35. The Pattern That Held
Domain: Security Frameworks — NIST, MITRE ATT&CK, Cyber Kill Chain, Diamond Model POV: Thread Reading time: ~15 minutes
In the months after the new compact was ratified, Thread began to notice something about the way the city’s defenders thought about the adversary.
They thought in fragments. Individual attacks, individual responses, individual lessons learned. The voice-device in the corridor was one incident; the poisoned shipment was another; the gear-chamber breach was a third. Each was analyzed separately, remediated separately, and filed away separately. There was no framework that connected them — no shared language for describing how the adversary operated, no common model for understanding the stages of an attack, no systematic way of sharing knowledge across the different teams and systems that were defending the city.
“We need a framework,” Thread said to the fellowship, late one night in the shed. “Not another procedure or another control. A way of thinking — a shared mental model that everyone can use to understand the adversary and to communicate about threats. Without a framework, every incident is unique, and every lesson has to be relearned.”
The framework that Thread developed drew on several sources — the old treatises that Quill had been studying, the patterns that Thread had been observing, the lessons that the fellowship had learned over months of defending the city.
The first component was a model of the adversary’s attack lifecycle — a sequence of stages that every significant attack seemed to follow. Thread called it the “Chain of Intrusion,” echoing terminology from the old treatises. Reconnaissance: the adversary gathered information about the target, probing defenses, identifying vulnerabilities, mapping the attack surface. Weaponization: the adversary developed or acquired the tools needed to exploit the vulnerabilities. Delivery: the adversary introduced the tools into the target’s environment — through a phishing message, a compromised supply chain, a social engineering attack. Exploitation: the adversary triggered the vulnerability, gaining initial access. Installation: the adversary established persistence — a backdoor, a compromised account, a mechanism that would survive reboots and resets. Command and Control: the adversary established a channel for communicating with the compromised system. Actions on Objectives: the adversary achieved their goal — stealing data, disrupting operations, corrupting infrastructure.
“Every significant attack we have experienced,” Thread explained, “followed this pattern. The voice-device: reconnaissance of the corridors, weaponization of the recording mechanism, delivery through Vale’s compromised agents, exploitation of Kip’s trust, and so on. The gear-chamber breach: reconnaissance of the barriers, weaponization of the Shroud-matter, delivery through the coordinated assault, exploitation of the boundary controller weaknesses. If we understand the pattern, we can disrupt the attack at any stage — not just the exploitation stage, where most of our defenses are concentrated.”
The second component was a model of the adversary’s techniques — a taxonomy of the specific methods that Vale and his agents had used. Thread compiled the taxonomy from the incident reports, the SIEM logs, the investigation findings, and the debriefings of the compromised insiders who had cooperated. Each technique was described and categorized: the initial access techniques (phishing, supply chain compromise, social engineering), the persistence techniques (backdoors, compromised accounts, corrupted mechanisms), the lateral movement techniques (credential theft, segment boundary exploitation), the exfiltration techniques (data theft, communication channel compromise). The taxonomy was not static — new techniques were added as they were discovered, old techniques were refined as new information became available.
The third component was a model of the adversary themselves — not just Vale, but the network of agents and allies and opportunists who had been attacking the city. Thread called it the “Adversary Profile”: a structured description of who the adversary was, what they wanted, what capabilities they possessed, and what infrastructure they relied on. The profile was updated continuously as new intelligence became available, and it was shared with every team that was involved in the city’s defense.
“This is what the treatises call a framework,” Quill said, studying the documents that Thread had produced. “A structured way of thinking about security that is consistent across different teams and different incidents. The NIST framework — named after an ancient institution that no longer exists — describes five functions: Identify, Protect, Detect, Respond, Recover. The Cyber Kill Chain describes the stages of an attack. The MITRE ATT&CK framework catalogs adversary techniques. And the Diamond Model describes the relationships between adversaries, capabilities, infrastructure, and victims. All of these frameworks serve the same purpose: to give defenders a shared language and a shared understanding.”
“Our framework serves that purpose too,” Thread said. “Not by copying the old frameworks exactly — the city is different from the world they were designed for. But by adapting their principles to our context. Every team in the city — the engineers, the archivists, the magistrates, the investigators — can use the Chain of Intrusion to understand how an attack is progressing. Every analyst can use the Technique Taxonomy to identify what the adversary is doing. Every strategist can use the Adversary Profile to anticipate what the adversary will do next.”
The framework proved its value during an attack that was unlike any the city had faced before.
A new adversary — not Vale, not the Archipelago faction, not the black market operatives — launched a campaign of information warfare against the city. False proclamations, fabricated evidence of corruption among the magistrates, manipulated communications that made it appear as though the council was planning to abandon the outer districts. The attack did not target the city’s infrastructure; it targeted the city’s trust — the belief that the council was acting in the citizens’ interests, the confidence that the defenses were holding, the social cohesion that had kept the city functioning through months of crisis.
The attack did not fit neatly into any of the patterns that the city’s defenders had prepared for. But because Thread had developed a framework — because the defenders had a shared language for describing adversarial behavior — they were able to adapt. The Chain of Intrusion helped them identify the attack’s stages: the reconnaissance (identifying the city’s social vulnerabilities), the weaponization (fabricating convincing falsehoods), the delivery (disseminating the falsehoods through compromised communication channels), the exploitation (eroding trust in the council). The Technique Taxonomy helped them categorize the adversary’s methods: disinformation, impersonation, psychological manipulation. And the Adversary Profile — updated continuously with new intelligence — helped them understand who was behind the attack and what they ultimately wanted.
The attack was repelled. Not by any single countermeasure, but by the combination of many: the public information campaign that Quill had established during the crisis, the communication channels that Kip had hardened against compromise, the culture of skepticism that the awareness program had cultivated. And the framework — the shared language and the shared understanding — was what allowed all of these defenses to work together.
“A framework is not a solution,” Thread said, at the debrief that followed. “It is a way of thinking about solutions. It does not tell you what to do. It tells you how to understand the problem. And understanding the problem is the first step toward solving it.”