
- Not evidence that the deception grid works. One decoy fired once in eleven months, on the objective rather than on the path to it, and a coverage measurement taken afterwards found four decoys across one of ten terrain layers.
- Not a reconstitution case. No form of reconstitution appears anywhere in this timeline, because the agency does not operate one — the service was restored by repointing configuration, not by rebuilding from a verified copy, and nothing here should be read as evidence that a rebuild path exists.
- Not, in the end, a story about a clever adversary. Everything this case establishes is about the defender: which alerts reach a human, which actions need permission, which degradations have been rehearsed, and how much of the response was improvised because the artifact that would have carried it had never been written.
The other case runs the opposite posture: The hunt that found nothing, and what that was worth — proactive hunt, 40 beats. The two are meant to be read against each other, and the contrast between them is computed rather than asserted.