# Tiber Style Tlpt

> Apply intelligence-led, threat-led penetration testing (TLPT) approaches in the spirit of TIBER-EU/CBEST — critical functions, CTI scenarios, controlled live testing, and structured closure. Use when designing or preparing for regulatory-style red teaming in financial or critical-entity contexts.

- Skill: `itsual/tiber-style-tlpt` (Agent Skill)
- Install (CLI): `npx skillmds@latest add itsual/tiber-style-tlpt`
- Raw SKILL.md: https://api.skillmd.com/api/skills/itsual/tiber-style-tlpt/raw
- Safety review: pending
- Works with: Claude Code, Claude.ai, OpenAI Codex
- Category: Security
- Author: itsual (https://skillmd.com/u/itsual)
- Updated: 2026-09-21
- Page: https://skillmd.com/skills/itsual/tiber-style-tlpt

---


# TIBER-Style / Threat-Led Testing (TLPT)

## Overview

TIBER-EU and related frameworks (e.g. CBEST, DORA TLPT expectations) define intelligence-led red teaming against critical functions using realistic threat scenarios, with rigorous governance and learning-focused closure.

## When to Use

- Financial-sector or critical-entity regulatory-style tests
- Designing critical-function-centric scenarios
- Separating threat intel and red-team roles appropriately
- Planning purple closure workshops after live tests

## Core Practices

- Identify critical functions and underlying systems end-to-end
- Commission or produce targeted threat intelligence for scenario design
- Build scenarios that mimic relevant adversaries against those functions
- Govern the test with clear roles (entity, authority if any, TI provider, red team)
- Execute under strict RoE on agreed live scope
- Capture defensive performance along the attack path
- Close with structured purple teaming, remediation planning, and evidence of improvement

## Principles

- Critical functions — not only “interesting servers” — define scope
- Intelligence quality drives scenario realism
- Independence/separation of TI and red team is often required or preferred
- The outcome is resilience improvement, not a pass/fail trophy

## Verification

- [ ] Critical functions are defined and agreed
- [ ] Scenarios trace to threat intelligence
- [ ] Closure includes purple learning and remediation ownership

