Every Technique, Individually.
The forms of maneuver are what a commander directs. Techniques are what gets emplaced, and there are 154 of them. Each one has an entry here: what it does, the observable that shows it working, the ground it sits on, the phases it is live in, and the controls an assessor would use to test it. The counts on this page are measured off the technique table, not restated from anywhere else.
Where the Catalog Is Thick, and Where It Is Thin.
A catalog this size is only useful if its distribution is visible. Weight in the technique table is a statement about where the framework thinks defensive work actually lives — and a thin layer is not automatically a gap, but it is always a question worth asking out loud.
Techniques by Form of Maneuver
Techniques by Terrain Layer
Techniques Employed, by Campaign Phase
| Phase | Techniques employed | Cyber objective |
|---|---|---|
| Phase 0 — ShapeSet conditions | 87 of 154 — 56% of the catalog | Continuous terrain preparation, zero-trust hardening, partnerships, threat intelligence. |
| Phase I — DeterRaise adversary cost | 53 of 154 — 34% of the catalog | Visible hardening, a deception grid, and a stated attribution posture. |
| Phase II — Seize InitiativeContest first contact | 31 of 154 — 20% of the catalog | Detect early, canalize movement, and buy decision time. |
| Phase III — DominateDefeat the attempt | 41 of 154 — 27% of the catalog | Hunt, contain, evict. |
| Phase IV — StabilizeRestore secure operations | 21 of 154 — 14% of the catalog | Eradicate, verify, and preserve availability through the recovery. |
| Phase V — Enable / RestoreHand back to garrison | 17 of 154 — 11% of the catalog | Recover, harden, and update the doctrine and the intelligence requirements. |
Phase 0 — Shape
Set conditions
- Techniques employed
- 87 of 154 — 56% of the catalog
- Cyber objective
- Continuous terrain preparation, zero-trust hardening, partnerships, threat intelligence.
Phase I — Deter
Raise adversary cost
- Techniques employed
- 53 of 154 — 34% of the catalog
- Cyber objective
- Visible hardening, a deception grid, and a stated attribution posture.
Phase II — Seize Initiative
Contest first contact
- Techniques employed
- 31 of 154 — 20% of the catalog
- Cyber objective
- Detect early, canalize movement, and buy decision time.
Phase III — Dominate
Defeat the attempt
- Techniques employed
- 41 of 154 — 27% of the catalog
- Cyber objective
- Hunt, contain, evict.
Phase IV — Stabilize
Restore secure operations
- Techniques employed
- 21 of 154 — 14% of the catalog
- Cyber objective
- Eradicate, verify, and preserve availability through the recovery.
Phase V — Enable / Restore
Hand back to garrison
- Techniques employed
- 17 of 154 — 11% of the catalog
- Cyber objective
- Recover, harden, and update the doctrine and the intelligence requirements.
Six Things, in the Same Order, Every Time.
An entry is written to be looked up rather than read through. Everything on it either comes from the published technique table or is derived from it — the relations, the adjacency and the position within a form are computed, so no two pages can disagree about the same fact.
What it does
One imperative sentence. The technique stated as an action somebody can be tasked with.
The observable
What shows it is working — an indicator, not a control and not a product.
Where it sits
The form it implements and the terrain layer it is emplaced on, both linked.
When it is employed
The campaign phases it is live in, which is usually more than one.
How it is assessed
The controls that test it, each linked to its full reference entry.
What it is next to
Declared relations in both directions, and the techniques its assessment surface overlaps.
Grouped by the Form They Implement.
Techniques are grouped by form because that is how they are chosen: a commander picks the form against a situation, and the engineer picks from inside it. Within a form they are in catalog order, which is also the order the entries page through.
M1 · Screen / Guard
Gain early warning and buy reaction time before the adversary touches key terrain.
M1.01External Attack Surface Enumeration
Continuously enumerate everything the agency exposes to the internet, from the outside in, on the same cadence an adversary would.
M1.02Shadow and Forgotten Asset Discovery
Reconcile discovered internet-facing assets against the authoritative inventory and drive the difference to zero.
M1.03Certificate and Domain Watch
Watch certificate transparency and registration feeds for lookalike domains and unsanctioned certificates issued in the agency name.
Seed uniquely identifying tokens in externally reachable surfaces so that reconnaissance touching them is unambiguous.
M1.05Authentication Geography Baseline
Baseline where, when and from what the population legitimately authenticates, so deviation is measurable rather than anecdotal.
M1.06Credential Exposure Monitoring
Monitor public and criminal sources for agency credentials, session artifacts and tokens offered for sale or dumped.
M1.07Partner and Advisory Intake
Operate a named, timed intake path for CISA, sector and law-enforcement reporting that ends in a decision rather than a mailbox.
M1.08Public Service Abuse Telemetry
Instrument public-facing services for abuse patterns — enumeration, scripted submission, credential stuffing — distinct from application errors.
M1.09Supply Chain and Vendor Watch
Track the security posture and incident disclosures of vendors and integrators whose products sit on key terrain.
M1.10Named-Campaign Indicator Watch
Maintain standing collection against the specific campaigns the intelligence requirements name, not against indicators in general.
M1.11Operational Technology Asset Discovery
Discover control-system assets passively, because active scanning of a safety-instrumented network is itself an availability risk.
M1.12Workforce Credential Exposure Monitoring
Watch the outside world for agency credentials and staff identities appearing where they should not, on the same cadence you watch the network perimeter.
M1.13Physical Access Anomaly Detection
Read badge and access-control telemetry as an intelligence source rather than an audit artifact, and correlate it with logical access.
M1.14Supplier Exposure Monitoring
Monitor the suppliers and components that reach into the estate for breach disclosure, advisory and exposure, because their compromise is your compromise.
Discover devices reaching the estate from the identity plane outward rather than from the management console, because the console can only report what it already manages.
M2 · Defense in Depth
Ensure no single failure is decisive.
Define trust zones that reflect real boundaries and assurance differences, and record which elements sit in which.
M2.02Policy Enforcement Point Placement
Place an enforcement point at every zone boundary so that crossing is a decision, not a route.
M2.03Crown-Jewel Enclave
Isolate the decisive data behind its own enforcement point, with its own authorization policy and its own telemetry.
M2.04Independent Control Redundancy
Ensure the controls guarding key terrain fail independently — no shared agent, identity, console or vendor across a protection floor.
M2.05Endpoint Detection and Response Coverage
Achieve and prove sensor coverage across the managed fleet, with unmanaged devices treated as a measured gap rather than an assumption.
Make device health a precondition of access, so a compromised or non-compliant endpoint cannot spend a valid credential.
M2.07Web Application Protection
Front public applications with request-level inspection tuned to the application, not to a generic ruleset.
M2.08API Authorization Enforcement
Enforce per-call authorization at an API gateway rather than trusting network position or a shared key.
M2.09Data-at-Rest Encryption and Key Separation
Encrypt decisive data with keys held outside the system that reads it, so storage compromise is not data compromise.
M2.10Egress Data Loss Prevention
Inspect and constrain outbound movement of the record types the campaign exists to protect.
M2.11Workload Hardening Baseline
Hold servers, images and containers to a declared baseline, and treat drift from it as a finding.
M2.12Secrets Management
Remove long-lived secrets from code, images and configuration into brokered, rotated, audited storage.
M2.13Backup Isolation and Immutability
Hold recovery data outside the blast radius of the production identity plane and make it immutable for its retention window.
M2.14Control Failure Detection
Detect when a control stops working — sensor silent, policy unapplied, agent removed — as a security event in its own right.
M2.15Safety Instrumented Layer Integrity
Keep the safety layer independent of the control layer, so a compromise of operations cannot defeat the function that prevents harm.
M2.16Role-Based Privilege Minimization
Give each role the least authority its work requires, so a compromised person yields the least ground.
M2.17Facility Defense in Depth
Layer physical controls so that defeating one barrier does not deliver the floor, the rack or the media inside it.
M2.18Component Provenance Verification
Know what is inside what you deploy, and verify it came from who it claims, before it runs on your ground.
M3 · Envelopment
Make identity, not network location, the decisive plane — surround the adversary with policy.
M3.01Phishing-Resistant Authentication
Move the population to authenticators that cannot be relayed or replayed by a proxy.
M3.02Conditional Access Policy Engine
Concentrate access decisions in one policy decision point that sees identity, device, network and behavior together.
Re-evaluate authorization during a session on changed signal, rather than only at sign-in.
Grant privilege for a bounded task and window, with the grant itself recorded as an event.
M3.05Privileged Access Workstations
Require administration of decisive systems from dedicated, hardened, separately governed endpoints.
M3.06Machine and Service Identity Governance
Give non-human identities owners, expiry and scope on the same terms as human ones.
M3.07Standing Privilege Elimination
Systematically remove permanent administrative rights, replacing them with request-and-grant paths.
M3.08Identity Lifecycle Enforcement
Bind joiner, mover and leaver events to authoritative sources so access follows the person, not the ticket.
M3.09External-User Identity Assurance
Apply proportionate identity assurance to public and partner users of mission services without denying access to the public.
Bind credentials cryptographically to hardware so that stolen material cannot be spent elsewhere.
M3.11Session and Token Revocation Path
Maintain a tested path to invalidate sessions and tokens estate-wide within a stated interval.
M3.12Authorization Policy as Code
Express access policy as reviewed, version-controlled, testable code rather than console state.
M3.13Federation Trust Boundary Control
Enumerate every federated trust into the estate, own each one, and constrain what it may assert.
M3.14Entitlement Recertification
Review entitlements on a cadence against actual use, and remove what is not used.
M3.15Break-Glass Account Control
Hold emergency accounts under split control with alerting on any use, so the last resort is not the soft target.
Bind issued tokens to sender and context so a captured token cannot be replayed from elsewhere.
M3.17Authentication Anomaly Scoring
Score authentication against the behavioral baseline and feed the score back into the policy decision point.
M3.18Identity Provider Tamper Detection
Treat the identity provider as decisive terrain: alert on federation, policy, key and admin changes independently of the provider itself.
Bind every privileged account to a named, current, cleared human, so an orphaned credential has nowhere to hide.
M3.20Supplier Identity Federation
Bring supplier access under the agency's own identity plane rather than standing local accounts the agency cannot see or revoke.
M4 · Obstacle / Canalization
Force the adversary onto ground you own and watch.
M4.01Microsegmentation
Reduce reachability between workloads to what is declared, so lateral movement requires defeating policy rather than finding a route.
M4.02East-West Deny by Default
Make the default answer between segments "no", with exceptions declared, owned and expiring.
M4.03Egress Filtering and Allow-Listing
Constrain outbound destinations so command channels must use paths you inspect.
M4.04DNS Control and Sinkholing
Route resolution through controlled resolvers, log it, and sinkhole known-bad and newly registered domains.
M4.05Application Allow-Listing
Constrain what may execute on decisive endpoints to what is approved and signed.
M4.06Administrative Path Restriction
Confine administrative protocols to declared corridors from declared sources.
M4.07Cloud Boundary Enforcement
Enforce account, VPC and role boundaries in the cloud with the same rigor as network segments on the ground.
M4.08Instrumented Corridor Design
Deliberately leave the paths you want an adversary to take, and instrument them heavily.
Constrain and log removable media on endpoints holding or reaching decisive data.
M4.10Bastion and Jump-Host Enforcement
Force privileged access to decisive systems through recorded, brokered hosts.
M4.11Protocol and Port Restriction
Permit only the protocols the design requires, and treat the rest as a canalization opportunity.
M4.12Denied-Path Register Enforcement
Maintain the explicit register of paths that must never exist, and test continuously that they do not.
M4.13Operational Technology Segregation
Separate control-system networks from the enterprise with an enforced, inspectable boundary rather than a documented intention.
M4.14Control Protocol Constraint
Permit only the industrial protocols and function codes the process requires, and deny engineering commands from outside the corridor.
M4.15Physical Zone Segregation
Divide facilities into zones whose boundaries are enforced and logged, so physical movement is as canalised as network movement.
M4.16Maintenance Access Constraint
Force vendor and remote maintenance onto a supervised, time-boxed path instead of standing access into the estate.
M4.17Supplier Access Canalisation
Route every supplier into a defined broker rather than directly onto mission systems, so their traffic crosses ground you instrument.
M5 · Ambush
Trade space for information and time, and impose cost.
M5.01Decoy Records in the Data Layer
Seed the record stores with realistic decoy records whose only purpose is to be accessed by someone who should not.
M5.02Honeytokens in Document Stores
Place tokenized documents in collaboration and file estate where staged collection would find them.
M5.03Decoy Credentials
Seed credential stores, memory and configuration with credentials that are valid-looking and monitored but powerless.
M5.04Honeypot Services in Corridors
Place responsive services in the lateral corridors so that scanning and movement produce contact rather than silence.
M5.05Canary Files on Endpoints
Distribute monitored files across the endpoint fleet to detect mass encryption and mass collection early.
Publish plausible but unused API and administrative endpoints that only enumeration would find.
Plant privileged-looking accounts and group memberships that no legitimate process ever touches.
Stand up monitored buckets, roles and secrets that legitimate workloads never call.
Route deception alerts on a separate, high-trust path that bypasses ordinary triage queues.
M5.10Deception Coverage Measurement
Measure what share of the data layer is actually seeded, and treat the unseeded remainder as a gap.
M5.11Control Network Deception
Place decoy controllers and engineering workstations on the control network, where legitimate traffic is narrow and predictable.
M5.12Phishing Deception and Reporting
Exercise the workforce against realistic lures and treat the reporting rate, not the click rate, as the measure that matters.
M5.13Physical Deception
Seed facilities with tokens whose only plausible use is by someone who should not have them — dropped media, decoy badges, decoy racks.
M6 · Delay
Buy decision time and prevent the adversary culminating on the objective.
Slow request rates as risk rises, so automation loses its advantage while humans keep service.
M6.02Step-Up Authentication on Anomaly
Demand stronger proof at the moment behavior deviates, rather than uniformly at sign-in.
Cap the rate and volume of bulk retrieval so a successful intrusion cannot become a successful exfiltration in one pass.
M6.04Session Duration Reduction Under Alert
Shorten session and token lifetimes automatically while the estate is in contact.
M6.05Approval Gates on High-Impact Actions
Require a second, human authorization for the small set of actions that would be decisive if abused.
M6.06Tarpitting and Response Delay
Introduce deliberate latency on suspicious paths, so an adversary spends time you are spending on decision.
M6.07Progressive Lockout
Escalate friction against an identity under attack without handing an attacker a denial-of-service lever.
M6.08Change and Deploy Freeze Under Contact
Suspend routine change into decisive systems while in contact, so the adversary cannot hide in the noise of normal deployment.
Bound the cost and breadth of a single query against mission data stores.
Hold vendor updates in a staging ring long enough to observe them, trading a little currency for the ability to not deploy a compromised build estate-wide.
M7 · Counterattack
Seize the initiative and evict before the adversary reaches the objective.
M7.01Hypothesis-Driven Hunting
Hunt against stated hypotheses drawn from the intelligence requirements, not against whatever the queue surfaced.
Convert fused assessments into a ranked, worked hunt backlog with explicit confidence on each entry.
M7.03Automated Containment Playbooks
Encode containment as tested automation so the decision, not the execution, is the slow step.
M7.04Host Isolation on Confirmation
Sever a host from the network on confirmed compromise while preserving it for analysis.
Execute a scoped, ordered reset of credentials and tokens across the compromised blast radius.
M7.06Build Pipeline Integrity Hunt
Hunt the build pipeline specifically, because poisoning it envelops everything downstream.
M7.07Persistence Sweep
Sweep systematically for persistence across identity, endpoint, cloud and application layers before declaring eradication.
M7.08Lateral Path Audit
Recompute what the adversary could reach from where they stand, and close the paths ahead of them.
M7.09Detection Engineering from Hunt
Convert every hunt finding into a durable detection with an owner and a test.
Test whether each emplaced maneuver actually performs, using the cell success indicator as the pass condition.
M7.11Eviction Sequencing
Plan eviction as a single sequenced action, so the adversary cannot re-enter through what is evicted last.
M7.12Adversary Dwell Reconstruction
Reconstruct how long the adversary held the ground, so temporal advantage is computed rather than estimated.
Track which terrain has been hunted, how recently, and against which hypotheses.
Hunt for deviation in the physical process itself, not only in the network, because a competent adversary will look correct on the wire.
M7.15Insider Risk Investigation
Run a defined, rights-respecting process to resolve an insider indication, rather than improvising one under pressure.
M7.16Supply Chain Compromise Hunting
Hunt for the specific behaviors a compromised supplier or component would produce, on the assumption that it is already inside.
M7.17Malicious Message Eviction
Remove a delivered malicious message from every mailbox it reached, including forwards and delegated copies, rather than only from the originally reported one.
M8 · Isolation / Retrograde
Give ground deliberately to preserve the force. Degrade gracefully; never fail open.
M8.01Automated Segment Severing
Hold a tested capability to sever a segment or zone on decision, without an unplanned outage of everything else.
M8.02Estate-Wide Session Revocation
Invalidate every session and token across the estate as one action when the identity plane is in doubt.
M8.03Read-Only Service Degradation
Degrade mission services to read-only or queued operation rather than exposing or losing the corpus.
M8.04Fail-Secure Default Posture
Ensure that when a control fails, the estate denies rather than permits — including under load and during recovery.
M8.05Federation Trust Suspension
Suspend an inbound federated trust independently, without dismantling the identity plane around it.
Quarantine a cloud account or subscription — revoking roles and cutting peering — as one rehearsed action.
M8.07Egress Blackhole
Cut outbound reachability for a defined scope to stop exfiltration and command channels while analysis continues.
M8.08Statutory Availability Floor
Declare in advance which mission functions may never be taken offline, and design containment around them.
M8.09Contained Forensic Preservation
Preserve evidence in a way that survives containment and recovery, on storage the adversary could not reach.
M8.10Third-Party Connection Cutout
Cut a specific partner or vendor connection on decision without taking down the shared boundary.
M8.11Restoration Preconditions
Define what must be true before anything comes back — no restoration on hope.
Rehearse degradation and severing on the real estate, because an untested retrograde is a plan, not a capability.
M8.13Safe-State Isolation
Sever the control network to a defined safe state that preserves the physical process, rather than a network state that abandons it.
M8.14Rapid Offboarding and Revocation
Remove all access from a departing or suspended person in one action, in a time measured against the tempo an insider needs.
M8.15Facility Isolation
Be able to sever a building or floor from the estate without severing the mission, and know in advance what that costs.
M8.16Supplier Severance
Be able to cut a supplier's access immediately and continue the mission, because the alternative is negotiating with an intrusion.
M8.17Device Decommissioning and Sanitization
Remove a retired, lost or reassigned device from the estate's trust and sanitize its media within a period derived from what its retained trust could do.
M9 · Spoiling Attack
Disrupt adversary staging before the attack is launched.
M9.01Advisory-Driven Pre-Blocking
Block infrastructure named in partner reporting before it is used against you, on a stated clock.
M9.02Targeted Emergency Patching
Patch out of cycle when intelligence — not the calendar — says a specific weakness is being used now.
M9.03Staged Infrastructure Denial
Deny resolution and reachability to infrastructure observed staging against the sector, not only against you.
M9.04Sector Intelligence Exchange
Contribute and consume in the sector and federal exchanges so pre-emption is possible at all.
M9.05Pre-Emptive Credential Invalidation
Invalidate credentials on exposure intelligence, before misuse, accepting the friction.
M9.06Vendor Compromise Response
Hold a rehearsed path to constrain a compromised vendor or integrator connection on disclosure.
M9.07Exploited-Vulnerability Catalog Enforcement
Treat authoritative known-exploited catalogs as a directive with an owner and a due date on the terrain register.
M9.08Workforce Threat Briefing
Tell the workforce what is actually being attempted against agencies like yours, so recognition happens before the click.
M9.09Supplier Advisory Pre-emption
Act on supplier and component advisories before exploitation reaches you, including by staging the update or constraining the access.
M10 · Exploitation & Pursuit
Convert contact into durable advantage rather than closing the ticket.
M10.01Indicator-to-Detection Conversion
Convert every indicator observed in contact into a durable, tested detection rather than a one-time block.
M10.02Avenue Closure Verification
Verify by test that the avenue actually used is closed — not that a change was made.
M10.03Terrain Overlay Update
Update the terrain overlay with what contact revealed, including everything the map got wrong.
M10.04Intelligence Requirement Revision
Revise the priority intelligence requirements from what the engagement showed you could not see.
M10.05Community Reporting
Report to CISA and sector partners so the next agency starts from your contact.
M10.06Doctrine and Catalog Update
Fold what was learned back into the maneuver catalog, the control set and the rules of engagement.
M10.07Supply Chain Lesson Propagation
Feed what a supplier incident taught you back into acquisition and into the terrain register, so the next contract starts from it.
M11 · Reconstitution
Restore the mission on evidence, not on hope — and prove it before you need it.
M11.01Recovery Objective Declaration
Declare, per mission service, how quickly it must return and how much data loss is survivable — before an incident forces the answer.
M11.02Isolated Recovery Environment
Hold the means of recovery outside the blast radius of the production identity plane, so compromise cannot reach what rebuilds you.
M11.03Golden Image and Rebuild Path
Maintain a trusted, tested build path so rebuilding is a procedure rather than an improvisation under pressure.
M11.04Identity Plane Reconstitution
Rehearse rebuilding the identity plane itself, the one system every other recovery depends on.
M11.05Recovery Data Integrity Verification
Prove restored data is what it was before contact, rather than restoring the adversary's edits along with it.
M11.06Service Restoration Sequencing
Restore in a declared order that respects dependency and statutory priority, so the first service back is the one that must be.
M11.07Reconstitution Exercise
Exercise recovery against a real failure scenario on a stated cadence, because an untested recovery plan is a document.
M11.08Key Personnel Continuity
Name the roles without which recovery cannot proceed, and make sure none of them is one person deep.
M11.09Alternate Facility Activation
Be able to run the mission from somewhere else, and prove it by doing so rather than by documenting it.
M11.10Supplier-Independent Rebuild
Ensure recovery does not depend on the availability or the integrity of the supplier who may be the reason you are recovering.
M11.11Mailbox and Message Restoration
Restore mailboxes and messages removed during eviction or lost in the incident, verified against an integrity record, before returning the service to use.