Full attack paths

Build Your Own Narrative

Assessments are customizable — and they chain. Start from an APT pack or assemble a Custom Attack Chain, then tell the story of an intrusion: phishing → purple teaming → ransomware Impact, one project timeline, operator-paced unlocks.

  1. T1566PhishingInitial access. Unlock the next chapter on click, submit, or train.
  2. ATT&CK chainPurple teaming / customAPT pack or your own check order — execution through C2.
  3. T1486RansomwareImpact after purple teaming completes. Blow up or Recover on a lab path.

Custom Attack Chain

Pick the techniques, set the order

Use a published APT similarity pack, or build your own path from the catalog — execution, persistence, credential access, C2, and more — then grade each stage live.

  • Reorder checks to match the story you want to tell
  • Marker or Payload probe mode per scenario
  • Same MITRE IDs as standalone purple teaming runs

Milestone unlocks

Chain phishing into the host path

People-risk opens the door. Purple teaming stays locked until click, submit, or train — then ransomware Impact unlocks only after the purple teaming chapter completes.

  • Unlock purple teaming on phishing click, submit, or train
  • Ransomware waits until purple teaming is complete
  • Operators stay in control — unlock notifies; Play stays intentional

One engagement

Grade the full attack path

Pass and fail still mean blocked vs succeeded — now across the whole narrative, not just a single scenario. Brief with evidence and PDF when you are ready.

  • Shared project timeline for every chapter
  • Pair with phishing and ransomware testing
  • Technique guidance for every fail on the path

Use narrative campaigns only on users and hosts you are authorized to assess. See the ParitySH license.