01Comprehensive detection engineering bundles including Sigma, Splunk, KQL artifacts, MITRE ATT&CK heatmaps, and SOAR integration hooks.
02Adaptive adversary scenarios tied to real-world APT/FIN actor playbooks and sector-aware CVEs.
030 GitHub stars
04Full incident response suite offering deep investigations, forensic artifact generation, purple-team scorecards, and executive reporting capabilities.
05Robust operational guardrails featuring append-only audit logs, approval-gated RBAC, a 'stop_simulation' kill switch, and automated risk/control synchronization.
06Command-chain drill-down with pseudo CLI steps, guardrails, and MITRE ATT&CK references for each attack phase.