No matter how complete your control catalog, your ATO package or your compliance calendar, a determined adversary can typically find a way into your network.
But where do you put your defense? What do you move first, and what do you give up to hold what matters? The ASOM-Fed™ framework answers those questions by providing a defender's knowledge base of durable forms of defensive maneuver and the techniques that implement them — arrayed on federal cyber terrain rather than listed as controls. Armed with it, agencies can plan defense as a campaign with a main effort, not as an undifferentiated grind.
An adversary-behavior matrix tells you what will be done to you. It does not tell you how to array your own force. ASOM-Fed is the complementary half: the columns are the ten forms of defensive cyber maneuver — durable categories that outlive any product — and the cells are the techniques that give each form effect on real ground.
The distinction is doctrinal, not cosmetic. Forms of maneuver are chosen by leaders and stated as intent; techniques are chosen by engineers and change constantly. Separating them is what lets a CISO direct a defense without having to be an engineer, and lets engineers re-tool without re-writing the plan.
ASOM-Fed fuses two mature bodies of Army doctrine that are rarely combined — the scheme of maneuver from operational art, and the analytic process of ATP 2-33.4 — onto the federal zero-trust terrain described by the CISA Zero Trust Maturity Model, NIST SP 800-207, TIC 3.0 and OMB M-22-09.
It is agency-agnostic by construction. Every technique here is written against a generic Federal Reference Agency archetype; adopters substitute their own systems, boundaries and mission threads. threatDefendr publishes it as an open reference framework — free to use, free to extend.
Threat courses of action come from many sources — past incidents, commercial intelligence, information-sharing groups, and partner advisories. ASOM-Fed gives analysts a common language to state what a given adversary forces you to do: array the same matrix against the most-likely and the most-dangerous course of action, and the difference between the two overlays is your planning problem.
Score your own estate cell by cell — implemented, partial, or absent — and the matrix becomes a campaign plan rather than a poster. Whole columns that come up red are not missing products; they are forms of maneuver you cannot currently perform, which is a far more actionable finding than an open POA&M.
The best defense is a tested defense. Because every cell states what success looks like, the matrix doubles as an assessment plan: a red team is given a form of maneuver to defeat, and the cell's success indicator is the pass/fail condition. This finds gaps in visibility, tooling and process the way an exercise does — and then fixes them through the M10 column.
threatDefendr encourages agencies, integrators and researchers to adopt ASOM-Fed, extend the maneuver catalog, and contribute techniques back. The framework is unclassified, illustrative, and built from public sources only.
Eleven columns — the durable forms of defensive cyber maneuver. One hundred and fifty cells — the techniques that give them effect. Select any cell for its intent, its success indicator, its terrain layer, and the ASOM-Fed controls that make it assessable.
My coverage is live. Click any cell to open it and set its state, or shift-click a cell to cycle absent → partial → implemented in place. Scores are kept in this browser only and never leave it. Export JSON writes them out for your GRC system.