Every Break-In Has a Three-Act Structure
I spent 30 years studying campaigns for their structure. Now I study intrusions for theirs.

Part 8 of an ongoing series. Read Part 1 here.
"You really need to study past attacks to know what to look for."
I wrote that in my journal this week, halfway through Linux Security Monitoring, half-frustrated with a process tree I couldn't quite parse. I underlined it. Then I put the pen down and thought: I already know this sentence. I've known it for thirty years. I just used to apply it to something else.
Here's the thing nobody tells you about advertising: nothing is original. Not really. Every campaign that ever worked follows a structure someone else already found. You don't invent a great ad from nothing — you study the ones that landed. Cannes Lions winners. The old case histories everyone in the industry has seen a hundred times. You learn to recognize the shape of "this works" before you can build another one.
Hook. Tension. Payoff. Every single time. The execution changes — the client, the product, the decade — but the bones underneath are the same three-act structure, over and over. Once you've seen it enough times, you stop noticing the surface and start seeing the skeleton.
That's exactly what I'm doing now. Except the campaigns are break-ins.
This week I moved from Windows Security Monitoring into Linux. First thing I noticed: Linux logs are literal. Windows makes you decode; Linux mostly just tells you. grep, comm, diff — three commands, and suddenly you're reading a system's diary instead of guessing at it. I wrote that Linux is "the friendlier system" and that bash fluency is a genuine advantage. I meant it. It's the first tool in this whole path that felt like it was on my side.
But fluency in the language isn't the same as fluency in the story. And that's where the process tree tripped me up.
A process tree is parent, child, grandchild — this spawned that, which spawned this. On paper it's simple. In practice, staring at a real one, I kept losing the thread. Where does this chain of custody actually start? What's the inciting incident?
Then it hit me: I've spent my whole career reading exactly this shape. An org chart. An account hierarchy. Who briefed whom, who signed off, where the idea actually originated before it got filtered through four rounds of approval. I know how to trace lineage. I just didn't recognize it wearing a different costume.
The real unlock this week wasn't a tool. It was a book.
I'm reading Sparc Flow's Hack Like a Pornstar — a fictionalized, blow-by-blow account of a real intrusion, start to finish. And it read, to me, exactly like a great campaign case study. Not a technical manual. A narrative. Recon first — quiet, patient, figuring out the target before you ever touch it. Then the opening — the phish, the exposed service, the one weak door in a wall of strong ones. Then the third act: escalation, lateral movement, the objective. Every intrusion that actually works follows that shape. Recon. Entry. Payoff.
That's a three-act structure. That's a campaign brief. That's a pitch deck. I've built a hundred of those. I just built them to sell sneakers and banks and beer.
I used to keep a mental library of campaigns — the ones that won, the ones that should have won and didn't, the ones that broke a rule on purpose and got away with it. When a new brief landed on my desk, I wasn't starting from zero. I was pattern-matching against everything I'd already studied, looking for the shape that fit.
That's the library I'm building now. Except instead of Cannes winners, it's CVEs and real-world breach postmortems. Instead of "what made this campaign land," it's "what made this door open." Same discipline. Same muscle. Different archive.
And the frustrating part — the process tree I couldn't read, the Windows logs I had to slow down for — that's not a sign I'm bad at this. That's just what it looks like before you've built the library yet. Nobody walks into their first agency job and instantly recognizes a three-act structure either. You see it the fiftieth time, not the first.
I turned down an internship a few weeks back because it wasn't the right brief. I know what "the right shape" feels like, even under pressure, even without every technical detail nailed down yet. That instinct didn't come from TryHackMe. It came from thirty years of learning to smell a bad structure before I could always explain why it was bad.
Now I'm pointing that same instinct at intrusions instead of insights. Studying the recon. Studying the opening. Studying the payoff. Building the library one attack at a time, the same slow, unglamorous way I built the other one — one case study, one late night, one "oh, that's why that worked" at a time.
The tools are new. grep wasn't in my old toolkit. Process trees weren't either.
But "study the ones that worked until you can see the shape without thinking" — that's not new at all.
I've been doing that since before I knew it had a name.





