What It Does
Revise the priority intelligence requirements from what the engagement showed you could not see.
Observable indicator. Requirements change after contact rather than persisting by inertia.
Where It Sits
A technique is chosen from inside a form and emplaced on one layer. Both are the catalog’s own declarations; the position is counted in catalog order.
- Form of maneuverM10 Exploitation & PursuitConvert contact into durable advantage rather than closing the ticket.
- Terrain layerTX Cross-CuttingThe enablers of movement. Key terrain: The telemetry pipeline, the orchestration layer, the rules of engagement.
- Position in the form4 of 7M10 carries 7 cataloged techniques; this is the 4th in catalog order.
Phases It Is Employed In
Employed in one phase of the campaign. A phase named here means at least this technique is live in it — not that the form it belongs to is the main effort.
- Phase VEnable / RestoreRecover, harden, and update the doctrine and the intelligence requirements.
Controls That Assess It
The controls the catalog names against this technique. They are what an assessor would test to establish that it is emplaced and working — the indicator above is what shows it is working, which is a different question.
- CE-2 Priority Intelligence RequirementsCycle Execution and Assurance — To direct analytic effort at named questions, so that collection and hunting answer what the accountable authority needs rather than processing what arrives.
- CE-6 Cycle Record and TrendCycle Execution and Assurance — To answer whether the program is improving — a question no point-in-time assessment can address.
- EN-2 Engagement ReconstructionEngagement and Pursuit — To establish what actually happened, since every consolidation activity depends on a reconstruction and none of them can be performed without one.
In MITRE D3FEND
Intelligence Requirement Revision — an analytic governance activity.
Related Techniques
The catalog declares no relation for this entry, and no other entry names it — the inverse is derived here, so an incoming edge would show up even though this one never declared it. The techniques below share its assessment surface, which is the nearest adjacency the data supports.
Assessed Alongside
Not a declared relation: these are the techniques whose assessing controls overlap this one’s, ranked by how much of the two assessment surfaces coincide. Showing 6 of 34 that share at least one control.
- 2 shared controlsM7.12 Adversary Dwell ReconstructionM7 Counterattack · TX Cross-Cutting
- CE-6
- EN-2
- 1 shared controlM1.04 Perimeter Canary TokensM1 Screen / Guard · T5 Data
- CE-2
- 1 shared controlM1.05 Authentication Geography BaselineM1 Screen / Guard · T1 Identity
- CE-2
- 1 shared controlM1.06 Credential Exposure MonitoringM1 Screen / Guard · T1 Identity
- CE-2
- 1 shared controlM1.07 Partner and Advisory IntakeM1 Screen / Guard · TX Cross-Cutting
- CE-2
- 1 shared controlM1.10 Named-Campaign Indicator WatchM1 Screen / Guard · TX Cross-Cutting
- CE-2