ADVERSARY SIMULATION — 03

Real TTPs.
Private lab.

We simulate the actual adversary — C2 beaconing, lateral, API abuse — without touching prod. Then hand the blue team the detections.

SCENARIOS
  • C2 beacon lab — periodic beacons + DNS tunneling + detection tuning (RITA/Zeek)
  • API/AppSec — IDOR/BOLA, SSRF, authz (HackerOne-grade报告)
  • SpiderFoot OSINT → nuclei → ZAP → optional Acunetix (licensed)
› beacon: every 60s → 45.2.34.1:443 | JA3 flagged
› Sigma: idor_probe.yml → 200 vs 403 mismatch alert
BLUE TEAM HAND-OFF

Sigma rules + Sigma/Zeek + YARA + runbook. Purple team tabletop included on Standard/Forge.

Book Simulation — Forge $38k →

No prod active recon without ROE — lab-only by default.