
from decepticon4,244
Adversary-emulation profile that maps APT29 (Cozy Bear) ATT&CK TTPs to Decepticon tooling for realistic, cloud- and identity-focused red-team exercises.
This SKILL provides a comprehensive adversary-emulation profile for APT29 (Cozy Bear / Midnight Blizzard), translating MITRE ATT&CK techniques into runnable guidance for the Decepticon red-team framework. It documents targeting, notable campaigns, detailed TTP mappings across the attack lifecycle (initial access, credential access, lateral movement, C2, exfiltration), recommended tooling analogues, and explicit emulation guidance emphasizing cloud/identity-first techniques (Golden SAML, OAuth abuse, password spraying, supply-chain compromise). The profile includes operational advice on stealth, egress rotation, and cleanup — suitable for authorized, scope-limited exercises.
Use this skill when running authorized red-team or purple-team engagements that need to emulate a patient, identity-centric nation-state espionage actor. It's appropriate for cloud-focused threat simulation (Microsoft 365/Entra flows), supply-chain scenario drills, and testing detection/response for OAuth/federation abuses. Only use inside approved scopes and with signed authorization.
Best used with agent runtimes that expose shell/CI and cloud tooling (Decepticon/Red-team agents, shell-enabled Claude/Copilot-style agents able to run bash/CI steps).
This skill has not been reviewed by our automated audit pipeline yet.
Scanner Skill — Decepticon
High-volume codebase scanner that shards work, ranks suspicious locations, and promotes a concise set of candidates for deeper analysis.
AD Overview (Decepticon)
Playbook and workflows for Active Directory offensive operations: BloodHound ingestion, Kerberoasting, ADCS ESC scanning, DCSync and LAPS extraction.