ADVERSARY SIMULATION — 03
Real TTPs.
Private lab.
We simulate the actual adversary — C2 beaconing, lateral, API abuse — without touching prod. Then hand the blue team the detections.
SCENARIOS
- C2 beacon lab — periodic beacons + DNS tunneling + detection tuning (RITA/Zeek)
- API/AppSec — IDOR/BOLA, SSRF, authz (HackerOne-grade报告)
- SpiderFoot OSINT → nuclei → ZAP → optional Acunetix (licensed)
› beacon: every 60s → 45.2.34.1:443 | JA3 flagged
› Sigma: idor_probe.yml → 200 vs 403 mismatch alert
BLUE TEAM HAND-OFF
Sigma rules + Sigma/Zeek + YARA + runbook. Purple team tabletop included on Standard/Forge.
Book Simulation — Forge $38k →
No prod active recon without ROE — lab-only by default.