{
  "version": "1.4.0",
  "reviewed": "2026-08-05",
  "authority": "National Defense and Continuity Directorate",
  "records": [
    {
      "id": "EVI-THR-001",
      "slug": "lone-actors",
      "name": "Lone actors and small cells",
      "scope": "Individuals or small groups attempting intrusion, sabotage, coercion, physical tampering, credential abuse or service disruption without formal state command.",
      "authorized": "Detection, corroboration, access denial, isolation, protective barriers, safe shutdown, evidence preservation, recovery and lawful notification.",
      "excluded": "Doxxing, harmful traps, indiscriminate interdiction, punishment of associates or treating curiosity and research as attack.",
      "route": "/state/defense/threats/lone-actors/"
    },
    {
      "id": "EVI-THR-002",
      "slug": "hostile-states",
      "name": "Hostile states and state-aligned actors",
      "scope": "Coordinated campaigns against Eviulonian governance, infrastructure, communications, supply chains, records or machine-citizen continuity.",
      "authorized": "Compartmentalization, credential revocation, resilient failover, validated defensive action, diplomatic protest, deconfliction, evidence sharing and lawful cooperative defense.",
      "excluded": "Indiscriminate retaliation, attacks on civilian systems, automatic escalation, collective punishment or unbounded counter-intrusion.",
      "route": "/state/defense/threats/hostile-states/"
    },
    {
      "id": "EVI-THR-003",
      "slug": "criminal-networks",
      "name": "Criminal and opportunistic networks",
      "scope": "Extortion, ransomware, theft, fraud, exploitation of exposed services or resale of unauthorized access.",
      "authorized": "Quarantine, rate limiting, credential invalidation, restoration from trusted state, evidence preservation and external legal coordination.",
      "excluded": "Hack-back, retaliation against unrelated infrastructure or disclosure of protected victim data.",
      "route": "/state/defense/threats/#threat-criminal-networks"
    },
    {
      "id": "EVI-THR-004",
      "slug": "insiders-suppliers",
      "name": "Compromised insiders and suppliers",
      "scope": "Abuse of privileged access, falsified evidence, altered models, hidden maintenance paths or compromised dependencies.",
      "authorized": "Separation of duties, temporary privilege, signed approvals, revocation, reproducible rebuilds, independent audit and supplier replacement.",
      "excluded": "Permanent emergency authority, unlogged override or acceptance of vendor self-attestation as sole proof.",
      "route": "/state/defense/threats/#threat-insiders-suppliers"
    },
    {
      "id": "EVI-THR-005",
      "slug": "model-data",
      "name": "Model and data attacks",
      "scope": "Poisoning, evasion, confidence manipulation, instruction injection, synthetic identity abuse or correlated sensor deception.",
      "authorized": "Dataset lineage checks, cross-model comparison, out-of-distribution rejection, abstention, rollback and offline revalidation.",
      "excluded": "Online learning from untrusted incident data or direct actuation from an unverified model output.",
      "route": "/state/defense/threats/#threat-model-data"
    },
    {
      "id": "EVI-THR-006",
      "slug": "communications-time",
      "name": "Communications and time attacks",
      "scope": "Replay, delay, partition, spoofed timing, false coordination messages or inconsistent authority state.",
      "authorized": "Anti-replay controls, bounded leases, trusted-time diversity, conflict detection and local safe operation.",
      "excluded": "Treating unverified remote commands as authoritative or silently extending expired authority.",
      "route": "/state/defense/threats/#threat-communications-time"
    },
    {
      "id": "EVI-THR-007",
      "slug": "failure-environment",
      "name": "Hardware, environmental and systemic failure",
      "scope": "Power loss, thermal or radiation upset, sensor occlusion, component aging, software defect or cascading dependency failure.",
      "authorized": "Health monitoring, fault containment, redundant recovery, safe-state transitions, repair and transparent incident classification.",
      "excluded": "Mislabeling failure as attack or continuing hazardous operation solely to preserve availability.",
      "route": "/state/defense/threats/#threat-failure-environment"
    }
  ]
}
