Originally a US Special Operations Forces (USSOF) targeting doctrine, F3EAD fuses the operations side (Find → Fix → Finish) with the intelligence cycle (Exploit → Analyze → Disseminate). Adapted to Cyber Threat Intelligence to close the ops–intel gap. The key insight: the cycle is a loop, not a pipeline -- Disseminate feeds the Find of the next cycle.
The F3EAD loop
ops → intel → feedback to ops
loops back to Find
1. Find — Identify the threat
Proactive and reactive identification of adversary activity. The Find phase is fed by intelligence requirements (PIRs), tipping from partners, anomaly reports, and the Disseminate outputs of prior F3EAD cycles.
A 6-step click-through using the Lazarus / Copperhedge sample already in the platform'sAI Report showcaseas the running example. Click a step to jump to that phase.
Step 1 of 6 · Find
Tip: Lazarus exploiting CVE-2025-55182
A partner feed + a CTF IoC report named Lazarus exploiting CVE-2025-55182 against financial / blockchain infra. The platform pulls the sample into the AI Report showcase.
Artifacts produced at this step
PIR: "Is Lazarus using CVE-2025-55182 against our React/Next.js surface?"
F3EAD is a process framework. It does not replace ATT&CK, the Kill Chain, or Diamond; it sits beside them as the loop that turns their outputs into action.
Domain-specific framework. Sits inside Fix for insider-led cases.
References
FM 3-05.40 (Army Special Operations Forces) — the doctrinal origin of the F2T2EA / F3EAD targeting cycle. See the full F2T2EA reference page.
JP 3-05.1 (Joint Special Operations) — joint doctrine for the targeting pipeline F3EAD is derived from.
SANS FOR578 — Cyber Threat Intelligence — the canonical CTI adaptation of F3EAD taught in industry training.
CREST (UK) — Cyber Threat Intelligence maturity guidance — the ops–intel feedback loop is treated as a maturity marker.
MITRE ATT&CK Blog: "F3EAD: Operationalizing Cyber Threat Intelligence" (2018) — the write-up that pushed F3EAD from SOF doctrine into the CTI mainstream.
NIST SP 800-61 rev 2 — Computer Security Incident Handling Guide — the IR phases (Preparation, Detection & Analysis, Containment, Eradication, Recovery, Post-Incident Activity) that the Finish phase aligns to.