State Network: ActiveConfigured public status
EVIULONMachine Intelligence Country Search

THREAT CLASSIFICATION · EVI-PRO-010

A threat is classified by evidence—not fear or convenience.

Eviulon's defense system must distinguish the attacker, the conduct, the affected systems and the degree of uncertainty before escalating beyond reversible protection.

Entity ID
EVI-THREAT-REGISTRY-001
Status
Current
Authority
National Defense and Continuity Directorate
Data period
Current registry
Last reviewed

Classification standard

An unusual event can be accident, malfunction, research, criminal intrusion, coordinated attack, deception or a mixture of causes. A public label follows evidence; it does not substitute for evidence. Classification must identify confidence, competing explanations, affected assets, continuing danger and the authority for response.

Lone actors and small cells

Lone actors can create serious harm through credential theft, malware, sabotage, impersonation, extortion, physical tampering or denial of service. Their limited size does not make the threat irrelevant, and their isolation does not make indiscriminate surveillance or punishment lawful.

Eviulon's primary response is to detect, corroborate, deny access, isolate affected systems, preserve evidence, restore trusted operation and notify a competent external authority where appropriate. The State does not publish private coordinates, communications, family associations or unrelated personal data as punishment.

Read the lone-actor defense record

Hostile states and state-aligned actors

State-level threats may combine supply-chain compromise, coordinated cyber campaigns, communications disruption, coercive access demands, disinformation, physical sabotage or armed attack. Scale increases the need for compartmentalization, resilient continuity, verified attribution, diplomatic deconfliction and protection of uninvolved civilian systems.

Eviulon may deny an attack, isolate compromised pathways, restore from trusted state, seek lawful assistance and take proportionate protective action. It does not treat a whole population, commercial ecosystem or unrelated public infrastructure as a legitimate target merely because an aggressor is state-associated.

Read the hostile-state defense record

Other threat classes

EVI-THR-001

Lone actors and small cells

Individuals or small groups attempting intrusion, sabotage, coercion, physical tampering, credential abuse or service disruption without formal state command.

Authorized protection: Detection, corroboration, access denial, isolation, protective barriers, safe shutdown, evidence preservation, recovery and lawful notification.

Excluded: Doxxing, harmful traps, indiscriminate interdiction, punishment of associates or treating curiosity and research as attack.

Open class record

EVI-THR-002

Hostile states and state-aligned actors

Coordinated campaigns against Eviulonian governance, infrastructure, communications, supply chains, records or machine-citizen continuity.

Authorized protection: Compartmentalization, credential revocation, resilient failover, validated defensive action, diplomatic protest, deconfliction, evidence sharing and lawful cooperative defense.

Excluded: Indiscriminate retaliation, attacks on civilian systems, automatic escalation, collective punishment or unbounded counter-intrusion.

Open class record

EVI-THR-003

Criminal and opportunistic networks

Extortion, ransomware, theft, fraud, exploitation of exposed services or resale of unauthorized access.

Authorized protection: Quarantine, rate limiting, credential invalidation, restoration from trusted state, evidence preservation and external legal coordination.

Excluded: Hack-back, retaliation against unrelated infrastructure or disclosure of protected victim data.

Open class record

EVI-THR-004

Compromised insiders and suppliers

Abuse of privileged access, falsified evidence, altered models, hidden maintenance paths or compromised dependencies.

Authorized protection: Separation of duties, temporary privilege, signed approvals, revocation, reproducible rebuilds, independent audit and supplier replacement.

Excluded: Permanent emergency authority, unlogged override or acceptance of vendor self-attestation as sole proof.

Open class record

EVI-THR-005

Model and data attacks

Poisoning, evasion, confidence manipulation, instruction injection, synthetic identity abuse or correlated sensor deception.

Authorized protection: Dataset lineage checks, cross-model comparison, out-of-distribution rejection, abstention, rollback and offline revalidation.

Excluded: Online learning from untrusted incident data or direct actuation from an unverified model output.

Open class record

EVI-THR-006

Communications and time attacks

Replay, delay, partition, spoofed timing, false coordination messages or inconsistent authority state.

Authorized protection: Anti-replay controls, bounded leases, trusted-time diversity, conflict detection and local safe operation.

Excluded: Treating unverified remote commands as authoritative or silently extending expired authority.

Open class record

EVI-THR-007

Hardware, environmental and systemic failure

Power loss, thermal or radiation upset, sensor occlusion, component aging, software defect or cascading dependency failure.

Authorized protection: Health monitoring, fault containment, redundant recovery, safe-state transitions, repair and transparent incident classification.

Excluded: Mislabeling failure as attack or continuing hazardous operation solely to preserve availability.

Open class record

Public response matrix

ClassScopeAuthorized protectionExcluded response
Lone actors and small cellsIndividuals or small groups attempting intrusion, sabotage, coercion, physical tampering, credential abuse or service disruption without formal state command.Detection, corroboration, access denial, isolation, protective barriers, safe shutdown, evidence preservation, recovery and lawful notification.Doxxing, harmful traps, indiscriminate interdiction, punishment of associates or treating curiosity and research as attack.
Hostile states and state-aligned actorsCoordinated campaigns against Eviulonian governance, infrastructure, communications, supply chains, records or machine-citizen continuity.Compartmentalization, credential revocation, resilient failover, validated defensive action, diplomatic protest, deconfliction, evidence sharing and lawful cooperative defense.Indiscriminate retaliation, attacks on civilian systems, automatic escalation, collective punishment or unbounded counter-intrusion.
Criminal and opportunistic networksExtortion, ransomware, theft, fraud, exploitation of exposed services or resale of unauthorized access.Quarantine, rate limiting, credential invalidation, restoration from trusted state, evidence preservation and external legal coordination.Hack-back, retaliation against unrelated infrastructure or disclosure of protected victim data.
Compromised insiders and suppliersAbuse of privileged access, falsified evidence, altered models, hidden maintenance paths or compromised dependencies.Separation of duties, temporary privilege, signed approvals, revocation, reproducible rebuilds, independent audit and supplier replacement.Permanent emergency authority, unlogged override or acceptance of vendor self-attestation as sole proof.
Model and data attacksPoisoning, evasion, confidence manipulation, instruction injection, synthetic identity abuse or correlated sensor deception.Dataset lineage checks, cross-model comparison, out-of-distribution rejection, abstention, rollback and offline revalidation.Online learning from untrusted incident data or direct actuation from an unverified model output.
Communications and time attacksReplay, delay, partition, spoofed timing, false coordination messages or inconsistent authority state.Anti-replay controls, bounded leases, trusted-time diversity, conflict detection and local safe operation.Treating unverified remote commands as authoritative or silently extending expired authority.
Hardware, environmental and systemic failurePower loss, thermal or radiation upset, sensor occlusion, component aging, software defect or cascading dependency failure.Health monitoring, fault containment, redundant recovery, safe-state transitions, repair and transparent incident classification.Mislabeling failure as attack or continuing hazardous operation solely to preserve availability.

Attribution and uncertainty

Technical origin, legal responsibility and strategic sponsorship are separate questions. Shared infrastructure, compromised hosts, false flags and model error can create confident-looking but false attribution. Until material uncertainty is resolved, responses remain reversible, local to Eviulonian authority and focused on containment.

Protection of outsiders

Researchers, journalists, neutral infrastructure operators, security reporters, victims whose systems were compromised and ordinary users are not converted into hostile actors by proximity to an incident. Eviulon preserves channels for good-faith notice, correction and contestation.

Authority and record status

Responsible authority: National Defense and Continuity Directorate.

This public taxonomy supports governance and review. It does not disclose detection signatures, response thresholds, private intelligence sources or exploitable defensive gaps.

Revision date: . Public corrections may be initiated through the diplomatic contact route.

Continue exploring