What problem does it solve?
SOC teams often deploy detection rules without verifying they actually fire against real attack techniques, leaving silent coverage gaps. This Skill structures a collaborative purple team exercise where red team attack execution and blue team SIEM monitoring happen in real time, so every detection rule is proven or remediated on the spot.
Core Features & Use Cases
- ATT&CK-Mapped Test Planning: Builds a technique-by-technique test matrix mapping MITRE ATT&CK IDs to test tools, expected alerts, and detection latency metrics.
- Guided Execution and Monitoring: Provides Atomic Red Team commands for technique execution alongside Splunk SPL queries for real-time blue team detection tracking.
- Same-Day Gap Remediation: Walks through writing new detection rules for missed techniques and re-testing them during the exercise, then generates a coverage report.
- Use Case: A SOC runs a quarterly FIN7-scenario exercise across a test VLAN, discovers LSASS access and C2 beaconing are undetected, builds the missing Splunk rules during the session, and raises detection coverage from 73% to 93%.
Quick Start
Plan and run a purple team exercise that validates my detection rules against FIN7 techniques using Atomic Red Team and my SIEM.