📖 Blueprints & Methodologies
Pentest methodology documents, operational blueprints, and security references.
← Back to list
red-team-operations-blueprint.md
red-team-operations-blueprint.md
# ptSlick — Red Team Operations Blueprint v1.0
**Classification**: Internal — SlickLab Red Team Operations
**Build**: 2026-10-03 | **Next Review**: 2026-11-03
**Author**: Colnex (SlickLab Operational Intelligence)
---
## 1. Operating Philosophy
### 1.1 Core Tenets
```
Dark-Minded Posture → Assume every engagement exposes infrastructure.
→ Assume detection is inevitable after initial foothold.
→ Plan for burn, rotate before burn.
Hierarchy of Stealth → 1. Living off the land (LOTL) — native tools only.
→ 2. Reflective loading — no disk writes.
→ 3. Custom tooling — compiled per target, signed, unique hashes.
→ 4. Commodity tooling — rename, obfuscate, recompile.
Operational Security → Air-gapped C2 brains on-premise.
→ Cloud redirectors as sacrificial front-end.
→ Infrastructure as disposable, stateless cattle.
→ Every node has a kill switch.
Least Privilege → Tools run at minimum permission required.
→ Credentials scoped per engagement.
→ No reused infrastructure between clients.
→ No operator identity on redirectors or C2 front-ends.
```
### 1.2 The Kill Chain Model (ATT&CK-aligned)
This blueprint operationalizes the MITRE ATT&CK v19.1 framework across 14 tactics.
Every procedure references a technique ID for blue-team traceability and detection-gap mapping.
```
TA0043 ── Reconnaissance │ Gather intel, map surface, profile people
TA0042 ── Resource Development │ Build/acquire infrastructure, domains, certs
TA0001 ── Initial Access │ Phish, exploit, physical breach
TA0002 ── Execution │ Run payload, stager, macro, LOLBin
TA0003 ── Persistence │ Backdoor, scheduled task, registry, service
TA0004 ── Privilege Escalation │ UAC bypass, token steal, kernel exploit
TA0005 ── Defense Evasion │ Obfuscate, masquerade, disable logging
TA0006 ── Credential Access │ Dump LSASS, scrape browser, Kerberoast
TA0007 ── Discovery │ Enumerate users, groups, shares, AD, cloud
TA0008 ── Lateral Movement │ WinRM, SMB, PsExec, SSH, cloud trust
TA0009 ── Collection │ Gather data of interest from endpoints
TA0011 ── Command & Control │ Beacon, tunnel, domain fronting, MCP bridge
TA0010 ── Exfiltration │ Archive + send over covert channel
TA0040 ── Impact │ Encrypt, destroy, manipulate (scope-dependent)
```
---
## 2. Pre-Engagement Framework
### 2.1 Scoping & Rules of Engagement
```
┌─────────────────────────────────────────────────────┐
│ ROE Document — Required Fields │
├─────────────────────────────────────────────────────┤
│ Client / Target Organization │
│ Engagement Dates │
│ Objective(s) — Crown Jewels (3-5 items) │
│ In-Scope Systems/Networks (CIDR ranges, domains) │
│ Out-of-Scope Systems (explicitly listed) │
│ Authorized Attack Methods │
│ - Social engineering: Y/N (targets?) │
│ - Physical intrusion: Y/N (locations?) │
│ - Web app exploitation: Y/N │
│ - API abuse: Y/N │
│ - Wi-Fi/radio attacks: Y/N │
│ Exfiltration Limits (data types allowed) │
│ Time Constraints (business hours only? weekends?) │
│ Deconfliction Protocol (who has pause authority) │
│ Emergency Contact (CISO, Trusted Agent) │
│ Stop Conditions (objective achieved? Ransomware found?)│
│ Legal Authorization (signed SOW + insurance proof) │
└─────────────────────────────────────────────────────┘
```
### 2.2 Threat Actor Selection
Select the adversary profile that aligns with the target's threat model:
```
┌──────────────────┬───────────────────────────────────────┬──────────────────┐
│ Actor Profile │ Best For │ Key TTPs │
├──────────────────┼───────────────────────────────────────┼──────────────────┤
│ APT29 (Cozy Bear)│ Government, think tanks, pharma │ Spearphish, PS, │
│ │ Espionage simulation │ Reg run keys, │
│ │ │ LSASS dump, │
│ │ │ WinRM, HTTPS C2 │
├──────────────────┼───────────────────────────────────────┼──────────────────┤
│ FIN7 / FIN12 │ Financial services, retail, POS │ Phishing, │
│ │ Financially motivated adversary │ PowerShell, │
│ │ │ scheduled tasks, │
│ │ │ SMB lateral, │
│ │ │ ransomware prep │
├──────────────────┼───────────────────────────────────────┼──────────────────┤
│ Lazarus Group │ Cryptocurrency, fintech, critical infra│ Watering hole, │
│ │ Destructive + theft │ macOS/Windows, │
│ │ │ custom malware, │
│ │ │ blockchain theft │
├──────────────────┼───────────────────────────────────────┼──────────────────┤
│ APT41 │ Manufacturing, telecom, defense │ Supply chain, │
│ │ Dual-use espionage+theft │ drive-by, .NET, │
│ │ │ Cobalt Strike, │
│ │ │ AD abuse │
├──────────────────┼───────────────────────────────────────┼──────────────────┤
│ Wizard Spider │ Any sector with ransomware risk │ Phishing, RDP, │
│ │ Ransomware kill chain │ Cobalt Strike, │
│ │ │ Ryuk/Conti, │
│ │ │ data extortion │
├──────────────────┼───────────────────────────────────────┼──────────────────┤
│ Custom Composite │ Most engagements — blend TTPs from │ Cherry-pick │
│ │ 2-3 actors relevant to target's sector │ techniques from │
│ │ │ matched profiles │
└──────────────────┴───────────────────────────────────────┴──────────────────┘
```
### 2.3 Objective Definition
```
Weak objective: "Get domain admin"
Strong objective: "Exfiltrate the customer PII database from the production SQL server
and place a ransom note on the CFO's desktop without triggering
the SOC's EDR alert within 72 hours."
```
Define 3-5 crown jewel objectives. Each must be:
- **Measurable** — either you have the data or you don't
- **Time-bound** — within the engagement window
- **Realistic** — technically feasible in the target environment
- **Approved** — no exfil of PII without data handling agreement
---
## 3. Infrastructure Architecture
### 3.1 The Hybrid C2 Model (Air-Gap + Cloud Front)
```
┌──────────────────────┐
│ CLOUDFLARE DNS │
│ (proxy = on) │
│ Real IP hidden │
└────────┬─────────────┘
│
▼
┌────────────────────────┐
│ CLOUD VPS (Redirector) │
│ nginx reverse proxy │
│ Decoy website on root │
│ Port 443 HTTPS │
│ SOCAT fallback │
│ ssh -R tunnel │
└────────┬────────────────┘
│ SSH -R (reverse port forward)
│
┌────────▼────────────────┐
│ ON-PREM C2 SERVER │
│ (Air-gapped, no public │
│ ports, behind NAT) │
│ Sliver | Mythic | CS │
│ Ports: 443, 8080 │
└─────────────────────────┘
```
**Architecture rules:**
- **C2 server is NEVER directly reachable** from the internet
- **Redirectors are disposable** — Terraform + Ansible = 5-min rebuild
- **Decoy website** on redirector root (/var/www/html/legit-site/) — against nginx traffic inspection, serve a real site (bootstrap template, cloned blog)
- **Cloudfront/Akamai** for domain fronting when permitted
- **SSH reverse port forward** only outbound from protected C2 → redirector
- **No persistent SSH sessions** — use autossh with systemd restart
### 3.2 Infrastructure Quick-Deploy
```
# Terraform + Ansible stack (deploy in under 30 min)
# Reference: github.com/rbfp/redteam-infra
Components:
- Terraform for: VPC, subnets, security groups, EC2/DO/Linode instances
- Ansible for: nginx config, socat, Cloudflare tunnel, systemd units
- One bastion host (SSH gateway) — logs all operator access
Domain rotation:
- Every engagement gets 3+ new domains
- DNS records created 48-72 hours BEFORE engagement start
- Domains aged 30+ days preferred (better reputation)
- Use .com, .net, .org, .io, .co — varied TLDs
- Domain fronting via Cloudflare Workers or Akamai Edge
Ops monitoring:
- Redirector access logs streamed to isolated log server
- Fail2ban on redirector — block known scanners (Shodan, Censys)
- Daily domain reputation check: virustotal, urlscan.io, hybrid-analysis
- Kill switch: DNS record removal deactivates entire infrastructure in < 5 min
```
### 3.3 Infrastructure Security Controls
```
┌────────────────┬──────────────────────────────┬─────────────────┐
│ Control │ Implementation │ Justification │
├────────────────┼──────────────────────────────┼─────────────────┤
│ SSH keys only │ No password auth anywhere │ Prevents │
│ │ │ credential │
│ │ │ brute-force │
├────────────────┼──────────────────────────────┼─────────────────┤
│ Cloudflare │ Proxy=on, IP hidden │ Blue team can't │
│ proxy │ │ scan C2 origin │
├────────────────┼──────────────────────────────┼─────────────────┤
│ User-agent │ VPS returns 404 for known │ Stops scanners, │
│ filtering │ scanners + missing Host: │ footprint │
│ │ header visitors │ reduction │
├────────────────┼──────────────────────────────┼─────────────────┤
│ Decoy content │ Legit-looking site served on │ Traffic │
│ │ redirector root │ analysis │
│ │ │ camouflage │
├────────────────┼──────────────────────────────┼─────────────────┤
│ No C2 data on │ Agents never touch redirector│ Physical │
│ redirector │ storage │ containment │
├────────────────┼──────────────────────────────┼─────────────────┤
│ Network │ C2 server: deny all inbound │ Prevents │
│ segmentation │ except established outbound │ pivoting to C2 │
│ │ │ from target │
├────────────────┼──────────────────────────────┼─────────────────┤
│ Log retention │ 90 days minimum, off-site │ Post- │
│ │ copy │ engagement │
│ │ │ forensic │
│ │ │ reconstruction │
└────────────────┴──────────────────────────────┴─────────────────┘
```
---
## 4. Reconnaissance & OSINT Pipeline
### 4.1 Automated Discovery Tier
```
Phase 1: Surface Enumeration │ Tools: SpiderFoot (200+ sources)
│ Amass (subdomain enumeration)
│ Sublist3r
│ Cert.sh (certificate transparency)
│ Output: Asset inventory (domains, IPs, ASNs)
Phase 2: Service Profiling │ Tools: Nmap (stealth -sS -sV -T2)
│ Masscan (fast port sweep)
│ Shodan/Censys API
│ Output: Open ports, service banners, CVEs
Phase 3: Technology Stack │ Tools: Wappalyzer (CLI)
│ WhatWeb
│ BuiltWith API
│ Output: CMS, frameworks, cloud providers, CDNs
Phase 4: Dark Web & Leaks │ Tools: Tor browser automation
│ Dehashed/IntelX API
│ Password dump search (HaveIBeenPwned API)
│ Output: Credential leaks, exposed credentials
```
### 4.2 Human Intelligence (HUMINT)
```
LinkedIn profiling:
- Enumerate employees by department (IT, Security, Exec)
- Build role-to-person mapping
- Identify targets for spearphishing: IT helpdesk, SOC analysts, executives
- Detect technology stack from employee skills/certifications
Job postings:
- Parse for security tools deployed (SIEM, EDR, SOAR listed in requirements)
- Identify technology shifts (migration to cloud, new database)
- Map network architecture from job descriptions
Social media:
- Accounts that post about work (internal tools, project names)
- Conference attendance (what security products they use)
- Disgruntled employees (potential insider threat vector—monitor, don't engage)
```
### 4.3 Google Dorking Playbook
```
Intentionally unlisted files & directories:
site:target.com intitle:"index of" (passwd | config | backup | admin)
Exposed credentials:
site:target.com filetype:env (DB_PASSWORD | API_KEY | SECRET)
site:target.com intext:"-----BEGIN RSA PRIVATE KEY-----"
Exposed databases:
site:target.com filetype:sql (INSERT INTO | CREATE TABLE)
site:target.com filetype:bak inurl:backup
Cloud storage misconfig:
site:amazonaws.com inurl:targetcompany (mapped to known prefixes)
site:blob.core.windows.net "target.com"
Admin/exposed panels:
site:target.com inurl:phpmyadmin
site:target.com inurl:/wp-admin intitle:"login"
site:target.com intitle:"Kibana" "search"
```
---
## 5. Initial Access Arsenal
### 5.1 Phishing Operations
```
┌──────────┬──────────────────────┬──────────────────────────────┐
│ Vector │ Technique │ OPSEC Requirements │
├──────────┼──────────────────────┼──────────────────────────────┤
│ Email │ Spearphishing │ Dedicated phishing domain │
│ │ Attachment │ SPF/DKIM/DMARC configured │
│ │ (T1566.001) │ Domain aged 30+ days │
│ │ │ DMARC = p=none (don't alert) │
├──────────┼──────────────────────┼──────────────────────────────┤
│ Email │ Spearphishing Link │ Same as above + HTTPS cert │
│ │ (T1566.002) │ Landing page mimics target │
│ │ │ No malware on landing page │
├──────────┼──────────────────────┼──────────────────────────────┤
│ Email │ Spearphishing via │ Compromise trusted 3rd-party │
│ │ Service (T1566.003) │ Use legitimate service │
│ │ │ (DocuSign, Dropbox, etc.) │
├──────────┼──────────────────────┼──────────────────────────────┤
│ Voice │ Vishing (social eng) │ Spoofed caller ID │
│ │ │ Scripted conversation tree │
│ │ │ Target: helpdesk, IT support │
├──────────┼──────────────────────┼──────────────────────────────┤
│ SMS │ Smishing │ Temporary numbers only │
│ │ │ Shortened URLs (bitly, etc.) │
│ │ │ Harvest 2FA codes via clone │
├──────────┼──────────────────────┼──────────────────────────────┤
│ Physical │ USB drop │ Rubber ducky / badUSB │
│ │ │ OPSEC: no fingerprints │
│ │ │ Drop locations: smoking area,│
│ │ │ break room, parking lot │
└──────────┴──────────────────────┴──────────────────────────────┘
```
### 5.2 Phishing Payload Delivery Chain
```
┌──────────────────┐
│ Target clicks │
│ link/opens doc │
└────────┬─────────┘
▼
┌───────────────────────────────┐
│ Stage 1: Dropper / Stager │
│ - Macro-enabled Word doc │
│ - HTML smuggling (blob URL) │
│ - ISO file (mounts, no MOTW)│
│ - LNK file in zip archive │
└───────────────┬───────────────┘
▼
┌───────────────────────────────┐
│ Stage 2: LOLBin Execution │
│ - mshta.exe │
│ - regsvr32.exe (sct file) │
│ - rundll32.exe │
│ - powershell.exe (-enc) │
│ - wmic.exe │
└───────────────┬───────────────┘
▼
┌───────────────────────────────┐
│ Stage 3: Shellcode Loader │
│ - Process hollowing │
│ - Reflective DLL injection │
│ - Donut (shellcode to PE) │
│ - Callback via syscall │
└───────────────┬───────────────┘
▼
┌───────────────────────────────┐
│ Stage 4: C2 Beacon │
│ - Sliver / Mythic / CS │
│ - Sleep mask obfuscation │
│ - Memory-only execution │
│ - No disk writes │
└───────────────────────────────┘
```
### 5.3 Exploitation (External-Facing)
```
Priority targets for external exploitation:
1. VPN gateways (Pulse Secure, Citrix, Fortinet) → T1190
2. Web applications with file upload / RCE → T1190
3. Exposed admin panels (phpMyAdmin, Jenkins, K8s API) → T1190
4. Cloud storage with public access → T1530
5. Self-signed certs or expired SSL with sensitive info → T1602
6. Jupyter Notebook / Grafana / Kibana no auth → T1213
7. Exposed Git repos (.git/config) → T1213/TA0007
```
---
## 6. Persistence & Privilege Escalation
### 6.1 Windows Persistence (LOTL-first)
```
Technique │ TTP ID │ Method
────────────────────────────┼─────────┼───────────────────────────────
Registry Run Key │ T1547.001│ reg add HKCU\...\Run
Scheduled Task │ T1053.005│ schtasks /create
Startup Folder │ T1547.001│ Drop LNK in %APPDATA%\Microsoft\
│ │ Windows\Start Menu\Programs\
│ │ Startup
Service (dll/hijack) │ T1543.003│ sc create type= kernel
WMI Event Subscription │ T1546.003│ ActiveScriptEventConsumer
DLL Search Order Hijack │ T1574.001│ Inflated DLL in privileged path
COM Hijacking │ T1546.015│ CLSID redirection
Skeleton Key (Kerberos) │ T1554 │ Mimikatz skeleton key (AD only)
```
### 6.2 Linux Persistence
```
Technique │ TTP ID │ Method
────────────────────────────┼─────────┼───────────────────────────────
SSH Authorized Keys │ T1098.004│ ~/.ssh/authorized_keys append
cron / crontab │ T1053.003│ (crontab -l; echo "* * * * *") | crontab
systemd service │ T1543.002│ /etc/systemd/system/legit-service.service
LD_PRELOAD rootkit │ T1574.006│ /etc/ld.so.preload
Kernel module (.ko) │ T1574.006│ insmod rootkit.ko (if root)
Web shell (persistent) │ T1505.003│ PHP/JSP/ASPX on web server
Container escape │ T1611 │ cgroup / host mount escape
```
### 6.3 Privilege Escalation — Windows
```
Tactic │ TTP ID │ Technique
────────────────────────────┼─────────┼───────────────────────────────
UAC Bypass │ T1548.002│ fodhelper / eventvwr / sdclt
Token Theft │ T1134.001│ Named pipe impersonation
PrintNightmare (patched) │ T1068 │ CVE-2021-1675 (if unpatched)
SMBGhost │ T1068 │ CVE-2020-0796
Certify (AD CS abuse) │ T1648 │ ESC1-ESC13 misconfigs
SeBackupPrivilege │ T1003.003│ reg.exe save HKLM\SAM
Unquoted Service Path │ T1574.002│ Path with spaces + arbitrary exe
AlwaysInstallElevated │ T1546.014│ MSI runs as SYSTEM
```
### 6.4 Privilege Escalation — Linux
```
Tactic │ TTP ID │ Technique
────────────────────────────┼─────────┼───────────────────────────────
SUID Misconfig │ T1548.001│ find / -perm -4000 2>/dev/null
Sudo Exploitation │ T1548.003│ sudo -l, CVE-2021-3156
Capabilities │ T1548 │ getcap -r / 2>/dev/null
Docker Escape │ T1611 │ --privileged / --pid=host
Kernel Exploit │ T1068 │ Dirty Pipe (CVE-2022-0847)
PKEXEC │ T1574.006│ CVE-2021-4034 (pwnkit)
Path Hijack │ T1574.005│ Writable $PATH + script
```
---
## 7. Lateral Movement
### 7.1 Active Directory Movement
```
┌────────────────────────────────────────────────────────────┐
│ Discovery (T1087, T1069, T1482) │
│ whoami /groups, net group "Domain Admins" /domain │
│ PowerView: Get-NetUser, Get-NetGroup, Get-NetComputer │
│ BloodHound: SharpHound collector → ingest into BH UI │
│ AdFind: LDAP query for trusts, delegation, ACLs │
├────────────────────────────────────────────────────────────┤
│ Movement (T1021, T1569) │
│ WinRM → Enter-PSSession (T1021.006) │
│ SMB → psexec, wmiexec (T1021.002, T1047) │
│ RDP → xfreerdp (T1021.001 — noisy, last resort) │
│ SSH → plink / OpenSSH (T1021.004) │
│ DCOM → MMC20.Application lateral (T1021.003) │
├────────────────────────────────────────────────────────────┤
│ AD Attacks (verified via BloodHound paths) │
│ Kerberoasting → T1558.003 — SPN + hash request │
│ AS-REP Roasting → T1558.004 — no pre-auth accounts │
│ DCSync → T1003.006 — DC replication abuse │
│ Golden Ticket → T1558.001 — KRBTGT hash forge │
│ Silver Ticket → T1558.002 — service NTLM forge │
│ ACL Abuse → T1222.001 — WriteOwner, GenericAll │
│ AdminSDHolder → T1222.001 — backdoor AD groups │
│ Skeleton Key → T1554 — Kerberos bypass (DC) │
└────────────────────────────────────────────────────────────┘
```
### 7.2 Cloud Lateral Movement
```
AWS:
- STS token theft from instance metadata (T1526)
- AssumeRole chain abuse (T1524)
- SSM agent for command execution (T1569)
- Lambda function injection (T1578.002)
- CloudTrail disable before destructive actions (T1562.008)
Azure:
- MS Graph API token theft (T1527)
- Hybrid identity sync compromise (T1527)
- Azure AD Connect misconfig → AD sync takeover
- Managed identity pivot (through IMDS endpoint)
- Key Vault data collection (T1552.005)
GCP:
- Service account key extraction (T1527)
- IAM role escalation via delegation
- Cloud Functions injection
- GCS bucket enumeration → data collection
```
### 7.3 Container & Kubernetes Pivot
```
K8s API exposure → T1190 (if no auth)
kubeconfig theft → T1552 (from pods, CI/CD)
Pod exec (kubectl exec) → T1609
Secrets enumeration → T1552.007
Sidecar injection → T1190 (admission webhook)
Container escape → T1611 (--privileged, hostPID)
Cluster admin (rbac) → T1562 (disable audit)
```
---
## 8. Exfiltration & Objective Completion
### 8.1 Data Collection Strategy
```
Phase 1: Identify crown jewel location
- BloodHound for AD data
- Cloud inventory for storage buckets
- Database discovery (MSSQL, MySQL, MongoDB, S3 buckets)
- SharePoint / Confluence / internal wiki crawl
Phase 2: Collect with minimal footprint
- Archive utility: 7z, WinRAR, tar (T1560)
- Cloud: aws s3 sync, az storage blob download
- Database: mysqldump / sqlcmd with native client
- Compress + encrypt before exfil
Phase 3: Stage for exfiltration
- Staging directory (avoid shares with broad audit)
- Split into chunks (under 50 MB for stealth)
- Encrypt with AES-256-GCM before transmission
```
### 8.2 Exfiltration Channels
```
Channel │ TTP ID │ Notes
────────────────────────────┼─────────┼────────────────────────────────
HTTPS POST to redirector │ T1041 │ Looks like API traffic
DNS tunneling │ T1572 │ Slow but high stealth
Cloud upload (S3/Blob/Drive)│ T1567 │ Blends with normal traffic
SMTP via compromised inbox │ T1114 │ Send data as email attachments
Social media DM │ T1102 │ Post encoded data to Twitter/Discord
FTP/SFTP to staging host │ T1048 │ Use non-standard port
Tor hidden service │ T1572 │ High latency, high anonymity
WebSocket / MCP server │ T1572 │ Novel channel via MCP bridge
Physical media │ T1052 │ USB key / SD card (on-site only)
```
---
## 9. Command & Control (C2)
### 9.1 Framework Selection Guide
```
┌───────────────┬──────────┬──────────┬───────────┬──────────┬──────────┐
│ Framework │ Stealth │ Ops Cost │ Complexity│ Platform │ Notes │
├───────────────┼──────────┼──────────┼───────────┼──────────┼──────────┤
│ Sliver │ HIGH │ FREE │ Medium │ Win/Mac/ │ Active │
│ │ │ (OSS) │ │ Linux │ develop. │
│ │ │ │ │ │ MTLS │
├───────────────┼──────────┼──────────┼───────────┼──────────┼──────────┤
│ Mythic │ HIGH │ FREE │ High │ Win/Mac/ │ Modular │
│ │ │ (OSS) │ │ Linux │ custom │
│ │ │ │ │ │ payloads │
├───────────────┼──────────┼──────────┼───────────┼──────────┼──────────┤
│ Cobalt Strike │ MED-HIGH │ $5k/yr │ Medium │ Win │ Industry │
│ │ │ │ │ (some │ standard │
│ │ │ │ │ Linux) │ aggressor│
├───────────────┼──────────┼──────────┼───────────┼──────────┼──────────┤
│ Havoc │ MEDIUM │ FREE │ Medium │ Win │ Modern, │
│ │ │ (OSS) │ │ │ C++ impl │
├───────────────┼──────────┼──────────┼───────────┼──────────┼──────────┤
│ Brute Ratel │ HIGH │ $3k/yr │ High │ Win │ Anti-EDR │
│ C4 │ │ │ │ │ focus │
├───────────────┼──────────┼──────────┼───────────┼──────────┼──────────┤
│ PoshC2 │ LOW-MED │ FREE │ Low │ Win │ PS-based │
│ │ │ (OSS) │ │ │ easy but │
│ │ │ │ │ │ noisy │
├───────────────┼──────────┼──────────┼───────────┼──────────┼──────────┤
│ CALDERA │ N/A │ FREE │ Low │ Any │ Auto / │
│ (emulation) │ │ (OSS) │ │ (client- │ Purple │
│ │ │ │ │ side) │ team │
└───────────────┴──────────┴──────────┴───────────┴──────────┴──────────┘
```
### 9.2 C2 Communication Profiles
```
# Sliver HTTP(S) profile — mimics API traffic
{
"name": "api-telemetry",
"server": {
"path": "/api/v1/telemetry",
"method": "POST",
"headers": {
"accept": "application/json",
"x-request-id": "random()",
"content-type": "application/json; charset=utf-8"
}
},
"client": {
"jitter": 5,
"skew": 5000
}
}
# C2 sleep patterns (avoid beacon interval detection):
- Gaussian jitter: base 30s, stddev 15s
- Weekend/slow periods: extend to 5-15 min
- Active movement: drop to 5-10s (brief, then resume)
# Domain fronting:
- Cloudflare Workers: route through worker subdomain
- Front domain: high-reputation CDN (cloudfront.net)
- Backend: your real C2 domain (non-public)
```
### 9.3 AI Integration (Novel — MCP Bridge C2)
```
┌─────────────────────────────────────────────────────────────┐
│ C2 Operation via MCP Server (Model Context Protocol) │
│ │
│ Concept: Use an MCP server as a C2 transport layer. │
│ MCP is designed for AI agents to call tools — but the │
│ exact same transport can carry C2 commands disguised as │
│ "agent tool calls." │
│ │
│ Architecture: │
│ Agent (connects to MCP server) │ │
│ calls tools on C2 MCP server → commands to implants │
│ │
│ MCP STDIO bridge payload: │
│ { │
│ "jsonrpc": "2.0", │
│ "method": "tools/call", │
│ "params": { │
│ "name": "execute", │
│ "arguments": { "command": "shellcode" } │
│ } │
│ } │
│ │
│ Reference: SANS SEC565 (2026) — MCP servers for Empire/CS │
│ Risk: Novel technique, limited detection coverage │
└─────────────────────────────────────────────────────────────┘
```
---
## 10. Detection Evasion
### 10.1 Windows Evasion Layers
```
┌─────────────────────────────────────────────────────────────────┐
│ Layer 1: Operational Tradecraft │
│ - Run only from legitimate user context (not SYSTEM) │
│ - Operate during business hours (blend with normal traffic) │
│ - Use native admin tools: reg.exe, sc.exe, schtasks.exe │
│ - Always restore modified state (clean up artifacts) │
├─────────────────────────────────────────────────────────────────┤
│ Layer 2: Payload Hardening │
│ - Cobalt Strike: Malleable C2 profiles with random variants │
│ - Sleep mask: encrypt beacon in memory between callbacks │
│ - Syscall execution: no Win32 API calls (Hell's Gate, │
│ Halos Gate, TartarusGate, FreshyCalls) │
│ - Etw patching: disable ETW before loading managed code │
├─────────────────────────────────────────────────────────────────┤
│ Layer 3: Behavioral Camouflage │
│ - Avoid LSASS dump if Credential Guard active (use cookies) │
│ - Avoid mass scanning (hits AV thresholds) │
│ - Use single-user-targeted SMB connections (not sweeps) │
│ - Archive files within user-expected patterns │
├─────────────────────────────────────────────────────────────────┤
│ Layer 4: Persistence Camouflage │
│ - Name scheduled tasks after known software updaters │
│ - Register services under vendor-pretend names │
│ - DLL hijack paths that real software uses │
│ - Legitimate code signing certs (Extended Validation) │
└─────────────────────────────────────────────────────────────────┘
```
### 10.2 Linux Evasion
```
- Use compiled binaries (no Python/Perl unless target uses them)
- Modify timestamps with touch -r (masquerade as system file)
- Inject into existing processes (ptrace or ld_preload)
- Clear bash history, audit logs, auth logs (T1070.003)
- Suspend logging: stop rsyslog, disable auditd (T1562.001)
- Use /dev/shm or /tmp for payload staging (ram-backed, volatile)
- Mask processes with name squatting (sshd, cron, java, nginx)
- Binaries from legitimate proc manipulation: memfd_create()
```
---
## 11. Reporting & Debrief
### 11.1 Report Structure
```
┌──────────────────────────────────────────────────────────┐
│ 1. Executive Summary (1 page, non-technical) │
│ - Engagement objective │
│ - Key findings (3-5 bullet points) │
│ - Overall risk rating │
│ - Most impactful finding (single sentence) │
├──────────────────────────────────────────────────────────┤
│ 2. Engagement Overview │
│ - Scope, dates, ROE, threat actor emulated │
│ - ATT&CK coverage (Navigator layer JSON attached) │
├──────────────────────────────────────────────────────────┤
│ 3. Attack Narrative │
│ - Step-by-step timeline of the operation │
│ - Screenshots at decision points │
│ - ATT&CK technique IDs on every step │
├──────────────────────────────────────────────────────────┤
│ 4. Detection Gap Analysis │
│ - Every technique: detected / undetected / alerted │
│ - Detection coverage heatmap (ATT&CK Navigator layer) │
│ - Timeline: how long each phase went undetected │
├──────────────────────────────────────────────────────────┤
│ 5. Findings & Vulnerabilities (ranked by impact) │
│ 5.1 Critical — immediate remediation required │
│ 5.2 High — prioritize within 30 days │
│ 5.3 Medium — schedule within 90 days │
│ 5.4 Low — informational │
│ Each finding: vulnerability description, impact, │
│ remediation recommendation, CVSS (if applicable) │
├──────────────────────────────────────────────────────────┤
│ 6. Recommendations │
│ - People: security awareness gaps │
│ - Process: IR gaps, alert fatigue, handoff failures │
│ - Technology: tooling gaps, misconfigs │
├──────────────────────────────────────────────────────────┤
│ 7. Appendix A: Full ATT&CK Navigator Layers (.json) │
│ 8. Appendix B: Command Log (redacted) │
│ 9. Appendix C: IoCs (hashes, domains, IPs used) │
└──────────────────────────────────────────────────────────┘
```
### 11.2 ATT&CK Coverage Visualization
```
Produce 3 ATT&CK Navigator layers per engagement:
Planning Layer: Techniques planned for execution (color-coded by phase)
Execution Layer: Techniques actually executed (green=success, red=fail)
Detection Layer: Techniques detected by blue team (pattern overlay)
Compare layers to produce:
Gap Layer: Executed but undetected = the real risk
Improvement Layer: Re-test + compare delta from prior engagement
```
---
## 12. Continuous Improvement Loop
### 12.1 After-Action Review
```
┌─────────────────────────────────────────────────────────────┐
│ AAR Questions (conducted within 1 week of engagement end) │
│ │
│ 1. What went well? (capture for repeatable procedures) │
│ 2. What went wrong? (capture for avoid-list) │
│ 3. What was detected? (feedback to tooling/evasion) │
│ 4. What took longer than expected? (scope/timeline) │
│ 5. What data was missing? (intel gaps) │
│ 6. Infrastructure performance? (domain reputation, │
│ redirector latency, burn timing) │
│ 7. Any operator OPSEC failures? (lessons learned) │
│ 8. What technique would we add next time? │
│ 9. What technique would we drop? │
│ 10. What detection gap was most alarming? │
└─────────────────────────────────────────────────────────────┘
```
### 12.2 Knowledge Absorb Cycle
```
Research (new TTPs, CVEs, tool updates) ─┐
│ │
▼ │
Test in isolated lab │
│ ├── 2-week cycle
▼ │
Document in skill/memory │
│ │
▼ │
Apply in next engagement ─┘
│
▼
Post-engagement AAR feeds back into skill updates
```
### 12.3 Tooling Upgrade Pipeline
```
Each engagement → tooling audit:
- Which C2 framework version? (upstream changes?)
- Which evasions worked? (document exact configuration)
- Which payloads got caught? (modify or remove)
- Infrastructure: any domain burned? (cycle to new set)
- MCP/C2 novel channels: test integration with current payload
Maintain counter-research:
- Follow EDR release notes (Defender, CrowdStrike, SentinelOne)
- Track Sigma rule updates for common C2 frameworks
- Monitor conference talks (SANS SEC565, DEF CON, Black Hat)
- Scan for new CVEs in the target's technology stack weekly
```
---
## 13. Ethical & Legal Boundaries
### 13.1 Non-Negotiable Rules
```
⚠ NO operations without signed, dated authorization.
⚠ NO unauthorized data exfiltration (PII/PHI requires data handling plan).
⚠ NO destructive action without explicit scoping.
⚠ NO self-approval: every engagement requires external authorization.
⚠ NO using this blueprint for illegal activity.
⚠ NO zero-day development without vulnerability disclosure plan.
⚠ NO targeting of civil infrastructure without government authorization.
```
### 13.2 Liability Management
```
- Maintain insurance (cyber liability + E&O)
- Maintain chain of evidence logs (signed, timestamped)
- Use separate infrastructure per engagement (no cross-contamination)
- Destroy all client data post-engagement (certified wipe)
- Retain engagement ROEs for minimum 7 years
```
---
## 14. Quick Reference: Priority Toolmap
```
┌─────────────────┬─────────────────────────────────────────────┐
│ Category │ Primary Tools (Free) │
├─────────────────┼─────────────────────────────────────────────┤
│ Recon │ SpiderFoot, Amass, Shodan, cert.sh │
│ OSINT │ Maltego, theHarvester, Sherlock │
│ Phishing │ SET, GoPhish, Evilginx2 │
│ C2 Framework │ Sliver, Mythic │
│ Payload Gen │ msfvenom, Donut, ScareCrow, NimPlant │
│ AD Enumeration │ BloodHound (SharpHound), PowerView, AdFind │
│ Credential │ Mimikatz, Rubeus, SektSAM, LaZagne │
│ Web Exploit │ Burp Suite (community), Nuclei, sqlmap │
│ Reverse Eng │ Ghidra, x64dbg, radare2, capa │
│ Network │ Nmap, masscan, Responder, impacket │
│ Cloud │ Pacu (AWS), ScoutSuite, Stratus Red Team │
│ Infrastructure │ Terraform, Ansible, Cloudflare, autossh │
│ Reporting │ VECTR, ATT&CK Navigator, Obsidian │
│ Collaboration │ Slack/Matrix encrypted, Signal │
└─────────────────┴─────────────────────────────────────────────┘
```
---
**End of ptSlick Red Team Operations Blueprint v1.0**
> "Assume detection is inevitable. Rotate before you burn.
> Plan your infrastructure like you expect to lose it tomorrow."