ASOM-Fedv6.1Open the explorer
Reference manual · techniques

Every Technique, Individually.

The forms of maneuver are what a commander directs. Techniques are what gets emplaced, and there are 154 of them. Each one has an entry here: what it does, the observable that shows it working, the ground it sits on, the phases it is live in, and the controls an assessor would use to test it. The counts on this page are measured off the technique table, not restated from anywhere else.

154Cataloged techniquesEach with a reference entry of its own
11Forms they implementEvery form carries at least one technique
10Terrain layers drawn onThinnest is T6 and T8 at 7
78Controls that assess themEvery control in the catalog is named by at least one
Shape

Where the Catalog Is Thick, and Where It Is Thin.

A catalog this size is only useful if its distribution is visible. Weight in the technique table is a statement about where the framework thinks defensive work actually lives — and a thin layer is not automatically a gap, but it is always a question worth asking out loud.

Exhibit 1

Techniques by Form of Maneuver

Counted from the technique table. The heaviest form is M3 Envelopment with 20; the lightest is M10 Exploitation & Pursuit with 7. Weight here is a count of cataloged entries, not the risk-reduction weighting the framework contract assigns a form — those are different numbers and the site has confused them before.
Exhibit 2

Techniques by Terrain Layer

Where each technique is emplaced, counted off the same table. 10 of 10 layers carry at least one. The thinnest is T6 Operational Technology and T8 Facilities at 7 — which is worth reading as an open question about the layer rather than as a claim that it needs less defending.
Exhibit 3

Techniques Employed, by Campaign Phase

PhaseTechniques employedCyber objective
Phase 0 — ShapeSet conditions87 of 154 — 56% of the catalogContinuous terrain preparation, zero-trust hardening, partnerships, threat intelligence.
Phase I — DeterRaise adversary cost53 of 154 — 34% of the catalogVisible hardening, a deception grid, and a stated attribution posture.
Phase II — Seize InitiativeContest first contact31 of 154 — 20% of the catalogDetect early, canalize movement, and buy decision time.
Phase III — DominateDefeat the attempt41 of 154 — 27% of the catalogHunt, contain, evict.
Phase IV — StabilizeRestore secure operations21 of 154 — 14% of the catalogEradicate, verify, and preserve availability through the recovery.
Phase V — Enable / RestoreHand back to garrison17 of 154 — 11% of the catalogRecover, harden, and update the doctrine and the intelligence requirements.

Phase 0 — Shape

Set conditions

Techniques employed
87 of 154 — 56% of the catalog
Cyber objective
Continuous terrain preparation, zero-trust hardening, partnerships, threat intelligence.

Phase I — Deter

Raise adversary cost

Techniques employed
53 of 154 — 34% of the catalog
Cyber objective
Visible hardening, a deception grid, and a stated attribution posture.

Phase II — Seize Initiative

Contest first contact

Techniques employed
31 of 154 — 20% of the catalog
Cyber objective
Detect early, canalize movement, and buy decision time.

Phase III — Dominate

Defeat the attempt

Techniques employed
41 of 154 — 27% of the catalog
Cyber objective
Hunt, contain, evict.

Phase IV — Stabilize

Restore secure operations

Techniques employed
21 of 154 — 14% of the catalog
Cyber objective
Eradicate, verify, and preserve availability through the recovery.

Phase V — Enable / Restore

Hand back to garrison

Techniques employed
17 of 154 — 11% of the catalog
Cyber objective
Recover, harden, and update the doctrine and the intelligence requirements.
A technique is counted in every phase it is employed in, so these 250 employments spread across 154 techniques rather than partitioning them. The shape is the point: the campaign is heaviest before contact, which is what a framework built on shaping and deterrence should look like.
How to Read an Entry

Six Things, in the Same Order, Every Time.

An entry is written to be looked up rather than read through. Everything on it either comes from the published technique table or is derived from it — the relations, the adjacency and the position within a form are computed, so no two pages can disagree about the same fact.

What it does

One imperative sentence. The technique stated as an action somebody can be tasked with.

The observable

What shows it is working — an indicator, not a control and not a product.

Where it sits

The form it implements and the terrain layer it is emplaced on, both linked.

When it is employed

The campaign phases it is live in, which is usually more than one.

How it is assessed

The controls that test it, each linked to its full reference entry.

What it is next to

Declared relations in both directions, and the techniques its assessment surface overlaps.

The Catalog

Grouped by the Form They Implement.

Techniques are grouped by form because that is how they are chosen: a commander picks the form against a situation, and the engineer picks from inside it. Within a form they are in catalog order, which is also the order the entries page through.

M1 · Screen / Guard

15 techniquesThe form that opens the campaign

Gain early warning and buy reaction time before the adversary touches key terrain.

  • M1.01External Attack Surface Enumeration

    Continuously enumerate everything the agency exposes to the internet, from the outside in, on the same cadence an adversary would.

    T3 NetworksPhases 0, I3 assessing controls

  • M1.02Shadow and Forgotten Asset Discovery

    Reconcile discovered internet-facing assets against the authoritative inventory and drive the difference to zero.

    T3 NetworksPhase 05 assessing controls

  • M1.03Certificate and Domain Watch

    Watch certificate transparency and registration feeds for lookalike domains and unsanctioned certificates issued in the agency name.

    T3 NetworksPhases 0, I2 assessing controls

  • M1.04Perimeter Canary Tokens

    Seed uniquely identifying tokens in externally reachable surfaces so that reconnaissance touching them is unambiguous.

    T5 DataPhases 0, I2 assessing controls

  • M1.05Authentication Geography Baseline

    Baseline where, when and from what the population legitimately authenticates, so deviation is measurable rather than anecdotal.

    T1 IdentityPhases 0, II2 assessing controls

  • M1.06Credential Exposure Monitoring

    Monitor public and criminal sources for agency credentials, session artifacts and tokens offered for sale or dumped.

    T1 IdentityPhases 0, I2 assessing controls

  • M1.07Partner and Advisory Intake

    Operate a named, timed intake path for CISA, sector and law-enforcement reporting that ends in a decision rather than a mailbox.

    TX Cross-CuttingPhases 0, I2 assessing controls

  • M1.08Public Service Abuse Telemetry

    Instrument public-facing services for abuse patterns — enumeration, scripted submission, credential stuffing — distinct from application errors.

    T4 Applications and WorkloadsPhases 0, II3 assessing controls

  • M1.09Supply Chain and Vendor Watch

    Track the security posture and incident disclosures of vendors and integrators whose products sit on key terrain.

    TX Cross-CuttingPhase 02 assessing controls

  • M1.10Named-Campaign Indicator Watch

    Maintain standing collection against the specific campaigns the intelligence requirements name, not against indicators in general.

    TX Cross-CuttingPhases 0, I2 assessing controls

  • M1.11Operational Technology Asset Discovery

    Discover control-system assets passively, because active scanning of a safety-instrumented network is itself an availability risk.

    T6 Operational TechnologyPhase 03 assessing controls

  • M1.12Workforce Credential Exposure Monitoring

    Watch the outside world for agency credentials and staff identities appearing where they should not, on the same cadence you watch the network perimeter.

    T7 WorkforcePhases 0, I3 assessing controls

  • M1.13Physical Access Anomaly Detection

    Read badge and access-control telemetry as an intelligence source rather than an audit artifact, and correlate it with logical access.

    T8 FacilitiesPhases 0, II3 assessing controls

  • M1.14Supplier Exposure Monitoring

    Monitor the suppliers and components that reach into the estate for breach disclosure, advisory and exposure, because their compromise is your compromise.

    T9 Supply ChainPhases 0, I4 assessing controls

  • M1.15Device Estate Discovery

    Discover devices reaching the estate from the identity plane outward rather than from the management console, because the console can only report what it already manages.

    T2 DevicesPhase 03 assessing controls

M2 · Defense in Depth

18 techniquesThe form that makes no single failure decisive

Ensure no single failure is decisive.

  • M2.01Trust Zone Architecture

    Define trust zones that reflect real boundaries and assurance differences, and record which elements sit in which.

    T3 NetworksPhase 02 assessing controls

  • M2.02Policy Enforcement Point Placement

    Place an enforcement point at every zone boundary so that crossing is a decision, not a route.

    T3 NetworksPhase 03 assessing controls

  • M2.03Crown-Jewel Enclave

    Isolate the decisive data behind its own enforcement point, with its own authorization policy and its own telemetry.

    T5 DataPhases 0, I2 assessing controls

  • M2.04Independent Control Redundancy

    Ensure the controls guarding key terrain fail independently — no shared agent, identity, console or vendor across a protection floor.

    TX Cross-CuttingPhase 02 assessing controls

  • M2.05Endpoint Detection and Response Coverage

    Achieve and prove sensor coverage across the managed fleet, with unmanaged devices treated as a measured gap rather than an assumption.

    T2 DevicesPhase 04 assessing controls

  • M2.06Device Posture Gating

    Make device health a precondition of access, so a compromised or non-compliant endpoint cannot spend a valid credential.

    T2 DevicesPhases 0, I3 assessing controls

  • M2.07Web Application Protection

    Front public applications with request-level inspection tuned to the application, not to a generic ruleset.

    T4 Applications and WorkloadsPhase 02 assessing controls

  • M2.08API Authorization Enforcement

    Enforce per-call authorization at an API gateway rather than trusting network position or a shared key.

    T4 Applications and WorkloadsPhase 02 assessing controls

  • M2.09Data-at-Rest Encryption and Key Separation

    Encrypt decisive data with keys held outside the system that reads it, so storage compromise is not data compromise.

    T5 DataPhase 03 assessing controls

  • M2.10Egress Data Loss Prevention

    Inspect and constrain outbound movement of the record types the campaign exists to protect.

    T5 DataPhases 0, III2 assessing controls

  • M2.11Workload Hardening Baseline

    Hold servers, images and containers to a declared baseline, and treat drift from it as a finding.

    T2 DevicesPhase 03 assessing controls

  • M2.12Secrets Management

    Remove long-lived secrets from code, images and configuration into brokered, rotated, audited storage.

    T4 Applications and WorkloadsPhase 03 assessing controls

  • M2.13Backup Isolation and Immutability

    Hold recovery data outside the blast radius of the production identity plane and make it immutable for its retention window.

    T5 DataPhases 0, IV2 assessing controls

  • M2.14Control Failure Detection

    Detect when a control stops working — sensor silent, policy unapplied, agent removed — as a security event in its own right.

    TX Cross-CuttingPhase 04 assessing controls

  • M2.15Safety Instrumented Layer Integrity

    Keep the safety layer independent of the control layer, so a compromise of operations cannot defeat the function that prevents harm.

    T6 Operational TechnologyPhase 02 assessing controls

  • M2.16Role-Based Privilege Minimization

    Give each role the least authority its work requires, so a compromised person yields the least ground.

    T7 WorkforcePhase 02 assessing controls

  • M2.17Facility Defense in Depth

    Layer physical controls so that defeating one barrier does not deliver the floor, the rack or the media inside it.

    T8 FacilitiesPhase 02 assessing controls

  • M2.18Component Provenance Verification

    Know what is inside what you deploy, and verify it came from who it claims, before it runs on your ground.

    T9 Supply ChainPhase 02 assessing controls

M3 · Envelopment

20 techniquesThe usual main effort

Make identity, not network location, the decisive plane — surround the adversary with policy.

  • M3.01Phishing-Resistant Authentication

    Move the population to authenticators that cannot be relayed or replayed by a proxy.

    T1 IdentityPhases 0, I4 assessing controls

  • M3.02Conditional Access Policy Engine

    Concentrate access decisions in one policy decision point that sees identity, device, network and behavior together.

    T1 IdentityPhases 0, I3 assessing controls

  • M3.03Continuous Authorization

    Re-evaluate authorization during a session on changed signal, rather than only at sign-in.

    T1 IdentityPhases 0, II3 assessing controls

  • M3.04Just-in-Time Privilege

    Grant privilege for a bounded task and window, with the grant itself recorded as an event.

    T1 IdentityPhases 0, I2 assessing controls

  • M3.05Privileged Access Workstations

    Require administration of decisive systems from dedicated, hardened, separately governed endpoints.

    T2 DevicesPhases 0, I3 assessing controls

  • M3.06Machine and Service Identity Governance

    Give non-human identities owners, expiry and scope on the same terms as human ones.

    T1 IdentityPhase 03 assessing controls

  • M3.07Standing Privilege Elimination

    Systematically remove permanent administrative rights, replacing them with request-and-grant paths.

    T1 IdentityPhases 0, I2 assessing controls

  • M3.08Identity Lifecycle Enforcement

    Bind joiner, mover and leaver events to authoritative sources so access follows the person, not the ticket.

    T1 IdentityPhase 02 assessing controls

  • M3.09External-User Identity Assurance

    Apply proportionate identity assurance to public and partner users of mission services without denying access to the public.

    T1 IdentityPhases 0, I3 assessing controls

  • M3.10Device-Bound Credentials

    Bind credentials cryptographically to hardware so that stolen material cannot be spent elsewhere.

    T2 DevicesPhases 0, I4 assessing controls

  • M3.11Session and Token Revocation Path

    Maintain a tested path to invalidate sessions and tokens estate-wide within a stated interval.

    T1 IdentityPhases 0, III3 assessing controls

  • M3.12Authorization Policy as Code

    Express access policy as reviewed, version-controlled, testable code rather than console state.

    T1 IdentityPhase 03 assessing controls

  • M3.13Federation Trust Boundary Control

    Enumerate every federated trust into the estate, own each one, and constrain what it may assert.

    T1 IdentityPhases 0, I3 assessing controls

  • M3.14Entitlement Recertification

    Review entitlements on a cadence against actual use, and remove what is not used.

    T1 IdentityPhase 02 assessing controls

  • M3.15Break-Glass Account Control

    Hold emergency accounts under split control with alerting on any use, so the last resort is not the soft target.

    T1 IdentityPhases 0, IV2 assessing controls

  • M3.16Token Replay Protection

    Bind issued tokens to sender and context so a captured token cannot be replayed from elsewhere.

    T1 IdentityPhases 0, II3 assessing controls

  • M3.17Authentication Anomaly Scoring

    Score authentication against the behavioral baseline and feed the score back into the policy decision point.

    T1 IdentityPhases 0, II3 assessing controls

  • M3.18Identity Provider Tamper Detection

    Treat the identity provider as decisive terrain: alert on federation, policy, key and admin changes independently of the provider itself.

    T1 IdentityPhases 0, III4 assessing controls

  • M3.19Human-to-Account Binding

    Bind every privileged account to a named, current, cleared human, so an orphaned credential has nowhere to hide.

    T7 WorkforcePhases 0, I2 assessing controls

  • M3.20Supplier Identity Federation

    Bring supplier access under the agency's own identity plane rather than standing local accounts the agency cannot see or revoke.

    T9 Supply ChainPhases 0, I2 assessing controls

M4 · Obstacle / Canalization

17 techniquesThe form that chooses the ground

Force the adversary onto ground you own and watch.

  • M4.01Microsegmentation

    Reduce reachability between workloads to what is declared, so lateral movement requires defeating policy rather than finding a route.

    T3 NetworksPhases 0, I2 assessing controls

  • M4.02East-West Deny by Default

    Make the default answer between segments "no", with exceptions declared, owned and expiring.

    T3 NetworksPhases 0, I2 assessing controls

  • M4.03Egress Filtering and Allow-Listing

    Constrain outbound destinations so command channels must use paths you inspect.

    T3 NetworksPhases 0, I2 assessing controls

  • M4.04DNS Control and Sinkholing

    Route resolution through controlled resolvers, log it, and sinkhole known-bad and newly registered domains.

    T3 NetworksPhases 0, I2 assessing controls

  • M4.05Application Allow-Listing

    Constrain what may execute on decisive endpoints to what is approved and signed.

    T2 DevicesPhases 0, I3 assessing controls

  • M4.06Administrative Path Restriction

    Confine administrative protocols to declared corridors from declared sources.

    T3 NetworksPhases 0, I2 assessing controls

  • M4.07Cloud Boundary Enforcement

    Enforce account, VPC and role boundaries in the cloud with the same rigor as network segments on the ground.

    T3 NetworksPhase 02 assessing controls

  • M4.08Instrumented Corridor Design

    Deliberately leave the paths you want an adversary to take, and instrument them heavily.

    T3 NetworksPhases I, II2 assessing controls

  • M4.09Removable Media Control

    Constrain and log removable media on endpoints holding or reaching decisive data.

    T2 DevicesPhase 03 assessing controls

  • M4.10Bastion and Jump-Host Enforcement

    Force privileged access to decisive systems through recorded, brokered hosts.

    T3 NetworksPhases 0, I2 assessing controls

  • M4.11Protocol and Port Restriction

    Permit only the protocols the design requires, and treat the rest as a canalization opportunity.

    T3 NetworksPhase 02 assessing controls

  • M4.12Denied-Path Register Enforcement

    Maintain the explicit register of paths that must never exist, and test continuously that they do not.

    T3 NetworksPhase 02 assessing controls

  • M4.13Operational Technology Segregation

    Separate control-system networks from the enterprise with an enforced, inspectable boundary rather than a documented intention.

    T6 Operational TechnologyPhases 0, I3 assessing controls

  • M4.14Control Protocol Constraint

    Permit only the industrial protocols and function codes the process requires, and deny engineering commands from outside the corridor.

    T6 Operational TechnologyPhases 0, I2 assessing controls

  • M4.15Physical Zone Segregation

    Divide facilities into zones whose boundaries are enforced and logged, so physical movement is as canalised as network movement.

    T8 FacilitiesPhases 0, I2 assessing controls

  • M4.16Maintenance Access Constraint

    Force vendor and remote maintenance onto a supervised, time-boxed path instead of standing access into the estate.

    T8 FacilitiesPhases I, II2 assessing controls

  • M4.17Supplier Access Canalisation

    Route every supplier into a defined broker rather than directly onto mission systems, so their traffic crosses ground you instrument.

    T9 Supply ChainPhases I, II2 assessing controls

M5 · Ambush

13 techniquesThe cheapest high-confidence detection available

Trade space for information and time, and impose cost.

  • M5.01Decoy Records in the Data Layer

    Seed the record stores with realistic decoy records whose only purpose is to be accessed by someone who should not.

    T5 DataPhases I, II3 assessing controls

  • M5.02Honeytokens in Document Stores

    Place tokenized documents in collaboration and file estate where staged collection would find them.

    T5 DataPhases I, II3 assessing controls

  • M5.03Decoy Credentials

    Seed credential stores, memory and configuration with credentials that are valid-looking and monitored but powerless.

    T1 IdentityPhases I, II5 assessing controls

  • M5.04Honeypot Services in Corridors

    Place responsive services in the lateral corridors so that scanning and movement produce contact rather than silence.

    T3 NetworksPhases I, II3 assessing controls

  • M5.05Canary Files on Endpoints

    Distribute monitored files across the endpoint fleet to detect mass encryption and mass collection early.

    T2 DevicesPhases I, II3 assessing controls

  • M5.06Decoy Service Endpoints

    Publish plausible but unused API and administrative endpoints that only enumeration would find.

    T4 Applications and WorkloadsPhases I, II3 assessing controls

  • M5.07Identity-Plane Deception

    Plant privileged-looking accounts and group memberships that no legitimate process ever touches.

    T1 IdentityPhases I, II3 assessing controls

  • M5.08Decoy Cloud Resources

    Stand up monitored buckets, roles and secrets that legitimate workloads never call.

    T4 Applications and WorkloadsPhases I, II3 assessing controls

  • M5.09Deception Alert Routing

    Route deception alerts on a separate, high-trust path that bypasses ordinary triage queues.

    TX Cross-CuttingPhases I, III4 assessing controls

  • M5.10Deception Coverage Measurement

    Measure what share of the data layer is actually seeded, and treat the unseeded remainder as a gap.

    T5 DataPhases 0, I3 assessing controls

  • M5.11Control Network Deception

    Place decoy controllers and engineering workstations on the control network, where legitimate traffic is narrow and predictable.

    T6 Operational TechnologyPhases I, II3 assessing controls

  • M5.12Phishing Deception and Reporting

    Exercise the workforce against realistic lures and treat the reporting rate, not the click rate, as the measure that matters.

    T7 WorkforcePhases 0, I3 assessing controls

  • M5.13Physical Deception

    Seed facilities with tokens whose only plausible use is by someone who should not have them — dropped media, decoy badges, decoy racks.

    T8 FacilitiesPhase I3 assessing controls

M6 · Delay

10 techniquesThe form that buys decision time

Buy decision time and prevent the adversary culminating on the objective.

  • M6.01Adaptive Rate Limiting

    Slow request rates as risk rises, so automation loses its advantage while humans keep service.

    T4 Applications and WorkloadsPhases II, III2 assessing controls

  • M6.02Step-Up Authentication on Anomaly

    Demand stronger proof at the moment behavior deviates, rather than uniformly at sign-in.

    T1 IdentityPhases II, III3 assessing controls

  • M6.03Bulk Export Throttling

    Cap the rate and volume of bulk retrieval so a successful intrusion cannot become a successful exfiltration in one pass.

    T5 DataPhases II, III2 assessing controls

  • M6.04Session Duration Reduction Under Alert

    Shorten session and token lifetimes automatically while the estate is in contact.

    T1 IdentityPhases II, III3 assessing controls

  • M6.05Approval Gates on High-Impact Actions

    Require a second, human authorization for the small set of actions that would be decisive if abused.

    TX Cross-CuttingPhases II, III3 assessing controls

  • M6.06Tarpitting and Response Delay

    Introduce deliberate latency on suspicious paths, so an adversary spends time you are spending on decision.

    T3 NetworksPhase II2 assessing controls

  • M6.07Progressive Lockout

    Escalate friction against an identity under attack without handing an attacker a denial-of-service lever.

    T1 IdentityPhase II2 assessing controls

  • M6.08Change and Deploy Freeze Under Contact

    Suspend routine change into decisive systems while in contact, so the adversary cannot hide in the noise of normal deployment.

    T4 Applications and WorkloadsPhase III2 assessing controls

  • M6.09Query Complexity Limits

    Bound the cost and breadth of a single query against mission data stores.

    T4 Applications and WorkloadsPhases II, III2 assessing controls

  • M6.10Update Staging and Soak

    Hold vendor updates in a staging ring long enough to observe them, trading a little currency for the ability to not deploy a compromised build estate-wide.

    T9 Supply ChainPhases II, III2 assessing controls

M7 · Counterattack

17 techniquesThe form that seizes the initiative

Seize the initiative and evict before the adversary reaches the objective.

  • M7.01Hypothesis-Driven Hunting

    Hunt against stated hypotheses drawn from the intelligence requirements, not against whatever the queue surfaced.

    TX Cross-CuttingPhases II, III2 assessing controls

  • M7.02Fusion-Fed Hunt Backlog

    Convert fused assessments into a ranked, worked hunt backlog with explicit confidence on each entry.

    TX Cross-CuttingPhases II, III3 assessing controls

  • M7.03Automated Containment Playbooks

    Encode containment as tested automation so the decision, not the execution, is the slow step.

    TX Cross-CuttingPhase III3 assessing controls

  • M7.04Host Isolation on Confirmation

    Sever a host from the network on confirmed compromise while preserving it for analysis.

    T2 DevicesPhase III3 assessing controls

  • M7.05Credential Reset Sweep

    Execute a scoped, ordered reset of credentials and tokens across the compromised blast radius.

    T1 IdentityPhase III2 assessing controls

  • M7.06Build Pipeline Integrity Hunt

    Hunt the build pipeline specifically, because poisoning it envelops everything downstream.

    T4 Applications and WorkloadsPhase III2 assessing controls

  • M7.07Persistence Sweep

    Sweep systematically for persistence across identity, endpoint, cloud and application layers before declaring eradication.

    T2 DevicesPhases III, IV3 assessing controls

  • M7.08Lateral Path Audit

    Recompute what the adversary could reach from where they stand, and close the paths ahead of them.

    T3 NetworksPhases II, III2 assessing controls

  • M7.09Detection Engineering from Hunt

    Convert every hunt finding into a durable detection with an owner and a test.

    TX Cross-CuttingPhases III, V2 assessing controls

  • M7.10Purple-Team Validation

    Test whether each emplaced maneuver actually performs, using the cell success indicator as the pass condition.

    TX Cross-CuttingPhases 0, V2 assessing controls

  • M7.11Eviction Sequencing

    Plan eviction as a single sequenced action, so the adversary cannot re-enter through what is evicted last.

    TX Cross-CuttingPhase III3 assessing controls

  • M7.12Adversary Dwell Reconstruction

    Reconstruct how long the adversary held the ground, so temporal advantage is computed rather than estimated.

    TX Cross-CuttingPhases III, IV3 assessing controls

  • M7.13Hunt Coverage Accounting

    Track which terrain has been hunted, how recently, and against which hypotheses.

    TX Cross-CuttingPhase V2 assessing controls

  • M7.14Process Anomaly Hunting

    Hunt for deviation in the physical process itself, not only in the network, because a competent adversary will look correct on the wire.

    T6 Operational TechnologyPhases II, III2 assessing controls

  • M7.15Insider Risk Investigation

    Run a defined, rights-respecting process to resolve an insider indication, rather than improvising one under pressure.

    T7 WorkforcePhase III2 assessing controls

  • M7.16Supply Chain Compromise Hunting

    Hunt for the specific behaviors a compromised supplier or component would produce, on the assumption that it is already inside.

    T9 Supply ChainPhase III3 assessing controls

  • M7.17Malicious Message Eviction

    Remove a delivered malicious message from every mailbox it reached, including forwards and delegated copies, rather than only from the originally reported one.

    T4 Applications and WorkloadsPhase III3 assessing controls

M8 · Isolation / Retrograde

17 techniquesThe form that is hardest to authorize

Give ground deliberately to preserve the force. Degrade gracefully; never fail open.

  • M8.01Automated Segment Severing

    Hold a tested capability to sever a segment or zone on decision, without an unplanned outage of everything else.

    T3 NetworksPhase III3 assessing controls

  • M8.02Estate-Wide Session Revocation

    Invalidate every session and token across the estate as one action when the identity plane is in doubt.

    T1 IdentityPhase III3 assessing controls

  • M8.03Read-Only Service Degradation

    Degrade mission services to read-only or queued operation rather than exposing or losing the corpus.

    T4 Applications and WorkloadsPhases III, IV2 assessing controls

  • M8.04Fail-Secure Default Posture

    Ensure that when a control fails, the estate denies rather than permits — including under load and during recovery.

    TX Cross-CuttingPhases 0, III2 assessing controls

  • M8.05Federation Trust Suspension

    Suspend an inbound federated trust independently, without dismantling the identity plane around it.

    T1 IdentityPhase III2 assessing controls

  • M8.06Cloud Account Quarantine

    Quarantine a cloud account or subscription — revoking roles and cutting peering — as one rehearsed action.

    T4 Applications and WorkloadsPhase III2 assessing controls

  • M8.07Egress Blackhole

    Cut outbound reachability for a defined scope to stop exfiltration and command channels while analysis continues.

    T3 NetworksPhase III2 assessing controls

  • M8.08Statutory Availability Floor

    Declare in advance which mission functions may never be taken offline, and design containment around them.

    TX Cross-CuttingPhases III, IV2 assessing controls

  • M8.09Contained Forensic Preservation

    Preserve evidence in a way that survives containment and recovery, on storage the adversary could not reach.

    T5 DataPhases III, IV3 assessing controls

  • M8.10Third-Party Connection Cutout

    Cut a specific partner or vendor connection on decision without taking down the shared boundary.

    T3 NetworksPhase III2 assessing controls

  • M8.11Restoration Preconditions

    Define what must be true before anything comes back — no restoration on hope.

    TX Cross-CuttingPhase IV3 assessing controls

  • M8.12Degradation Rehearsal

    Rehearse degradation and severing on the real estate, because an untested retrograde is a plan, not a capability.

    TX Cross-CuttingPhases 0, IV2 assessing controls

  • M8.13Safe-State Isolation

    Sever the control network to a defined safe state that preserves the physical process, rather than a network state that abandons it.

    T6 Operational TechnologyPhase III3 assessing controls

  • M8.14Rapid Offboarding and Revocation

    Remove all access from a departing or suspended person in one action, in a time measured against the tempo an insider needs.

    T7 WorkforcePhases III, IV3 assessing controls

  • M8.15Facility Isolation

    Be able to sever a building or floor from the estate without severing the mission, and know in advance what that costs.

    T8 FacilitiesPhase III3 assessing controls

  • M8.16Supplier Severance

    Be able to cut a supplier's access immediately and continue the mission, because the alternative is negotiating with an intrusion.

    T9 Supply ChainPhases III, IV2 assessing controls

  • M8.17Device Decommissioning and Sanitization

    Remove a retired, lost or reassigned device from the estate's trust and sanitize its media within a period derived from what its retained trust could do.

    T2 DevicesPhases 0, V3 assessing controls

M9 · Spoiling Attack

9 techniquesThe form that uses someone else’s contact

Disrupt adversary staging before the attack is launched.

  • M9.01Advisory-Driven Pre-Blocking

    Block infrastructure named in partner reporting before it is used against you, on a stated clock.

    TX Cross-CuttingPhases 0, I2 assessing controls

  • M9.02Targeted Emergency Patching

    Patch out of cycle when intelligence — not the calendar — says a specific weakness is being used now.

    T4 Applications and WorkloadsPhases 0, I2 assessing controls

  • M9.03Staged Infrastructure Denial

    Deny resolution and reachability to infrastructure observed staging against the sector, not only against you.

    T3 NetworksPhases 0, I2 assessing controls

  • M9.04Sector Intelligence Exchange

    Contribute and consume in the sector and federal exchanges so pre-emption is possible at all.

    TX Cross-CuttingPhases 0, V3 assessing controls

  • M9.05Pre-Emptive Credential Invalidation

    Invalidate credentials on exposure intelligence, before misuse, accepting the friction.

    T1 IdentityPhases 0, I2 assessing controls

  • M9.06Vendor Compromise Response

    Hold a rehearsed path to constrain a compromised vendor or integrator connection on disclosure.

    TX Cross-CuttingPhases 0, I2 assessing controls

  • M9.07Exploited-Vulnerability Catalog Enforcement

    Treat authoritative known-exploited catalogs as a directive with an owner and a due date on the terrain register.

    T4 Applications and WorkloadsPhase 02 assessing controls

  • M9.08Workforce Threat Briefing

    Tell the workforce what is actually being attempted against agencies like yours, so recognition happens before the click.

    T7 WorkforcePhases 0, I2 assessing controls

  • M9.09Supplier Advisory Pre-emption

    Act on supplier and component advisories before exploitation reaches you, including by staging the update or constraining the access.

    T9 Supply ChainPhases 0, I3 assessing controls

M10 · Exploitation & Pursuit

7 techniquesThe form that is skipped

Convert contact into durable advantage rather than closing the ticket.

  • M10.01Indicator-to-Detection Conversion

    Convert every indicator observed in contact into a durable, tested detection rather than a one-time block.

    TX Cross-CuttingPhases IV, V2 assessing controls

  • M10.02Avenue Closure Verification

    Verify by test that the avenue actually used is closed — not that a change was made.

    TX Cross-CuttingPhases IV, V3 assessing controls

  • M10.03Terrain Overlay Update

    Update the terrain overlay with what contact revealed, including everything the map got wrong.

    TX Cross-CuttingPhase V3 assessing controls

  • M10.04Intelligence Requirement Revision

    Revise the priority intelligence requirements from what the engagement showed you could not see.

    TX Cross-CuttingPhase V3 assessing controls

  • M10.05Community Reporting

    Report to CISA and sector partners so the next agency starts from your contact.

    TX Cross-CuttingPhase V3 assessing controls

  • M10.06Doctrine and Catalog Update

    Fold what was learned back into the maneuver catalog, the control set and the rules of engagement.

    TX Cross-CuttingPhase V2 assessing controls

  • M10.07Supply Chain Lesson Propagation

    Feed what a supplier incident taught you back into acquisition and into the terrain register, so the next contract starts from it.

    T9 Supply ChainPhase V3 assessing controls

M11 · Reconstitution

11 techniquesThe form that is asserted and not demonstrated

Restore the mission on evidence, not on hope — and prove it before you need it.

  • M11.01Recovery Objective Declaration

    Declare, per mission service, how quickly it must return and how much data loss is survivable — before an incident forces the answer.

    T4 Applications and WorkloadsPhase 03 assessing controls

  • M11.02Isolated Recovery Environment

    Hold the means of recovery outside the blast radius of the production identity plane, so compromise cannot reach what rebuilds you.

    T5 DataPhases 0, IV2 assessing controls

  • M11.03Golden Image and Rebuild Path

    Maintain a trusted, tested build path so rebuilding is a procedure rather than an improvisation under pressure.

    T2 DevicesPhases 0, IV2 assessing controls

  • M11.04Identity Plane Reconstitution

    Rehearse rebuilding the identity plane itself, the one system every other recovery depends on.

    T1 IdentityPhase IV3 assessing controls

  • M11.05Recovery Data Integrity Verification

    Prove restored data is what it was before contact, rather than restoring the adversary's edits along with it.

    T5 DataPhase IV1 assessing control

  • M11.06Service Restoration Sequencing

    Restore in a declared order that respects dependency and statutory priority, so the first service back is the one that must be.

    T4 Applications and WorkloadsPhases IV, V4 assessing controls

  • M11.07Reconstitution Exercise

    Exercise recovery against a real failure scenario on a stated cadence, because an untested recovery plan is a document.

    TX Cross-CuttingPhases 0, V2 assessing controls

  • M11.08Key Personnel Continuity

    Name the roles without which recovery cannot proceed, and make sure none of them is one person deep.

    T7 WorkforcePhases 0, V2 assessing controls

  • M11.09Alternate Facility Activation

    Be able to run the mission from somewhere else, and prove it by doing so rather than by documenting it.

    T8 FacilitiesPhases IV, V3 assessing controls

  • M11.10Supplier-Independent Rebuild

    Ensure recovery does not depend on the availability or the integrity of the supplier who may be the reason you are recovering.

    T9 Supply ChainPhase IV2 assessing controls

  • M11.11Mailbox and Message Restoration

    Restore mailboxes and messages removed during eviction or lost in the incident, verified against an integrity record, before returning the service to use.

    T4 Applications and WorkloadsPhases IV, V3 assessing controls