ASOM-Fedv6.1Open the explorer
M7 · In contact · 17 techniques

Counterattack

Seize the initiative and evict before the adversary reaches the objective.

Intent, Mechanism and Indicator

Seize the initiative and evict before the adversary reaches the objective.

Role. The form that seizes the initiative

Mechanism

Threat hunting against hypotheses raised in the FUSE step; automated containment playbooks.

Observable indicator

Mean time to evict is inside the adversary’s dwell budget.

Terrain It Consumes

Derived from where the form’s techniques are actually emplaced. The highlighted layer is the one the catalog names as its principal ground — the rest is terrain the form still has to touch, and that spread is how much of the estate employing it implicates.

Campaign Phasing

Dominance is taken from the campaign model; participation is derived from the techniques themselves. A form is usually present in more phases than it leads, and confusing the two is how a scheme ends up with no main effort.

PhaseRolePhase objectiveTechniques employed
Phase 0 — ShapeSet conditionsSupportingContinuous terrain preparation, zero-trust hardening, partnerships, threat intelligence.1 of 17
Phase II — Seize InitiativeContest first contactSupportingDetect early, canalize movement, and buy decision time.4 of 17
Phase III — DominateDefeat the attemptDominant — main effortHunt, contain, evict.15 of 17
Phase IV — StabilizeRestore secure operationsSupportingEradicate, verify, and preserve availability through the recovery.2 of 17
Phase V — Enable / RestoreHand back to garrisonDominant — main effortRecover, harden, and update the doctrine and the intelligence requirements.3 of 17

Phase 0 — Shape

Set conditions

Role
Supporting
Phase objective
Continuous terrain preparation, zero-trust hardening, partnerships, threat intelligence.
Techniques employed
1 of 17

Phase II — Seize Initiative

Contest first contact

Role
Supporting
Phase objective
Detect early, canalize movement, and buy decision time.
Techniques employed
4 of 17

Phase III — Dominate

Defeat the attempt

Role
Dominant — main effort
Phase objective
Hunt, contain, evict.
Techniques employed
15 of 17

Phase IV — Stabilize

Restore secure operations

Role
Supporting
Phase objective
Eradicate, verify, and preserve availability through the recovery.
Techniques employed
2 of 17

Phase V — Enable / Restore

Hand back to garrison

Role
Dominant — main effort
Phase objective
Recover, harden, and update the doctrine and the intelligence requirements.
Techniques employed
3 of 17

Employment

When to Choose It

Choose counterattack when contact is confirmed or strongly hypothesised and you can complete eviction inside the adversary’s dwell budget. The judgment is timing rather than appetite: evicting early on partial understanding tips the adversary, burns the collection, and buys a second intrusion by an adversary who now knows what you can see. Evicting late is worse. The scheme should state, before contact, which of those errors the agency prefers.

Precondition

A hypothesis. Hunting without one is sampling, and sampling an estate of this size returns whatever the analyst already expected to find.

What It Costs

The scarcest currency on the list — people. Hunt capacity is a small number of experienced analysts who cannot be procured at short notice, and every hour of hunting is an hour not spent on detection engineering. Automated containment converts that cost into availability risk instead, which is a real trade rather than a free one.

Rules of Engagement

Hunting is always authorized — it is observation. Containment is where the line sits: host isolation and credential reset on confirmed compromise belong in the pre-authorized set, because their cost is bounded and their value decays in minutes. Anything that degrades a mission service, or that touches a system outside the agency’s boundary, needs the AO.

How It Fails

Not whether it fails — how. Each of these is a state in which the form is still reported as implemented and has stopped producing the advantage it was chosen for.

  1. Eviction is partial. The host is isolated and the token is not; the account is reset and the mailbox rule survives; the pipeline is cleaned and the artifact it published is already deployed.
  2. Eviction is unsequenced, so the first action warns the adversary and the remaining actions land on an estate they have already left for a position you have not found.
  3. Hunting is undirected. Without a fused backlog, the hunt drifts toward the telemetry that is pleasant to query rather than toward the terrain the threat course of action names.
  4. What was hunted is never accounted for, so coverage is anecdotal and the same three data sources are searched every cycle while two others are never searched at all.
  5. Findings never become detections, which means the hunt is re-run manually next quarter for the same adversary behavior.

Techniques (17)

Grouped by the terrain layer each is emplaced on. Techniques are the perishable layer of the framework — they churn, the form does not — so each is stated as what it does and the observable that shows it is working, never as a product.

T1 · Identity1 technique

  • M7.05

    Credential Reset Sweep

    Execute a scoped, ordered reset of credentials and tokens across the compromised blast radius.

    IndicatorThe reset completes without leaving a re-entry credential.

    Phases
    • III
    Assessed by

T2 · Devices2 techniques

  • M7.04

    Host Isolation on Confirmation

    Sever a host from the network on confirmed compromise while preserving it for analysis.

    IndicatorConfirmed hosts are isolated inside the stated interval.

    Phases
    • III
    Assessed by
  • M7.07

    Persistence Sweep

    Sweep systematically for persistence across identity, endpoint, cloud and application layers before declaring eradication.

    IndicatorEradication is declared on evidence across every layer.

    Phases
    • III
    • IV
    Assessed by

T3 · Networks1 technique

  • M7.08

    Lateral Path Audit

    Recompute what the adversary could reach from where they stand, and close the paths ahead of them.

    IndicatorReachability from the foothold is reduced during the engagement.

    Phases
    • II
    • III
    Assessed by

T4 · Applications and Workloads2 techniques

  • M7.06

    Build Pipeline Integrity Hunt

    Hunt the build pipeline specifically, because poisoning it envelops everything downstream.

    IndicatorPipeline integrity is verified rather than assumed after contact.

    Phases
    • III
    Assessed by
  • M7.17

    Malicious Message Eviction

    Remove a delivered malicious message from every mailbox it reached, including forwards and delegated copies, rather than only from the originally reported one.

    IndicatorA reported message is removed estate-wide, not only where it was reported.

    Phases
    • III
    Assessed by

T6 · Operational Technology1 technique

  • M7.14

    Process Anomaly Hunting

    Hunt for deviation in the physical process itself, not only in the network, because a competent adversary will look correct on the wire.

    IndicatorProcess behavior outside its engineering envelope is investigated as a security event.

    Phases
    • II
    • III
    Assessed by

T7 · Workforce1 technique

  • M7.15

    Insider Risk Investigation

    Run a defined, rights-respecting process to resolve an insider indication, rather than improvising one under pressure.

    IndicatorInsider indications reach a documented disposition within a stated period.

    Phases
    • III
    Assessed by

T9 · Supply Chain1 technique

  • M7.16

    Supply Chain Compromise Hunting

    Hunt for the specific behaviors a compromised supplier or component would produce, on the assumption that it is already inside.

    IndicatorSupplier-origin behaviors are hunted on a stated cadence, not only on advisory.

    Phases
    • III
    Assessed by

TX · Cross-Cutting8 techniques

  • M7.01

    Hypothesis-Driven Hunting

    Hunt against stated hypotheses drawn from the intelligence requirements, not against whatever the queue surfaced.

    IndicatorEvery hunt traces to a priority intelligence requirement.

    Phases
    • II
    • III
    Assessed by
  • M7.02

    Fusion-Fed Hunt Backlog

    Convert fused assessments into a ranked, worked hunt backlog with explicit confidence on each entry.

    IndicatorFusion output becomes hunt work rather than a report.

    Phases
    • II
    • III
    Assessed by
  • M7.03

    Automated Containment Playbooks

    Encode containment as tested automation so the decision, not the execution, is the slow step.

    IndicatorContainment executes in seconds once the decision is made.

    Phases
    • III
    Assessed by
  • M7.09

    Detection Engineering from Hunt

    Convert every hunt finding into a durable detection with an owner and a test.

    IndicatorNo hunt finding is left as tribal knowledge.

    Phases
    • III
    • V
    Assessed by
  • M7.10

    Purple-Team Validation

    Test whether each emplaced maneuver actually performs, using the cell success indicator as the pass condition.

    IndicatorEvery claimed maneuver has been demonstrated, not asserted.

    Phases
    • 0
    • V
    Assessed by
  • M7.11

    Eviction Sequencing

    Plan eviction as a single sequenced action, so the adversary cannot re-enter through what is evicted last.

    IndicatorEviction happens once, not in rounds.

    Phases
    • III
    Assessed by
  • M7.12

    Adversary Dwell Reconstruction

    Reconstruct how long the adversary held the ground, so temporal advantage is computed rather than estimated.

    IndicatorDwell is measured from evidence for every engagement.

    Phases
    • III
    • IV
    Assessed by
  • M7.13

    Hunt Coverage Accounting

    Track which terrain has been hunted, how recently, and against which hypotheses.

    IndicatorUnhunted terrain is visible and dispositioned.

    Phases
    • V
    Assessed by

Controls That Assess It

Derived from the controls the form’s own techniques name, so the assessment surface cannot disagree with the catalog. A control reached by many techniques is load-bearing for this form; one reached by a single technique is not, and an assessor sampling it will learn very little.

By Family

By Control

  • SM-6 Maneuver Effectiveness Validation4 techniquesTo replace assumed effectiveness with demonstrated effectiveness, so the coverage figure reflects what controls do rather than what was assumed of them.
  • TA-4 Pre-authorized Response4 techniquesTo remove authority latency from the decision loop, so that the segment most programs cannot shorten with tooling is shortened by governance.
  • CE-2 Priority Intelligence Requirements3 techniquesTo direct analytic effort at named questions, so that collection and hunting answer what the accountable authority needs rather than processing what arrives.
  • EN-5 Eradication and Transition to Recovery3 techniquesTo ensure the adversary is actually gone before the mission is restored, and that the transition is a decision rather than a drift.
  • SM-5 Branches and Sequels3 techniquesTo decide contingency responses before contact, so that the decision loop under pressure is a selection rather than a design exercise.
  • CE-3 Fusion and Confidence2 techniquesTo distinguish assessment from assertion, so that decisions taken on analytic conclusions carry the uncertainty of those conclusions with them.
  • CE-4 Coverage and Residual Risk Computation2 techniquesTo produce a posture figure that can be reproduced and challenged rather than asserted, so that the number carries authority beyond the tool that generated it.
  • CE-5 Remediation Backlog Prioritization2 techniquesTo make the backlog answer where the next hour of work goes, rather than enumerate everything wrong.
  • CE-6 Cycle Record and Trend2 techniquesTo answer whether the program is improving — a question no point-in-time assessment can address.
  • CG-4 Findings Disposition2 techniquesTo ensure every finding reaches a decision, so that the open set reflects work in progress rather than accumulated neglect.
  • DV-3 Endpoint Sensor Coverage and Liveness1 techniqueTo know what the estate can actually see, and to detect the loss of that visibility as an event rather than at the next assessment.
  • EN-1 Event Declaration and Triage1 techniqueTo convert raw events into a decided position quickly, since this is the segment of the decision loop that most often binds.
  • EN-2 Engagement Reconstruction1 techniqueTo establish what actually happened, since every consolidation activity depends on a reconstruction and none of them can be performed without one.
  • EN-4 Escalation and Engagement Authority1 techniqueTo remove the search for a decision-maker from the decision loop, which is where the decide segment is usually spent.
  • FO-4 Operational Technology Terrain1 techniqueTo stop operational technology being scored as though it were a server estate, and to make the connections between the two declarable.
  • KT-1 Decisive Point Identification1 techniqueTo concentrate defensive effort on the small number of elements whose loss is decisive, so that priority is a stated judgment rather than an emergent property of the asset register.
  • KT-4 Adversary Reachability Assessment1 techniqueTo produce a computed, repeatable answer to the question a control catalog cannot ask — can they get there from here — and to record the answer as a trend rather than a one-time finding.
  • KT-5 Barrier Sufficiency1 techniqueTo make the barriers on which negative reachability results depend into named, owned, monitored controls, so that the assurance KT-4 provides cannot be silently withdrawn.
  • LC-2 Component Provenance1 techniqueTo know where deployed components came from and what is inside them, so that a compromise disclosed anywhere can be located here.
  • LC-4 Update Integrity and Staging1 techniqueTo limit the blast radius of a compromised trusted update, so that supply chain compromise reaches a ring rather than the estate.
  • SM-4 Main Effort Designation1 techniqueTo concentrate defensive priority at a declared point, so that subordinate decisions follow from it without referral.
  • TA-1 Decision Loop Measurement1 techniqueTo make the defender's tempo a measured quantity rather than an impression, so that the numerator of temporal advantage exists at all.
  • TA-2 Adversary Dwell Estimation1 techniqueTo establish the denominator of temporal advantage with an explicit, challengeable basis, so the comparison the framework rests on can be argued with.
  • TA-3 Temporal Advantage Threshold1 techniqueTo convert the temporal advantage figure into a governed condition with an escalation consequence, so that being behind is a decision the organization has to make rather than a number it can note.
  • WF-4 Insider Risk Position1 techniqueTo be able to resolve an indication proportionately and lawfully, so that the organization is neither unable to act nor acting without safeguards.

The tempo controls test time-to-evict against dwell; the maneuver-tracking controls test whether hunt findings were converted into detections rather than closed; the cycle-execution controls test hunt coverage accounting and the evidentiary record. Ask for the dwell reconstruction from the last real incident — it is the only number here that cannot be produced from a tool’s dashboard.

Sequencing

A scheme names a sequence, not a set. These are the ordinary neighbors of this form — not a mandatory order, but the order in which each one’s preconditions are usually met.

Typically Preceded By

  • M5 AmbushDecoy interactions and deception telemetry are the cleanest hunt triggers.
  • M6 DelayDelay is what makes eviction inside the dwell budget arithmetically possible.
  • M1 Screen / GuardThe screen and the fused assessment supply the hypotheses worth hunting.

Typically Followed By

Named as a successor by M5 Ambush, M6 Delay. Derived from those forms’ own declarations, so the two directions of the sequence cannot disagree.

Named as a predecessor by M8 Isolation / Retrograde, M10 Exploitation & Pursuit. Derived the same way, from the other direction.