purple-team-automation

Installation
SKILL.md

Purple Team Automation

Authorization Boundary

  • Run only in environments with written approval, change windows, and rollback owners.
  • Tag every test with a unique campaign-id for cleanup and timeline reconstruction.
  • No data destruction, no real credential theft, no third-party services targeted.

Campaign Workflow

  1. Pick an adversary or technique set with business relevance; cite ATT&CK IDs and known intrusion sets.
  2. Draft an emulation plan: prerequisites, steps, expected telemetry, success/fail criteria, cleanup.
  3. Execute with invoke-atomicredteam, caldera operations, stratus, or custom scripts in isolated runners.
  4. Capture telemetry across EDR, Sysmon, cloud audit, network, identity, and SIEM.
  5. Compare expected vs observed events; flag missing logs, parsing failures, and rule misses.
  6. File defensive backlog: new detections, tuning, telemetry enablement, and response runbook updates.

Coverage Scoring

Installs
1
GitHub Stars
3
First Seen
Aug 26, 2026
purple-team-automation — masriyan/gemini-security-skills