Performing Purple Team Atomic Testing
Overview
Cybersecurity skill for performing purple team atomic testing. Follows industry best practices and security standards.
When to Use
Trigger phrases:
"performing purple team atomic testing"
"Use when working with performing purple team atomic testing"
Validating detection coverage against specific MITRE ATT&CK techniques
Running purple team exercises using Atomic Red Team test library
Performing ATT&CK coverage gap analysis to identify blind spots in SIEM/EDR
Building a detection validation loop: execute atomic test, check SIEM, tune rule, retest
Generating ATT&CK Navigator heatmap layers for executive reporting
Automating continuous atomic testing in CI/CD or scheduled pipelines
Mapping threat intelligence reports to executable atomic tests
Do not use for full-scope red team engagements requiring custom implants or live adversary simulation beyond atomic tests; use Caldera, SCYTHE, or Cobalt Strike for advanced adversary emulation.
DISCLAIMER: Atomic Red Team tests execute real attack techniques. Run only on systems you own or have explicit written authorization to test. Many tests modify system state, create artifacts, or trigger security alerts. Always execute cleanup commands after testing. Never run atomic tests in production without risk acceptance from stakeholders.
When NOT to Use
- When you lack proper authorization for testing
- For production systems without change management
- When the task requires legal or compliance expertise beyond technical scope
Prerequisites
- Windows host with PowerShell 5.1+ or PowerShell Core 7+ (Linux/macOS supported for cross-platform atomics)
- Invoke-AtomicRedTeam PowerShell module installed from PSGallery
- Atomic Red Team atomics repository cloned locally
- SIEM/EDR with log ingestion from test endpoints (Splunk, Elastic, Microsoft Sentinel, CrowdStrike)
- MITRE ATT&CK Navigator (web-based or local instance) for layer visualization
- Python 3.9+ with
mitreattack-python, pyyaml, and requests for automation scripts
- Sigma rules repository for detection correlation
- Administrative/root access on test endpoints
- Isolated test environment (lab, sandbox, or dedicated test range)
Workflow
# Example: IOC detection
import re
IOC_PATTERNS = {
"ip": r"\b(?:\d{1,3}\.){3}\d{1,3}\b",
"domain": r"\b[a-z0-9-]+\.[a-z]{2,}\b",
"hash_md5": r"\b[a-f0-9]{32}\b",
"hash_sha256": r"\b[a-f0-9]{64}\b",
}
def extract_iocs(text: str) -> dict:
return {k: re.findall(v, text) for k, v in IOC_PATTERNS.items()}
- Plan Operations — Define objectives, scope, and success criteria for purple team atomic testing operations.
- Prepare Environment — Set up tools, access, and data sources required for purple team atomic testing.
- Execute Core Workflow — Perform the purple team atomic testing operations following established procedures.
- Validate Results — Verify that results meet quality standards and objectives.
- Report Findings — Document results, observations, and recommendations.
- Follow Up — Track remediation actions and verify fixes where applicable.
Tools
- Analysis Platform — Data processing and visualization
- Collaboration Tools — Team coordination and knowledge sharing
Process
- Design — Define interface, identify patterns, plan implementation
- Implement — Write code following existing conventions, add tests
- Verify — Run tests, check integration, validate behavior
Verification
Anti-Rationalization Table
| Rationalization |
Reality |
| "We are too small to be targeted" |
Automated attacks target everyone. Size does not matter. |
| "Security slows us down" |
A breach slows you down 100x more. Build security in from the start. |
| "We will fix it after launch" |
Vulnerabilities in production are exploited within hours. Fix before deploy. |
1---2name: performing-purple-team-atomic-testing3description: Use when executing Atomic Red Team tests mapped to MITRE ATT&CK techniques, performing coverage gap analysis across the ATT&CK matrix, and running detection validation loops to measure blue team visibility. Covers Invoke-AtomicRedTeam PowerShell execution, ATT&CK Navigator layer generation for heatmaps, Sigma rule correlation, and continuous atomic testing pipelines.4license: Apache-2.05---67# Performing Purple Team Atomic Testing89## Overview1011Cybersecurity skill for performing purple team atomic testing. Follows industry best practices and security standards.1213## When to Use1415**Trigger phrases:**16- "performing purple team atomic testing"17- "Use when working with performing purple team atomic testing"181920- Validating detection coverage against specific MITRE ATT&CK techniques21- Running purple team exercises using Atomic Red Team test library22- Performing ATT&CK coverage gap analysis to identify blind spots in SIEM/EDR23- Building a detection validation loop: execute atomic test, check SIEM, tune rule, retest24- Generating ATT&CK Navigator heatmap layers for executive reporting25- Automating continuous atomic testing in CI/CD or scheduled pipelines26- Mapping threat intelligence reports to executable atomic tests2728**Do not use** for full-scope red team engagements requiring custom implants or live adversary simulation beyond atomic tests; use Caldera, SCYTHE, or Cobalt Strike for advanced adversary emulation.2930**DISCLAIMER**: Atomic Red Team tests execute real attack techniques. Run only on systems you own or have explicit written authorization to test. Many tests modify system state, create artifacts, or trigger security alerts. Always execute cleanup commands after testing. Never run atomic tests in production without risk acceptance from stakeholders.313233## When NOT to Use3435- When you lack proper authorization for testing36- For production systems without change management37- When the task requires legal or compliance expertise beyond technical scope383940## Prerequisites4142- Windows host with PowerShell 5.1+ or PowerShell Core 7+ (Linux/macOS supported for cross-platform atomics)43- Invoke-AtomicRedTeam PowerShell module installed from PSGallery44- Atomic Red Team atomics repository cloned locally45- SIEM/EDR with log ingestion from test endpoints (Splunk, Elastic, Microsoft Sentinel, CrowdStrike)46- MITRE ATT&CK Navigator (web-based or local instance) for layer visualization47- Python 3.9+ with `mitreattack-python`, `pyyaml`, and `requests` for automation scripts48- Sigma rules repository for detection correlation49- Administrative/root access on test endpoints50- Isolated test environment (lab, sandbox, or dedicated test range)5152## Workflow5354```python55# Example: IOC detection56import re5758IOC_PATTERNS = {59 "ip": r"\b(?:\d{1,3}\.){3}\d{1,3}\b",60 "domain": r"\b[a-z0-9-]+\.[a-z]{2,}\b",61 "hash_md5": r"\b[a-f0-9]{32}\b",62 "hash_sha256": r"\b[a-f0-9]{64}\b",63}6465def extract_iocs(text: str) -> dict:66 return {k: re.findall(v, text) for k, v in IOC_PATTERNS.items()}67```68691. **Plan Operations** — Define objectives, scope, and success criteria for purple team atomic testing operations.702. **Prepare Environment** — Set up tools, access, and data sources required for purple team atomic testing.713. **Execute Core Workflow** — Perform the purple team atomic testing operations following established procedures.724. **Validate Results** — Verify that results meet quality standards and objectives.735. **Report Findings** — Document results, observations, and recommendations.746. **Follow Up** — Track remediation actions and verify fixes where applicable.7576## Tools7778- **Analysis Platform** — Data processing and visualization79- **Collaboration Tools** — Team coordination and knowledge sharing808182## Process83841. **Design** — Define interface, identify patterns, plan implementation851. **Implement** — Write code following existing conventions, add tests861. **Verify** — Run tests, check integration, validate behavior8788## Verification8990- [ ] All purple team atomic testing procedures executed completely and documented91- [ ] Findings validated against multiple data sources92- [ ] False positives identified and filtered93- [ ] Results documented with evidence and timestamps94- [ ] Recommendations provided with risk-based prioritization9596## Anti-Rationalization Table9798| Rationalization | Reality |99|---|---|100| "We are too small to be targeted" | Automated attacks target everyone. Size does not matter. |101| "Security slows us down" | A breach slows you down 100x more. Build security in from the start. |102| "We will fix it after launch" | Vulnerabilities in production are exploited within hours. Fix before deploy. |