A Thousand Devices Is Not a Hunt Scope.
No hypothesis fits a thousand hosts. Ask “is there anything bad on the network” and there is no query that answers it, no population to run against, and no condition under which you are finished. This is the procedure that replaces the question: reduce the estate to rooms, rank them, and clear them one at a time by a drill that produces a dated, falsifiable statement each time it runs.
Stop Counting Devices.
The unit of work is the room: one segment, examined at one terrain layer, against one hypothesis. Not a subnet — a subnet is a piece of ground, and a room is a piece of ground plus the question being asked of it. The same subnet therefore appears three or four times, once per layer that matters on it.
The pairing is what makes a clearing statement decidable. “The finance VLAN is clear” cannot be falsified by anybody. “On the finance VLAN, at the device layer, no host executed an unsigned binary from a user-writable path in the last thirty days” has a population, a window, and a way of being wrong.
The Reduction, at True Proportion — One Dot per Device.
Computed from the archetype estate, including the dots. A thousand hosts is not a work queue; 26 segments is a map; 80 rooms is a schedule. Eighty is a number you can put dates against, and a thousand is not.
It Comes from the Overlay, Not the Console
That is not a preference. An endpoint console reports on what it is installed on, so it will always answer 100%, and the hosts it never knew about are precisely the ones worth hunting. The population comes from terrain inventory (TM-1), which is the only artifact that knows about ground no agent was ever deployed to.
It Scales Sublinearly
Ten thousand devices is not ten times the work. It is more segments, but the same layers, and the room count grows with how the estate is partitioned rather than with how many things are in it. Estates acquire hosts far faster than they acquire segments, which is why this is the reduction that makes the problem finite.
Decide Which Room Is First.
A command decision, taken at Array and owned by the Authorizing Official. It is the point at which the main effort is designated (SM-4) and the only point at which the estate is looked at whole. It is not the analyst’s call, and it is not a standing preference.
The rank is deliberately crude — three small integers multiplied, then decayed by how recently the room was cleared: consequence × exposure × proximity × staleness.
- Consequence 1–5
- What it costs if this ground is held by someone else. Mission impact, not asset price. Source: Your asset register.
- Exposure 1–5
- How many mapped avenues terminate in this segment or transit it. Source: Avenues of approach (KT-3).
- Proximity 1–3
- Contains a decisive point (3), adjacent to one (2), or neither (1). Source: Decisive points (KT-1).
- Staleness ×1 to ×3
- Cycles since this room was last cleared, capped. Never cleared takes the cap. Source: Hunt results — last clearance date.
A more sophisticated score would be harder to argue with in a room full of people who disagree, and being argued with is the entire point of publishing the order. A stakeholder who thinks their segment is ranked too low can see exactly which of the three numbers to contest.
The Same Nine Classes, Plotted.
The ranking table below is this picture sorted. Reading them together is the point: the matrix shows why the order is what it is, and the board shows where this cycle stops.
The Board, with the Arithmetic Showing and a Line Where This Cycle’s Throughput Runs Out.
Device count is not priority. The user VLANs hold 52% of the fleet and rank eighth of nine, while twenty-five identity hosts rank second. A hunt program that works an asset list in numerical order has already forfeited most of the value available to it — and the inversion here is arithmetic rather than taste.
The Drill.
The drill is seven steps, performed identically in every room. Each sits inside a cycle step that already exists, cites the controls that govern it, and carries a gate — the condition that must hold before the next step may begin. A step whose gate fails is not skipped. It sends the room somewhere.
The Drill as a Flow, Bracketed by the Two Cycle-Scope Steps Around It.
Note the fan at step 5: three exits, not two. Every hunt flowchart ever drawn has “found” and “not found”. The third exit is where the honesty lives, and dropping it is what turns a hunt program into a reassurance service.
SEQUENCE · ONCE PER CYCLE · ARRAY
Rank the rooms and draw the line at what this cycle can actually reach. Choosing the order is a command decision, not an analyst’s. It is where the main effort is designated, and it is the only step at which the estate is looked at whole.
- 1
Declare
Write the hypothesis, and write what would falsify it.
Gate. Can you state what you would have to see to be wrong? No falsifier means no hunt. Return the room to the queue and re-frame it.
Fails as: Collecting first and forming the question from what came back. The finding is then guaranteed and worthless — it is a description of the telemetry, not a test of the ground.
FRAME · CE-2
- 2
Bound
Take the room’s population from the terrain overlay, not from a tool console.
Gate. Is the overlay entry for this segment younger than its refresh cadence? A stale overlay makes every later percentage a guess. Refresh the entry first; that is Map work, and it is cheap next to a wrong denominator.
Fails as: Letting the EDR console define the population. It reports on what it is installed on, so it will answer 100% every time, and the hosts it never knew about are exactly the ones worth hunting.
MAP · TM-1 · TM-6 · TM-7
- 3
Reach
Split the population into what your telemetry can actually see in the window, and what it cannot.
Gate. Is the reachable share above the floor this room’s consequence requires? Below the floor the sweep cannot produce a clearance, only an anecdote. Run it anyway if it is cheap, but the room exits at NOT COMPUTED and the gap goes to the backlog.
Fails as: Treating the unreachable set as an inconvenience to be resolved later. It is the finding. An adversary that has chosen its ground has chosen ground you cannot see.
MAP · DV-3 · KT-4 · M1
- 4
Sweep
Run the technique against the reachable set. The technique’s stated indicator is the clearing standard — do not invent a looser one at the keyboard.
Gate. Did the sweep complete over the whole reachable set, or did it time out part-way? A partial sweep silently shrinks the denominator you already fought for. Re-run against the remainder or move the remainder into the unreachable set explicitly.
Fails as: Widening the query until something comes back. The hunt then measures the analyst’s persistence rather than the ground’s condition.
MANEUVER · SM-2 · CG-3 · M1 · M5
- 5
Adjudicate
Assign one of three verdicts and a confidence with a stated basis.
Gate. Which of the three exits does the evidence support? There is no fourth exit. "Probably fine" is NOT COMPUTED wearing a confident face.
Fails as: Collapsing three outcomes into two. Everything that is not contact becomes "clear", the unreachable remainder disappears into it, and coverage becomes a number that only goes up.
FUSE · CE-3
- 6
Hold
Emplace something that keeps the room clear after you leave — an obstacle, a sensor, or a policy.
Gate. Is there now something in the room that would notice a change? Then the clearance expires the moment you leave, and the honest expiry is one cycle rather than three. Record it that way.
Fails as: Clearing without holding. That is patrolling: the same rooms are re-hunted forever, coverage never accumulates, and the team’s effort is spent re-establishing what it already knew.
MANEUVER · SM-2 · SM-7 · KT-5 · M2 · M4 · M5
- 7
Mark
Write the clearance record: scope, window, fidelity, falsifier, holder, and expiry.
Gate. Could a different analyst re-run this from the record alone? Then it is a memory, not a mark, and the next cycle will clear this room again from scratch.
Fails as: Recording the verdict without the window and the fidelity. A clearance with no window is undated, so it can never expire, so the coverage figure built on it never decays and quietly becomes fiction.
ASSESS · CE-4 · CE-6 · CG-4
The Three Exits
CLEARED
The hypothesis was falsified across the reachable population, inside the window.
Mark it, hold it, take the next room.
Adds to coverage — for as long as its expiry says, and no longer.
CONTACT
The indicator was observed. The hypothesis survived the attempt to kill it.
Stop clearing. The cycle changes phase and the reactive path takes over.
Does not add to coverage. Clearing resumes after the engagement, from a re-derived overlay.
NOT COMPUTED
The reachable share was too small, or the window too short, to decide either way.
Re-queue the room and raise the collection gap as next cycle’s intelligence requirement.
Adds to the remainder, which is published beside coverage rather than netted out of it.
ROLL UP · ONCE PER CYCLE · ASSESS
Publish coverage with the unreachable remainder in the same sentence. A cleared fraction reported without its remainder is the number that made everyone comfortable last quarter. The two travel together or neither is published.
The Arithmetic That Says Whether You Can Afford It.
The question behind the question. A procedure that works beautifully on one segment and cannot be run across the estate is a demonstration, not a capability. The governing fact is that a clearance expires.
Which makes coverage a rate rather than an achievement. A team clearing R rooms per cycle, where a clearance stands for 3 cycles, sustains R × 3 cleared rooms and no more — however the result is written up, and no matter how much reporting discipline is applied to it. Terrain change takes a slice off the top first: about 6% of rooms per cycle are invalidated by a change to the ground beneath them, which is roughly 5 rooms here.
Throughput Against the Coverage It Can Honestly Hold.
The curve is a ceiling. Below the churn line a team is losing ground faster than it takes it, and its published coverage figure describes rooms whose clearance has already lapsed — the most common failure state for a hunt program, and an invisible one from the inside.
Two hunters. That is the answer to “is this scalable”, and it is worth being precise about what makes it true: the estate is held not because two people can examine a thousand devices, but because eighty rooms at half an analyst-day each is sixteen analyst-days, and sixteen analyst-days is two people spending eight days a cycle hunting. Change any input and the arithmetic follows honestly. Halve the hunt time and coverage settles at 49% — a defensible posture, as long as it is reported as 49%.
What this buys that a coverage percentage does not: which ground is currently cleared, with dates; which ground has never been reachable, which is a collection-gap backlog and a budget argument rather than a shrug; and what a marginal hunter is worth, which turns “we need more people” into a specific claim about a specific percentage.
What You Publish at the End of the Pass.
Coverage and the remainder belong in the same sentence, always. CE-4 already requires the denominator to be stated; clearing makes that cheap to satisfy, because the denominator was established at step 2 of every room and the remainder at step 3.
Cycle 7 — 31 rooms attempted, 26 cleared, 1 contact, 4 not computed.
Cleared ground now 58/80 rooms (73%), against a denominator taken from the terrain overlay.
The 4 not-computed rooms are all in facilities and building systems, where sensor coverage reaches 12% of the population; that gap is next cycle’s first intelligence requirement.
Nine cleared rooms expire before cycle 9 and are already queued.
Note what that paragraph makes impossible. It cannot be read as “we are 73% secure”, because the ground and the window are attached to the number. It cannot silently carry a stale clearance, because expiries are stated. And it cannot bury the facilities gap, because the gap is in the same four lines as the result — which is the outcome the worked proactive case arrived at the long way round, on a single corridor, over seven days.
No New Objects. One New Scope.
A fair question, and worth answering precisely — “we added a thing to the framework” is the easiest and least useful response to a hard operational question.
All seven sit inside the six cycle steps. Declare is Frame, Bound and Reach are Map, Sweep and Hold are Maneuver, Adjudicate is Fuse, Mark is Assess.
The published hunt cases already carry met, not-met and not-computed, and record what each beat did not establish.
Hunt results, including negative results — already a first-class published product. Its negative half is the clearance record under another name.
CE-4 already requires coverage to be computed over the overlay population, with the denominator stated.
Main effort designation (SM-4) and remediation backlog prioritization (CE-5), at Array.
New — and not an object class. A scope: the (segment × layer) pair a single falsifiable hypothesis fits inside.
New as a number. The framework said clearances go stale; it did not say how fast, and without a rate the throughput arithmetic cannot be done at all.
So the framework did not need eleven forms of maneuver to become twelve. It needed the cycle run at a scope small enough for a hypothesis to fit, repeatedly, with the results accumulating into a number that decays. If a future version promotes clearing to a named form, that is a decision about the admission criteria for forms — and it should be argued there, on those criteria, rather than settled here.
The Smallest Honest Version Fits in One Cycle.
- 1
Draw the segments
Not the assets — the segments, with an owner each. If this takes more than a day, that is itself the first finding, and it is a TM-1 finding.
- 2
Score the three factors
For each segment, in a meeting, in an hour. Publish the order and let people argue with it.
- 3
Clear one room
The top segment’s highest-consequence layer. Run all seven steps and write the clearance record even though it feels like overhead at a sample size of one. The record is the artifact; the finding is a by-product.
- 4
Count how long it took
That is your R, and the curve above turns it into a coverage ceiling and a staffing number the same afternoon.
- 5
Publish the ceiling, not the aspiration
A program that opens with “at current staffing we can honestly hold 45% of the estate” has more credibility than one reporting 100% coverage of an undefined denominator — and it has an argument attached.
Every Step of the Drill Cites a Control That Governs It.
The drill is not a separate methodology bolted onto the framework. It is the same six-step loop, turned at a scope small enough for one falsifiable question to fit inside, many times per cycle instead of once. Reading the loop at full estate scope is the shortest way to see why the room-scale version inherits its gates.