Originally a US Special Operations Forces (USSOF) targeting doctrine, F3EAD fuses the operations side (Find → Fix → Finish) with the intelligence cycle (Exploit → Analyze → Disseminate). Adapted to Cyber Threat Intelligence to close the ops–intel gap. The key insight: the cycle is a loop, not a pipeline -- Disseminate feeds the Find of the next cycle.
Proactive and reactive identification of adversary activity. The Find phase is fed by intelligence requirements (PIRs), tipping from partners, anomaly reports, and the Disseminate outputs of prior F3EAD cycles.
A 6-step click-through using the Lazarus / Copperhedge sample already in the platform'sAI Report showcaseas the running example. Click a step to jump to that phase.
Step 1 of 6 · Find
A partner feed + a CTF IoC report named Lazarus exploiting CVE-2025-55182 against financial / blockchain infra. The platform pulls the sample into the AI Report showcase.
Artifacts produced at this step
next: Fix
F3EAD is a process framework. It does not replace ATT&CK, the Kill Chain, or Diamond; it sits beside them as the loop that turns their outputs into action.
| Note | |||||
|---|---|---|---|---|---|
| F3EAD | process | How does the team operate end-to-end on a target? | CTI + SOC + IR | /ti/f3ead | Closes the ops-intel feedback loop. Pairs with every other framework here. |
| Lockheed Kill Chain | content | What phases did the intrusion pass through? | DFIR + SOC | /d/kill-chain | Linear, 7 phases. Criticised for being too sequential for modern intrusions. |
| MITRE ATT&CK | content | Which specific techniques did the adversary use? | Detection eng + CTI | /ti/mitre | The shared vocabulary. F3EAD uses ATT&CK inside the Analyze phase. |
| Diamond Model | content | Who did what to whom, and how? | CTI + IR | /d/diamond | Per-event reconstruction. Slots into Analyze. |
| ACH | process | Which hypothesis best explains the evidence? | CTI analysts | /ti/ach | Structured analytic technique used inside the Analyze phase. |
| Insider Threat Matrix | content | What motive, means, preparation, or infringement is in play? | Insider-threat teams | /ti/insider-threat-matrix | Domain-specific framework. Sits inside Fix for insider-led cases. |