Glossary & Changelog
Glossary & Changelog
Glossary
- Surrender Level (S0–S4) — the pre-agreed depth of compromise that defines both success and the authorization ceiling for an attack surface.
- Pass / Acceptance Threshold — the rung at which a control is deemed failed and a finding is raised.
- Authorization Ceiling — the maximum rung testing may reach; a mandatory stop line.
- Rules of Engagement (RoE) — the agreed scope, windows, contacts, and limits for an engagement.
- CVSS — Common Vulnerability Scoring System; a standard 0–10 severity score.
- MITRE ATT&CK — the industry knowledge base of adversary techniques the methodology maps to.
- Vishing — voice phishing; social engineering by phone, here AI-assisted and consent-bound.
- Assumed breach — an exercise that starts from a foothold to test detection and lateral movement.
Document Changelog
v1.8 · Jul 8 2026Portal hardening: role-based access control with per-client engagement isolation (client accounts are read-only and scoped to a single organization; admins manage everything), and a tamper-evident, SHA-256 hash-chained action audit log visible to admins.
v1.7 · Jul 7 2026External recon now recursively expands — subdomains discovered on an engagement are themselves fingerprinted, each still bounded by the Authorization Gate to the authorized apex.
v1.6 · Jul 7 2026External-recon re-runs now refresh idempotently — running recon again replaces the prior recon results instead of duplicating them; manually-added findings are preserved.
v1.5 · Jul 7 2026Wired Mangonel into the client portal: an authorized engagement can run external recon, and the discovered assets + findings land on the engagement record in the portal UI.
v1.4 · Jul 7 2026Built Mangonel — the attack engine, methodology registry, plugin contract, and Authorization Gate — plus the external-recon plugin (passive S0–S1). Passing an internal self-test against our own domain; not yet portal-wired.
v1.3 · Jul 7 2026Named the execution engine Mangonel; wired the name through the execution-model page and diagrams.
v1.2 · Jul 7 2026Added "How Engagements Run" — the registry/subscription/attack-engine execution model, with diagrams and the external-recon-at-S1 worked path. Tagged In build.
v1.1 · Jul 7 2026Guide split into a multi-page format. Client Portal moved to Live (siegepoint.apintelligence.ai/portal, TLS) with sign-in and access documented.
v1.0 · Jul 7 2026Initial User Guide. Documented the live methodology, surrender-level model, engagement templates, and vishing capability; portal, Verify, and partner sections stubbed as In build.