What problem does it solve?
During authorized red team engagements against monitored targets, security states change in real time in response to testing activity (such as SOC patch deployment, concurrent attacker activity, or WAF rule updates). Teams often miss these valuable incident response findings or incorrectly retract original vulnerability evidence when confirmed issues stop reproducing mid-engagement.
Core Features & Use Cases
- Baseline & State Diff Tracking: Provides a structured workflow to capture pre-engagement target fingerprints and track deltas in response times, headers, lockout counts, and other metrics during testing.
- Standardized IR Observation Templates: Includes pre-built finding templates for three common mid-engagement events: WAF rule deployment, active concurrent password spray attacks, and detection-induced rate limiting or IP blocks.
- Attribution Discipline: Includes mathematical checks and logging requirements to distinguish between security events caused by your own testing and external attacker activity, such as verifying you did not trigger M365 Smart Lockouts before attributing new locks to an active campaign.
- Use Case: For authorized red team engagements against monitored targets, this skill turns SOC response times and mid-test state changes into actionable client capability findings, while preserving evidence of original vulnerabilities even after they are mitigated.
Quick Start
Use the mid-engagement-ir-detection skill to capture pre-engagement baseline metrics and document any mid-test security state changes as formal client findings during your authorized red team engagement.