Skip to main contentSkip to main content
Room Banner
Back to all walkthroughs
Room Icon

Atomic Bird Goes Purple #2

Premium room

Time to simulate hunting and detecting activities to sharpen your purple teaming skills.

medium

45 min

5,060

User profile photo.

To access material, start machines and answer questions login.

Throughout this module, you have built a solid foundation in threat emulation. You learned the core concepts and processes behind emulation exercises, explored how threat modeling helps identify and prioritize the threats that matter most, and got hands-on with Atomic Red Team to emulate real adversary techniques and observe how defenses respond to them.

This room is the follow-up to Atomic Bird Goes Purple #1. Building on what you practiced there, you will continue working through real-life scenarios using customised atomic tests to implement tailored purple teaming exercises and familiarise yourself with sample attack chains. It is recommended to complete the first room and fulfil its prerequisites before starting here.

A high-level mapping of the custom tests covered in this room is listed below. Each task also shares the basic techniques and storyline of the planned custom actions.

Task Base Tactics Reference Techniques Implemented Actions
#2
  • TA003:
  • TA004: Privilege Escalation
  • TA005: Defense Evasion
  • TA006: Credential Access
  • T1036.004
  • T1552.001
  • T1078.003
  • Cleartext Data Search
  • Account Creation
#3
  • TA003:
  • TA004: Privilege Escalation
  • TA007: Discovery
  • TA009: Collection
  • TA0040: Impact
  • T1012
  • T1112
  • T1491
  • T1543.003
  • Service Creation
  • Defacement
  • Filetype Modification
  • Planting Reverse Shell in Registry

Learning Objectives

  • Gain hands-on threat emulation experience.
  • Familiarise yourself with artefacts created by adversary tactics and techniques.
  • Experience emulation and detection to improve your overall security defences.

Room Prerequisites

It is recommended to complete the prior rooms of this module before starting here:

Connecting to the Machine

Before moving forward, start your lab machine by clicking the Start Lab Machine button below. The machine will open in split view and will need about 2 minutes to fully boot. In case you cannot see it, click the Show Split View button at the top of the page.

Set up your virtual environment

To successfully complete this room, you'll need to set up your virtual environment. This involves starting the Target Machine, ensuring you're equipped with the necessary tools and access to tackle the challenges ahead.
Lab machine
Status:Off
Answer the questions below

Start the attached VM and proceed to the next task.