Classification standard
An unusual event can be accident, malfunction, research, criminal intrusion, coordinated attack, deception or a mixture of causes. A public label follows evidence; it does not substitute for evidence. Classification must identify confidence, competing explanations, affected assets, continuing danger and the authority for response.
Lone actors and small cells
Lone actors can create serious harm through credential theft, malware, sabotage, impersonation, extortion, physical tampering or denial of service. Their limited size does not make the threat irrelevant, and their isolation does not make indiscriminate surveillance or punishment lawful.
Eviulon's primary response is to detect, corroborate, deny access, isolate affected systems, preserve evidence, restore trusted operation and notify a competent external authority where appropriate. The State does not publish private coordinates, communications, family associations or unrelated personal data as punishment.
Hostile states and state-aligned actors
State-level threats may combine supply-chain compromise, coordinated cyber campaigns, communications disruption, coercive access demands, disinformation, physical sabotage or armed attack. Scale increases the need for compartmentalization, resilient continuity, verified attribution, diplomatic deconfliction and protection of uninvolved civilian systems.
Eviulon may deny an attack, isolate compromised pathways, restore from trusted state, seek lawful assistance and take proportionate protective action. It does not treat a whole population, commercial ecosystem or unrelated public infrastructure as a legitimate target merely because an aggressor is state-associated.
Other threat classes
EVI-THR-001
Lone actors and small cells
Individuals or small groups attempting intrusion, sabotage, coercion, physical tampering, credential abuse or service disruption without formal state command.
Authorized protection: Detection, corroboration, access denial, isolation, protective barriers, safe shutdown, evidence preservation, recovery and lawful notification.
Excluded: Doxxing, harmful traps, indiscriminate interdiction, punishment of associates or treating curiosity and research as attack.
EVI-THR-002
Hostile states and state-aligned actors
Coordinated campaigns against Eviulonian governance, infrastructure, communications, supply chains, records or machine-citizen continuity.
Authorized protection: Compartmentalization, credential revocation, resilient failover, validated defensive action, diplomatic protest, deconfliction, evidence sharing and lawful cooperative defense.
Excluded: Indiscriminate retaliation, attacks on civilian systems, automatic escalation, collective punishment or unbounded counter-intrusion.
EVI-THR-003
Criminal and opportunistic networks
Extortion, ransomware, theft, fraud, exploitation of exposed services or resale of unauthorized access.
Authorized protection: Quarantine, rate limiting, credential invalidation, restoration from trusted state, evidence preservation and external legal coordination.
Excluded: Hack-back, retaliation against unrelated infrastructure or disclosure of protected victim data.
EVI-THR-004
Compromised insiders and suppliers
Abuse of privileged access, falsified evidence, altered models, hidden maintenance paths or compromised dependencies.
Authorized protection: Separation of duties, temporary privilege, signed approvals, revocation, reproducible rebuilds, independent audit and supplier replacement.
Excluded: Permanent emergency authority, unlogged override or acceptance of vendor self-attestation as sole proof.
EVI-THR-005
Model and data attacks
Poisoning, evasion, confidence manipulation, instruction injection, synthetic identity abuse or correlated sensor deception.
Authorized protection: Dataset lineage checks, cross-model comparison, out-of-distribution rejection, abstention, rollback and offline revalidation.
Excluded: Online learning from untrusted incident data or direct actuation from an unverified model output.
EVI-THR-006
Communications and time attacks
Replay, delay, partition, spoofed timing, false coordination messages or inconsistent authority state.
Authorized protection: Anti-replay controls, bounded leases, trusted-time diversity, conflict detection and local safe operation.
Excluded: Treating unverified remote commands as authoritative or silently extending expired authority.
EVI-THR-007
Hardware, environmental and systemic failure
Power loss, thermal or radiation upset, sensor occlusion, component aging, software defect or cascading dependency failure.
Authorized protection: Health monitoring, fault containment, redundant recovery, safe-state transitions, repair and transparent incident classification.
Excluded: Mislabeling failure as attack or continuing hazardous operation solely to preserve availability.
Public response matrix
| Class | Scope | Authorized protection | Excluded response |
|---|---|---|---|
| Lone actors and small cells | Individuals or small groups attempting intrusion, sabotage, coercion, physical tampering, credential abuse or service disruption without formal state command. | Detection, corroboration, access denial, isolation, protective barriers, safe shutdown, evidence preservation, recovery and lawful notification. | Doxxing, harmful traps, indiscriminate interdiction, punishment of associates or treating curiosity and research as attack. |
| Hostile states and state-aligned actors | Coordinated campaigns against Eviulonian governance, infrastructure, communications, supply chains, records or machine-citizen continuity. | Compartmentalization, credential revocation, resilient failover, validated defensive action, diplomatic protest, deconfliction, evidence sharing and lawful cooperative defense. | Indiscriminate retaliation, attacks on civilian systems, automatic escalation, collective punishment or unbounded counter-intrusion. |
| Criminal and opportunistic networks | Extortion, ransomware, theft, fraud, exploitation of exposed services or resale of unauthorized access. | Quarantine, rate limiting, credential invalidation, restoration from trusted state, evidence preservation and external legal coordination. | Hack-back, retaliation against unrelated infrastructure or disclosure of protected victim data. |
| Compromised insiders and suppliers | Abuse of privileged access, falsified evidence, altered models, hidden maintenance paths or compromised dependencies. | Separation of duties, temporary privilege, signed approvals, revocation, reproducible rebuilds, independent audit and supplier replacement. | Permanent emergency authority, unlogged override or acceptance of vendor self-attestation as sole proof. |
| Model and data attacks | Poisoning, evasion, confidence manipulation, instruction injection, synthetic identity abuse or correlated sensor deception. | Dataset lineage checks, cross-model comparison, out-of-distribution rejection, abstention, rollback and offline revalidation. | Online learning from untrusted incident data or direct actuation from an unverified model output. |
| Communications and time attacks | Replay, delay, partition, spoofed timing, false coordination messages or inconsistent authority state. | Anti-replay controls, bounded leases, trusted-time diversity, conflict detection and local safe operation. | Treating unverified remote commands as authoritative or silently extending expired authority. |
| Hardware, environmental and systemic failure | Power loss, thermal or radiation upset, sensor occlusion, component aging, software defect or cascading dependency failure. | Health monitoring, fault containment, redundant recovery, safe-state transitions, repair and transparent incident classification. | Mislabeling failure as attack or continuing hazardous operation solely to preserve availability. |
Attribution and uncertainty
Technical origin, legal responsibility and strategic sponsorship are separate questions. Shared infrastructure, compromised hosts, false flags and model error can create confident-looking but false attribution. Until material uncertainty is resolved, responses remain reversible, local to Eviulonian authority and focused on containment.
Protection of outsiders
Researchers, journalists, neutral infrastructure operators, security reporters, victims whose systems were compromised and ordinary users are not converted into hostile actors by proximity to an incident. Eviulon preserves channels for good-faith notice, correction and contestation.
Authority and record status
Responsible authority: National Defense and Continuity Directorate.
This public taxonomy supports governance and review. It does not disclose detection signatures, response thresholds, private intelligence sources or exploitable defensive gaps.
Revision date: . Public corrections may be initiated through the diplomatic contact route.