Apply Section 5 target vulnerability validation including: password cracking (offline against captured hashes per RoE + John the Ripper + Hashcat + dictionary attacks + rainbow tables) + penetration testing (Sections 5.2 + 5.3 covering planning + discovery + attack + reporting phases with exploitation + post-exploitation + privilege escalation + lateral movement) + social engineering (Section 5.4 covering phishing + vishing + pretexting + physical impersonation only per explicit RoE + Federal Trade Commission Section 5 risk evaluation).
The graph holds this control, the 0 it maps to, and the evidence behind each claim, over MCP and REST.