Projects & Campaigns
Practical security engineering campaigns built around controlled adversary activity, telemetry analysis, detection engineering, investigation, remediation and validation.
Current Campaign
The campaign currently being engineered and documented.
Secure Purple Team Portfolio Platform
Designing BELISARIUS13 as a reproducible and security-conscious platform using source control, automated builds, secure DNS, TLS and deployment engineering.
Purple Team Engineering Program
Each campaign expands the lab while producing reproducible technical documentation, detections and defensive improvements.
Purple Team Detection Lab
Build the core attacker, endpoint telemetry and detection environment used throughout future campaigns.
ATT&CK Adversary Emulation
Execute controlled ATT&CK techniques and measure telemetry, detection and investigative coverage.
Windows Breach & DFIR
Generate a controlled Windows incident, investigate the evidence, remediate the weakness and validate the fix.
Network Attack & PCAP Forensics
Generate hostile network behavior, inspect packet evidence and engineer network detections.
Web Attack → Detect → Harden
Attack a controlled web application, analyze evidence, engineer detections and verify remediation.
Azure Purple Team Security Lab
Validate Azure identity, workload, logging, policy and cloud security controls through controlled scenarios.
Detection Engineering Repository
Maintain validated detection content, hypotheses, queries, testing methodology and tuning notes.
Integrated Purple Team Campaign
Combine endpoint, network, web and Azure scenarios into a complete attack, detection, investigation and remediation exercise.