Two Courses of Action, and What the Agency Could Do About Them.
The terrain overlay says what ground exists. A course of action says how an adversary intends to cross it. Doctrine asks for two — the most likely, which the standing posture has to answer every day, and the most dangerous, which the branches and the recovery plan have to answer — and the pair is the point: planning against only one of them is how a program ends up strong everywhere the adversary is not.
Illustrative · not an assessment
Two sketches against an archetype. Neither is intelligence, and neither describes a real agency.
These courses are modeled against the Federal Reference Agency — the same illustrative estate at the same maturity as the coverage baseline and the case studies. The adversary sketches are analytic constructs written from public doctrine, not reporting on any campaign, and every judgment of likelihood is a judgment about this archetype’s terrain rather than about anybody’s threat picture.
What is not illustrative is the demand: which techniques each course requires is taken from the framework’s own published COA overlay, and how much of that demand goes unmet is computed from the same coverage grading the baseline page uses. An adopter builds their own two courses; this page shows what the product looks like when it is finished.
48Cells the likely course demands21 of them absent on this baseline
47Cells the dangerous course demands22 of them absent on this baseline
29Demanded by bothWhere one investment answers two problems — the main effort
35.4% / 35.1%Answered, likely / dangerousNeither course is answered better than the other
The Overlay
Where a Single Investment Answers Two Problems.
The overlay marks the cells each course demands, and marks separately the cells both demand. That third set is not a convenience — it is the only place on the matrix where one decision buys down two different futures, which is what makes it the main effort.
The most-likely course of action is a patient, credentialed adversary after mission records. The most-dangerous is a supply-chain compromise of the build pipeline that envelops everything downstream. Cells demanded by both are where a single investment answers two problems — that is where the main effort goes.
ASOM-Fed Defensive Maneuver Framework v6.1 · overlay “Threat COA comparison”
The overlay is a selection, not a partition. It names 66 of the catalog’s techniques across the two courses; the rest are not being judged and are not being called unnecessary. They are simply not what these two particular courses turn on.
ValidatedImplemented and validated — counts in full
PartialPartial — emplaced but unproven or incomplete — counts half
AbsentAbsent — the maneuver cannot currently be performed — counts nothing
Most likely · course A
Credentialed access to mission records
Objective. Sustained, quiet read access to the non-public record set the agency holds on behalf of the public, exfiltrated at a rate that resembles ordinary use.
The actor
A patient, resourced actor with no need for a novel exploit: it buys or phishes a credential, waits, and behaves like a user. Capability is ordinary; tradecraft is in the waiting.
The decisive point
The conditional-access policy engine. An actor who is authorized past it does not have to defeat any control below it, because every control below it is asking the engine for permission.
The agency’s crown-jewel data is reachable through an application that a few hundred staff identities are entitled to use, and that application has a reporting path built for bulk export because the mission requires bulk export. No boundary has to be broken for the records to move; the export is a feature.
Identity is the cheapest way in and the agency knows it, which is why identity is also the best-funded ground here. That does not make this course unlikely — it makes it slow. The actor does not need to defeat phishing-resistant authentication everywhere; it needs one population where the assurance is weaker, and the external-user population is that population on almost every federal estate.
Nothing about this course requires the adversary to be noisy. Every action in it is an action a legitimate user also takes, which is why detection here depends on baselining behavior rather than on matching a signature.
What Culmination Looks like for Them
The records are copied and the access persists. There is no outage, no ransom note and no adversary error to detect — the agency learns of it from a third party, months later, if at all.
A harvested credential at the public authentication surface
A credential taken from an infostealer log, a phishing kit or a reused password is presented at the same authentication surface the public uses. The session that results is legitimate in every respect except who is holding it.
Why it works on this estate. The external-user population is the largest identity surface the agency runs and the one whose assurance it controls least, because the credential lives on somebody else’s device. Strong authentication for staff does not reach it.
The adversary takes the artifact issued after authentication — a session token, a refresh token, a cookie — and replays it. Multi-factor authentication has already happened, correctly, and is not asked again.
Why it works on this estate. Sessions on this estate are long, and authorization is evaluated at the start of a session rather than per request. That combination makes a token worth more than a password, and it is the gap phishing-resistant authentication does not close.
Legitimate entitlement used at illegitimate volume
The held identity uses the mission application exactly as intended, through the reporting and export path the mission requires, at a rate no human workflow produces.
Why it works on this estate. The export capability is not a weakness to be removed — the agency has a statutory reason for it. That makes rate, not permission, the only thing separating use from exfiltration on this avenue.
From a mission account to the identity plane itself
Having established a foothold, the adversary moves toward the accounts and the configuration that decide access, rather than toward more data. Entitlement becomes the objective.
Why it works on this estate. Standing privilege still exists on this estate for the platform and cloud teams, because removing it breaks routine work. Every one of those accounts is a route to the decisive point.
Restore the mission on evidence, not on hope — and prove it before you need it.
Cells demanded
3 of 11 in the form
What the baseline supplies
0% — 0 validated, 0 partial, 3 absent
Illustrative Demand from the published COA overlay (this course’s own cells plus the cells both courses demand); supply from the coverage grading on the baseline. Forms this course does not demand are omitted.
Across the whole course: 48 cells demanded, 7 validated, 20 partial, 21 absent — 35.4% answered.
What would say this is running
Authentication from a geography, device class or hour that the population baseline does not carry, followed by no failure — success is the signal, not failure.
A session that survives a credential reset, which means the token was taken rather than the password.
Reporting or export volume from one identity that is inside the application’s limits and outside that identity’s own history.
Agency credentials or session artifacts offered for sale before any of this, which is the earliest warning available and the one that costs least to act on.
What would argue against it
The observed access is confined to data the identity is entitled to and used at its historical rate — volume anomalies with an ordinary explanation are the most common false positive here, and closing them is analytic work, not a formality.
The account’s activity stops when the user is contacted, which points at credential sharing or an unmanaged automation rather than an adversary.
The path used is one no external actor could reach without first holding privileged infrastructure access, which would make this the other course.
If this is the wrong one to plan against. Planning only against this course buys an identity plane that is genuinely strong and a recovery capability that has never been exercised. The agency survives the ordinary case and has no answer at all to the extraordinary one.
Most dangerous · course B
Pipeline compromise into the data layer
Objective. Durable, privileged presence in the workload tier, arriving through a channel the agency treats as trusted, with reach into the data layer and into the means of recovery.
The actor
An actor willing to spend months and to compromise somebody else first — a supplier, an integrator, or the agency’s own build system — in order to arrive inside the trust boundary as a change the agency deployed itself.
The decisive point
The deployment identity — the non-person credential the pipeline uses to change production. Holding it converts every subsequent action into an authorized one.
The build pipeline holds credentials that outrank every human in the estate: it deploys to production, it is expected to change production, and its activity is indistinguishable from the change management it implements. Nothing else on the estate combines that much authority with that little scrutiny.
The managed-service path is the same problem with a contract in front of it. A provider that reaches production with standing access the agency cannot revoke on its own has, in maneuver terms, an avenue of approach the agency does not control the obstacle on.
The reason this is the most dangerous rather than merely the worst-sounding is what it does to recovery. An adversary that arrives through the deployment path is inside the mechanism the agency would use to restore itself, so the restore is suspect and the backups are reachable by the credentials that were taken.
What Culmination Looks like for Them
The adversary holds the workload tier and the path back into it. Eviction requires rebuilding from artifacts whose integrity is the thing in question, and the statutory availability floor keeps running while that is decided.
A signed update from a supplier the agency cannot audit
A component the agency installs, trusts and updates automatically carries the adversary’s code, signed with the supplier’s own key and delivered through the supplier’s own channel.
Why it works on this estate. The agency’s trust in the update path is structural: it is what allows patching to happen at all. Nothing in the reference profile stages or verifies an update independently of the supplier who produced it.
The adversary modifies what the pipeline builds or what it deploys. The change arrives in production as a deployment, through the mechanism the agency uses for every legitimate change.
Why it works on this estate. Pipeline activity is change activity. There is no behavioral anomaly to find, because changing production is the pipeline’s function, and the credentials that do it are held where the pipeline can read them.
The non-person identity that deploys is taken and used directly. It is not subject to joiner-mover-leaver, it is rarely recertified, and its entitlements were sized for convenience.
Why it works on this estate. Machine identity governance on this estate is partial. The identity plane is well defended for humans and the population that is not human is the one holding production rights.
The managed-service provider’s access is used, from the provider’s own compromised estate, over a connection the agency treats as internal.
Why it works on this estate. The reference profile’s provider reaches production with access the agency cannot revoke on its own — the obstacle on this avenue is administered by somebody else, which in maneuver terms means the agency does not hold it.
Restore the mission on evidence, not on hope — and prove it before you need it.
Cells demanded
4 of 11 in the form
What the baseline supplies
12.5% — 0 validated, 1 partial, 3 absent
Illustrative Demand from the published COA overlay (this course’s own cells plus the cells both courses demand); supply from the coverage grading on the baseline. Forms this course does not demand are omitted.
Across the whole course: 47 cells demanded, 8 validated, 17 partial, 22 absent — 35.1% answered.
What would say this is running
A deployment that no work item explains, or an artifact whose provenance does not resolve to a reviewed change.
A workload identity authenticating from outside the pipeline, or holding entitlements no pipeline stage needs.
A supplier disclosure, advisory or breach notification touching a component that sits on key terrain — the one indicator that arrives before anything happens on the agency’s own estate.
Changes to the trust configuration itself: a new federation relationship, a new signing key, a new identity provider trust.
What would argue against it
Every unexplained deployment resolves to an emergency change with a retrospective record — common, and not evidence of anything except a change process under strain.
The workload identity’s anomalous behavior tracks a platform migration the agency is itself running.
The supplier disclosure names a component the terrain register shows the agency does not run, which is a question for the register’s currency rather than for the SOC.
If this is the wrong one to plan against. Planning only against this course spends the program on supply-chain assurance and pipeline integrity while the ordinary credentialed path — the one that will actually be used — stays answered by a control set nobody has tested under contact.
Main Effort
The 29 cells both courses demand.
This is the set the framework says to weight first, and on this baseline 13 of them are absent — 37.9% answered. A main effort that is under half-supplied is not a priority, it is a finding.
Both courses are answered almost entirely from the zero-trust pillars and the cross-cutting layer. That is a fact about these two courses, not a statement that the other ground is safe — and reading it as the latter is the most expensive mistake available on this page.
Exhibit 3
Demanded Cells by Terrain Layer, Both Courses
Layer
Most likely
Most dangerous
T1 IdentityThe high ground
19 cells · 7 absent
8 cells · 2 absent
T2 DevicesThe entry fords
Not demanded
2 cells · 0 absent
T3 NetworksThe corridors
8 cells · 4 absent
9 cells · 4 absent
T4 Applications and WorkloadsThe urban terrain
4 cells · 2 absent
8 cells · 6 absent
T5 DataThe objective
8 cells · 4 absent
7 cells · 3 absent
T6 Operational TechnologyGround you cannot maneuver freely on
Not demanded
Not demanded
T7 WorkforceTerrain that is also the force
Not demanded
Not demanded
T8 FacilitiesThe physical boundary
Not demanded
Not demanded
T9 Supply ChainThe lines of communication
Not demanded
Not demanded
TX Cross-CuttingThe enablers of movement
9 cells · 4 absent
13 cells · 7 absent
T1 Identity
The high ground
Most likely
19 cells · 7 absent
Most dangerous
8 cells · 2 absent
T2 Devices
The entry fords
Most likely
Not demanded
Most dangerous
2 cells · 0 absent
T3 Networks
The corridors
Most likely
8 cells · 4 absent
Most dangerous
9 cells · 4 absent
T4 Applications and Workloads
The urban terrain
Most likely
4 cells · 2 absent
Most dangerous
8 cells · 6 absent
T5 Data
The objective
Most likely
8 cells · 4 absent
Most dangerous
7 cells · 3 absent
T6 Operational Technology
Ground you cannot maneuver freely on
Most likely
Not demanded
Most dangerous
Not demanded
T7 Workforce
Terrain that is also the force
Most likely
Not demanded
Most dangerous
Not demanded
T8 Facilities
The physical boundary
Most likely
Not demanded
Most dangerous
Not demanded
T9 Supply Chain
The lines of communication
Most likely
Not demanded
Most dangerous
Not demanded
TX Cross-Cutting
The enablers of movement
Most likely
9 cells · 4 absent
Most dangerous
13 cells · 7 absent
Illustrative Counted from the COA overlay joined to each technique’s declared terrain layer, with absences from the coverage grading. Every layer is listed, including the ones neither course touches — a row of zeroes is the most informative row here.
4 layers carry no demanded cell in either course: T6 Operational Technology, T7 Workforce, T8 Facilities, T9 Supply Chain. 4 of those 4 are layers this framework added precisely because a federal estate has measurable ground there. Their absence here means a third course — one that runs through operational technology, the workforce or a supplier’s own network — would be answered by cells neither of these two sketches has asked for, and the coverage baseline grades that ground thinnest of all.
The Comparison
Two Courses Are Only Useful If the Pair Drives a Decision.
The comparison is the deliverable, not the sketches. These are the four questions it has to answer, and for this archetype three of the four answers are already computable from the tables above.
Which cells do both courses demand?
That set is the main effort by construction: one investment answers two problems, and it is the only place on the matrix where that is true.
Where is a course demanded and the capability absent?
An absent cell on a demanded avenue is not a gap in a control catalog — it is a move the agency cannot make while the adversary is making theirs.
Which course does the current posture actually answer better?
If the answer is neither, in roughly equal measure, the posture was not built against either course. That is the ordinary finding, and it is this baseline’s finding.
What would have to be true for the dangerous course to become the likely one?
Usually one observable: a supplier disclosure on key terrain, or a trust change nobody requested. Naming it in advance is what makes the branch executable.
For this baseline the third answer is neither: the likely course is 35.4% answered and the dangerous one 35.1%. A posture built deliberately against either would show a gap between those two numbers. The absence of a gap is the finding — this estate’s controls were selected against a catalog rather than against an adversary.
Limits
What a Course of Action Is Not.
A model with no stated limits gets read as a claim about everything. These four are the ones this page would otherwise invite.
These are two courses, not a threat model. An adversary is not obliged to pick either, and a third course that runs through operational technology, the workforce or the facilities would be answered by cells neither of these demands.
The likelihood judgment is about this archetype’s terrain, not about any real agency’s intelligence picture. An agency with a different mission has a different most-likely course, and should build its own rather than adopt this one.
A COA sketch is a hypothesis with an expiry date. It is a product of the Map step, refreshed every cycle, and one that survives four cycles unchanged should be suspected of being a description of the defender rather than of the adversary.
Neither course names an actor, a campaign or a tool. Naming one would make the sketch obsolete the moment the tool changed, and would make the plan depend on attribution the agency mostly cannot do.
New to this vocabulary? Terrain layer, form of maneuver, technique and control are different classes of thing, and swapping two of them produces work that looks correct and decides nothing. The object model states each one with the question it answers and the class it is most often mistaken for.