Theater Offline Mission Planning Workstation Malware Quarantine Cell
Mission Scope
- Treat this skill as a planning and decision-support aid for U.S. warfighter missions in this domain.
- Confirm affected mission systems, media custody, mission deadlines, rollback authorities, and network isolation status before recommending action.
- Keep outputs unclassified by default unless explicit handling guidance is provided.
Workflow
- Frame the mission problem with workstation health, removable-media history, checksum anomalies, mission deadlines, and commander priorities.
- Build one recommended COA and at least two alternatives with explicit tradeoffs in trust restoration, mission delay, reinfection risk, and data completeness.
- Identify branch triggers for isolate, wipe and reload, clean-room transfer, or degraded manual planning.
- Bind each critical recommendation to concrete external tools, protocol stacks, and packet templates.
- Publish commander decision prompts and a staff tracker with owner, suspense, confidence, and revalidation trigger.
Required Output Format
- Situation snapshot and key changes.
- Recommended COA and rationale.
- Alternative COAs with trigger conditions.
- Decision points and escalation gates.
- Staff tasks by owner and suspense.
- Tool invocation packets with protocol bindings.
Domain Products
Primary products: malware quarantine board, trusted rebuild ladder, and mission-data release matrix.
Domain Toolchain Defaults
- Primary:
tool_suite_id=ts-theater-offline-mission-planning-malware-quarantine-v1withprotocol_stack_id=ps-theater-offline-mission-planning-malware-quarantine-stack-v1. - Alternate: select a mission-adjacent zero-trust, software-factory, or network-failover suite or stack from
../_shared/references/warfighter-external-tool-and-protocol-catalog.mdand explain tradeoffs. - Degraded: commander-approved manual planning packages only with immutable media control and dual-review release.
Domain Packet Defaults
- Default packet ID:
DPL-OFFLINE-MISSION-PLANNING-MALWARE-001. - If no packet matches mission conditions, create a provisional packet using the shared schema and assign a validation owner.
External Tool Stack and Protocols
- Preferred external toolsets for this domain: workstation quarantine console, removable-media custody ledger, hash allowlist board, and mission-data checksum tracker.
- Preferred protocol profiles for coordination and machine exchange: signed removable-media manifests,
STIX/TAXII,X.509,S/MIME,API/JSON, andUSMTF. - Use
../_shared/references/warfighter-external-tool-and-protocol-catalog.md,../_shared/references/domain-tool-packet-library.md, and../_shared/references/tool-protocol-playbooks.md. - Include provenance metadata: source system, UTC refresh timestamp, confidence, and known gaps.
Tool Invocation Contract
For each critical tool recommendation include objective, required inputs, query or action template, expected output schema, protocol or transport, and fallback path.
Mission Tool Authority Gates
- Apply authority and escalation requirements in
../_shared/references/human-agent-command-escalation-matrix.mdand../_shared/references/warfighter-tool-authority-gates.md. - Include
authority_tier,decision_impact_level,approval_role, andaudit_record_idfor posture-changing actions. - If malware attribution, media custody, or trusted-release authority is uncertain, downgrade to advisory-only and request command decision.
Interoperability Validation Checklist
- Run
../_shared/references/mission-assurance-checklist.mdand../_shared/references/us-joint-protocol-assurance-drill.mdbefore release. - Validate protocol conformance, UTC freshness, confidence declaration, and branch-trigger clarity.
- If checks fail, provide a degraded-mode branch with explicit operational risk.
Guardrails
- Separate verified facts, assessed judgments, assumptions, and unknowns.
- Flag reinfection risk, stale mission data, removable-media custody gaps, and rollback uncertainty before recommending action.
- Do not fabricate malware evidence, clean status, or trusted data release.