What problem does it solve?
This Skill bridges the gap between offensive and defensive security teams by providing a structured framework for simulating real-world adversary tactics, techniques, and procedures (TTPs) to rigorously test and improve an organization's detection and response capabilities.
Core Features & Use Cases
- Adversary Emulation: Execute realistic attack scenarios using tools like CALDERA and Atomic Red Team.
- Detection Gap Analysis: Map existing detections against ATT&CK, identify blind spots, and prioritize remediation.
- Emulation Planning: Translate threat intelligence into actionable test plans.
- Cloud Security Testing: Utilize tools like CloudGoat for cloud-specific adversary emulation.
- Use Case: A security team wants to validate their SIEM rules against common credential access techniques. They use this Skill to emulate LSASS dumping (T1003.001) with CALDERA, observe if their SIEM alerts, and if not, use the provided Sigma rule template to create a new detection.
Quick Start
Use the purple-team skill to emulate the LSASS dump technique using CALDERA and validate detection coverage.