mid-engagement-ir-detection

Monitor client SOC responses and attacker activity during red-team engagements.

5|Updated May 27, 2026
One-click install
npx skills add https://github.com/cybersecwoman/Kiro-BugHunter --skill mid-engagement-ir-detection-cybersecwoman
Or copy as Structured Prompt for Agent
Please help me install this Agent Skill.
Skill: mid-engagement-ir-detection
Source: https://github.com/cybersecwoman/Kiro-BugHunter/tree/main/skills/mid-engagement-ir-detection
Command: npx skills add https://github.com/cybersecwoman/Kiro-BugHunter --skill mid-engagement-ir-detection-cybersecwoman

SYSTEM DOCUMENTATION & REQUIREMENTS

💡 This Skill includes scripts (resource) and references (resource) components.

What problem does it solve?

This Skill enables the detection of client SOC patches, attacker activity, and security-state changes during red-team engagements, converting these observations into actionable findings.

Core Features & Use Cases

  • Detect SOC Patching: Identify client SOC responses to attacks in real-time.
  • Observe Attacker Activity: Monitor and report on external attacker campaigns.
  • Security State Changes: Track and document changes in the target's security posture.
  • Use Case: Imagine a red-team exercise where the client patches a vulnerability within minutes of detection. This Skill will confirm the patch, provide evidence of the vulnerability, and highlight the client's incident response capabilities.

Quick Start

Trigger the mid-engagement-ir-detection skill during an active red-team engagement to monitor for SOC patches and attacker activity.

Frequently Asked Questions about mid-engagement-ir-detection

High-intent search queries and answers about installing and using this skill.

FAQPage Schema
How do I detect SOC patching and incident response during a red-team engagement?

To detect SOC patching during a red-team engagement, monitor client responses and security posture changes in real-time. This requires logging timestamps and headers to identify when vulnerabilities are patched and confirm incident response capabilities.

What is mid-engagement detection for security posture changes?

Mid-engagement detection tracks target security posture changes by observing SOC responses and external attacker activity. It captures real-time patches and attacker campaigns, converting these observations into actionable findings with response evidence.

Can I monitor external attacker activity while conducting a red-team exercise?

You can monitor external attacker activity during red-team exercises by analyzing target security state changes. The process logs external campaigns alongside SOC responses, providing documented evidence of concurrent malicious activity.

Do I need baseline fingerprinting before monitoring SOC responses during an engagement?

Pre-engagement baseline fingerprinting is required before monitoring SOC responses. Establishing this baseline allows accurate identification of real-time patches and security posture changes by comparing during-engagement logs against the initial state.

How do I document evidence of a client patching a vulnerability in real-time?

Document real-time vulnerability patching by logging client SOC responses, timestamps, and headers during the engagement. Comparing these during-engagement logs against pre-engagement baselines confirms the patch and highlights incident response capabilities.

What are the limitations of detecting security posture changes during active red-team exercises?

Detection of security posture changes relies on continuous during-engagement logging of responses and headers. Without accurate pre-engagement baseline fingerprinting, confirming whether real-time patches are direct SOC responses to attacks is difficult.

Related Skills