Intent, Mechanism and Indicator
Disrupt adversary staging before the attack is launched.
Role. The form that uses someone else’s contact
Act on CISA, JCDC, FBI and ISAC intelligence to pre-block staged infrastructure and pre-patch targeted CVEs.
A named campaign never reaches the avenue of approach.
Terrain It Consumes
Derived from where the form’s techniques are actually emplaced. The highlighted layer is the one the catalog names as its principal ground — the rest is terrain the form still has to touch, and that spread is how much of the estate employing it implicates.
- T1IdentityThe high ground1 technique
- T3NetworksThe corridors1 technique
- T4Applications and WorkloadsThe urban terrain2 techniques
- T7WorkforceTerrain that is also the force1 technique
- T9Supply ChainThe lines of communication1 technique
- TXCross-CuttingThe enablers of movement3 techniques · principal ground
Campaign Phasing
Dominance is taken from the campaign model; participation is derived from the techniques themselves. A form is usually present in more phases than it leads, and confusing the two is how a scheme ends up with no main effort.
| Phase | Role | Phase objective | Techniques employed |
|---|---|---|---|
| Phase 0 — ShapeSet conditions | Dominant — main effort | Continuous terrain preparation, zero-trust hardening, partnerships, threat intelligence. | 9 of 9 |
| Phase I — DeterRaise adversary cost | Supporting | Visible hardening, a deception grid, and a stated attribution posture. | 7 of 9 |
| Phase V — Enable / RestoreHand back to garrison | Supporting | Recover, harden, and update the doctrine and the intelligence requirements. | 1 of 9 |
Phase 0 — Shape
Set conditions
- Role
- Dominant — main effort
- Phase objective
- Continuous terrain preparation, zero-trust hardening, partnerships, threat intelligence.
- Techniques employed
- 9 of 9
Phase I — Deter
Raise adversary cost
- Role
- Supporting
- Phase objective
- Visible hardening, a deception grid, and a stated attribution posture.
- Techniques employed
- 7 of 9
Phase V — Enable / Restore
Hand back to garrison
- Role
- Supporting
- Phase objective
- Recover, harden, and update the doctrine and the intelligence requirements.
- Techniques employed
- 1 of 9
Employment
When to Choose It
Choose the spoiling attack whenever a partner names infrastructure, a campaign or a vulnerability with your terrain on the other end. It is the highest-leverage form available to a federal agency specifically because federal defenders sit inside a reporting community: another agency’s contact becomes your shaping operation at almost no cost. Reach for it especially when the named vulnerability is on a service you cannot patch quickly — pre-blocking the staged infrastructure buys the patch window.
Precondition
An intake path with a clock on it. A spoiling attack is only available during the window between a partner publishing and the adversary arriving, and that window is usually days.
What It Costs
Paid in borrowed confidence. You are acting on someone else’s assessment against your own availability, and a block placed on a shared or misattributed indicator breaks a legitimate service with no incident to justify it. Emergency patching draws down the change budget and the goodwill of delivery teams, both of which are finite.
Rules of Engagement
Blocking infrastructure named in an authoritative advisory should be pre-authorized with a stated review interval — the tempo value is entirely in acting the same day. Emergency patching outside the change window, and pre-emptive invalidation of credentials at scale, need the AO because both have mission impact.
How It Fails
Not whether it fails — how. Each of these is a state in which the form is still reported as implemented and has stopped producing the advantage it was chosen for.
- Advisories reach a mailbox rather than a decision, and the disposition happens after the campaign does.
- Pre-blocks are placed with no expiry and no owner, so the block list grows into an unmaintained liability nobody dares to prune.
- Patching is driven by the catalog rather than by reachability, so effort goes to a critical vulnerability on an unreachable host while a reachable medium stays open.
- The advisory is actioned technically and never fed back into intelligence requirements, so the same adversary returns through an adjacent path and is met as a stranger.
- Nobody checks whether the named infrastructure was already contacted before the block. Pre-emption is assumed where the correct finding was contact.
Techniques (9)
Grouped by the terrain layer each is emplaced on. Techniques are the perishable layer of the framework — they churn, the form does not — so each is stated as what it does and the observable that shows it is working, never as a product.
T1 · Identity — 1 technique
- M9.05
Pre-Emptive Credential Invalidation
Invalidate credentials on exposure intelligence, before misuse, accepting the friction.
IndicatorExposed credentials are dead before they are tried.
Phases- 0
- I
T3 · Networks — 1 technique
- M9.03
Staged Infrastructure Denial
Deny resolution and reachability to infrastructure observed staging against the sector, not only against you.
IndicatorSector-staged infrastructure never reaches an avenue of approach.
Phases- 0
- I
T4 · Applications and Workloads — 2 techniques
- M9.02
Targeted Emergency Patching
Patch out of cycle when intelligence — not the calendar — says a specific weakness is being used now.
IndicatorActively exploited weaknesses are closed ahead of the routine cycle.
Phases- 0
- I
- M9.07
Exploited-Vulnerability Catalog Enforcement
Treat authoritative known-exploited catalogs as a directive with an owner and a due date on the terrain register.
IndicatorCatalog entries are closed on their due dates, with exceptions owned.
Phases- 0
T7 · Workforce — 1 technique
- M9.08
Workforce Threat Briefing
Tell the workforce what is actually being attempted against agencies like yours, so recognition happens before the click.
IndicatorBriefings cite current campaigns and reach the roles those campaigns target.
Phases- 0
- I
T9 · Supply Chain — 1 technique
- M9.09
Supplier Advisory Pre-emption
Act on supplier and component advisories before exploitation reaches you, including by staging the update or constraining the access.
IndicatorAdvisories affecting named suppliers are dispositioned within the stated window.
Phases- 0
- I
TX · Cross-Cutting — 3 techniques
- M9.01
Advisory-Driven Pre-Blocking
Block infrastructure named in partner reporting before it is used against you, on a stated clock.
IndicatorNamed infrastructure is blocked within the intake window.
Phases- 0
- I
- M9.04
Sector Intelligence Exchange
Contribute and consume in the sector and federal exchanges so pre-emption is possible at all.
IndicatorThe agency both receives and contributes actionable reporting.
Phases- 0
- V
- M9.06
Vendor Compromise Response
Hold a rehearsed path to constrain a compromised vendor or integrator connection on disclosure.
IndicatorA vendor disclosure produces a constraint, not a meeting.
Phases- 0
- I
Controls That Assess It
Derived from the controls the form’s own techniques name, so the assessment surface cannot disagree with the catalog. A control reached by many techniques is load-bearing for this form; one reached by a single technique is not, and an assessor sampling it will learn very little.
By Family
- CECycle Execution and Assurance3 controls · reaches 8 of 9 techniques
- CGCommand and Governance2 controls · reaches 4 of 9 techniques
- TATempo and Temporal Advantage1 control · reaches 2 of 9 techniques
- ENEngagement and Pursuit1 control · reaches 1 of 9 techniques
- KTKey Terrain and Decisive Points1 control · reaches 1 of 9 techniques
- LCLines of Communication2 controls · reaches 1 of 9 techniques
- TMTerrain Management1 control · reaches 1 of 9 techniques
- WFWorkforce Terrain1 control · reaches 1 of 9 techniques
By Control
- CE-2 Priority Intelligence Requirements5 techniques — To direct analytic effort at named questions, so that collection and hunting answer what the accountable authority needs rather than processing what arrives.
- CE-5 Remediation Backlog Prioritization2 techniques — To make the backlog answer where the next hour of work goes, rather than enumerate everything wrong.
- CG-4 Findings Disposition2 techniques — To ensure every finding reaches a decision, so that the open set reflects work in progress rather than accumulated neglect.
- CG-5 Control Inheritance Mapping2 techniques — To keep the framework additive, so that adopting it adds assessment effort only where it adds assessable content.
- TA-4 Pre-authorized Response2 techniques — To remove authority latency from the decision loop, so that the segment most programs cannot shorten with tooling is shortened by governance.
- CE-7 Brief Generation and Distribution1 technique — To produce one document per cycle that an Authorizing Official can decide from, rather than a dashboard nobody decides from.
- EN-6 Engagement Communication1 technique — To ensure the people who must know, do — inside the agency, across the federal community, and among those the mission serves.
- KT-3 Avenue of Approach Analysis1 technique — To convert the estate's connectivity into a set of named approach routes, so that defense can be emplaced on the routes that exist rather than distributed evenly across ground.
- LC-1 Supplier Terrain Register1 technique — To make third parties positional, so that supplier risk is assessed against what a supplier can reach rather than against what they were contracted to do.
- LC-4 Update Integrity and Staging1 technique — To limit the blast radius of a compromised trusted update, so that supply chain compromise reaches a ring rather than the estate.
- TM-5 Connection and Denied-Path Register1 technique — To record connectivity as three distinct states — permitted, denied, unknown — so that reachability conclusions rest on tested denials rather than on absence of evidence.
- WF-3 Role-Based Readiness1 technique — To prepare people for the attacks their role attracts, and to know whether the preparation worked.
The cycle-execution controls test intake, disposition and the vulnerability-response path; the command controls test supplier and partner coordination. The honest metric is elapsed time from advisory receipt to disposition, reported as a distribution rather than a mean — the tail is where the misses are.
Sequencing
A scheme names a sequence, not a set. These are the ordinary neighbors of this form — not a mandatory order, but the order in which each one’s preconditions are usually met.
Typically Preceded By
- M1 Screen / GuardThe screen operates the intake path that a spoiling attack acts on.
Typically Followed By
- M2 Defense in DepthWhat was pre-blocked in a hurry is layered properly afterwards.
- M4 Obstacle / CanalizationA campaign that named your ground says which corridors deserve obstacles.
Named as a successor by M1 Screen / Guard. Derived from those forms’ own declarations, so the two directions of the sequence cannot disagree.