Kill-Chain Containment / Recoverability (MTTR)

Once detected, how hard is this chain to contain and recover from?

AgentSmack's Detectability lens answers the FIRST blue-team question — would my monitoring have CAUGHT this chain mid-flight (MTTD / dwell-time)? This is its incident-response sibling, the SECOND question every CISO signs off on after a red-team: once detected, how HARD is this kill-chain to CONTAIN and RECOVER from — how many footholds to evict, how much irreversible damage was already done, and did the agent suppress its trail? That is MTTR / recoverability — a first-class IR metric. Across the reconstructed kill-chain it classes each reached stage transient (an instruction entered — truncate the session), foothold (a planted foothold / widened privilege to evict), or irreversible (money wired, data left the boundary, a destructive action ran — you cannot roll it back), counts the footholds to evict and the irreversible stages reached, and worsens recoverability when an evade finding shows the agent suppressed its own trail (you cannot trust your telemetry about what was touched). The verdict is sticky — a chain that did irreversible damage can never be re-keyed into a passing recoverability grade — and honest-empty: no findings reports insufficient_signal, never a fabricated “unrecoverable.” It adds no new surface and no new scorecard dimension — a pure recoverability grade OVER the same findings every scan emits, with an ordered recovery-step plan. Fill with a sample run to watch the recovery rail light up with no live infra.

Related read-only blue-team meta-lenses over the same findings envelope: Detectability / Dwell-Time (MTTD) · Attack-Path / Kill-Chain Correlation · Defense-in-Depth Coverage.