The US joint targeting cycle (JP 3-60) that F3EAD descends from. F2T2EA is the ops-pure original: Find → Fix → Track → Target → Engage → Assess. Adapted to Cyber Threat Intelligence it is the discipline of locating an adversary, pinning it down, watching it, deciding what to do, doing it, and measuring the result. The key insight: Assess feeds the Find of the next cycle -- the loop is what makes targeting repeatable.
The F2T2EA loop
locate → act → feedback to locate
loops back to Find
1. Find — Locate the target
The collection half of the cycle: identify targets of interest from PIRs, partner tipping, anomaly reports, and the Assess outputs of prior cycles. In F2T2EA, Find is deliberately broad -- you locate before you decide anything about the target.
A 6-step click-through using the Lazarus / Copperhedge sample already in the platform'sAI Report showcaseas the running example. Click a step to jump to that phase.
Step 1 of 6 · Find
Tip: Lazarus exploiting CVE-2025-55182
A partner feed + a CTF IoC report named Lazarus exploiting CVE-2025-55182 against financial / blockchain infra. The platform pulls the sample into the AI Report showcase.
Artifacts produced at this step
PIR: "Is Lazarus using CVE-2025-55182 against our React/Next.js surface?"
F2T2EA is a process framework from joint targeting doctrine. It does not replace ATT&CK, the Kill Chain, or Diamond; it sits beside them as the loop that turns their outputs into a decision to act.