purple-team-automation
Installation
SKILL.md
Purple Team Automation
Authorization Boundary
- Run only in environments with written approval, change windows, and rollback owners.
- Tag every test with a unique
campaign-idfor cleanup and timeline reconstruction. - No data destruction, no real credential theft, no third-party services targeted.
Campaign Workflow
- Pick an adversary or technique set with business relevance; cite ATT&CK IDs and known intrusion sets.
- Draft an emulation plan: prerequisites, steps, expected telemetry, success/fail criteria, cleanup.
- Execute with
invoke-atomicredteam,calderaoperations,stratus, or custom scripts in isolated runners. - Capture telemetry across EDR, Sysmon, cloud audit, network, identity, and SIEM.
- Compare expected vs observed events; flag missing logs, parsing failures, and rule misses.
- File defensive backlog: new detections, tuning, telemetry enablement, and response runbook updates.