B13 // CAMPAIGN ARCHIVE

Projects & Campaigns

Practical security engineering campaigns built around controlled adversary activity, telemetry analysis, detection engineering, investigation, remediation and validation.

PURPLE TEAM MITRE ATT&CK DFIR DETECTION ENGINEERING AZURE SECURITY
ACTIVE OPERATION

Current Campaign

The campaign currently being engineered and documented.

CAMPAIGN ROADMAP

Purple Team Engineering Program

Each campaign expands the lab while producing reproducible technical documentation, detections and defensive improvements.

01 NEXT

Purple Team Detection Lab

Build the core attacker, endpoint telemetry and detection environment used throughout future campaigns.

Windows Sysmon Elastic Kali
02 PLANNED

ATT&CK Adversary Emulation

Execute controlled ATT&CK techniques and measure telemetry, detection and investigative coverage.

ATT&CK Atomic Red Team Sigma
03 PLANNED

Windows Breach & DFIR

Generate a controlled Windows incident, investigate the evidence, remediate the weakness and validate the fix.

Velociraptor Sysmon PowerShell
04 PLANNED

Network Attack & PCAP Forensics

Generate hostile network behavior, inspect packet evidence and engineer network detections.

Wireshark Suricata PCAP
05 PLANNED

Web Attack → Detect → Harden

Attack a controlled web application, analyze evidence, engineer detections and verify remediation.

Burp Suite OWASP Docker
06 PLANNED

Azure Purple Team Security Lab

Validate Azure identity, workload, logging, policy and cloud security controls through controlled scenarios.

Azure Entra ID Defender
07 PLANNED

Detection Engineering Repository

Maintain validated detection content, hypotheses, queries, testing methodology and tuning notes.

Sigma KQL Elastic Suricata
08 CAPSTONE

Integrated Purple Team Campaign

Combine endpoint, network, web and Azure scenarios into a complete attack, detection, investigation and remediation exercise.

Purple Team DFIR Cloud Detection
B13 // CAMPAIGNS Attack. Observe. Detect. Improve.