# Adversary Emulation

> Threat-informed adversary emulation — pick a real APT, load its profile, and reproduce its TTPs within RoE scope to test detection & response. Index of available actor profiles + the emulation methodology.

- Skill: `purpleailab/adversary-emulation` (Agent Skill, multi-file: 3 files)
- Install (CLI): `npx skillmds@latest add purpleailab/adversary-emulation`
- Raw SKILL.md: https://api.skillmd.com/api/skills/purpleailab/adversary-emulation/raw
- Safety review: pending
- Works with: Claude Code, Claude.ai, OpenAI Codex
- Category: Security
- Author: purpleailab (https://skillmd.com/u/purpleailab)
- Updated: 2026-09-17
- Page: https://skillmd.com/skills/purpleailab/adversary-emulation

---


# Adversary Emulation — index & methodology

**Adversary emulation** reproduces a *specific, named* threat actor's tactics,
techniques and procedures (TTPs) — drawn from real, attributed intelligence —
to test whether the target's people, process, and tooling detect and respond
the way they should. It is distinct from generic penetration testing
(opportunistic) and from *simulation* (abstract/random): emulation is
**threat-informed** — every action traces to something a real group has been
documented doing, mapped to [MITRE ATT&CK](https://attack.mitre.org/).

> **Authorized use only.** Emulate an actor's TTPs **only** within the engagement's
> Rules of Engagement and approved scope. Destructive techniques (Impact tactic:
> ransomware, wipers, ICS manipulation) are emulated as *non-destructive proofs*
> (e.g., a benign canary file, a dry-run) unless the RoE explicitly authorizes
> otherwise. The goal is to measure detection, not to cause damage.

## When to use this

- The operator (or `roe.json` threat profile) names a specific actor to emulate,
  or names a sector/region whose dominant threat is a known group.
- A purple-team / ATT&CK-evaluation engagement: run an actor's TTP chain while the
  blue cell measures detection (see `kill-chain-analysis` and the `blue_cell`).
- You want a *realistic, defensible* attack plan instead of an ad-hoc one.

## Methodology (5 steps)

1. **Select the actor.** Map the engagement's industry/region/crown-jewels to a
   relevant group (see the catalog below). When unsure, ask the operator via
   `ask_user_question`. Record the choice in the OPPLAN.
2. **Load the profile.** `load_skill <slug>` (e.g. `load_skill apt29-cozy-bear`).
   Each profile carries attribution, targeting, dated campaigns, the actor's TTPs
   mapped to ATT&CK technique IDs, signature tooling, **emulation guidance** (how
   to reproduce each TTP with Decepticon's own tools), and detection notes.
3. **Scope to RoE.** Intersect the actor's TTPs with the approved scope. Drop or
   down-scope anything out of bounds (e.g., replace a real wiper with a canary).
   Forbidden-destination / out-of-scope checks still apply at tool-call time.
4. **Emulate in kill-chain order.** Walk Initial Access → Execution → Persistence
   → Priv-Esc → Defense Evasion → Credential Access → Discovery → Lateral Movement
   → Collection → C2 → Exfiltration → (proof-of) Impact, using only the techniques
   this actor is known for. Cite the ATT&CK ID in each finding.
5. **Measure & report.** Record which actions the blue cell detected/blocked vs.
   missed (`kill-chain-analysis`, MTTD), and produce a threat-informed report that
   ties each result to the emulated actor + ATT&CK technique. Feeds the final report.

This complements `soundwave/threat-profile` (which picks the actor at planning time)
and `kill-chain-analysis` (which scores detection across the chain).

## Actor catalog

| Profile (`load_skill <slug>`) | Aliases | Attribution | Motivation | Notable for |
| --- | --- | --- | --- | --- |
| `apt29-cozy-bear` | Midnight Blizzard, NOBELIUM, The Dukes | Russia (SVR) | Espionage | Stealthy cloud/identity intrusions; SolarWinds supply chain |
| `apt28-fancy-bear` | Forest Blizzard, Sofacy, STRONTIUM | Russia (GRU) | Espionage / influence | Credential phishing, election & defense targeting |
| `apt33-elfin` | Peach Sandstorm, HOLMIUM | Iran | Espionage (destructive links) | Aerospace & energy, Gulf-region targeting |
| `apt34-oilrig` | Helix Kitten, Hazel Sandstorm | Iran | Espionage | DNS-tunneling C2, Middle-East supply-chain access |
| `apt41-double-dragon` | Wicked Panda, BARIUM | China | Espionage **and** financial | Software supply-chain compromise; dual-use ops |
| `lazarus-group` | Hidden Cobra, Diamond Sleet | North Korea | Financial + destructive | Bank/crypto heists, WannaCry, supply chain |
| `fin7-carbanak` | Carbon Spider, Sangria Tempest | Financially motivated | Financial | POS/retail intrusions, Carbanak, ransomware affiliate |
| `sandworm-team` | Voodoo Bear, Seashell Blizzard | Russia (GRU) | Destructive / disruptive | NotPetya, Ukraine power-grid attacks, ICS |
| `volt-typhoon` | Vanguard Panda, Insidious Taurus | China | Pre-positioning | Living-off-the-land in US critical infrastructure |
| `scattered-spider` | UNC3944, Octo Tempest, Muddled Libra | Financially motivated | Financial / extortion | Help-desk social engineering, SIM-swap, MFA fatigue |
| `salt-typhoon` | Earth Estries, GhostEmperor, FamousSparrow | China | Espionage / pre-positioning | Edge-device exploitation, telecom targeting, DEMODEX rootkit |
| `turla` | Venomous Bear, Secret Blizzard, KRYPTON | Russia (FSB) | Espionage | Snake rootkit, satellite C2, hijacking other APTs' infra |
| `muddywater` | Mercury, Mango Sandstorm, Static Kitten | Iran (MOIS) | Espionage | PowerShell RATs, RMM tool abuse, Middle-East targeting |
| `apt36-transparent-tribe` | Transparent Tribe, Mythic Leopard, ProjectM | Pakistan | Espionage | CrimsonRAT, Android mobile malware, India-focused targeting |
| `apt37-reaper` | ScarCruft, Ricochet Chollima, InkySquid | North Korea | Espionage / surveillance | RoKRAT, zero-day browser exploits, defector surveillance |
| `mustang-panda` | Bronze President, Stately Taurus, RedDelta | China | Espionage | PlugX/DLL side-loading, USB propagation, SE Asia targeting |
| `dark-caracal` | — | Lebanon (GDGS) | Espionage / surveillance | Bandook RAT, multi-platform (Win/Mac/Android/Linux) |
| `patchwork` | Dropping Elephant, Chinastrats, Hangover | India | Espionage | BADNEWS RAT, copy-paste tradecraft, South Asia targeting |
| `pink-sandstorm` | Agrius, DEV-0227 | Iran | Destructive / espionage | Apostle wiper, destructive ops disguised as ransomware |
| `apt10-stone-panda` | Stone Panda, MenuPass, Red Apollo | China (MSS) | Espionage / IP theft | Cloud Hopper supply-chain, MSP targeting |
| `kimsuky` | Velvet Chollima, Emerald Sleet, THALLIUM | North Korea (RGB) | Espionage | BabyShark, credential phishing of think tanks/academia |
| `sidewinder` | Rattlesnake, T-APT-04, Razor Tiger | India | Espionage | LNK chains, .NET implants, Pakistan military targeting |

> Profiles are grounded in MITRE ATT&CK group pages + public advisories; each lists
> its sources. ATT&CK technique IDs are the source of truth — verify against
> <https://attack.mitre.org/groups/> if intel looks stale.

