Adversary emulation with Caldera
We already introduced Caldera and covered some basic usage of the solution in Chapter 9, Purple Team Infrastructure. This chapter showed some interesting examples of how we could easily automate the usage and the execution of the Atomic Red Team tests repository on a host where the Caldera agent has been installed.
However, creating an emulation plan based only on Atomic Red Team or the top 10 TTPs can be a time-consuming task and not relevant to the reality we may face. To increase our maturity, we can look for incident response reports to generate intelligence that can later be translated into an emulation plan that will be played by our offensive team, just as we saw in Chapter 3, Carrying Out Adversary Emulation with CTI. Scythe, a cybersecurity company from the US, published very detailed and quickly actionable emulation plans. The company is developing and maintaining a very promising Breach Attack Simulation (BAS) platform, which is regularly...