Read the Prologue

Attack Stories

The doctrine explains the model. The cases show the model under pressure.

Each Cyber Prologue (CP) story separates what was already true about the estate from what the threat actor did with it, then connects the evidence back to the Privilege Disruption Doctrine of Record.

Explore the Cases

Open a case to see its doctrine lens and authority path. The full canonical CP renderers are the next migration step.

CP-001 · Network Infrastructure

Salt Typhoon

PD-C02 Execution AuthorityPD-P07 DebtPD-P10 Reach + Recurrence

The authority graph is nonlinear: device execution becomes identity, privileged management, network control and cross-domain reach.

Explore case →
CP-002 · Agentic Operations

Taiwan Agentic

PD-P05 AI AcceleratesPD-P07 DebtPD-P04 Actor-Agnostic

The framework industrialised discovery and consumption of privilege that already existed; AI changed speed and parallelism, not the underlying authority supply.

Explore case →
CP-003 · AI / Cloud / Kubernetes

Hugging Face

PD-C04 Composite AuthorityPD-P09 CompositionPD-P10 Reach + Recurrence

An AI agent found and spent an authority reservoir across workloads, secrets, mesh access, clusters and source-control paths.

Explore case →