How Engagements Run
How Engagements Run — Subscriptions & the Attack Engine
Two tiers: the catalog and your subscription
The platform keeps a registry — the catalog of every methodology it is approved to run. Your engagement is a subscription: the subset of that catalog you select, bound to your surfaces, targets, and depth. The engine that executes it all — Mangonel — runs only the intersection of three gates, so your selection is both what you bought and the boundary you consented to.
If a methodology isn't registered, the engine can't see it. If your engagement didn't subscribe to it, the engine won't run it — even when it's approved. And nothing runs deeper than your ceiling.
What you select
- Attack surfaces — external network, web/API, internal, cloud, social/voice.
- Methodologies per surface — a surface can offer more than one package; you subscribe to the ones you want.
- Depth (Surrender ceiling) per surface — S0–S1 recon-only through S4 objective (see Surrender Levels).
Didn't subscribe to social engineering? Your employees cannot be vished on that engagement. Selection is consent, per surface.
A worked path: external recon at S1
The full path from a selection on the contract to results on your engagement record:
- You subscribe the external-network surface to the external-recon methodology, ceiling S1.
- Mangonel resolves the runnable set (registry ∩ subscription ∩ ceiling) and builds the plan.
- The Authorization Gate checks each technique: recon runs at S0–S1 against in-scope targets only, and is passive — so it clears automatically, no human approval needed.
- Recon techniques execute: passive DNS, certificate transparency, subdomain enumeration, service-exposure mapping, technology fingerprinting.
- Each emits normalized output — Assets and Findings in the same shape every methodology produces, so results interoperate.
- Assets and findings land on the engagement record, become visible in the portal, and feed any deeper surfaces you subscribed (recon is the input to everything else).