ASOM-Fedv6.1Open the explorer
HUNT · touches 78 of 78 controls

Hunt team

Responsible for five controls and consulted on twelve — the smallest footprint in the framework, and structurally the most adversarial to it.

0AccountableAnswers for the outcome
3ResponsibleDoes the work
18ConsultedAsked before it is settled
57InformedTold after it is settled
The Role

What It Is.

Owns. Counterattack. Works the hypotheses that Fuse raises.
Doctrinal origin. The counterattack force. Committed on a hypothesis, at a time of the defender’s choosing, to seize initiative rather than to restore a service.

Hunt is Responsible for avenue-of-approach analysis (KT-3), adversary reachability (KT-4), maneuver effectiveness validation (SM-6), priority cyber intelligence requirements (CE-2) and fusion (CE-3). Five controls, and three of them exist to disprove something the program has claimed: that the routes are enumerated, that the decisive points are out of reach, and that the maneuvers actually do what the scheme says they do.

That is the role. A hunt team is not a third triage tier with a better name, and it is not an incident-response overflow pool. It is committed against a hypothesis raised in Fuse, and its output is a finding about the defense as often as it is a finding about an adversary.

The independence problem is real and worth stating plainly. SM-6 asks hunt to validate the effectiveness of maneuvers that the SOC operates. Where hunt reports to the same leadership that is measured on those maneuvers, the validation is structurally compromised — not because anyone is dishonest, but because the question stops being asked hard. Small agencies cannot always separate the two; those that cannot should say so in the assessment record rather than let the reader assume an independence that does not exist.

Derived

Every Control It Touches.

Computed from the RACI each control carries, not written down a second time. If an assignment changes in the manual, this list changes with it.

Accountable0 controls

Answers for the outcome. Exactly one role per control, and it is not delegable.

None. This role holds no accountable assignment anywhere in the framework.

Responsible3 controls

Does the work, or shares it. More than one role may be Responsible for the same control.

Consulted18 controls

Asked before the control is settled, because it holds knowledge the accountable role does not.

Derived

What It Puts into the Chain.

The outputs declared by every control this role is Accountable or Responsible for, and where each one goes. 10 products across 3 controls.

SMScheme of Maneuver

ENEngagement and Pursuit

Derived

What It Depends On.

The inputs those same controls declare. Anything sourced from another control is a dependency on another role; anything marked as outside the framework has to be obtained from the wider organization.

SMScheme of Maneuver

ENEngagement and Pursuit

Capability

What the Role Has to Be Good At.

Hypothesis formation

A hunt starts from a stated, falsifiable proposition tied to a priority requirement — not from a technique list and not from a calendar slot.

Telemetry depth

Reachability (KT-4) is answered on permitted paths, but the confirmation that a denied path is actually denied lives in raw data most dashboards summarize away.

Adversary emulation

SM-6 validation means executing the tradecraft the maneuver claims to stop, safely and with a record, and accepting the result when the maneuver does not stop it.

Delivering the unwelcome answer

The most valuable sentence this role produces is “the decisive point is reachable, here is the shortest path.” Everything about the surrounding program will make that sentence expensive to say.

Recording the null result

A hunt that found nothing has to leave behind the hypothesis, the data examined and the coverage achieved — otherwise nobody can tell a clean estate from a shallow hunt.

Failure

How It Goes Wrong.

Each of these is a way the role can appear to be operating — the artifacts arrive, the chart still shows one accountable party — while producing nothing the defense can use.

Absorbed into triage

The most common death of a hunt capability: it becomes the escalation queue, its hypotheses are never worked, and CE-3 loses its only independent input.

Hunting the calendar

Monthly hunts on a rotating technique list, unconnected to any intelligence requirement. Activity is high, CE-2 closes nothing.

Validating its own chain of command

SM-6 findings that are always favorable to the team that owns the maneuvers. Check whether SM-6 has ever produced a finding that cost someone money.

Silence read as success

“No findings this quarter” reported as an outcome rather than as an input requiring the hypothesis record to interpret it.

Tooling as strategy

A hunt program defined by its platform rather than by its questions. The platform changes every three years; the questions do not.

Relationships

Against the Other Five.

The shared count beside each is derived — how many controls the two roles both appear on. The note is authored: what the relationship is actually for, and where it breaks.

Cyber Threat Intelligence cell78 shared controls

The tightest coupling in the framework. Fuse raises the hypothesis, hunt tests it, and the answer returns to the same control (CE-3) with a confidence attached.

SOC / Defensive Operations78 shared controls

Hunt validates what the SOC operates. Keep the reporting lines apart far enough that SM-6 can come back negative.

Authorizing Official / CISO78 shared controls

Hunt is where an Authorizing Official finds out whether the coverage numbers mean anything. Consulted on defensive intent (CG-1) and rules of engagement (CG-3) for exactly that reason.

Platform and product owners78 shared controls

Hunt operates on ground platform owners run, often in production. That relationship is built before it is needed, or it is not available when it is.

Governance / RMF / ISSO78 shared controls

The thinnest relationship of the six — hunt is Consulted on nothing the ISSO is Responsible for except insider risk position (WF-4). Its findings reach governance through CE-3 and CG-4 rather than directly.