Doctrine of Record · v1.2

Privilege Disruption

DENY THE CONVERSION OF ACCESS INTO CONTROL.

Reshaping adversary behavior by disrupting the privilege and Execution Authority required to turn access into persistence, privilege escalation, lateral movement, operational control, and impact.

The Doctrine in 3 Questions

A simple path from concept to operational meaning.

01 · PD-D01

What is Privilege Disruption?

Deny the conversion of access into control.

A cybersecurity doctrine focused on the privilege and Execution Authority a threat actor needs to advance an operation.

Operational meaning: Access is not the end state. Govern the privilege and authority required to turn presence into persistence, escalation, movement, and control.
02 · Strategic Problem

Why does it matter?

Threat actors may already have access. What authority remains?

Privilege debt increases the Execution Authority a successful compromise can inherit.

Example: One compromised identity may carry privilege the environment no longer needs. The intrusion earned the identity; the environment supplied the additional leverage.

AI-era implication: AI can accelerate the discovery and exercise of available authority. Privilege debt determines how much authority a successful compromise can inherit.
03 · PD-OC01–04

How does it operate?

Apply the doctrine continuously.

GovernHuntDisruptRetire
Govern known privilege and authority. Hunt for exposure and emerging authority paths. Disrupt illegitimate authority before it becomes control. Retire privilege that no longer has an operational purpose.

“Privilege Disruption is the doctrine that gives defenders a playbook for proactive cyber defense.”

State Agency Cyber Defender

10 Foundational Principles

What must remain true regardless of technology, actor type, or implementation.

The Authority Model

Privilege and Execution Authority are related, but not interchangeable. The model holds across human, non-human, automated, and agentic actors.

PD-C06IdentityWho or what is acting.
PD-C01PrivilegeThe entitlement attached to the actor.
PD-C07Capability / ToolThe mechanism through which privilege is exercised.
PD-C02Execution AuthorityWhat the actor can actually cause to happen.
ActionThe exercise of authority.
ImpactThe resulting operational or mission consequence.
Privilege DebtExcess Privilege → Excess Inheritable Execution AuthorityDebt increases how much authority can be inherited when a debt-bearing identity is compromised.

“No more stops at the fuel pump to refuel. Privilege disruption increases the cost to refuel.”

Federal Defense Contractor

“Disrupting privilege brings control to the agent chaos we’re seeing with AI-enabled cyberattacks.”

State Agency CISO

Zero Trust → Privilege Disruption

Zero Trust governs whether access should be granted. Privilege Disruption governs what authority remains after access is granted — and whether that authority can be prevented from becoming adversary control.

ZERO TRUST

Govern access

Explicitly verify the actor, resource and conditions under which access is granted.

PRIVILEGE DISRUPTION

Govern inheritable authority

Assume access can occur. Reduce the privilege and Execution Authority a successful compromise can inherit and compose.

STRATEGY

Deterrence by Denial

Shape the adversary by making compromised access carry less standing value and fewer reusable paths to control.

MECHANISM

Continuous Privilege Disruption

Find and retire privilege that should not exist; bound what must remain; interrupt illegitimate authority at execution time.

INTELLIGENCE

Read the Prologue

Find authority-supplying conditions and warning signals before they become realized ATT&CK behavior.

Zero Trust principlePrivilege Disruption extensionProactive move
Least PrivilegeLNPB — Leave No Privilege BehindContinuously find and retire privilege that should not exist.
Least Privilege (residual)Privilege DisruptionJIT, scoped and ephemeral authority; stop access converting into meaningful control.
Assume CompromiseRead the PrologueHunt pre-existing authority paths and warnings before adversary behavior is realized.
Explicit VerificationPreserve the access decisionPD does not replace verification; it governs the consequential authority that remains after it.

“Shaping adversary behavior, introducing costs and consequences into this mix.”

Sean Cairncross, National Cyber Director · Source

See the Doctrine in the Wild

The doctrine explains the model. Attack Stories show how privilege, debt, authority, and control appear in real campaigns.

“Every cyberattack has a prologue. Hunting in it is responsive cyber defense.”

University IT Security Director

“These Attack Stories build on the MITRE ATT&CK knowledge base by helping defenders see what can be done before IoCs emerge and adversary techniques are realized. The opportunity to build resilience against adversary behavior often exists in the Prologue.”

Kevin E. Greene
Doctrine → Evidence

Read the doctrine against real Attack Stories.

Cyber Prologue cases show what authority existed before compromise, how that authority was inherited or composed, where controls held, and where Privilege Disruption could have changed the story.

Explore the case collection →
THREAT-INFORMED DEFENSE · R2.2

Connect the Prologue to protection capabilities.

Explore how 43 authority-supplying conditions connect through MITRE ATT&CK to NIST SP 800-53 controls, with transparent CTID attribution and a five-story control heat map.

Explore the mapping →
NEW IN ATTACK STORIES · R2.1

The Prologue expands into OT and new attack research.

Explore CP-004 Risevatnet, the collection’s first operational technology case, and CP-006 QTFY Infrastructure Quartermaster.

Explore the new stories ↓
CP-001 · Attack Story

Salt Typhoon

PD-P07 · DebtPD-P03 · Authority

Explore the conditions that existed before compromise and the privilege paths that made the operation consequential.

Read story →
CP-002 · Attack Story

Taiwan Agentic

PD-P05 · AIPD-P07 · Debt

See how AI-driven activity intersects with privilege, inherited authority, and attack progression.

Read story →
CP-003 · Attack Story

Hugging Face

PD-P09 · CompositionPD-P10 · Recurrence

Trace the Prologue, privilege conditions, and Execution Authority that shaped the attack story.

Read story →
CP-004 · Attack Story

Risevatnet | OT

OT · Water ControlPD-P07 · Debt

A weakly held credential stood directly in front of remote valve-control authority, producing an unusually shallow path from access to physical consequence.

Read story →
CP-006 · Attack Story

QTFY Infrastructure Quartermaster

Campaign InfrastructureAuthority Boundaries

Separates campaign-scale infrastructure, concealed reach and victim-side authority without collapsing multiple estates into one kill chain.

Read story →