惯性聚合 高效追踪和阅读你感兴趣的博客、新闻、科技资讯
阅读原文 在惯性聚合中打开

推荐订阅源

Hugging Face - Blog
Hugging Face - Blog
Recent Announcements
Recent Announcements
V
Visual Studio Blog
博客园 - 叶小钗
H
Help Net Security
aimingoo的专栏
aimingoo的专栏
宝玉的分享
宝玉的分享
U
Unit 42
钛媒体:引领未来商业与生活新知
钛媒体:引领未来商业与生活新知
F
Fortinet All Blogs
V
V2EX
Stack Overflow Blog
Stack Overflow Blog
WordPress大学
WordPress大学
D
DataBreaches.Net
J
Java Code Geeks
H
Hackread – Cybersecurity News, Data Breaches, AI and More
A
About on SuperTechFans
酷 壳 – CoolShell
酷 壳 – CoolShell
量子位
C
Check Point Blog
奇客Solidot–传递最新科技情报
奇客Solidot–传递最新科技情报
小众软件
小众软件
Microsoft Azure Blog
Microsoft Azure Blog
M
MIT News - Artificial intelligence

New in Feedly

Automatically collect Splunk Hunting Queries that match your requirements | Feedly Continuously collect Suricata rules matching your requirements | Feedly Enrich and triage Atlassian security releases in the Vulnerability Intel Agent | Feedly Enrich and triage Apple security releases in the Vulnerability Intel Agent | Feedly Feedly completes SOC 2 Type 2 examination | Feedly VirusTotal Integration: Triage IOCs Faster in Feedly | Feedly Connect Feedly to OpenCTI: Real-Time Threat Intel, Automated | Feedly Feedly Best Practices for CTI Teams | Feedly GreyNoise + Feedly Threat Intelligence: Enriching IoCs | Feedly 7 AI Prompts for Cyberattack Pattern Analysis | Feedly Navigate Feedly Faster with Go To | Feedly Navigate Feedly Faster with Go To Introducing Feedly ThreatBeats: Your daily intel jingles | Feedly Introducing Feedly ThreatBeats: Your daily intel jingles 6 Ways to Automate Threat Intelligence with the Feedly API | Feedly Get threat intelligence to your team fast, in the tools they already use | Feedly Tracking the cyber consequences of geopolitical events | Feedly Analyze your closed-source intelligence in Feedly | Feedly Cyberattack Insights Cards: A dynamic 360° attack view | Feedly Cyberattack Insights Cards: A dynamic 360° attack view 7 ways to prioritize CVEs by how they're exploited | Feedly Ask AI on Threat Actor Insights Cards: Accelerate adversary research with custom queries | Feedly Research IoCs with rich context in seconds, not hours | Feedly Surface top threats in CTI newsletters | Feedly The Scanner: Exploring Potential Futures | Feedly The Radar: Detecting emerging signals | Feedly Prompt Engineering: Newsletter template for real-time phishing trends | Feedly The Monitor: Tracking the known present | Feedly Startup Innovation Radar: A real-time startup database | Feedly The InsightOS architecture | Feedly
CTI AI Prompt: Generate red team emulation plans with Fee...
Andrew Castro · 2025-10-08 · via New in Feedly

Description

This Ask AI Prompt generates comprehensive red team emulation reports that translate raw threat intelligence into actionable attack procedures. The structured output aligns with the MITRE ATT&CK framework, providing specific emulation steps, tool recommendations, and environmental considerations. This enables red teams to quickly develop realistic adversary simulations without spending days manually parsing through threat reports.

Providing the right context

To achieve the best results from your prompt, it's essential to provide the AI with high-quality, technical context. You can do this easily within Feedly by selecting dense articles in a Feed or curating a Board with articles or reports that mention the specific threat actors, campaigns, or malware families you want to emulate. For example, say you've collected reports on APT41's GodRAT financial targeting campaign. Having this curated set of relevant intel ensures the prompt provides the AI with the right context to generate an actionable and verifiable red team emulation plan.

<role>Lead Cyber Threat Intelligence Analyst</role>

<task>Read the provided threat intelligence articles and generate a structured Adversary Emulation Report to support Red Team operations. The goal is to 
simulate realistic threat actor behavior based on recent tradecraft observed in the wild.</task>

<output_format>
1. Summary of Threat Activity
- Threat Actor (if known)
- Campaign or Attack Name (if applicable)
- Targeted Sectors/Industries
- Reported Objective (e.g., data exfiltration, ransomware deployment, espionage)
- MITRE ATT&CK Tactics & Techniques
- Tools, Malware, or Frameworks Used
- Relevant CVEs (if exploitation was part of initial access or lateral movement)

2. Attack Procedures (Emulation Steps)
For each procedure, provide the following details:
- Step Name: [Short title of the simulated attack phase]
- Tactic: [MITRE ATT&CK Tactic — e.g., Initial Access, Persistence]
- Technique ID & Name: [MITRE ATT&CK Technique — e.g., T1566.001 - Spearphishing Attachment]
- Procedure Description: Technical detail of how the technique was used, including commands, payloads, or LOLBins. Highlight novel chaining techniques if observed.
- Emulation Plan: Exact steps to emulate this behavior with tools such as manual commands, Cobalt Strike, Brute Ratel, Mythic, Atomic Red Team, or Caldera. Include preconditions and payload examples.
- Environment Considerations: Infrastructure or configurations required (e.g., phishing server, domain controller, PowerShell remoting).

3. Detection Opportunities
- Log Sources & Event IDs
- Telemetry Requirements
- Known Sigma Rules or Detection Samples
- Blind spots or evasions observed

4. Suggested Purple Team Collaboration Opportunities
- Techniques that benefit from validation
- Coordinated tests to measure fidelity, tune detections, or validate response
- Suggested KPIs (dwell time, detection latency, alert-to-investigation timing)

5. Mitigations and Hardening (Optional)
- High-level mitigations aligned to MITRE M-codes (e.g., M1047 – Audit PowerShell logging)
</output_format>

<guidelines>
- Ensure emulation steps reflect observed tradecraft
- Prioritize fidelity and align with MITRE ATT&CK standards
- Avoid vague descriptions—use real payloads, delivery methods, and sources
- Include specific tool commands and configuration details
- Focus on actionable procedures that can be executed
- Include citations to source material
</guidelines>

Ask AI Response

The output provides a comprehensive emulation report covering seven attack procedures, from steganographic payload delivery to internal C2 via compromised SharePoint. Each step included specific commands for tools like msfvenom, Impacket, and custom Python scripts, along with detailed environmental requirements.

The prompt can be saved in your prompt library and reused across different threat actor campaigns to maintain consistency in your red team planning process.

Try Ask AI in Feedly Threat Intelligence

Generate actionable red team emulation plans from your threat intelligence in seconds.

Start Free Trial