What problem does it solve?
Security teams need to validate whether their detection and response capabilities actually work against realistic adversary behavior, but ad-hoc penetration tests often miss stealth, persistence, and objective-based scenarios that real APT actors use.
Core Features & Use Cases
- End-to-End Engagement Methodology: Covers all phases from OSINT reconnaissance and initial access through lateral movement, exfiltration, and reporting, mapped to MITRE ATT&CK tactics and techniques.
- Operational Guidance with Real Commands: Provides concrete commands for tools like Amass, theHarvester, GoPhish, Rubeus, Impacket, and C2 frameworks such as Havoc and Sliver.
- Detection Gap Measurement: Defines metrics like MTTD, MTTR, TTP coverage, and dwell time, plus purple team recommendations for closing detection gaps.
- Use Case: A red team operator planning an authorized engagement against a corporate Active Directory environment uses this Skill to structure the operation, select ATT&CK techniques per phase, timestamp evidence, and produce a report with a detection gap analysis for the SOC.
Quick Start
Ask the AI to plan a full-scope red team engagement against an authorized target environment, mapping each phase to MITRE ATT&CK techniques and defining measurable objectives.