The execution layer: the pages that drive a live, time-boxed assessment — routing when you stall, and evidence discipline so the report writes itself. Technique detail lives in the Field Manual; this is the cockpit you operate from.
🚦 Drive
- Engagement_Cockpit — the single page to keep open: time-box checkpoints, phase tracker, host tracker, credential ledger, and the where-to-go-next router.
🧭 Route — “where do I go next?”
- Symptom_Index — start from what you’re seeing (an error or odd behaviour) → likely cause, route, and proof to capture.
- Decision_Trees — start from your access state; the hub for the six situation pages, each carrying a
⏱️ Stop condition: - Attack_Patterns — reusable, box-agnostic pattern cards distilled from the write-ups.
📝 Report
- Reporting_SysReptor — evidence discipline (folders, logging, screenshots), the findings tracker, and the SysReptor workflow.
- Finding_Library — reusable finding templates seeded from the manual’s
📝 Reporting Triggerblocks.
Operating loop: keep the Engagement_Cockpit open → when stuck, route by symptom (Symptom_Index) or by access state (Decision_Trees) → recognise the shape (Attack_Patterns) → capture evidence as you go (Reporting_SysReptor) → assemble findings (Finding_Library).