detection framework · traditional + AI plane · v0 · maturity reviewed 2026-08
adversary effort detection framework
Hierarchy of Hurt
weslambert · inspired by David Bianco's Pyramid of Pain (2013)
※This is a working framework, not a finished one — actively maintained, imperfect by design, and revised as real-world evidence (like JADEPUFFER) shows where it's incomplete. Layer boundaries, maturity calls, and hurt scores are judgment calls open to disagreement. If something's wrong, thin, or missing — open a PR or an issue, or reach out directly. Feedback that challenges the framework is more useful than feedback that just agrees with it.
How this relates to the Pyramid of Pain
Pyramid of Pain
Asks how difficult an indicator is for the adversary to change — and uses that difficulty as a practical, indicator-level proxy for what it costs them to recover. Bianco's original framing already ties pain to the adversary's actual investment: time spent on research, development, and retraining, not just technical mutability.
Hierarchy of Hurt
Asks the same recovery-cost question directly, for cases where difficulty-to-change stops being a reliable stand-in for it — clearest today in model fingerprint and synthetic identity, not uniformly across every AI-plane layer.
For most of the Foundation layers, difficulty-to-change is a genuinely reliable proxy for recovery cost, which is why Bianco's ordering has held up for over a decade largely unchanged — a hash is cheap to change and cheap to recover from, a TTP is hard to change and costly to recover from. HoH's Foundation layers follow that same ordering because there's no reason to relitigate a proxy that's still working.
The proxy stops working cleanly in at least two places. Swapping which LLM you use is trivially easy — an API call, arguably cheaper than rotating an IP — so ranking by change-difficulty alone would put it near the bottom. But whichever model gets used leaves a signature that can't be stripped by prompting, so getting caught here costs attribution exposure regardless of how cheap the swap was. That's why model fingerprint sits near the top of HoH instead. Synthetic identity plausibly follows the same pattern — a new persona is cheap to spin up, but a burned legend and lost trust history aren't. It's murkier elsewhere in the AI plane, though. Linguistic laundering doesn't obviously break the proxy at all — multi-pass laundering is genuinely effortful, so Bianco's original "harder to do, more valuable to detect" logic already tracks it reasonably well. And the prompt/interaction plane's high hurt score has more to do with almost nobody having built the visibility to detect it yet than with recovery cost outstripping change-difficulty — that's a defender-capability gap, not a proxy-validity gap, and treating it the same as the fingerprint case would overstate how novel the AI plane's challenge to PoP actually is. This isn't a gap in Bianco's thinking — his own framing was about recovery cost from the start, and difficulty-to-change was simply the best available proxy for it in 2013. Where it breaks, it's a gap in the proxy, in a domain that didn't exist yet — and it doesn't break the same way everywhere in that domain.
Hurt, here, means operational disruption cost. Detecting an IP address may delay an adversary for minutes — new VPS, new IP, back in operation. Detecting a tool forces them to rebuild or replace it — days to weeks of disruption. Detecting a TTP requires retraining operators and rebuilding muscle memory across the team. Detecting a TA operational signature forces them to retool their entire approach to how they run operations. At the AI plane, the adversary faces constraints they cannot simply spend their way out of: a model fingerprint is baked in by training and cannot be removed by prompting.
Lower-level detections — IPs, hashes, domains — remain essential for rapid response and volume triage. They are not dismissed here. But they impose limited long-term operational cost on a capable adversary. The framework is designed to help defenders understand that distinction and invest accordingly.
The framework is organized into three sections. The Foundation layers draw on Bianco's original structure, enriched with concrete event examples, data sources, and ATT&CK mappings. The HoH Extended layers add the TA operational signature as a bridge between traditional tradecraft and AI-assisted operations. The AI plane layers extend the same disruption-cost principle into territory that simply didn't exist in 2013 — model fingerprinting, linguistic laundering, synthetic identity operations, and the prompt/interaction plane.
Why this exists
Most detection frameworks stop at TTPs. The cost-of-disruption framing has not been applied to AI-assisted adversary operations — influence campaigns, BEC, synthetic persona networks, AI-augmented impersonation, and now fully agentic intrusion operations — which are already operational threats. Defenders need a structured way to think about where to invest, what to detect, and what operational cost each detection layer imposes on the adversary.
Modern adversaries can rotate infrastructure in minutes, regenerate malware automatically, and rebuild artifacts on demand. Change itself is cheap. But operational recovery — rebuilding tradecraft, retraining operators, redesigning workflows, absorbing the exposure cost of being detected — is not always cheap. That asymmetry is what the Hierarchy of Hurt is built to exploit. The question defenders should be asking is not just "can we detect this?" but "does detecting this actually cost the adversary something meaningful?"
The linguistic laundering concept — treating multi-model AI content generation as a money-laundering analog with placement, layering, and integration phases — provides a novel detection primitive grounded in disruption cost. The adversary's evasion effort creates the signal. Every additional laundering pass costs compute time and operational overhead while generating new artifacts. The harder they work to reduce their fingerprint, the more laundering signature they produce. Evasion and detection become mutually reinforcing.
The framework is also a maturity roadmap, revised as of the 2026 review. Foundation and HoH Extended layers are operational today. Synthetic identity / persona operations has moved from research-stage to operationally tracked — dedicated narrative-threat platforms are already finding and attributing fabricated-persona campaigns in production, though it's specialist tooling, not mainstream SOC capability yet. The prompt/interaction plane and the linguistic laundering signature remain emerging: commercial building blocks exist, but most orgs haven't deployed anything like them internally. Model fingerprinting proper — attributing content to a specific model lineage rather than just detecting "AI-generated" — remains the one layer where genuine research-stage framing still holds. Knowing where you are on that curve, and what it would cost an adversary if you could detect at higher layers, is what drives investment decisions.
↻2026 review note: this paragraph used to treat the whole AI plane as one undifferentiated "research-stage" bucket. See the maturity chip on each layer in the browser view, and the gap analysis / roadmap tabs, for the split. Recent campaigns also now includes JADEPUFFER — an agentic threat actor that doesn't map cleanly onto any existing AI-plane layer, which is itself a signal the framework may need a fifth one.
// with credit to David Bianco
Bianco's Pyramid of Pain (2013) established a foundational insight for detection prioritization: indicators that are harder for adversaries to change are more valuable to detect, because that difficulty tracks what it costs the adversary to recover — his own post frames pain in terms of the research, development, and retraining effort a detection forces on them, not just abstract mutability. The Foundation layers here draw closest to that original structure and reasoning. The HoH Extended layers add the TA operational signature as a bridge. The AI plane layers apply the same recovery-cost reasoning directly to a detection surface that didn't exist in 2013, and where difficulty-to-change stops being a reliable proxy for it. The insight, and its grounding in adversary recovery cost, are Bianco's. The AI plane extension — and naming the specific cases where the difficulty-to-change proxy breaks down — is the original contribution here.
←click any layer on the left to explore itobservable artifacts · detection approaches · data sources
An ode to David Bianco's Pyramid of Pain (2013). The traditional base preserves Bianco's core concept — hashes/IOCs at the bottom, TTPs at the top — with host and network artifacts split into distinct layers reflecting their different telemetry stacks. TA operational signature bridges traditional tradecraft to the AI plane. Four AI-specific layers extend upward: model fingerprint, linguistic laundering, synthetic identity / persona operations, and the prompt/interaction plane. Click any layer to expand.
traditional (Bianco)
traditional+
AI detection plane
AI — emerging
maturity ↓
operational
emerging / specialist
research
adversary pain to evade →
Node graph showing relationships between layers. Click any node to highlight connections and see details.
Each layer plotted by adversary hurt score (how expensive to evade — Y axis) vs. defender visibility (how instrumented most orgs are today — X axis). The upper-left quadrant — high hurt, low visibility — is where the strategic gaps live: adversaries paying the highest cost to be caught, and almost nobody catching them. Click any dot to explore that layer.
Methodology note: visibility is derived from the maturity tier assigned in the 2026 review (operational ≈ 85, specialist-operational ≈ 45, emerging ≈ 30, research ≈ 15), not a separate defender survey. Treat it as directional, not measured — recalibrate against your own org's actual instrumentation if you're using this for investment decisions.
Detection investment roadmap — layers grouped by when a typical org can realistically operationalize them, with prerequisites drawn from the hierarchy dependency graph. Use this to sequence investment rather than jumping straight to the highest-pain layer. Click any card to explore that layer.
Methodology note: grouping follows the maturity tiers directly — Now = operational today, Next = emerging or specialist-tooling-only, Later = still genuine research. Prerequisites are read off the existing dependency graph (a layer's incoming edges), not a separately maintained plan.
Recent campaigns mapped across the hierarchy — point-in-time examples of how real adversary operations touch each layer, whether detection occurred, and which layers were evaded. Click any layer chip to explore that layer.