📖 Blueprints & Methodologies

Pentest methodology documents, operational blueprints, and security references.

← Back to list red-team-operations-blueprint.md
red-team-operations-blueprint.md
Download Raw
# ptSlick — Red Team Operations Blueprint v1.0
**Classification**: Internal — SlickLab Red Team Operations
**Build**: 2026-10-03 | **Next Review**: 2026-11-03
**Author**: Colnex (SlickLab Operational Intelligence)

---

## 1. Operating Philosophy

### 1.1 Core Tenets

```
Dark-Minded Posture       → Assume every engagement exposes infrastructure.
                          → Assume detection is inevitable after initial foothold.
                          → Plan for burn, rotate before burn.

Hierarchy of Stealth      → 1. Living off the land (LOTL) — native tools only.
                          → 2. Reflective loading — no disk writes.
                          → 3. Custom tooling — compiled per target, signed, unique hashes.
                          → 4. Commodity tooling — rename, obfuscate, recompile.

Operational Security      → Air-gapped C2 brains on-premise.
                          → Cloud redirectors as sacrificial front-end.
                          → Infrastructure as disposable, stateless cattle.
                          → Every node has a kill switch.

Least Privilege           → Tools run at minimum permission required.
                          → Credentials scoped per engagement.
                          → No reused infrastructure between clients.
                          → No operator identity on redirectors or C2 front-ends.
```

### 1.2 The Kill Chain Model (ATT&CK-aligned)

This blueprint operationalizes the MITRE ATT&CK v19.1 framework across 14 tactics.
Every procedure references a technique ID for blue-team traceability and detection-gap mapping.

```
TA0043 ── Reconnaissance         │ Gather intel, map surface, profile people
TA0042 ── Resource Development   │ Build/acquire infrastructure, domains, certs
TA0001 ── Initial Access         │ Phish, exploit, physical breach
TA0002 ── Execution              │ Run payload, stager, macro, LOLBin
TA0003 ── Persistence            │ Backdoor, scheduled task, registry, service
TA0004 ── Privilege Escalation   │ UAC bypass, token steal, kernel exploit
TA0005 ── Defense Evasion        │ Obfuscate, masquerade, disable logging
TA0006 ── Credential Access      │ Dump LSASS, scrape browser, Kerberoast
TA0007 ── Discovery              │ Enumerate users, groups, shares, AD, cloud
TA0008 ── Lateral Movement       │ WinRM, SMB, PsExec, SSH, cloud trust
TA0009 ── Collection             │ Gather data of interest from endpoints
TA0011 ── Command & Control      │ Beacon, tunnel, domain fronting, MCP bridge
TA0010 ── Exfiltration           │ Archive + send over covert channel
TA0040 ── Impact                 │ Encrypt, destroy, manipulate (scope-dependent)
```

---

## 2. Pre-Engagement Framework

### 2.1 Scoping & Rules of Engagement

```
    ┌─────────────────────────────────────────────────────┐
    │ ROE Document — Required Fields                       │
    ├─────────────────────────────────────────────────────┤
    │ Client / Target Organization                         │
    │ Engagement Dates                                     │
    │ Objective(s) — Crown Jewels (3-5 items)              │
    │ In-Scope Systems/Networks (CIDR ranges, domains)     │
    │ Out-of-Scope Systems (explicitly listed)              │
    │ Authorized Attack Methods                            │
    │   - Social engineering: Y/N (targets?)               │
    │   - Physical intrusion: Y/N (locations?)             │
    │   - Web app exploitation: Y/N                        │
    │   - API abuse: Y/N                                   │
    │   - Wi-Fi/radio attacks: Y/N                         │
    │ Exfiltration Limits (data types allowed)              │
    │ Time Constraints (business hours only? weekends?)     │
    │ Deconfliction Protocol (who has pause authority)      │
    │ Emergency Contact (CISO, Trusted Agent)               │
    │ Stop Conditions (objective achieved? Ransomware found?)│
    │ Legal Authorization (signed SOW + insurance proof)    │
    └─────────────────────────────────────────────────────┘
```

### 2.2 Threat Actor Selection

Select the adversary profile that aligns with the target's threat model:

```
┌──────────────────┬───────────────────────────────────────┬──────────────────┐
│ Actor Profile    │ Best For                              │ Key TTPs         │
├──────────────────┼───────────────────────────────────────┼──────────────────┤
│ APT29 (Cozy Bear)│ Government, think tanks, pharma       │ Spearphish, PS,  │
│                  │ Espionage simulation                  │ Reg run keys,     │
│                  │                                       │ LSASS dump,       │
│                  │                                       │ WinRM, HTTPS C2  │
├──────────────────┼───────────────────────────────────────┼──────────────────┤
│ FIN7 / FIN12     │ Financial services, retail, POS       │ Phishing,        │
│                  │ Financially motivated adversary        │ PowerShell,       │
│                  │                                       │ scheduled tasks,  │
│                  │                                       │ SMB lateral,     │
│                  │                                       │ ransomware prep   │
├──────────────────┼───────────────────────────────────────┼──────────────────┤
│ Lazarus Group    │ Cryptocurrency, fintech, critical infra│ Watering hole,   │
│                  │ Destructive + theft                   │ macOS/Windows,    │
│                  │                                       │ custom malware,   │
│                  │                                       │ blockchain theft │
├──────────────────┼───────────────────────────────────────┼──────────────────┤
│ APT41            │ Manufacturing, telecom, defense       │ Supply chain,    │
│                  │ Dual-use espionage+theft               │ drive-by, .NET,  │
│                  │                                       │ Cobalt Strike,   │
│                  │                                       │ AD abuse         │
├──────────────────┼───────────────────────────────────────┼──────────────────┤
│ Wizard Spider    │ Any sector with ransomware risk       │ Phishing, RDP,   │
│                  │ Ransomware kill chain                  │ Cobalt Strike,   │
│                  │                                       │ Ryuk/Conti,      │
│                  │                                       │ data extortion   │
├──────────────────┼───────────────────────────────────────┼──────────────────┤
│ Custom Composite │ Most engagements — blend TTPs from    │ Cherry-pick      │
│                  │ 2-3 actors relevant to target's sector │ techniques from  │
│                  │                                       │ matched profiles │
└──────────────────┴───────────────────────────────────────┴──────────────────┘
```

### 2.3 Objective Definition

```
Weak objective:    "Get domain admin"
Strong objective:  "Exfiltrate the customer PII database from the production SQL server
                    and place a ransom note on the CFO's desktop without triggering
                    the SOC's EDR alert within 72 hours."
```

Define 3-5 crown jewel objectives. Each must be:
- **Measurable** — either you have the data or you don't
- **Time-bound** — within the engagement window
- **Realistic** — technically feasible in the target environment
- **Approved** — no exfil of PII without data handling agreement

---

## 3. Infrastructure Architecture

### 3.1 The Hybrid C2 Model (Air-Gap + Cloud Front)

```
                              ┌──────────────────────┐
                              │    CLOUDFLARE DNS    │
                              │   (proxy = on)      │
                              │   Real IP hidden    │
                              └────────┬─────────────┘
                                       │
                                       ▼
                          ┌────────────────────────┐
                          │  CLOUD VPS (Redirector) │
                          │  nginx reverse proxy    │
                          │  Decoy website on root  │
                          │  Port 443 HTTPS         │
                          │  SOCAT fallback          │
                          │  ssh -R tunnel           │
                          └────────┬────────────────┘
                                   │ SSH -R (reverse port forward)
                                   │
                          ┌────────▼────────────────┐
                          │  ON-PREM C2 SERVER      │
                          │  (Air-gapped, no public │
                          │   ports, behind NAT)    │
                          │  Sliver | Mythic | CS   │
                          │  Ports: 443, 8080       │
                          └─────────────────────────┘
```

**Architecture rules:**
- **C2 server is NEVER directly reachable** from the internet
- **Redirectors are disposable** — Terraform + Ansible = 5-min rebuild
- **Decoy website** on redirector root (/var/www/html/legit-site/) — against nginx traffic inspection, serve a real site (bootstrap template, cloned blog)
- **Cloudfront/Akamai** for domain fronting when permitted
- **SSH reverse port forward** only outbound from protected C2 → redirector
- **No persistent SSH sessions** — use autossh with systemd restart

### 3.2 Infrastructure Quick-Deploy

```
# Terraform + Ansible stack (deploy in under 30 min)
# Reference: github.com/rbfp/redteam-infra

Components:
  - Terraform for: VPC, subnets, security groups, EC2/DO/Linode instances
  - Ansible for: nginx config, socat, Cloudflare tunnel, systemd units
  - One bastion host (SSH gateway) — logs all operator access

Domain rotation:
  - Every engagement gets 3+ new domains
  - DNS records created 48-72 hours BEFORE engagement start
  - Domains aged 30+ days preferred (better reputation)
  - Use .com, .net, .org, .io, .co — varied TLDs
  - Domain fronting via Cloudflare Workers or Akamai Edge

Ops monitoring:
  - Redirector access logs streamed to isolated log server
  - Fail2ban on redirector — block known scanners (Shodan, Censys)
  - Daily domain reputation check: virustotal, urlscan.io, hybrid-analysis
  - Kill switch: DNS record removal deactivates entire infrastructure in < 5 min
```

### 3.3 Infrastructure Security Controls

```
┌────────────────┬──────────────────────────────┬─────────────────┐
│ Control        │ Implementation               │ Justification   │
├────────────────┼──────────────────────────────┼─────────────────┤
│ SSH keys only  │ No password auth anywhere    │ Prevents        │
│                │                              │ credential      │
│                │                              │ brute-force     │
├────────────────┼──────────────────────────────┼─────────────────┤
│ Cloudflare     │ Proxy=on, IP hidden          │ Blue team can't │
│ proxy          │                              │ scan C2 origin  │
├────────────────┼──────────────────────────────┼─────────────────┤
│ User-agent     │ VPS returns 404 for known    │ Stops scanners, │
│ filtering      │ scanners + missing Host:     │ footprint       │
│                │ header visitors              │ reduction      │
├────────────────┼──────────────────────────────┼─────────────────┤
│ Decoy content  │ Legit-looking site served on │ Traffic         │
│                │ redirector root              │ analysis        │
│                │                              │ camouflage      │
├────────────────┼──────────────────────────────┼─────────────────┤
│ No C2 data on │ Agents never touch redirector│ Physical        │
│ redirector    │ storage                       │ containment     │
├────────────────┼──────────────────────────────┼─────────────────┤
│ Network        │ C2 server: deny all inbound  │ Prevents        │
│ segmentation  │ except established outbound   │ pivoting to C2  │
│               │                               │ from target     │
├────────────────┼──────────────────────────────┼─────────────────┤
│ Log retention  │ 90 days minimum, off-site    │ Post-           │
│                │ copy                          │ engagement      │
│                │                               │ forensic        │
│                │                               │ reconstruction │
└────────────────┴──────────────────────────────┴─────────────────┘
```

---

## 4. Reconnaissance & OSINT Pipeline

### 4.1 Automated Discovery Tier

```
Phase 1: Surface Enumeration   │ Tools: SpiderFoot (200+ sources)
                                │        Amass (subdomain enumeration)
                                │        Sublist3r
                                │        Cert.sh (certificate transparency)
                                │ Output: Asset inventory (domains, IPs, ASNs)

Phase 2: Service Profiling     │ Tools: Nmap (stealth -sS -sV -T2)
                                │        Masscan (fast port sweep)
                                │        Shodan/Censys API
                                │ Output: Open ports, service banners, CVEs

Phase 3: Technology Stack       │ Tools: Wappalyzer (CLI)
                                │        WhatWeb
                                │        BuiltWith API
                                │ Output: CMS, frameworks, cloud providers, CDNs

Phase 4: Dark Web & Leaks      │ Tools: Tor browser automation
                                │        Dehashed/IntelX API
                                │        Password dump search (HaveIBeenPwned API)
                                │ Output: Credential leaks, exposed credentials
```

### 4.2 Human Intelligence (HUMINT)

```
LinkedIn profiling:
  - Enumerate employees by department (IT, Security, Exec)
  - Build role-to-person mapping
  - Identify targets for spearphishing: IT helpdesk, SOC analysts, executives
  - Detect technology stack from employee skills/certifications

Job postings:
  - Parse for security tools deployed (SIEM, EDR, SOAR listed in requirements)
  - Identify technology shifts (migration to cloud, new database)
  - Map network architecture from job descriptions

Social media:
  - Accounts that post about work (internal tools, project names)
  - Conference attendance (what security products they use)
  - Disgruntled employees (potential insider threat vector—monitor, don't engage)
```

### 4.3 Google Dorking Playbook

```
Intentionally unlisted files & directories:
  site:target.com intitle:"index of" (passwd | config | backup | admin)

Exposed credentials:
  site:target.com filetype:env (DB_PASSWORD | API_KEY | SECRET)
  site:target.com intext:"-----BEGIN RSA PRIVATE KEY-----"

Exposed databases:
  site:target.com filetype:sql (INSERT INTO | CREATE TABLE)
  site:target.com filetype:bak inurl:backup

Cloud storage misconfig:
  site:amazonaws.com inurl:targetcompany (mapped to known prefixes)
  site:blob.core.windows.net "target.com"

Admin/exposed panels:
  site:target.com inurl:phpmyadmin
  site:target.com inurl:/wp-admin intitle:"login"
  site:target.com intitle:"Kibana" "search"
```

---

## 5. Initial Access Arsenal

### 5.1 Phishing Operations

```
┌──────────┬──────────────────────┬──────────────────────────────┐
│ Vector   │ Technique            │ OPSEC Requirements           │
├──────────┼──────────────────────┼──────────────────────────────┤
│ Email    │ Spearphishing        │ Dedicated phishing domain    │
│          │ Attachment           │ SPF/DKIM/DMARC configured    │
│          │ (T1566.001)          │ Domain aged 30+ days        │
│          │                      │ DMARC = p=none (don't alert) │
├──────────┼──────────────────────┼──────────────────────────────┤
│ Email    │ Spearphishing Link   │ Same as above + HTTPS cert   │
│          │ (T1566.002)          │ Landing page mimics target   │
│          │                      │ No malware on landing page   │
├──────────┼──────────────────────┼──────────────────────────────┤
│ Email    │ Spearphishing via    │ Compromise trusted 3rd-party │
│          │ Service (T1566.003)  │ Use legitimate service       │
│          │                      │ (DocuSign, Dropbox, etc.)    │
├──────────┼──────────────────────┼──────────────────────────────┤
│ Voice    │ Vishing (social eng) │ Spoofed caller ID            │
│          │                      │ Scripted conversation tree   │
│          │                      │ Target: helpdesk, IT support │
├──────────┼──────────────────────┼──────────────────────────────┤
│ SMS      │ Smishing             │ Temporary numbers only       │
│          │                      │ Shortened URLs (bitly, etc.) │
│          │                      │ Harvest 2FA codes via clone  │
├──────────┼──────────────────────┼──────────────────────────────┤
│ Physical │ USB drop             │ Rubber ducky / badUSB        │
│          │                      │ OPSEC: no fingerprints       │
│          │                      │ Drop locations: smoking area,│
│          │                      │ break room, parking lot     │
└──────────┴──────────────────────┴──────────────────────────────┘
```

### 5.2 Phishing Payload Delivery Chain

```
                  ┌──────────────────┐
                  │ Target clicks    │
                  │ link/opens doc   │
                  └────────┬─────────┘
                           ▼
           ┌───────────────────────────────┐
           │  Stage 1: Dropper / Stager    │
           │  - Macro-enabled Word doc     │
           │  - HTML smuggling (blob URL)  │
           │  - ISO file (mounts, no MOTW)│
           │  - LNK file in zip archive   │
           └───────────────┬───────────────┘
                           ▼
           ┌───────────────────────────────┐
           │  Stage 2: LOLBin Execution    │
           │  - mshta.exe                 │
           │  - regsvr32.exe (sct file)   │
           │  - rundll32.exe              │
           │  - powershell.exe (-enc)     │
           │  - wmic.exe                  │
           └───────────────┬───────────────┘
                           ▼
           ┌───────────────────────────────┐
           │  Stage 3: Shellcode Loader    │
           │  - Process hollowing         │
           │  - Reflective DLL injection  │
           │  - Donut (shellcode to PE)   │
           │  - Callback via syscall      │
           └───────────────┬───────────────┘
                           ▼
           ┌───────────────────────────────┐
           │  Stage 4: C2 Beacon          │
           │  - Sliver / Mythic / CS       │
           │  - Sleep mask obfuscation    │
           │  - Memory-only execution     │
           │  - No disk writes            │
           └───────────────────────────────┘
```

### 5.3 Exploitation (External-Facing)

```
Priority targets for external exploitation:

  1. VPN gateways (Pulse Secure, Citrix, Fortinet)           → T1190
  2. Web applications with file upload / RCE                 → T1190
  3. Exposed admin panels (phpMyAdmin, Jenkins, K8s API)     → T1190
  4. Cloud storage with public access                        → T1530
  5. Self-signed certs or expired SSL with sensitive info    → T1602
  6. Jupyter Notebook / Grafana / Kibana no auth              → T1213
  7. Exposed Git repos (.git/config)                          → T1213/TA0007
```

---

## 6. Persistence & Privilege Escalation

### 6.1 Windows Persistence (LOTL-first)

```
Technique                   │ TTP ID  │ Method
────────────────────────────┼─────────┼───────────────────────────────
Registry Run Key            │ T1547.001│ reg add HKCU\...\Run
Scheduled Task              │ T1053.005│ schtasks /create
Startup Folder              │ T1547.001│ Drop LNK in %APPDATA%\Microsoft\
                            │          │   Windows\Start Menu\Programs\
                            │          │   Startup
Service (dll/hijack)        │ T1543.003│ sc create type= kernel
WMI Event Subscription      │ T1546.003│ ActiveScriptEventConsumer
DLL Search Order Hijack     │ T1574.001│ Inflated DLL in privileged path
COM Hijacking               │ T1546.015│ CLSID redirection
Skeleton Key (Kerberos)     │ T1554    │ Mimikatz skeleton key (AD only)
```

### 6.2 Linux Persistence

```
Technique                   │ TTP ID  │ Method
────────────────────────────┼─────────┼───────────────────────────────
SSH Authorized Keys         │ T1098.004│ ~/.ssh/authorized_keys append
cron / crontab              │ T1053.003│ (crontab -l; echo "* * * * *") | crontab
systemd service              │ T1543.002│ /etc/systemd/system/legit-service.service
LD_PRELOAD rootkit          │ T1574.006│ /etc/ld.so.preload
Kernel module (.ko)          │ T1574.006│ insmod rootkit.ko (if root)
Web shell (persistent)       │ T1505.003│ PHP/JSP/ASPX on web server
Container escape             │ T1611    │ cgroup / host mount escape
```

### 6.3 Privilege Escalation — Windows

```
Tactic                      │ TTP ID  │ Technique
────────────────────────────┼─────────┼───────────────────────────────
UAC Bypass                  │ T1548.002│ fodhelper / eventvwr / sdclt
Token Theft                 │ T1134.001│ Named pipe impersonation
PrintNightmare (patched)    │ T1068    │ CVE-2021-1675 (if unpatched)
SMBGhost                    │ T1068    │ CVE-2020-0796
Certify (AD CS abuse)       │ T1648    │ ESC1-ESC13 misconfigs
SeBackupPrivilege           │ T1003.003│ reg.exe save HKLM\SAM
Unquoted Service Path       │ T1574.002│ Path with spaces + arbitrary exe
AlwaysInstallElevated       │ T1546.014│ MSI runs as SYSTEM
```

### 6.4 Privilege Escalation — Linux

```
Tactic                      │ TTP ID  │ Technique
────────────────────────────┼─────────┼───────────────────────────────
SUID Misconfig              │ T1548.001│ find / -perm -4000 2>/dev/null
Sudo Exploitation           │ T1548.003│ sudo -l, CVE-2021-3156
Capabilities                │ T1548    │ getcap -r / 2>/dev/null
Docker Escape               │ T1611    │ --privileged / --pid=host
Kernel Exploit              │ T1068    │ Dirty Pipe (CVE-2022-0847)
PKEXEC                      │ T1574.006│ CVE-2021-4034 (pwnkit)
Path Hijack                 │ T1574.005│ Writable $PATH + script
```

---

## 7. Lateral Movement

### 7.1 Active Directory Movement

```
┌────────────────────────────────────────────────────────────┐
│ Discovery (T1087, T1069, T1482)                            │
│   whoami /groups, net group "Domain Admins" /domain        │
│   PowerView: Get-NetUser, Get-NetGroup, Get-NetComputer    │
│   BloodHound: SharpHound collector → ingest into BH UI     │
│   AdFind: LDAP query for trusts, delegation, ACLs         │
├────────────────────────────────────────────────────────────┤
│ Movement (T1021, T1569)                                     │
│   WinRM →   Enter-PSSession (T1021.006)                    │
│   SMB  →    psexec, wmiexec (T1021.002, T1047)             │
│   RDP  →    xfreerdp (T1021.001 — noisy, last resort)      │
│   SSH  →    plink / OpenSSH (T1021.004)                    │
│   DCOM →    MMC20.Application lateral (T1021.003)          │
├────────────────────────────────────────────────────────────┤
│ AD Attacks (verified via BloodHound paths)                  │
│   Kerberoasting       → T1558.003 — SPN + hash request     │
│   AS-REP Roasting     → T1558.004 — no pre-auth accounts   │
│   DCSync              → T1003.006 — DC replication abuse   │
│   Golden Ticket       → T1558.001 — KRBTGT hash forge      │
│   Silver Ticket       → T1558.002 — service NTLM forge     │
│   ACL Abuse           → T1222.001 — WriteOwner, GenericAll │
│   AdminSDHolder       → T1222.001 — backdoor AD groups     │
│   Skeleton Key        → T1554    — Kerberos bypass (DC)    │
└────────────────────────────────────────────────────────────┘
```

### 7.2 Cloud Lateral Movement

```
AWS:
  - STS token theft from instance metadata (T1526)
  - AssumeRole chain abuse (T1524)
  - SSM agent for command execution (T1569)
  - Lambda function injection (T1578.002)
  - CloudTrail disable before destructive actions (T1562.008)

Azure:
  - MS Graph API token theft (T1527)
  - Hybrid identity sync compromise (T1527)
  - Azure AD Connect misconfig → AD sync takeover
  - Managed identity pivot (through IMDS endpoint)
  - Key Vault data collection (T1552.005)

GCP:
  - Service account key extraction (T1527)
  - IAM role escalation via delegation
  - Cloud Functions injection
  - GCS bucket enumeration → data collection
```

### 7.3 Container & Kubernetes Pivot

```
  K8s API exposure          → T1190 (if no auth)
  kubeconfig theft          → T1552 (from pods, CI/CD)
  Pod exec (kubectl exec)   → T1609
  Secrets enumeration       → T1552.007
  Sidecar injection         → T1190 (admission webhook)
  Container escape          → T1611 (--privileged, hostPID)
  Cluster admin (rbac)      → T1562 (disable audit)
```

---

## 8. Exfiltration & Objective Completion

### 8.1 Data Collection Strategy

```
Phase 1: Identify crown jewel location
  - BloodHound for AD data
  - Cloud inventory for storage buckets
  - Database discovery (MSSQL, MySQL, MongoDB, S3 buckets)
  - SharePoint / Confluence / internal wiki crawl

Phase 2: Collect with minimal footprint
  - Archive utility: 7z, WinRAR, tar (T1560)
  - Cloud: aws s3 sync, az storage blob download
  - Database: mysqldump / sqlcmd with native client
  - Compress + encrypt before exfil

Phase 3: Stage for exfiltration
  - Staging directory (avoid shares with broad audit)
  - Split into chunks (under 50 MB for stealth)
  - Encrypt with AES-256-GCM before transmission
```

### 8.2 Exfiltration Channels

```
Channel                     │ TTP ID  │ Notes
────────────────────────────┼─────────┼────────────────────────────────
HTTPS POST to redirector    │ T1041   │ Looks like API traffic
DNS tunneling               │ T1572   │ Slow but high stealth
Cloud upload (S3/Blob/Drive)│ T1567   │ Blends with normal traffic
SMTP via compromised inbox  │ T1114   │ Send data as email attachments
Social media DM             │ T1102   │ Post encoded data to Twitter/Discord
FTP/SFTP to staging host    │ T1048   │ Use non-standard port
Tor hidden service          │ T1572   │ High latency, high anonymity
WebSocket / MCP server      │ T1572   │ Novel channel via MCP bridge
Physical media              │ T1052   │ USB key / SD card (on-site only)
```

---

## 9. Command & Control (C2)

### 9.1 Framework Selection Guide

```
┌───────────────┬──────────┬──────────┬───────────┬──────────┬──────────┐
│ Framework     │ Stealth  │ Ops Cost │ Complexity│ Platform │ Notes    │
├───────────────┼──────────┼──────────┼───────────┼──────────┼──────────┤
│ Sliver        │ HIGH     │ FREE     │ Medium    │ Win/Mac/ │ Active   │
│               │          │ (OSS)    │           │ Linux    │ develop. │
│               │          │          │           │          │ MTLS     │
├───────────────┼──────────┼──────────┼───────────┼──────────┼──────────┤
│ Mythic        │ HIGH     │ FREE     │ High      │ Win/Mac/ │ Modular  │
│               │          │ (OSS)    │           │ Linux    │ custom   │
│               │          │          │           │          │ payloads │
├───────────────┼──────────┼──────────┼───────────┼──────────┼──────────┤
│ Cobalt Strike │ MED-HIGH │ $5k/yr  │ Medium    │ Win      │ Industry │
│               │          │          │           │ (some    │ standard │
│               │          │          │           │ Linux)   │ aggressor│
├───────────────┼──────────┼──────────┼───────────┼──────────┼──────────┤
│ Havoc         │ MEDIUM   │ FREE     │ Medium    │ Win      │ Modern,  │
│               │          │ (OSS)    │           │          │ C++ impl │
├───────────────┼──────────┼──────────┼───────────┼──────────┼──────────┤
│ Brute Ratel   │ HIGH     │ $3k/yr  │ High      │ Win      │ Anti-EDR │
│ C4            │          │          │           │          │ focus    │
├───────────────┼──────────┼──────────┼───────────┼──────────┼──────────┤
│ PoshC2        │ LOW-MED  │ FREE     │ Low       │ Win      │ PS-based │
│               │          │ (OSS)    │           │          │ easy but │
│               │          │          │           │          │ noisy    │
├───────────────┼──────────┼──────────┼───────────┼──────────┼──────────┤
│ CALDERA       │ N/A      │ FREE     │ Low       │ Any      │ Auto /   │
│ (emulation)   │          │ (OSS)    │           │ (client- │ Purple   │
│               │          │          │           │ side)   │ team     │
└───────────────┴──────────┴──────────┴───────────┴──────────┴──────────┘
```

### 9.2 C2 Communication Profiles

```
# Sliver HTTP(S) profile — mimics API traffic
{
  "name": "api-telemetry",
  "server": {
    "path": "/api/v1/telemetry",
    "method": "POST",
    "headers": {
      "accept": "application/json",
      "x-request-id": "random()",
      "content-type": "application/json; charset=utf-8"
    }
  },
  "client": {
    "jitter": 5,
    "skew": 5000
  }
}

# C2 sleep patterns (avoid beacon interval detection):
  - Gaussian jitter: base 30s, stddev 15s
  - Weekend/slow periods: extend to 5-15 min
  - Active movement: drop to 5-10s (brief, then resume)

# Domain fronting:
  - Cloudflare Workers: route through worker subdomain
  - Front domain: high-reputation CDN (cloudfront.net)
  - Backend: your real C2 domain (non-public)
```

### 9.3 AI Integration (Novel — MCP Bridge C2)

```
  ┌─────────────────────────────────────────────────────────────┐
  │ C2 Operation via MCP Server (Model Context Protocol)        │
  │                                                             │
  │ Concept: Use an MCP server as a C2 transport layer.         │
  │ MCP is designed for AI agents to call tools — but the       │
  │ exact same transport can carry C2 commands disguised as     │
  │ "agent tool calls."                                         │
  │                                                             │
  │ Architecture:                                               │
  │   Agent (connects to MCP server) │                          │
  │     calls tools on C2 MCP server → commands to implants    │
  │                                                             │
  │ MCP STDIO bridge payload:                                   │
  │   {                                                         │
  │     "jsonrpc": "2.0",                                       │
  │     "method": "tools/call",                                 │
  │     "params": {                                             │
  │       "name": "execute",                                    │
  │       "arguments": { "command": "shellcode" }               │
  │     }                                                       │
  │   }                                                         │
  │                                                             │
  │ Reference: SANS SEC565 (2026) — MCP servers for Empire/CS   │
  │ Risk: Novel technique, limited detection coverage           │
  └─────────────────────────────────────────────────────────────┘
```

---

## 10. Detection Evasion

### 10.1 Windows Evasion Layers

```
┌─────────────────────────────────────────────────────────────────┐
│ Layer 1: Operational Tradecraft                                 │
│   - Run only from legitimate user context (not SYSTEM)          │
│   - Operate during business hours (blend with normal traffic)   │
│   - Use native admin tools: reg.exe, sc.exe, schtasks.exe      │
│   - Always restore modified state (clean up artifacts)          │
├─────────────────────────────────────────────────────────────────┤
│ Layer 2: Payload Hardening                                      │
│   - Cobalt Strike: Malleable C2 profiles with random variants   │
│   - Sleep mask: encrypt beacon in memory between callbacks      │
│   - Syscall execution: no Win32 API calls (Hell's Gate,         │
│     Halos Gate, TartarusGate, FreshyCalls)                     │
│   - Etw patching: disable ETW before loading managed code       │
├─────────────────────────────────────────────────────────────────┤
│ Layer 3: Behavioral Camouflage                                  │
│   - Avoid LSASS dump if Credential Guard active (use cookies)  │
│   - Avoid mass scanning (hits AV thresholds)                   │
│   - Use single-user-targeted SMB connections (not sweeps)      │
│   - Archive files within user-expected patterns                │
├─────────────────────────────────────────────────────────────────┤
│ Layer 4: Persistence Camouflage                                 │
│   - Name scheduled tasks after known software updaters          │
│   - Register services under vendor-pretend names                │
│   - DLL hijack paths that real software uses                    │
│   - Legitimate code signing certs (Extended Validation)        │
└─────────────────────────────────────────────────────────────────┘
```

### 10.2 Linux Evasion

```
  - Use compiled binaries (no Python/Perl unless target uses them)
  - Modify timestamps with touch -r (masquerade as system file)
  - Inject into existing processes (ptrace or ld_preload)
  - Clear bash history, audit logs, auth logs (T1070.003)
  - Suspend logging: stop rsyslog, disable auditd (T1562.001)
  - Use /dev/shm or /tmp for payload staging (ram-backed, volatile)
  - Mask processes with name squatting (sshd, cron, java, nginx)
  - Binaries from legitimate proc manipulation: memfd_create()
```

---

## 11. Reporting & Debrief

### 11.1 Report Structure

```
┌──────────────────────────────────────────────────────────┐
│ 1. Executive Summary (1 page, non-technical)             │
│    - Engagement objective                                │
│    - Key findings (3-5 bullet points)                    │
│    - Overall risk rating                                 │
│    - Most impactful finding (single sentence)            │
├──────────────────────────────────────────────────────────┤
│ 2. Engagement Overview                                    │
│    - Scope, dates, ROE, threat actor emulated            │
│    - ATT&CK coverage (Navigator layer JSON attached)     │
├──────────────────────────────────────────────────────────┤
│ 3. Attack Narrative                                       │
│    - Step-by-step timeline of the operation              │
│    - Screenshots at decision points                      │
│    - ATT&CK technique IDs on every step                  │
├──────────────────────────────────────────────────────────┤
│ 4. Detection Gap Analysis                                │
│    - Every technique: detected / undetected / alerted    │
│    - Detection coverage heatmap (ATT&CK Navigator layer) │
│    - Timeline: how long each phase went undetected       │
├──────────────────────────────────────────────────────────┤
│ 5. Findings & Vulnerabilities (ranked by impact)         │
│    5.1 Critical — immediate remediation required         │
│    5.2 High — prioritize within 30 days                  │
│    5.3 Medium — schedule within 90 days                  │
│    5.4 Low — informational                               │
│    Each finding: vulnerability description, impact,      │
│    remediation recommendation, CVSS (if applicable)      │
├──────────────────────────────────────────────────────────┤
│ 6. Recommendations                                       │
│    - People: security awareness gaps                     │
│    - Process: IR gaps, alert fatigue, handoff failures   │
│    - Technology: tooling gaps, misconfigs                │
├──────────────────────────────────────────────────────────┤
│ 7. Appendix A: Full ATT&CK Navigator Layers (.json)      │
│ 8. Appendix B: Command Log (redacted)                   │
│ 9. Appendix C: IoCs (hashes, domains, IPs used)          │
└──────────────────────────────────────────────────────────┘
```

### 11.2 ATT&CK Coverage Visualization

```
Produce 3 ATT&CK Navigator layers per engagement:

  Planning Layer:   Techniques planned for execution (color-coded by phase)
  Execution Layer:  Techniques actually executed (green=success, red=fail)
  Detection Layer:  Techniques detected by blue team (pattern overlay)

  Compare layers to produce:
  Gap Layer:        Executed but undetected = the real risk
  Improvement Layer: Re-test + compare delta from prior engagement
```

---

## 12. Continuous Improvement Loop

### 12.1 After-Action Review

```
┌─────────────────────────────────────────────────────────────┐
│ AAR Questions (conducted within 1 week of engagement end)  │
│                                                             │
│ 1. What went well? (capture for repeatable procedures)     │
│ 2. What went wrong? (capture for avoid-list)               │
│ 3. What was detected? (feedback to tooling/evasion)        │
│ 4. What took longer than expected? (scope/timeline)        │
│ 5. What data was missing? (intel gaps)                     │
│ 6. Infrastructure performance? (domain reputation,         │
│    redirector latency, burn timing)                        │
│ 7. Any operator OPSEC failures? (lessons learned)          │
│ 8. What technique would we add next time?                  │
│ 9. What technique would we drop?                           │
│ 10. What detection gap was most alarming?                  │
└─────────────────────────────────────────────────────────────┘
```

### 12.2 Knowledge Absorb Cycle

```
Research (new TTPs, CVEs, tool updates)     ─┐
    │                                          │
    ▼                                          │
Test in isolated lab                           │
    │                                          ├── 2-week cycle
    ▼                                          │
Document in skill/memory                       │
    │                                          │
    ▼                                          │
Apply in next engagement                      ─┘
    │
    ▼
Post-engagement AAR feeds back into skill updates
```

### 12.3 Tooling Upgrade Pipeline

```
Each engagement → tooling audit:
  - Which C2 framework version? (upstream changes?)
  - Which evasions worked? (document exact configuration)
  - Which payloads got caught? (modify or remove)
  - Infrastructure: any domain burned? (cycle to new set)
  - MCP/C2 novel channels: test integration with current payload

Maintain counter-research:
  - Follow EDR release notes (Defender, CrowdStrike, SentinelOne)
  - Track Sigma rule updates for common C2 frameworks
  - Monitor conference talks (SANS SEC565, DEF CON, Black Hat)
  - Scan for new CVEs in the target's technology stack weekly
```

---

## 13. Ethical & Legal Boundaries

### 13.1 Non-Negotiable Rules

```
  ⚠  NO operations without signed, dated authorization.
  ⚠  NO unauthorized data exfiltration (PII/PHI requires data handling plan).
  ⚠  NO destructive action without explicit scoping.
  ⚠  NO self-approval: every engagement requires external authorization.
  ⚠  NO using this blueprint for illegal activity.
  ⚠  NO zero-day development without vulnerability disclosure plan.
  ⚠  NO targeting of civil infrastructure without government authorization.
```

### 13.2 Liability Management

```
- Maintain insurance (cyber liability + E&O)
- Maintain chain of evidence logs (signed, timestamped)
- Use separate infrastructure per engagement (no cross-contamination)
- Destroy all client data post-engagement (certified wipe)
- Retain engagement ROEs for minimum 7 years
```

---

## 14. Quick Reference: Priority Toolmap

```
┌─────────────────┬─────────────────────────────────────────────┐
│ Category        │ Primary Tools (Free)                        │
├─────────────────┼─────────────────────────────────────────────┤
│ Recon           │ SpiderFoot, Amass, Shodan, cert.sh          │
│ OSINT           │ Maltego, theHarvester, Sherlock             │
│ Phishing        │ SET, GoPhish, Evilginx2                     │
│ C2 Framework    │ Sliver, Mythic                              │
│ Payload Gen     │ msfvenom, Donut, ScareCrow, NimPlant        │
│ AD Enumeration  │ BloodHound (SharpHound), PowerView, AdFind  │
│ Credential      │ Mimikatz, Rubeus, SektSAM, LaZagne          │
│ Web Exploit     │ Burp Suite (community), Nuclei, sqlmap      │
│ Reverse Eng     │ Ghidra, x64dbg, radare2, capa               │
│ Network         │ Nmap, masscan, Responder, impacket          │
│ Cloud           │ Pacu (AWS), ScoutSuite, Stratus Red Team    │
│ Infrastructure  │ Terraform, Ansible, Cloudflare, autossh     │
│ Reporting       │ VECTR, ATT&CK Navigator, Obsidian           │
│ Collaboration   │ Slack/Matrix encrypted, Signal               │
└─────────────────┴─────────────────────────────────────────────┘
```

---

**End of ptSlick Red Team Operations Blueprint v1.0**

> "Assume detection is inevitable. Rotate before you burn.
>  Plan your infrastructure like you expect to lose it tomorrow."