Execution Authority
Device execution, authentication, privileged management, network-control and cross-domain authority appear as distinct planes.
The case record remains governed by its CP identifiers and evidence bands. This layer connects those findings to the Privilege Disruption Doctrine of Record without changing the underlying evidence.
Device execution, authentication, privileged management, network-control and cross-domain authority appear as distinct planes.
Root-level device authority and recovered credentials become usable administrative and network-control authority.
The case makes the conversion from access through privilege into persistence, escalation and lateral reach visible.
Pre-existing credentials, shared secrets and trusted relationships supply authority the adversary did not have to manufacture.
Created administrative accounts and pre-existing cross-domain relationships show how authority can persist and extend beyond one device.
Prologue records carry four bands describing how strongly the source establishes a pre-existing condition.
Attack story records carry three bands and point back to the prologue conditions the source supports.
No anchor is a valid state. It is counted, not filled in.
“Every cyberattack has a prologue, hunting in it is responsive cyber defense.”
University IT Security DirectorConditions present in the estate before the campaign realized them. Written by configuration, lifecycle and architecture decisions, not by the adversary. Spent by counts the documented behaviors that draw on each condition. A zero there is not an error. It marks a condition the source establishes independently of any behavior it documents, which is what keeps this catalog from being the attack story read backwards.
| ID | Band | Condition | Debt | Plane | Spent by |
|---|
Adversary behavior documented by the source, each pointing back to the prologue conditions it spent. Records with no source-supported anchor are marked and counted rather than assigned one.
| ID | Band | Behavior | PD Q | Tactic | ATT&CK | Anchors |
|---|
Empty categories are data. A category reading zero in this case is a finding about the campaign and the source, and it is what makes counts comparable across the collection.
Plane jump. A case-specific visualization of execution authority changing domains as the adversary converts one form of inherited authority into another. It is a rendering of execution authority geometry, not a doctrinal entity. Planes are chosen to fit this estate. A cloud, SaaS, OT or agentic case will render its own geometry against the same invariant spine.