Sync to interdiction doctrine: edition notes on quantum framework + Book VII, cut classes in kill-chain spec, index/READMEs repointed to interdiction-model.md
This commit is contained in:
@@ -35,7 +35,8 @@ Most security and resilience frameworks optimize for **robustness**—the abilit
|
||||
│ ├── executive-summary-cs.md # Czech version of board brief (Výkonné shrnutí)
|
||||
│ ├── c-suite-conversation-guide.md # Persuasion scripts for top management
|
||||
│ ├── t0-asset-framework.md # Tier 0 asset classification and protection
|
||||
│ └── quantum-vulnerability-management.md # Time-budgeted quanta model for the exploitation-first era (Book VII companion)
|
||||
│ ├── quantum-vulnerability-management.md # Original quanta model — superseded by interdiction-model.md
|
||||
│ └── interdiction-model.md # Minimum-cost cuts on a two-weight attack graph (current doctrine, Book VII companion)
|
||||
├── playbooks/ # Executable modernisation and response plans
|
||||
│ ├── rapid-modernisation-plan.md # 30-60-90-180 day transformation roadmap
|
||||
│ ├── endpoint-management-entry-vector.md # Intune/device management as engagement entry point
|
||||
@@ -70,7 +71,7 @@ Most security and resilience frameworks optimize for **robustness**—the abilit
|
||||
│ └── vertical-banking.md # Financial services regulatory alignment
|
||||
├── tools/ # Standalone runnable instruments (offline, single-file)
|
||||
│ ├── README.md # Tool index and design constraints
|
||||
│ └── kill-chain-assessment.html # Maps unknown estates → shortest existential path → quanta
|
||||
│ └── kill-chain-assessment.html # Maps unknown estates → cheapest existential path → cut classes
|
||||
├── books/ # The Antifragile Handbook (Books I–VII + field guides)
|
||||
└── assets/ # Diagrams, visuals, and presentation materials
|
||||
```
|
||||
|
||||
@@ -6,6 +6,10 @@
|
||||
|
||||
---
|
||||
|
||||
> **Terminology note (September 2026).** This book's doctrine has been sharpened into the **[Interdiction Model](../core/interdiction-model.md)**: the "quantum" is now the **cut** — every remediation priced as the removal of an edge in the attack graph, the planning object the minimum-cost cut that severs every mapped path to a crown jewel. The four lanes survive as cut classes (hour / day / sprint / dark), joined by a fifth, *declined*; the programme metric is cut depth (κ). The text below retains the original "quantum" wording; read them as the same discipline.
|
||||
|
||||
---
|
||||
|
||||
## The governing question
|
||||
|
||||
The first six books were written for a world in which the dominant way into an estate was a person — phished, tricked, talked past the controls. That assumption is now wrong. As of the 2026 Verizon DBIR, **exploitation of vulnerabilities is the leading initial-access vector in confirmed breaches — roughly twice phishing, for the first time in the report's history.** The front door changed. This book changes the lens to match.
|
||||
@@ -200,4 +204,4 @@ Move fast and fix things.
|
||||
|
||||
---
|
||||
|
||||
*Book VII of the Antifragile Handbook. Pairs with the [Quantum Vulnerability Management](../core/quantum-vulnerability-management.md) framework and the [Kill Chain Assessment app](../playbooks/kill-chain-assessment-app.md); the build-level companion is the [AI-Assisted TVM Blueprint](../playbooks/ai-assisted-tvm.md).*
|
||||
*Book VII of the Antifragile Handbook. Pairs with the [Interdiction Model](../core/interdiction-model.md) and the [Kill Chain Assessment app](../playbooks/kill-chain-assessment-app.md); the build-level companion is the [AI-Assisted TVM Blueprint](../playbooks/ai-assisted-tvm.md).*
|
||||
|
||||
@@ -76,9 +76,9 @@ Read this once you've built something worth protecting — it closes the origina
|
||||
|
||||
*The patch cycle was built for a world where you had weeks. That world is gone. Stop racing the attacker to the patch — change the race.*
|
||||
|
||||
The first six books assume the dominant way into an estate is a phished human. As of the 2026 Verizon DBIR that assumption is wrong: **exploitation of vulnerabilities is now the leading initial-access vector, roughly twice phishing.** This book changes the lens to match. It refuses the two losing moves — sorting 40,000 findings by CVSS, and trying to "patch faster" against a 4-hour exploitation window — and replaces them with the antifragile alternative: subtract the ~90% of criticals that aren't actually reachable, size the rest into **quanta** by time-to-existential-impact (hours / days / sprint, plus the dangerous *dark* quantum you can't yet size), contain the few that matter with compensating controls rather than waiting for a patch, and feed every exploited path back into a shorter kill chain.
|
||||
The first six books assume the dominant way into an estate is a phished human. As of the 2026 Verizon DBIR that assumption is wrong: **exploitation of vulnerabilities is now the leading initial-access vector, roughly twice phishing.** This book changes the lens to match. It refuses the two losing moves — sorting 40,000 findings by CVSS, and trying to "patch faster" against a 4-hour exploitation window — and replaces them with the antifragile alternative: subtract the ~90% of criticals that aren't actually reachable, size the rest into **cuts** by time-to-existential-impact (hour / day / sprint, plus the dangerous *dark* node you can't yet size), contain the few that matter with compensating controls rather than waiting for a patch, and feed every exploited path back into a shorter kill chain. *(Written when the discipline was called quantum vulnerability management; the current framework is the Interdiction Model — the book's quanta are today's cut classes.)*
|
||||
|
||||
It pairs with the [Quantum Vulnerability Management](../core/quantum-vulnerability-management.md) framework and the [Kill Chain Assessment app](../playbooks/kill-chain-assessment-app.md). Read it when the threat landscape — not the maturity model — forces the question.
|
||||
It pairs with the [Interdiction Model](../core/interdiction-model.md) and the [Kill Chain Assessment app](../playbooks/kill-chain-assessment-app.md). Read it when the threat landscape — not the maturity model — forces the question.
|
||||
|
||||
---
|
||||
|
||||
|
||||
@@ -6,6 +6,10 @@ This is the operating framework behind [Book VII — Vulnerability Management](.
|
||||
|
||||
---
|
||||
|
||||
> **Doctrine note (September 2026).** This framework has been generalised into the **[Interdiction Model](interdiction-model.md)**: the *quantum* is now the **cut** — every remediation is priced as the removal of an edge in a two-weight attack graph, and the planning object is the minimum-cost set of removals that severs every mapped path to a crown jewel. The four quanta survive as cut classes (hour / day / sprint / dark), joined by a fifth — *declined*, for work the arithmetic says not to do — and the programme metric is cut depth (κ). What follows is the original formulation, kept because its operational detail (the barbell, the ~90% subtraction, ghost patches, the engagement sequence) is unchanged; read "quantum" as "cut."
|
||||
|
||||
---
|
||||
|
||||
## The problem in one paragraph
|
||||
|
||||
Time-to-exploit has collapsed to roughly **4 hours** while median remediation sits at **43 days**; CVE volume has gone past **59,000/year** and the public enrichment data (NVD) is degrading; and as of the **2026 Verizon DBIR, vulnerability exploitation is the #1 initial-access vector, roughly twice phishing.** A human-paced, CVSS-sorted patch programme cannot close a gap that runs the wrong way by two orders of magnitude. The answer is not "patch faster." It is to **stop using the vulnerability list as the unit of work**, size remediation into time-budgeted quanta, contain the few that matter in hours, make the rest not matter through architecture, and feed every exploited path back into a shorter kill chain.
|
||||
|
||||
@@ -42,7 +42,7 @@ Operational and persuasion documents used in engagements. **Start every new clie
|
||||
| [Antifragile Manifest](core/antifragile-manifest.md) | Five pillars of antifragile enterprise | Executives, Architects, Consultants |
|
||||
| [AI Sovereignty Framework](core/ai-sovereignty-framework.md) | Strategic arguments and implementation for local AI | CISOs, CTOs, Security Architects |
|
||||
| [T0 Asset Framework](core/t0-asset-framework.md) | Tier 0 classification and protection for critical assets | Security Architects, Infrastructure Leads |
|
||||
| [Quantum Vulnerability Management](core/quantum-vulnerability-management.md) | Sizing remediation into time-budgeted quanta (hours/days/sprint/dark) for the exploitation-first era; companion to Book VII | CISOs, Vulnerability Management, Consultants |
|
||||
| [Interdiction Model](core/interdiction-model.md) | Minimum-cost cuts on a two-weight attack graph — the current vulnerability-management doctrine (supersedes the quanta framework); companion to Book VII | CISOs, Vulnerability Management, Consultants |
|
||||
| [Spontaneous Order Principles](core/spontaneous-order-principles.md) | Philosophical foundation for the five pillars | Executives, Architects, Strategists |
|
||||
|
||||
## Playbooks
|
||||
@@ -52,7 +52,7 @@ Operational and persuasion documents used in engagements. **Start every new clie
|
||||
| [Rapid Modernisation Plan](playbooks/rapid-modernisation-plan.md) | 30-60-90-180 day transformation roadmap | Program Managers, Consultants, CISOs |
|
||||
| [Endpoint Management Entry Vector](playbooks/endpoint-management-entry-vector.md) | Intune/device management as the ideal engagement entry point | M365 Consultants, Account Managers |
|
||||
| [AI-Assisted TVM Blueprint](playbooks/ai-assisted-tvm.md) | AI-powered vulnerability management for AI-powered adversaries | CTOs, CISOs, Vulnerability Management |
|
||||
| [Kill Chain Assessment App](playbooks/kill-chain-assessment-app.md) | Spec for the offline tool that maps unknown estates into an attack graph, computes the shortest existential path, and sizes quanta. Tool: [`tools/kill-chain-assessment.html`](tools/kill-chain-assessment.html) | Consultants, Assessors, Security Architects |
|
||||
| [Kill Chain Assessment App](playbooks/kill-chain-assessment-app.md) | Spec for the offline tool that maps unknown estates into an attack graph, computes the cheapest existential path, and sizes nodes into cut classes. Tool: [`tools/kill-chain-assessment.html`](tools/kill-chain-assessment.html) | Consultants, Assessors, Security Architects |
|
||||
| [Zero-Budget Vulnerability Discovery](playbooks/zero-budget-vulnerability-discovery.md) | Script-based and osquery-based server/container vuln discovery without Tenable/Qualys | Security Engineers, Consultants |
|
||||
| [Perimeter Scanning Capability](playbooks/perimeter-scanning-capability.md) | External attack surface strategy: build, partner, or hybrid | Security Architects, Consultants |
|
||||
| [Osquery: The Sovereign Discovery Platform](playbooks/osquery-custom-platform.md) | Build a custom vulnerability and asset inventory platform on osquery | Security Engineers, Consultants, CTOs |
|
||||
|
||||
@@ -2,7 +2,7 @@
|
||||
|
||||
> *"We say it in every engagement: find the kill chain first. But how do you find it in territory you've never seen? You don't start with the chain — you start with the questions that surface the edges, and you let the graph tell you where the shortest path to the end of the company actually runs."*
|
||||
|
||||
This document specifies the **Kill Chain Assessment app** — a single-file, offline browser tool a consultant runs during the diagnostic to turn an unknown estate into a mapped attack graph, compute the shortest existential path (the kill chain), and size every node on it into a remediation [quantum](../core/quantum-vulnerability-management.md).
|
||||
This document specifies the **Kill Chain Assessment app** — a single-file, offline browser tool a consultant runs during the diagnostic to turn an unknown estate into a mapped attack graph, compute the shortest existential path (the kill chain), and size every node on it into a remediation class — the [Interdiction Model](../core/interdiction-model.md)'s cut classes.
|
||||
|
||||
**The tool:** [`tools/kill-chain-assessment.html`](../tools/kill-chain-assessment.html) — open it in any browser. No install, no network, no data leaves the machine. State persists locally and exports to `.json` (to resume) and `.md` (to drop straight into the report or the [Findings Backlog](../assessment-templates/findings-backlog.md)).
|
||||
|
||||
@@ -28,11 +28,11 @@ A **node** is any asset, foothold, identity, or system. Each carries the attribu
|
||||
| **Tier** | T0 / T1 / T2 ([T0 Asset Framework](../core/t0-asset-framework.md)) | Blast-radius weighting |
|
||||
| **Entry point** | Internet-reachable or unauth foothold | Source of the chain |
|
||||
| **Crown jewel** | Existential — the org cannot operate without it | End of the chain |
|
||||
| **Reachable?** | Can the adversary actually get to it (yes/no/**unknown**) | Quantum sizing |
|
||||
| **Exploit available?** | Working path/exploit in the wild (yes/no/**unknown**) | Quantum sizing |
|
||||
| **Compensating control** | EDR / WAF / segmentation already in front | Quantum sizing (the ~90% subtraction) |
|
||||
| **Reachable?** | Can the adversary actually get to it (yes/no/**unknown**) | Cut class |
|
||||
| **Exploit available?** | Working path/exploit in the wild (yes/no/**unknown**) | Cut class |
|
||||
| **Compensating control** | EDR / WAF / segmentation already in front | Cut class (the ~90% subtraction) |
|
||||
|
||||
The "unknown" values are first-class, not placeholders: a node you cannot characterise is a **dark quantum**, and capturing it honestly is the point.
|
||||
The "unknown" values are first-class, not placeholders: a node you cannot characterise is a **dark node**, and capturing it honestly is the point.
|
||||
|
||||
### Moves (edges)
|
||||
|
||||
@@ -46,27 +46,28 @@ The app runs a **multi-source Dijkstra** from every entry point across the move
|
||||
- **P1** — on *some* path from an entry to a jewel (reachable-from-entry ∧ can-reach-a-jewel), but not on the cheapest one.
|
||||
- **P2 / off-chain** — not on any path to a crown jewel. Real, but not existential — housekeeping, not kill chain.
|
||||
|
||||
This is the [Move Fast](../core/move-fast-and-fix-things.md) doctrine made computable: *kill-chain position sets priority, not CVSS.*
|
||||
This is the [Move Fast](../core/move-fast-and-fix-things.md) doctrine made computable: *kill-chain position sets priority, not CVSS.* The [Interdiction Model](../core/interdiction-model.md) carries it further — every remediation is priced as the removal of an edge, and the planning object is the **minimum-cost cut** that severs every mapped path to a crown jewel; the tool's P0/P1/P2 classes map onto that model (P2 ≈ the *declined* class).
|
||||
|
||||
### Quantum sizing
|
||||
### Remediation sizing (cut classes)
|
||||
|
||||
Each node on a chain is sized into a [quantum](../core/quantum-vulnerability-management.md) by the same logic the framework defines:
|
||||
Each node on a chain is sized into a cut class by the logic the [Interdiction Model](../core/interdiction-model.md) defines:
|
||||
|
||||
| Quantum | Condition | Budget / action |
|
||||
|---------|-----------|-----------------|
|
||||
| **Critical** | On shortest chain, reachable **yes**, exploit **yes**, not compensated | **Hours** — sever reachability / compensating control now |
|
||||
| **Severe** | On a chain, reachable **or** exploit = yes | **Days** — one change window, verify enforcement |
|
||||
| **Standard** | On a chain, neither reachable nor exploitable yet | **Sprint** — batch; patch velocity fits here |
|
||||
| Class | Condition | Budget / action |
|
||||
|-------|-----------|-----------------|
|
||||
| **Hour-cut** (Critical) | On cheapest chain, reachable **yes**, exploit **yes**, not compensated | **Hours** — sever reachability / compensating control now |
|
||||
| **Day-cut** (Severe) | On a chain, reachable **or** exploit = yes | **Days** — one change window, verify enforcement |
|
||||
| **Sprint-cut** (Standard) | On a chain, neither reachable nor exploitable yet | **Sprint** — batch; patch velocity fits here |
|
||||
| **Dark** | On a chain but reachability **or** exploit = unknown | **Unsized** — route to discovery; characterise first |
|
||||
| **Declined** | Off-chain (P2): on no mapped path to a crown jewel | Documented risk acceptance with a review trigger — *not* backlog |
|
||||
|
||||
---
|
||||
|
||||
## How to run it in an engagement
|
||||
|
||||
1. **Open the tool** and clear the sample (or keep it as a worked reference). Switch to the **Discovery** tab — it lists, per layer, the questions and commands that surface edges (external scan for entries, the Connect sync account for the cloud↔on-prem bridge, BloodHound `shortestPath` for privilege, "what stops the business operating?" for jewels, flat-network checks for blast radius). This is the unknown-territory protocol.
|
||||
2. **Capture as you go.** Every finding from the [assessment team guide](../assessment-templates/assessment-team-guide.md) becomes a node; every "an attacker could move from X to Y" becomes a move. Mark entries and jewels. Leave reachability/exploit as *unknown* when you genuinely don't know — that flags the dark quanta to chase.
|
||||
3. **Read the chain.** The centre panel draws the attack graph and highlights the shortest existential path in red. The right panel sizes the quanta. If no path is found, either the estate is genuinely segmented there (note it as a win) or you haven't mapped the connecting moves yet — in unknown territory, assume the latter until proven.
|
||||
4. **Export.** `Export report .md` produces a kill-chain section, quantum-bucketed remediation, and a priority table ready to paste into the diagnostic deliverable. `Save .json` lets you resume or hand off.
|
||||
2. **Capture as you go.** Every finding from the [assessment team guide](../assessment-templates/assessment-team-guide.md) becomes a node; every "an attacker could move from X to Y" becomes a move. Mark entries and jewels. Leave reachability/exploit as *unknown* when you genuinely don't know — that flags the dark nodes to chase.
|
||||
3. **Read the chain.** The centre panel draws the attack graph and highlights the shortest existential path in red. The right panel sizes the cut classes. If no path is found, either the estate is genuinely segmented there (note it as a win) or you haven't mapped the connecting moves yet — in unknown territory, assume the latter until proven.
|
||||
4. **Export.** `Export report .md` produces a kill-chain section, class-bucketed remediation, and a priority table ready to paste into the diagnostic deliverable. `Save .json` lets you resume or hand off.
|
||||
5. **Close the loop.** After remediation, reload the `.json` and ask the antifragile question the framework demands: *did the chain get shorter?* A severed link or a collapsed privilege should visibly lengthen the shortest path or remove it entirely.
|
||||
|
||||
---
|
||||
@@ -90,4 +91,4 @@ The current tool is a self-contained synthesis instrument. Natural extensions, i
|
||||
|
||||
---
|
||||
|
||||
*Specified for [Book VII — Vulnerability Management](../books/06-vulnerability-management.md) and the [Quantum Vulnerability Management](../core/quantum-vulnerability-management.md) framework. The tool: [`tools/kill-chain-assessment.html`](../tools/kill-chain-assessment.html).*
|
||||
*Specified for [Book VII — Vulnerability Management](../books/06-vulnerability-management.md) and the [Interdiction Model](../core/interdiction-model.md). The tool: [`tools/kill-chain-assessment.html`](../tools/kill-chain-assessment.html).*
|
||||
|
||||
@@ -12,7 +12,7 @@
|
||||
|
||||
## 1. Why this needs to exist
|
||||
|
||||
The L1 [Kill Chain Assessment app](kill-chain-assessment-app.md) is a synthesis instrument: you feed it nodes and attacker moves you've already discovered, and it computes the shortest existential path and sizes the [quanta](../core/quantum-vulnerability-management.md). It assumes you already have findings — BloodHound paths, Entra checks, the [assessment team guide](../assessment-templates/assessment-team-guide.md) output.
|
||||
The L1 [Kill Chain Assessment app](kill-chain-assessment-app.md) is a synthesis instrument: you feed it nodes and attacker moves you've already discovered, and it computes the cheapest existential path and sizes nodes into [cut classes](../core/interdiction-model.md). It assumes you already have findings — BloodHound paths, Entra checks, the [assessment team guide](../assessment-templates/assessment-team-guide.md) output.
|
||||
|
||||
But on **day zero of a new engagement** you have none of that. You may not even have access yet — the contract may not permit infrastructure contact, the change-advisory board hasn't met, the client's legal team is still reviewing the scope. And yet this is exactly the moment the consultant most needs a hypothesis: *where is this company's kill chain likely to run, what should we ask, and what should we look at first when access arrives?*
|
||||
|
||||
@@ -78,7 +78,7 @@ The synthesis exports directly to the **L1 Kill Chain Assessment app's `.json` s
|
||||
|
||||
## 4. Threat-intelligence layer
|
||||
|
||||
ORION continuously contextualises the client against the *current* threat environment — the dimension a static questionnaire can't capture and the one that feeds the [quantum](../core/quantum-vulnerability-management.md) sort key's "exploit availability" axis:
|
||||
ORION continuously contextualises the client against the *current* threat environment — the dimension a static questionnaire can't capture and the one that feeds the [Interdiction Model](../core/interdiction-model.md)'s "exploit availability" axis:
|
||||
|
||||
- **CISA KEV and exploited-CVE feeds** — for the client's named technologies, what is being exploited *now*.
|
||||
- **Vendor advisories** — current critical advisories for their declared stack (the VPN appliance, the mail gateway, the ERP).
|
||||
@@ -248,4 +248,4 @@ Self-hosters bring their own LLM (Ollama / Azure OpenAI); hosted tier includes a
|
||||
|
||||
---
|
||||
|
||||
*Companion to the [Kill Chain Assessment app](kill-chain-assessment-app.md) (L1), [Book VII — Vulnerability Management](../books/06-vulnerability-management.md), and the [Quantum Vulnerability Management](../core/quantum-vulnerability-management.md) framework. Positioned in the suite alongside [ASTRAL, PULSAR, and AURORA](cqre-product-suite.md).*
|
||||
*Companion to the [Kill Chain Assessment app](kill-chain-assessment-app.md) (L1), [Book VII — Vulnerability Management](../books/06-vulnerability-management.md), and the [Interdiction Model](../core/interdiction-model.md). Positioned in the suite alongside [ASTRAL, PULSAR, and AURORA](cqre-product-suite.md).*
|
||||
|
||||
@@ -4,7 +4,7 @@ Standalone, runnable instruments that support the engagement — as distinct fro
|
||||
|
||||
| Tool | What it does | How to run |
|
||||
|------|--------------|------------|
|
||||
| [`kill-chain-assessment.html`](kill-chain-assessment.html) | Maps an unknown estate into an attack graph, computes the shortest existential path (the kill chain), and sizes every node into a remediation quantum. The synthesis instrument for the first act of every engagement. | Open in any browser. Offline, no install, no network. State persists locally; exports to `.json` and `.md`. |
|
||||
| [`kill-chain-assessment.html`](kill-chain-assessment.html) | Maps an unknown estate into an attack graph, computes the cheapest existential path (the kill chain), and sizes every node into a remediation class (the Interdiction Model's cut classes). The synthesis instrument for the first act of every engagement. | Open in any browser. Offline, no install, no network. State persists locally; exports to `.json` and `.md`. |
|
||||
|
||||
## Design constraints for tools in this directory
|
||||
|
||||
|
||||
Reference in New Issue
Block a user