Custom Attack Chain
Pick the techniques, set the order
Use a published APT similarity pack, or build your own path from the catalog — execution, persistence, credential access, C2, and more — then grade each stage live.
- Reorder checks to match the story you want to tell
- Marker or Payload probe mode per scenario
- Same MITRE IDs as standalone purple teaming runs
Milestone unlocks
Chain phishing into the host path
People-risk opens the door. Purple teaming stays locked until click, submit, or train — then ransomware Impact unlocks only after the purple teaming chapter completes.
- Unlock purple teaming on phishing click, submit, or train
- Ransomware waits until purple teaming is complete
- Operators stay in control — unlock notifies; Play stays intentional
One engagement
Grade the full attack path
Pass and fail still mean blocked vs succeeded — now across the whole narrative, not just a single scenario. Brief with evidence and PDF when you are ready.
- Shared project timeline for every chapter
- Pair with phishing and ransomware testing
- Technique guidance for every fail on the path