Performing Threat Emulation With Atomic Red Team

使用 atomic-operator Python 框架执行 Atomic Red Team 测试,进行 MITRE ATT&CK 技术验证。 从 YAML 原子测试加载测试定义、运行攻击模拟并验证检测覆盖率。适用于测试 SIEM 检测规则、 验证 EDR 覆盖率或开展紫队演练。

killvxk Updated

File contents

使用 Atomic Red Team 执行威胁模拟

说明

使用 atomic-operator 执行 Atomic Red Team 测试,针对 MITRE ATT&CK 技术验证检测覆盖率。

from atomic_operator import AtomicOperator

operator = AtomicOperator()
# 运行指定技术测试
operator.run(
    technique="T1059.001",  # PowerShell 执行
    atomics_path="./atomic-red-team/atomics",
)

关键工作流程:

  1. 克隆 atomic-red-team 仓库获取测试定义
  2. 选择与检测规则匹配的 ATT&CK 技术
  3. 使用 atomic-operator 执行原子测试
  4. 在 SIEM/EDR 中检查相应告警
  5. 记录检测缺口并更新规则

示例

# 解析原子测试 YAML 定义
import yaml
with open("atomics/T1059.001/T1059.001.yaml") as f:
    tests = yaml.safe_load(f)
for test in tests.get("atomic_tests", []):
    print(f"测试:{test['name']}")
    print(f"  支持平台:{test.get('supported_platforms', [])}")

killvxk/cybersecurity-skills-zh/tree/main/skills/performing-threat-emulation-with-atomic-red-team commit dc6910d3b5

Frequently asked questions

npx skillmds@latest add killvxk/performing-threat-emulation-with-atomic-red-team