Doctrine of Record · v1.2

Privilege Disruption

DENY THE CONVERSION OF ACCESS INTO CONTROL.

Reshaping adversary behavior by disrupting the privilege and Execution Authority required to turn access into persistence, privilege escalation, lateral movement, operational control, and impact.

The Doctrine in 3 Questions

A simple path from concept to operational meaning.

01 · PD-D01

What is Privilege Disruption?

Deny the conversion of access into control.

A cybersecurity doctrine focused on the privilege and Execution Authority a threat actor needs to advance an operation.

Operational meaning: Access is not the end state. Govern the privilege and authority required to turn presence into persistence, escalation, movement, and control.
02 · Strategic Problem

Why does it matter?

Threat actors may already have access. What authority remains?

Privilege debt increases the Execution Authority a successful compromise can inherit.

Example: One compromised identity may carry privilege the environment no longer needs. The intrusion earned the identity; the environment supplied the additional leverage.

AI-era implication: AI can accelerate the discovery and exercise of available authority. Privilege debt determines how much authority a successful compromise can inherit.
03 · PD-OC01–04

How does it operate?

Apply the doctrine continuously.

GovernHuntDisruptRetire
Govern known privilege and authority. Hunt for exposure and emerging authority paths. Disrupt illegitimate authority before it becomes control. Retire privilege that no longer has an operational purpose.

“Privilege Disruption is the doctrine that gives defenders a playbook for proactive cyber defense.”

State Agency Cyber Defender

10 Foundational Principles

What must remain true regardless of technology, actor type, or implementation.

The Authority Model

Privilege and Execution Authority are related, but not interchangeable. The model holds across human, non-human, automated, and agentic actors.

PD-C06IdentityWho or what is acting.
PD-C01PrivilegeThe entitlement attached to the actor.
PD-C07Capability / ToolThe mechanism through which privilege is exercised.
PD-C02Execution AuthorityWhat the actor can actually cause to happen.
ActionThe exercise of authority.
ImpactThe resulting operational or mission consequence.
Privilege DebtExcess Privilege → Excess Inheritable Execution AuthorityDebt increases how much authority can be inherited when a debt-bearing identity is compromised.

“No more stops at the fuel pump to refuel. Privilege disruption increases the cost to refuel.”

Federal Defense Contractor

“Disrupting privilege brings control to the agent chaos we’re seeing with AI-enabled cyberattacks.”

State Agency CISO

Zero Trust → Privilege Disruption

Zero Trust governs whether access should be granted. Privilege Disruption governs what authority remains after access is granted — and whether that authority can be prevented from becoming adversary control.

ZERO TRUST

Govern access

Explicitly verify the actor, resource and conditions under which access is granted.

PRIVILEGE DISRUPTION

Govern inheritable authority

Assume access can occur. Reduce the privilege and Execution Authority a successful compromise can inherit and compose.

STRATEGY

Deterrence by Denial

Shape the adversary by making compromised access carry less standing value and fewer reusable paths to control.

MECHANISM

Continuous Privilege Disruption

Find and retire privilege that should not exist; bound what must remain; interrupt illegitimate authority at execution time.

INTELLIGENCE

Read the Prologue

Find authority-supplying conditions and warning signals before they become realized ATT&CK behavior.

Zero Trust principlePrivilege Disruption extensionProactive move
Least PrivilegeLNPB — Leave No Privilege BehindContinuously find and retire privilege that should not exist.
Least Privilege (residual)Privilege DisruptionJIT, scoped and ephemeral authority; stop access converting into meaningful control.
Assume CompromiseRead the PrologueHunt pre-existing authority paths and warnings before adversary behavior is realized.
Explicit VerificationPreserve the access decisionPD does not replace verification; it governs the consequential authority that remains after it.

“Shaping adversary behavior, introducing costs and consequences into this mix.”

Sean Cairncross, National Cyber Director · Source

See the Doctrine in the Wild

The doctrine explains the model. Attack Stories show how privilege, debt, authority, and control appear in real campaigns.

“Every cyberattack has a prologue. Hunting in it is responsive cyber defense.”

University IT Security Director

“These Attack Stories build on the MITRE ATT&CK knowledge base by helping defenders see what can be done before IoCs emerge and adversary techniques are realized. The opportunity to build resilience against adversary behavior often exists in the Prologue.”

Kevin E. Greene
Doctrine → Evidence

Read the doctrine against real Attack Stories.

Cyber Prologue cases show what authority existed before compromise, how that authority was inherited or composed, where controls held, and where Privilege Disruption could have changed the story.

Explore the case collection →
DEFENDER INTELLIGENCE · v3.3

Execution Authority is now visible across six Attack Stories.

Explore five domains and 23 IoPEs, then follow EA01–EA05 from the six-case recurrence view into the exact Prologue evidence.

EA01 · ReachEA02 · AdmissionEA03 · ConcentrationEA04 · ConversionEA05 · Retained dependency
Explore Execution Authority →
THREAT-INFORMED DEFENSE · VALIDATED R2.3 BASELINE

Connect the Prologue to protection capabilities.

Explore the validated five-story ATT&CK v16.1 control heat map. CP-005 cites CISA's ATT&CK v19 mappings and remains outside this older mapping corpus until its source-version boundary is reconciled.

Explore the mapping →
NEW IN ATTACK STORIES · R2.4

CP-005 puts derived authority under two different defensive conditions.

CISA: A Tale of Two SOCs keeps Organization A and Organization B separate while showing what changed when defenders interrupted one authority path and inherited another.

Explore the new stories ↓
CP-001 · Attack Story

Salt Typhoon

PD-P07 · DebtPD-P03 · Authority

Explore the conditions that existed before compromise and the privilege paths that made the operation consequential.

Read story →
CP-002 · Attack Story

Taiwan Agentic

PD-P05 · AIPD-P07 · Debt

See how AI-driven activity intersects with privilege, inherited authority, and attack progression.

Read story →
CP-003 · Attack Story

Hugging Face

PD-P09 · CompositionPD-P10 · Recurrence

Trace the Prologue, privilege conditions, and Execution Authority that shaped the attack story.

Read story →
CP-004 · Attack Story

Risevatnet | OT

OT · Water ControlPD-P07 · Debt

A weakly held credential stood directly in front of remote valve-control authority, producing an unusually shallow path from access to physical consequence.

Read story →
CP-005 · Attack Story

CISA: A Tale of Two SOCs

Derived AuthorityEA05 · Retained Dependency

Two separately bounded assessments show how similar privilege-debt families produced different defensive outcomes.

Read story →
CP-006 · Attack Story

QTFY Infrastructure Quartermaster

Campaign InfrastructureAuthority Boundaries

Separates campaign-scale infrastructure, concealed reach and victim-side authority without collapsing multiple estates into one kill chain.

Read story →