{
  "version": "https://jsonfeed.org/version/1.1",
  "title": "cyberbuff",
  "description": "Developer, hacker, and open source contributor.",
  "home_page_url": "https://cyberbuff.dev",
  "feed_url": "https://cyberbuff.dev/feed.json",
  "language": "en-US",
  "authors": [
    {
      "name": "cyberbuff",
      "url": "https://cyberbuff.dev"
    }
  ],
  "items": [
    {
      "id": "https://cyberbuff.dev/blog/loas",
      "url": "https://cyberbuff.dev/blog/loas",
      "title": "Living Off the Orchard: AppleScript",
      "summary": "Offensive security testing framework for macOS that provides MITRE ATT&CK-mapped atomic tests using AppleScript and JXA techniques across multiple execution methods.",
      "content_html": "<p>Attackers can leverage built-in macOS tools like AppleScript and JXA (JavaScript for Automation) to access credentials, capture screenshots, and establish persistence without installing custom tools. Can your security controls detect these techniques?</p>\n<p><strong>L</strong>iving <strong>O</strong>ff the <strong>O</strong>rchard: <strong>A</strong>pple <strong>S</strong>cript (<a href=\"https://loas.dev\" rel=\"nofollow noreferrer noopener\" target=\"_blank\">LOAS</a>) is a library of AppleScript and JXA tests mapped to the <a href=\"https://attack.mitre.org/\" rel=\"nofollow noreferrer noopener\" target=\"_blank\">MITRE ATT&amp;CK®</a> framework that helps you answer that question. Security teams can use LOAS to quickly, portably, and reproducibly test their macOS environments using multiple execution methods, each generating different endpoint security logs.</p>\n<h2 id=\"who-should-use-loas\">Who Should Use LOAS?</h2>\n<ul>\n<li><strong>🔴 Red Team</strong> - Test realistic macOS attack scenarios without custom tools.</li>\n<li><strong>🔵 Blue Team</strong> - Validate detection rules against real adversary techniques and build comprehensive macOS monitoring and alerting.</li>\n</ul>\n<h2 id=\"getting-started\">Getting Started</h2>\n<p>Ready to start testing? The easiest way is to download pre-built artifacts from <a href=\"https://github.com/cyberbuff/loas/releases/latest\" rel=\"nofollow noreferrer noopener\" target=\"_blank\">GitHub releases</a>:</p>\n<div class=\"expressive-code\"><figure class=\"frame is-terminal\"><figcaption class=\"header\"><span class=\"title\"></span><span class=\"sr-only\">Terminal window</span></figcaption><pre data-language=\"bash\" class=\"wrap\" style=\"--ecMaxLine:84ch\"><code><div class=\"ec-line\"><div class=\"code\"><span style=\"--0:#99A0A6\"># Download pre-built tests from releases</span></div></div><div class=\"ec-line\"><div class=\"code\"><span style=\"--0:#99A0A6\"># https://github.com/cyberbuff/loas/releases/latest</span></div></div><div class=\"ec-line\"><div class=\"code\">\n</div></div><div class=\"ec-line\"><div class=\"code\"><span style=\"--0:#99A0A6\"># Execute your first test through any of the following methods:</span></div></div><div class=\"ec-line\"><div class=\"code\"><span style=\"--0:#B392F0\">osascript</span><span style=\"--0:#E1E4E8\"> </span><span style=\"--0:#79B8FF\">-e</span><span style=\"--0:#E1E4E8\"> </span><span style=\"--0:#9ECBFF\">&#39;short user name of (system info)&#39;</span><span style=\"--0:#E1E4E8\"> </span><span style=\"--0:#79B8FF\">-e</span><span style=\"--0:#E1E4E8\"> </span><span style=\"--0:#9ECBFF\">&#39;long user name of (system info)&#39;</span></div></div><div class=\"ec-line\"><div class=\"code\"><span style=\"--0:#B392F0\">osascript</span><span style=\"--0:#E1E4E8\"> </span><span style=\"--0:#9ECBFF\">get_user_using_system_info.scpt</span></div></div><div class=\"ec-line\"><div class=\"code\"><span style=\"--0:#B392F0\">swift</span><span style=\"--0:#E1E4E8\"> </span><span style=\"--0:#9ECBFF\">get_user_using_system_info.swift</span></div></div><div class=\"ec-line\"><div class=\"code\"><span style=\"--0:#B392F0\">./get_user_using_system_info</span></div></div></code></pre></figure></div>\n<p>The GitHub Actions workflow automatically generates all the artifacts needed for testing. However, if you want to compile them yourself:</p>\n<blockquote>\n<p>⚠️ <strong>Security Warning</strong>: All LOAS tests should only be run in isolated lab environments or with explicit authorization. These techniques can trigger security alerts and modify system state.</p>\n</blockquote>\n<div class=\"expressive-code\"><figure class=\"frame is-terminal\"><figcaption class=\"header\"><span class=\"title\"></span><span class=\"sr-only\">Terminal window</span></figcaption><pre data-language=\"bash\" class=\"wrap\" style=\"--ecMaxLine:58ch\"><code><div class=\"ec-line\"><div class=\"code\"><span style=\"--0:#99A0A6\"># Clone and setup</span></div></div><div class=\"ec-line\"><div class=\"code\"><span style=\"--0:#B392F0\">git</span><span style=\"--0:#E1E4E8\"> </span><span style=\"--0:#9ECBFF\">clone</span><span style=\"--0:#E1E4E8\"> </span><span style=\"--0:#9ECBFF\">https://github.com/cyberbuff/loas.git</span></div></div><div class=\"ec-line\"><div class=\"code\"><span style=\"--0:#79B8FF\">cd</span><span style=\"--0:#E1E4E8\"> </span><span style=\"--0:#9ECBFF\">loas</span></div></div><div class=\"ec-line\"><div class=\"code\"><span style=\"--0:#B392F0\">uv</span><span style=\"--0:#E1E4E8\"> </span><span style=\"--0:#9ECBFF\">sync</span></div></div><div class=\"ec-line\"><div class=\"code\">\n</div></div><div class=\"ec-line\"><div class=\"code\"><span style=\"--0:#99A0A6\"># Validate all tests</span></div></div><div class=\"ec-line\"><div class=\"code\"><span style=\"--0:#B392F0\">uv</span><span style=\"--0:#E1E4E8\"> </span><span style=\"--0:#9ECBFF\">run</span><span style=\"--0:#E1E4E8\"> </span><span style=\"--0:#9ECBFF\">main.py</span><span style=\"--0:#E1E4E8\"> </span><span style=\"--0:#9ECBFF\">validate</span></div></div><div class=\"ec-line\"><div class=\"code\">\n</div></div><div class=\"ec-line\"><div class=\"code\"><span style=\"--0:#99A0A6\"># Generate all test artifacts</span></div></div><div class=\"ec-line\"><div class=\"code\"><span style=\"--0:#B392F0\">uv</span><span style=\"--0:#E1E4E8\"> </span><span style=\"--0:#9ECBFF\">run</span><span style=\"--0:#E1E4E8\"> </span><span style=\"--0:#9ECBFF\">main.py</span><span style=\"--0:#E1E4E8\"> </span><span style=\"--0:#9ECBFF\">build</span></div></div><div class=\"ec-line\"><div class=\"code\">\n</div></div><div class=\"ec-line\"><div class=\"code\"><span style=\"--0:#99A0A6\"># Execute your first test</span></div></div><div class=\"ec-line\"><div class=\"code\"><span style=\"--0:#B392F0\">osascript</span><span style=\"--0:#E1E4E8\"> </span><span style=\"--0:#9ECBFF\">osascripts/T1033/get_user_using_system_info.scpt</span></div></div></code></pre></figure></div>\n<p>For detailed instructions on writing YAML tests and contributing, see the <a href=\"https://loas.dev/docs\" rel=\"nofollow noreferrer noopener\" target=\"_blank\">LOAS documentation</a>.</p>\n<h2 id=\"llm-optimized-documentation\">LLM-Optimized Documentation</h2>\n<p>Ready to use with Claude, ChatGPT, or Gemini right out of the box.</p>\n<ul>\n<li><strong>Full Documentation</strong> - Complete technique descriptions and implementation details in plain text format</li>\n<li><strong>Individual Technique Documentation</strong> - Access specific techniques at <code>https://loas.dev/docs/&lt;technique-id&gt;.mdx</code> (e.g., <code>T1005.mdx</code>, <code>T1087.001.mdx</code>)</li>\n</ul>\n<p><strong>Sample Prompt:</strong></p>\n<blockquote>\n<p>Read <a href=\"https://loas.dev/llms-full.txt\" rel=\"nofollow noreferrer noopener\" target=\"_blank\">https://loas.dev/llms-full.txt</a>. I want to ask questions about the techniques.</p>\n</blockquote>\n<h2 id=\"roadmap\">Roadmap</h2>\n<p>LOAS is actively evolving with planned enhancements:</p>\n<ul>\n<li><strong>CI/CD Testing</strong>: GitHub Actions workflows for automated validation, ensuring atomics remain compatible as Apple deprecates and replaces APIs across macOS versions</li>\n<li><strong>Expanded Technique Coverage</strong>: Adding more tests for MITRE ATT&amp;CK® techniques beyond the current 29 implementations.</li>\n</ul>\n<h2 id=\"conclusion\">Conclusion</h2>\n<p>As macOS continues to grow in enterprise environments, understanding and defending against AppleScript and JXA abuse becomes increasingly critical. LOAS provides security teams with the tools needed to:</p>\n<ul>\n<li><strong>Understand</strong> how threat actors weaponize legitimate macOS automation</li>\n<li><strong>Test</strong> detection coverage across multiple execution vectors</li>\n<li><strong>Validate</strong> security controls with <a href=\"https://attack.mitre.org/\" rel=\"nofollow noreferrer noopener\" target=\"_blank\">MITRE ATT&amp;CK®</a>-mapped techniques</li>\n<li><strong>Improve</strong> defensive capabilities through purple team collaboration</li>\n</ul>\n<h2 id=\"resources\">Resources</h2>\n<ul>\n<li><strong>GitHub Repository</strong>: <a href=\"https://github.com/cyberbuff/loas\" rel=\"nofollow noreferrer noopener\" target=\"_blank\">https://github.com/cyberbuff/loas</a></li>\n<li><strong>Documentation</strong>: <a href=\"https://loas.dev\" rel=\"nofollow noreferrer noopener\" target=\"_blank\">https://loas.dev</a></li>\n<li><strong>Latest Release</strong>: <a href=\"https://github.com/cyberbuff/loas/releases/latest\" rel=\"nofollow noreferrer noopener\" target=\"_blank\">https://github.com/cyberbuff/loas/releases/latest</a></li>\n<li><strong>MITRE ATT&amp;CK®</strong>: <a href=\"https://attack.mitre.org/matrices/enterprise/macos/\" rel=\"nofollow noreferrer noopener\" target=\"_blank\">macOS Matrix</a></li>\n<li><strong>Atomic Red Team</strong>: <a href=\"https://github.com/redcanaryco/atomic-red-team\" rel=\"nofollow noreferrer noopener\" target=\"_blank\">https://github.com/redcanaryco/atomic-red-team</a></li>\n<li><strong>Red Canary Threat Detection Report - AppleScript</strong>: <a href=\"https://redcanary.com/threat-detection-report/techniques/applescript/\" rel=\"nofollow noreferrer noopener\" target=\"_blank\">https://redcanary.com/threat-detection-report/techniques/applescript/</a></li>\n</ul>\n<hr/>\n<p><em>MITRE ATT&amp;CK® is a registered trademark of The MITRE Corporation.</em></p>\n<p><em>Want to contribute or have questions? Open an <a href=\"https://github.com/cyberbuff/loas/issues/new\" rel=\"nofollow noreferrer noopener\" target=\"_blank\">issue on GitHub</a> or reach out on X <a href=\"https://x.com/cyb3rbuff\" rel=\"nofollow noreferrer noopener\" target=\"_blank\">@cyb3rbuff</a></em></p>\n<p>All my content is cross posted to both <a href=\"https://cyberbuff.dev/blog\" rel=\"nofollow noreferrer noopener\" target=\"_blank\">cyberbuff.dev/blog</a> and <a href=\"https://cyberbuff.substack.com/\" rel=\"nofollow noreferrer noopener\" target=\"_blank\">Substack</a>. The custom blog supports hierarchical subposts with integrated table of contents, enabling readers to navigate complex topics or skip familiar sections. While Substack lacks this UI customization, it provides better subscription management and notifications. I maintain both platforms to serve different reader preferences, so use whichever suits you best.</p>",
      "image": "https://cyberbuff.dev/_astro/banner.D7XnSvf8.png",
      "date_published": "2025-11-27T00:00:00.000Z",
      "date_modified": "2025-11-27T00:00:00.000Z",
      "tags": [
        "Security",
        "macOS",
        "AppleScript",
        "Adversary Emulation"
      ]
    },
    {
      "id": "https://cyberbuff.dev/blog/loas/execution-methods",
      "url": "https://cyberbuff.dev/blog/loas/execution-methods",
      "title": "Execution Methods",
      "summary": "Learn how to execute LOAS tests using various methods and understand how each creates different detection telemetry.",
      "content_html": "<p>As discussed in the <a href=\"https://cyberbuff.dev/blog/loas/primer\">macOS Security Primer</a>, AppleScript and JXA are powerful automation tools that can be weaponized by attackers. Understanding how these techniques appear in your security logs is critical for detection engineering.</p>\n<p>LOAS tests can be executed using five different methods, each creating distinct forensic artifacts and detection opportunities:</p>\n<ol>\n<li><strong>CLI</strong> (<code>osascript -e</code>) - Direct command-line execution</li>\n<li><strong>Script files</strong> (<code>.scpt</code>) - Pre-saved AppleScript files</li>\n<li><strong>Swift wrappers</strong> (<code>.swift</code>) - AppleScript embedded in Swift</li>\n<li><strong>Applet</strong> (<code>.app</code>) - Packaged as macOS applet bundles</li>\n<li><strong>Compiled binaries</strong> - Standalone executables</li>\n</ol>\n<p>These execution methods are documented in detail in the <a href=\"https://redcanary.com/threat-detection-report/techniques/applescript/\" rel=\"nofollow noreferrer noopener\" target=\"_blank\">Red Canary Threat Detection Report</a>. This documentation builds upon and expands their work.</p>\n<p>Each method creates different traces in your security logs like different parent-child process relationships, file system events, and security audit logs. Understanding these variations is critical for building comprehensive detection rules.</p>\n<p>The <a href=\"https://github.com/cyberbuff/loas/releases/latest\" rel=\"nofollow noreferrer noopener\" target=\"_blank\">GitHub releases page</a> provides all of these different files for each test.</p>\n<p>If you would like to compile the files yourself, install <a href=\"https://docs.astral.sh/uv/getting-started/installation/\" rel=\"nofollow noreferrer noopener\" target=\"_blank\">uv</a> and then use the following commands:</p>\n<div class=\"expressive-code\"><figure class=\"frame is-terminal\"><figcaption class=\"header\"><span class=\"title\"></span><span class=\"sr-only\">Terminal window</span></figcaption><pre data-language=\"bash\" class=\"wrap\" style=\"--ecMaxLine:47ch\"><code><div class=\"ec-line\"><div class=\"code\"><span style=\"--0:#B392F0\">git</span><span style=\"--0:#E1E4E8\"> </span><span style=\"--0:#9ECBFF\">clone</span><span style=\"--0:#E1E4E8\"> </span><span style=\"--0:#9ECBFF\">https://github.com/cyberbuff/loas.git</span></div></div><div class=\"ec-line\"><div class=\"code\"><span style=\"--0:#79B8FF\">cd</span><span style=\"--0:#E1E4E8\"> </span><span style=\"--0:#9ECBFF\">loas</span></div></div><div class=\"ec-line\"><div class=\"code\"><span style=\"--0:#B392F0\">uv</span><span style=\"--0:#E1E4E8\"> </span><span style=\"--0:#9ECBFF\">sync</span></div></div><div class=\"ec-line\"><div class=\"code\"><span style=\"--0:#B392F0\">uv</span><span style=\"--0:#E1E4E8\"> </span><span style=\"--0:#9ECBFF\">run</span><span style=\"--0:#E1E4E8\"> </span><span style=\"--0:#9ECBFF\">main.py</span><span style=\"--0:#E1E4E8\"> </span><span style=\"--0:#9ECBFF\">build</span></div></div></code></pre></figure></div>\n<p>Each of these methods generates a different set of logs based on the execution tool.</p>\n<p>The sample Endpoint Security logs below were gathered using <a href=\"https://github.com/Brandon7CC/mac-monitor/\" rel=\"nofollow noreferrer noopener\" target=\"_blank\">Mac Monitor</a> for each execution method when retrieving clipboard content.</p>\n<h2 id=\"cli\">CLI</h2>\n<p>This is the simplest way to execute commands from this repository.</p>\n<div class=\"expressive-code\"><figure class=\"frame is-terminal\"><figcaption class=\"header\"><span class=\"title\"></span><span class=\"sr-only\">Terminal window</span></figcaption><pre data-language=\"bash\" class=\"wrap\" style=\"--ecMaxLine:28ch\"><code><div class=\"ec-line\"><div class=\"code\"><span style=\"--0:#B392F0\">osascript</span><span style=\"--0:#E1E4E8\"> </span><span style=\"--0:#79B8FF\">-e</span><span style=\"--0:#E1E4E8\"> </span><span style=\"--0:#9ECBFF\">&quot;the clipboard&quot;</span></div></div></code></pre></figure></div>\n<div class=\"flex justify-center\"><img src=\"https://cyberbuff.dev/_astro/osascript-cli.DO3_l1DK_Z1xs6W5.webp\" alt=\"CLI\" loading=\"lazy\" decoding=\"async\" width=\"3014\" height=\"1962\"></div>\n<h2 id=\"script\">Script</h2>\n<p>Download the script from the <a href=\"https://github.com/cyberbuff/loas/releases/latest\" rel=\"nofollow noreferrer noopener\" target=\"_blank\">releases page</a> and execute it with osascript.</p>\n<div class=\"expressive-code\"><figure class=\"frame is-terminal\"><figcaption class=\"header\"><span class=\"title\"></span><span class=\"sr-only\">Terminal window</span></figcaption><pre data-language=\"bash\" class=\"wrap\" style=\"--ecMaxLine:63ch\"><code><div class=\"ec-line\"><div class=\"code\"><span style=\"--0:#B392F0\">osascript</span><span style=\"--0:#E1E4E8\"> </span><span style=\"--0:#9ECBFF\">get_clipboard_content_using_applescript_defaults.scpt</span></div></div></code></pre></figure></div>\n<div class=\"flex justify-center\"><img src=\"https://cyberbuff.dev/_astro/osascript-file._dX8r2fS_2cSme.webp\" alt=\"File\" loading=\"lazy\" decoding=\"async\" width=\"2224\" height=\"1962\"></div>\n<h2 id=\"swift\">Swift</h2>\n<p>Download the Swift file from the <a href=\"https://github.com/cyberbuff/loas/releases/latest\" rel=\"nofollow noreferrer noopener\" target=\"_blank\">releases page</a> and execute it with Swift.</p>\n<p>Note: You might need to install Xcode Developer Tools to run Swift files.</p>\n<div class=\"expressive-code\"><figure class=\"frame is-terminal\"><figcaption class=\"header\"><span class=\"title\"></span><span class=\"sr-only\">Terminal window</span></figcaption><pre data-language=\"bash\" class=\"wrap\" style=\"--ecMaxLine:60ch\"><code><div class=\"ec-line\"><div class=\"code\"><span style=\"--0:#B392F0\">swift</span><span style=\"--0:#E1E4E8\"> </span><span style=\"--0:#9ECBFF\">get_clipboard_content_using_applescript_defaults.swift</span></div></div></code></pre></figure></div>\n<div class=\"flex justify-center\"><img src=\"https://cyberbuff.dev/_astro/swift.IjXB2o_L_2pNPsw.webp\" alt=\"Swift\" loading=\"lazy\" decoding=\"async\" width=\"2764\" height=\"1962\"></div>\n<h2 id=\"applet\">Applet</h2>\n<p>Download the <code>.app</code> file from the <a href=\"https://github.com/cyberbuff/loas/releases/latest\" rel=\"nofollow noreferrer noopener\" target=\"_blank\">releases page</a> and execute it.</p>\n<div class=\"expressive-code\"><figure class=\"frame is-terminal\"><figcaption class=\"header\"><span class=\"title\"></span><span class=\"sr-only\">Terminal window</span></figcaption><pre data-language=\"bash\" class=\"wrap\" style=\"--ecMaxLine:60ch\"><code><div class=\"ec-line\"><div class=\"code\"><span style=\"--0:#B392F0\">open</span><span style=\"--0:#E1E4E8\"> </span><span style=\"--0:#79B8FF\">-n</span><span style=\"--0:#E1E4E8\"> </span><span style=\"--0:#9ECBFF\">get_clipboard_content_using_applescript_defaults.app</span></div></div></code></pre></figure></div>\n<div class=\"flex justify-center\"><img src=\"https://cyberbuff.dev/_astro/app.CM9olerj_Z18urPq.webp\" alt=\"App\" loading=\"lazy\" decoding=\"async\" width=\"2224\" height=\"1962\"></div>\n<h2 id=\"binary\">Binary</h2>\n<p>Download the binary from the <a href=\"https://github.com/cyberbuff/loas/releases/latest\" rel=\"nofollow noreferrer noopener\" target=\"_blank\">releases page</a> and execute it.</p>\n<div class=\"expressive-code\"><figure class=\"frame is-terminal\"><figcaption class=\"header\"><span class=\"title\"></span><span class=\"sr-only\">Terminal window</span></figcaption><pre data-language=\"bash\" class=\"wrap\" style=\"--ecMaxLine:50ch\"><code><div class=\"ec-line\"><div class=\"code\"><span style=\"--0:#B392F0\">./get_clipboard_content_using_applescript_defaults</span></div></div></code></pre></figure></div>\n<div class=\"flex justify-center\"><img src=\"https://cyberbuff.dev/_astro/binaries.BBp5ry-A_2nQ3hP.webp\" alt=\"Binary\" loading=\"lazy\" decoding=\"async\" width=\"3014\" height=\"1962\"></div>",
      "date_published": "2025-11-27T00:00:00.000Z",
      "date_modified": "2025-11-27T00:00:00.000Z",
      "tags": [
        "Security",
        "macOS",
        "AppleScript",
        "Adversary Emulation"
      ]
    },
    {
      "id": "https://cyberbuff.dev/blog/loas/primer",
      "url": "https://cyberbuff.dev/blog/loas/primer",
      "title": "macOS Security Primer",
      "summary": "Understanding Living Off the Orchard attacks and why AppleScript/JXA techniques require specialized testing frameworks for macOS security.",
      "content_html": "<h2 id=\"what-is-living-off-the-landorchard\">What is “Living Off the Land/Orchard”?</h2>\n<p>“Living off the land” is a cybersecurity term describing attacks that use legitimate, pre-existing system tools instead of custom tools. Rather than bringing their own malicious software, attackers leverage the binaries, scripts, and libraries already installed on target systems. “Living Off the Orchard” is the macOS-specific variant of this concept - a play on Apple’s association with orchards.</p>\n<h3 id=\"why-attackers-choose-this-approach\">Why Attackers Choose This Approach</h3>\n<ul>\n<li><strong>🎯 Easily Accessible</strong> - No software installation required</li>\n<li><strong>👻 Reduced Footprint</strong> - No external tools needed, creating minimal filesystem artifacts</li>\n<li><strong>🫥 Blends with Normal Activity</strong> - Blend seamlessly with legitimate operations</li>\n<li><strong>🛡️ Evades Detection</strong> - Bypasses signature based detections by exploiting trust in system signed binaries</li>\n</ul>\n<h2 id=\"what-can-applescriptjxa-do\">What Can AppleScript/JXA Do?</h2>\n<p>AppleScript and JXA are powerful automation tools pre-installed on every Mac. While designed for legitimate system administration, these capabilities can be weaponized for:</p>\n<ul>\n<li><strong>Persistence mechanisms</strong> (login items, launch agents)</li>\n<li><strong>Credential access</strong> (password prompts)</li>\n<li><strong>Discovery operations</strong> (system information, user enumeration)</li>\n<li><strong>Defense evasion</strong> (hidden windows, execution delays, log deletion)</li>\n<li><strong>Collection</strong> (clipboard access, screenshot capture)</li>\n</ul>\n<h2 id=\"why-a-dedicated-applescript-testing-framework\">Why a Dedicated AppleScript Testing Framework?</h2>\n<p>While <a href=\"https://www.loobins.io/\" rel=\"nofollow noreferrer noopener\" target=\"_blank\">LOOBins</a> and <a href=\"https://github.com/redcanaryco/atomic-red-team\" rel=\"nofollow noreferrer noopener\" target=\"_blank\">Atomic Red Team</a> provide extensive macOS coverage, AppleScript and JXA deserve specialized focus.</p>\n<p>Making LOAS a separate framework allows for:</p>\n<ul>\n<li>\n<p><strong>Specialized Focus</strong>: Deep dive into macOS specific scripting nuances, TCC permissions, and application automation that would be lost in a general-purpose framework.</p>\n</li>\n<li>\n<p><strong>Multiple Execution Vectors</strong>: Each LOAS test can be executed through five different methods (CLI, script files, Swift, applets, binaries), each generating distinct detection telemetry. Adding this complexity to Atomic Red Team would be unwieldy.</p>\n</li>\n<li>\n<p><strong>Parameterized Testing</strong>: LOAS bridges the gap between documentation and testing. Unlike documentation libraries (LOLBAS, LOOBins, GTFOBins) that catalog techniques with example usage, LOAS delivers executable, parameterized tests designed for automated security validation.</p>\n</li>\n<li>\n<p><strong>Seamless Integration</strong>: LOAS uses a YAML specification similar to Atomic Red Team’s format. Conversion scripts transform LOAS tests into Atomic Red Team atomics, making integration seamless if you already use Atomic Red Team.</p>\n</li>\n</ul>\n<h3 id=\"real-world-threat-landscape\">Real-World Threat Landscape</h3>\n<p>Threat actors have consistently demonstrated the effectiveness of AppleScript and JXA in real-world attacks:</p>\n<ul>\n<li>\n<p><strong>OSX.Dok</strong> (2017): Banking trojan that leveraged AppleScript to create login items for persistence, prompting users for credentials to gain privilege escalation.</p>\n</li>\n<li>\n<p><strong>NetWire</strong> (2019): Remote access trojan observed using AppleScript for establishing persistence through login items on compromised macOS systems.</p>\n</li>\n<li>\n<p><strong>XCSSET</strong> (2020): Sophisticated macOS malware that used JXA extensively to check XProtect versions, evade detection, and steal Safari cookies and credentials.</p>\n</li>\n<li>\n<p><strong>Atomic Stealer</strong> (2023): Modern info-stealer that uses AppleScript’s Finder automation to copy Safari’s BinaryCookies files, bypassing traditional file access detection.</p>\n</li>\n</ul>\n<h3 id=\"see-it-in-action\">See It In Action</h3>\n<p>Here’s an example of how AppleScript can be used to prompt for credentials:</p>\n<div class=\"expressive-code\"><figure class=\"frame\"><figcaption class=\"header\"></figcaption><pre data-language=\"applescript\" class=\"wrap\" style=\"--ecMaxLine:172ch\"><code><div class=\"ec-line\"><div class=\"code\"><span style=\"--0:#F97583\">set</span><span style=\"--0:#E1E4E8\"> userPassword </span><span style=\"--0:#F97583\">to</span><span style=\"--0:#E1E4E8\"> </span><span style=\"--0:#79B8FF\">text</span><span style=\"--0:#E1E4E8\"> returned </span><span style=\"--0:#F97583\">of</span><span style=\"--0:#E1E4E8\"> (</span><span style=\"--0:#79B8FF\">display dialog</span><span style=\"--0:#E1E4E8\"> </span><span style=\"--0:#9ECBFF\">&quot;macOS Security Update&quot;</span><span style=\"--0:#E1E4E8\"> </span><span style=\"--0:#F97583\">&amp;</span><span style=\"--0:#E1E4E8\"> </span><span style=\"--0:#79B8FF\">return</span><span style=\"--0:#E1E4E8\"> </span><span style=\"--0:#F97583\">&amp;</span><span style=\"--0:#E1E4E8\"> </span><span style=\"--0:#9ECBFF\">&quot;Enter your password to continue:&quot;</span><span style=\"--0:#E1E4E8\"> default answer </span><span style=\"--0:#9ECBFF\">&quot;&quot;</span><span style=\"--0:#E1E4E8\"> </span><span style=\"--0:#F97583\">with</span><span style=\"--0:#E1E4E8\"> icon </span><span style=\"--0:#79B8FF\">1</span><span style=\"--0:#E1E4E8\"> </span><span style=\"--0:#F97583\">with</span><span style=\"--0:#E1E4E8\"> </span><span style=\"--0:#79B8FF\">hidden</span><span style=\"--0:#E1E4E8\"> answer)</span></div></div><div class=\"ec-line\"><div class=\"code\"><span style=\"--0:#99A0A6\">-- Credential now captured in userPassword variable</span></div></div></code></pre></figure></div>\n<div class=\"flex justify-center\"><p><img src=\"https://cyberbuff.dev/_astro/credential-prompt.DdOYHpar_ZKCkga.webp\" alt=\"Credential Prompt\" loading=\"lazy\" decoding=\"async\" width=\"1064\" height=\"608\"></p></div>\n<p>To your users, this looks like a legitimate system prompt. To your SIEM, it might look like nothing at all.</p>",
      "date_published": "2025-11-27T00:00:00.000Z",
      "date_modified": "2025-11-27T00:00:00.000Z",
      "tags": [
        "Security",
        "macOS",
        "AppleScript",
        "Adversary Emulation"
      ]
    },
    {
      "id": "https://cyberbuff.dev/blog/atomic-red-team-mcp/claude-becomes-c2",
      "url": "https://cyberbuff.dev/blog/atomic-red-team-mcp/claude-becomes-c2",
      "title": "Claude becomes C2",
      "summary": "Breaking Everything, Everywhere, All at Once",
      "content_html": "<p>Purple team exercises face a fundamental challenge: while attacks have become more sophisticated and cross-platform, our testing approaches remain fragmented. Security teams juggle platform-specific tooling, manual result correlation, and the constant context switching between testing environments.</p>\n<p>The solution? AI-powered orchestration that transforms rigid automation into intelligent, conversational security testing. In this post, you’ll discover how to transform your AI assistant into a multi-platform threat orchestrator that can simultaneously execute atomic tests across Windows, Linux, and macOS. We’ll walk through:</p>\n<ul>\n<li><strong>Setting up MCP servers</strong> on all three major operating systems</li>\n<li><strong>Centralized configuration</strong> that connects multiple servers to one AI assistant</li>\n<li><strong>Realistic attack scenarios</strong> like multi-platform persistence and protocol tunneling</li>\n<li><strong>Advanced orchestration</strong> where Claude manages entire multi-OS attack campaigns</li>\n</ul>\n<p>By the end, you’ll have Claude coordinating distributed atomic tests across your entire infrastructure through simple natural language commands like “Execute System Network Configuration Discovery atomics on all platforms and give me a consolidated report.”</p>\n<hr/>\n<p>This post continues from <a href=\"https://cyberbuff.substack.com/p/claude-becomes-the-apt?r=5wfbsg\" rel=\"nofollow noreferrer noopener\" target=\"_blank\">Part 1</a>, where we saw how Claude transforms from a helpful AI assistant into a sophisticated adversary emulation engine. Now, we’re taking it to the next level: multi-platform orchestration.</p>\n<p>Most foundational concepts—such as what MCP is, how Atomic Red Team MCP works, and the core introductory use cases—are thoroughly explained in Part 1 of this series. If you haven’t read <a href=\"https://cyberbuff.substack.com/p/claude-becomes-the-apt?r=5wfbsg\" rel=\"nofollow noreferrer noopener\" target=\"_blank\">Part 1</a> yet, I recommend starting there to get essential background before exploring the advanced orchestration techniques and multi-platform workflows described in this post.</p>\n<h2 id=\"the-multi-platform-challenge\">The Multi-Platform Challenge</h2>\n<p>Adversary emulation has evolved beyond manual coordination—tools like OpenAEV, Caldera, and other adversary emulation platforms already solve the basic multi-platform execution problem. You can absolutely orchestrate execution of atomic tests across Windows, Linux, and macOS using these established frameworks.</p>\n<p>But here’s what’s still missing: <strong>intelligent, conversational orchestration</strong>.</p>\n<p>Current tools require you to:</p>\n<ul>\n<li>Learn platform-specific interfaces and configuration syntax</li>\n<li>Pre-plan attack sequences in their native formats</li>\n<li>Context-switch between the orchestration tool and your analysis workflow</li>\n<li>Manually interpret results and plan follow-up actions</li>\n</ul>\n<p>Want to test registry persistence on Windows, then immediately adapt based on results? You’re still configuring playbooks, navigating web interfaces, or scripting custom logic.</p>\n<p>The real breakthrough isn’t just orchestration— it’s <strong>AI-powered orchestration that can analyze, learn, and adapt to your testing needs</strong>. What if you could simply say: <code>&quot;Execute registry persistence on Windows, analyze the logs using Splunk MCP, then recommend and run the best Linux persistence technique that would fit this attack scenario XYZ&quot;</code>?</p>\n<p>That’s where MCP orchestration transforms the game. You get the infrastructure orchestration of existing tools combined with the intelligent reasoning of LLMs, all through natural language instead of configuration files.</p>\n<h2 id=\"enter-the-cross-platform-c2-er-ai-assistant\">Enter the Cross-Platform C2… Er, AI Assistant</h2>\n<p>What if you could coordinate atomic tests across all platforms simultaneously using natural language? What if Claude could become your universal threat orchestrator, speaking fluent Windows, Linux, and macOS?</p>\n<p>That’s exactly what multiple MCP servers enable. By running Atomic Red Team MCP servers on different platforms and connecting them to a single AI assistant, you create a unified testing interface that enables centralized command and distributed execution.</p>\n<p>Here’s the architecture that makes it possible:</p>\n<div class=\"flex justify-center\"><p><img src=\"https://cyberbuff.dev/_astro/banner.BmR21x4n_ZhaXBE.webp\" alt=\"Multi-platform orchestration\" loading=\"lazy\" decoding=\"async\" width=\"2949\" height=\"2130\"></p></div>\n<h2 id=\"setting-up-your-distributed-testing-infrastructure\">Setting Up Your Distributed Testing Infrastructure</h2>\n<h3 id=\"prerequisites\">Prerequisites</h3>\n<p>Before You Begin</p>\n<p>Ensure you have the following installed on each target platform:</p>\n<p>All Platforms:</p>\n<ul>\n<li><strong>uv</strong> (Python package manager) — we’ll show installation commands below</li>\n<li><strong>Network connectivity</strong> between client and servers</li>\n<li><strong>Administrative/sudo privileges</strong> for service installation (production deployments)</li>\n</ul>\n<p>Client Machine:</p>\n<ul>\n<li><strong>npx</strong> (comes with Node.js) for MCP remote connections</li>\n<li><strong>Your AI assistant client</strong> (Claude Desktop, Cursor, etc.)</li>\n</ul>\n<p>Network Requirements:</p>\n<ul>\n<li>Port 8000 (or custom port) accessible between client and servers</li>\n<li>Firewall rules configured to allow inbound connections</li>\n</ul>\n<p>Optional but Recommended:</p>\n<ul>\n<li>SSH access to each server (for secure tunneling)</li>\n<li>Isolated test environment (VMs, containers, or dedicated test network)</li>\n<li>SIEM/SOAR MCPs (Splunk, etc.) and ticketing system MCPs (Jira, etc.) for automated detection correlation and workflow integration</li>\n</ul>\n<h3 id=\"step-1-mcp-server-deployment\">Step 1: MCP Server Deployment</h3>\n<p>Deploy MCP servers across your target platforms (Windows, Linux, and macOS). Make sure to save the authentication tokens from each deployment as these are needed to connect your AI assistant to the servers.</p>\n<p>💡 Tip: Always test in a lab before deploying on production systems</p>\n<p>Windows deployment (PowerShell):</p>\n<div class=\"expressive-code\"><figure class=\"frame is-terminal\"><figcaption class=\"header\"><span class=\"title\"></span><span class=\"sr-only\">Terminal window</span></figcaption><pre data-language=\"powershell\" class=\"wrap\" style=\"--ecMaxLine:100ch\"><code><div class=\"ec-line\"><div class=\"code\"><span style=\"--0:#99A0A6\"># Install uv</span></div></div><div class=\"ec-line\"><div class=\"code\">\n</div></div><div class=\"ec-line\"><div class=\"code\"><span style=\"--0:#E1E4E8\">powershell </span><span style=\"--0:#F97583\">-</span><span style=\"--0:#E1E4E8\">ExecutionPolicy ByPass </span><span style=\"--0:#F97583\">-</span><span style=\"--0:#E1E4E8\">c </span><span style=\"--0:#9ECBFF\">“irm https://astral.sh/uv/install.ps1 | iex”</span></div></div><div class=\"ec-line\"><div class=\"code\">\n</div></div><div class=\"ec-line\"><div class=\"code\"><span style=\"--0:#99A0A6\"># Generate secure authentication token</span></div></div><div class=\"ec-line\"><div class=\"code\">\n</div></div><div class=\"ec-line\"><div class=\"code\"><span style=\"--0:#E1E4E8\">$TOKEN </span><span style=\"--0:#F97583\">=</span><span style=\"--0:#E1E4E8\"> </span><span style=\"--0:#F97583\">-join</span><span style=\"--0:#E1E4E8\"> ((</span><span style=\"--0:#79B8FF\">48</span><span style=\"--0:#F97583\">..</span><span style=\"--0:#79B8FF\">57</span><span style=\"--0:#E1E4E8\">) </span><span style=\"--0:#F97583\">+</span><span style=\"--0:#E1E4E8\"> (</span><span style=\"--0:#79B8FF\">65</span><span style=\"--0:#F97583\">..</span><span style=\"--0:#79B8FF\">90</span><span style=\"--0:#E1E4E8\">) </span><span style=\"--0:#F97583\">+</span><span style=\"--0:#E1E4E8\"> (</span><span style=\"--0:#79B8FF\">97</span><span style=\"--0:#F97583\">..</span><span style=\"--0:#79B8FF\">122</span><span style=\"--0:#E1E4E8\">) </span><span style=\"--0:#F97583\">|</span><span style=\"--0:#E1E4E8\"> </span><span style=\"--0:#79B8FF\">Get-Random</span><span style=\"--0:#E1E4E8\"> </span><span style=\"--0:#F97583\">-</span><span style=\"--0:#E1E4E8\">Count </span><span style=\"--0:#79B8FF\">32</span><span style=\"--0:#E1E4E8\"> </span><span style=\"--0:#F97583\">|</span><span style=\"--0:#E1E4E8\"> </span><span style=\"--0:#79B8FF\">ForEach-Object</span><span style=\"--0:#E1E4E8\"> {[</span><span style=\"--0:#F97583\">char</span><span style=\"--0:#E1E4E8\">]$\\</span><span style=\"--0:#79B8FF\">_</span><span style=\"--0:#E1E4E8\">})</span></div></div><div class=\"ec-line\"><div class=\"code\"><span style=\"--0:#79B8FF\">Write-Host</span><span style=\"--0:#E1E4E8\"> </span><span style=\"--0:#9ECBFF\">&quot;Windows server token: </span><span style=\"--0:#E1E4E8\">$TOKEN</span><span style=\"--0:#9ECBFF\">&quot;</span><span style=\"--0:#E1E4E8\"> </span><span style=\"--0:#F97583\">-</span><span style=\"--0:#E1E4E8\">ForegroundColor Green</span></div></div><div class=\"ec-line\"><div class=\"code\">\n</div></div><div class=\"ec-line\"><div class=\"code\"><span style=\"--0:#99A0A6\"># Configure and launch</span></div></div><div class=\"ec-line\"><div class=\"code\">\n</div></div><div class=\"ec-line\"><div class=\"code\"><span style=\"--0:#E1E4E8\">$</span><span style=\"--0:#79B8FF\">env:</span><span style=\"--0:#E1E4E8\">ART_MCP_TRANSPORT </span><span style=\"--0:#F97583\">=</span><span style=\"--0:#E1E4E8\"> </span><span style=\"--0:#9ECBFF\">&quot;streamable-http&quot;</span></div></div><div class=\"ec-line\"><div class=\"code\"><span style=\"--0:#E1E4E8\">$</span><span style=\"--0:#79B8FF\">env:</span><span style=\"--0:#E1E4E8\">ART_EXECUTION_ENABLED </span><span style=\"--0:#F97583\">=</span><span style=\"--0:#E1E4E8\"> </span><span style=\"--0:#9ECBFF\">&quot;true&quot;</span></div></div><div class=\"ec-line\"><div class=\"code\"><span style=\"--0:#E1E4E8\">$</span><span style=\"--0:#79B8FF\">env:</span><span style=\"--0:#E1E4E8\">ART_MCP_PORT </span><span style=\"--0:#F97583\">=</span><span style=\"--0:#E1E4E8\"> </span><span style=\"--0:#9ECBFF\">&quot;8000&quot;</span></div></div><div class=\"ec-line\"><div class=\"code\"><span style=\"--0:#E1E4E8\">$</span><span style=\"--0:#79B8FF\">env:</span><span style=\"--0:#E1E4E8\">ART_MCP_HOST </span><span style=\"--0:#F97583\">=</span><span style=\"--0:#E1E4E8\"> </span><span style=\"--0:#9ECBFF\">&quot;0.0.0.0&quot;</span></div></div><div class=\"ec-line\"><div class=\"code\"><span style=\"--0:#E1E4E8\">$</span><span style=\"--0:#79B8FF\">env:</span><span style=\"--0:#E1E4E8\">ART_AUTH_TOKEN </span><span style=\"--0:#F97583\">=</span><span style=\"--0:#E1E4E8\"> $TOKEN</span></div></div><div class=\"ec-line\"><div class=\"code\">\n</div></div><div class=\"ec-line\"><div class=\"code\"><span style=\"--0:#E1E4E8\">uvx atomic</span><span style=\"--0:#F97583\">-</span><span style=\"--0:#E1E4E8\">red</span><span style=\"--0:#F97583\">-</span><span style=\"--0:#E1E4E8\">team</span><span style=\"--0:#F97583\">-</span><span style=\"--0:#E1E4E8\">mcp</span></div></div></code></pre></figure></div>\n<p><strong>Linux Deployment</strong></p>\n<div class=\"expressive-code\"><figure class=\"frame is-terminal\"><figcaption class=\"header\"><span class=\"title\"></span><span class=\"sr-only\">Terminal window</span></figcaption><pre data-language=\"bash\" class=\"wrap\" style=\"--ecMaxLine:47ch\"><code><div class=\"ec-line\"><div class=\"code\"><span style=\"--0:#99A0A6\"># Install uv</span></div></div><div class=\"ec-line\"><div class=\"code\">\n</div></div><div class=\"ec-line\"><div class=\"code\"><span style=\"--0:#B392F0\">curl</span><span style=\"--0:#E1E4E8\"> </span><span style=\"--0:#79B8FF\">-LsSf</span><span style=\"--0:#E1E4E8\"> </span><span style=\"--0:#9ECBFF\">https://astral.sh/uv/install.sh</span><span style=\"--0:#E1E4E8\"> </span><span style=\"--0:#F97583\">|</span><span style=\"--0:#E1E4E8\"> </span><span style=\"--0:#B392F0\">sh</span></div></div><div class=\"ec-line\"><div class=\"code\">\n</div></div><div class=\"ec-line\"><div class=\"code\"><span style=\"--0:#99A0A6\"># Generate secure token</span></div></div><div class=\"ec-line\"><div class=\"code\">\n</div></div><div class=\"ec-line\"><div class=\"code\"><span style=\"--0:#E1E4E8\">TOKEN</span><span style=\"--0:#F97583\">=</span><span style=\"--0:#E1E4E8\">$(</span><span style=\"--0:#B392F0\">openssl</span><span style=\"--0:#E1E4E8\"> </span><span style=\"--0:#9ECBFF\">rand</span><span style=\"--0:#E1E4E8\"> </span><span style=\"--0:#79B8FF\">-hex</span><span style=\"--0:#E1E4E8\"> </span><span style=\"--0:#79B8FF\">32</span><span style=\"--0:#E1E4E8\">)</span></div></div><div class=\"ec-line\"><div class=\"code\"><span style=\"--0:#79B8FF\">echo</span><span style=\"--0:#E1E4E8\"> </span><span style=\"--0:#9ECBFF\">&quot;Linux server token: </span><span style=\"--0:#E1E4E8\">$TOKEN</span><span style=\"--0:#9ECBFF\">&quot;</span></div></div><div class=\"ec-line\"><div class=\"code\">\n</div></div><div class=\"ec-line\"><div class=\"code\"><span style=\"--0:#99A0A6\"># Configure environment</span></div></div><div class=\"ec-line\"><div class=\"code\">\n</div></div><div class=\"ec-line\"><div class=\"code\"><span style=\"--0:#F97583\">export</span><span style=\"--0:#E1E4E8\"> ART_MCP_TRANSPORT</span><span style=\"--0:#F97583\">=</span><span style=\"--0:#9ECBFF\">&quot;streamable-http&quot;</span></div></div><div class=\"ec-line\"><div class=\"code\"><span style=\"--0:#F97583\">export</span><span style=\"--0:#E1E4E8\"> ART_EXECUTION_ENABLED</span><span style=\"--0:#F97583\">=</span><span style=\"--0:#9ECBFF\">&quot;true&quot;</span></div></div><div class=\"ec-line\"><div class=\"code\"><span style=\"--0:#F97583\">export</span><span style=\"--0:#E1E4E8\"> ART_MCP_PORT</span><span style=\"--0:#F97583\">=</span><span style=\"--0:#9ECBFF\">&quot;8000&quot;</span></div></div><div class=\"ec-line\"><div class=\"code\"><span style=\"--0:#F97583\">export</span><span style=\"--0:#E1E4E8\"> ART_MCP_HOST</span><span style=\"--0:#F97583\">=</span><span style=\"--0:#9ECBFF\">&quot;0.0.0.0&quot;</span></div></div><div class=\"ec-line\"><div class=\"code\"><span style=\"--0:#F97583\">export</span><span style=\"--0:#E1E4E8\"> ART_AUTH_TOKEN</span><span style=\"--0:#F97583\">=</span><span style=\"--0:#E1E4E8\">$TOKEN</span></div></div><div class=\"ec-line\"><div class=\"code\">\n</div></div><div class=\"ec-line\"><div class=\"code\"><span style=\"--0:#B392F0\">uvx</span><span style=\"--0:#E1E4E8\"> </span><span style=\"--0:#9ECBFF\">atomic-red-team-mcp</span></div></div></code></pre></figure></div>\n<p><strong>macOS Deployment</strong></p>\n<div class=\"expressive-code\"><figure class=\"frame is-terminal\"><figcaption class=\"header\"><span class=\"title\"></span><span class=\"sr-only\">Terminal window</span></figcaption><pre data-language=\"bash\" class=\"wrap\" style=\"--ecMaxLine:42ch\"><code><div class=\"ec-line\"><div class=\"code\"><span style=\"--0:#99A0A6\"># Generate secure token</span></div></div><div class=\"ec-line\"><div class=\"code\">\n</div></div><div class=\"ec-line\"><div class=\"code\"><span style=\"--0:#E1E4E8\">TOKEN</span><span style=\"--0:#F97583\">=</span><span style=\"--0:#E1E4E8\">$(</span><span style=\"--0:#B392F0\">openssl</span><span style=\"--0:#E1E4E8\"> </span><span style=\"--0:#9ECBFF\">rand</span><span style=\"--0:#E1E4E8\"> </span><span style=\"--0:#79B8FF\">-hex</span><span style=\"--0:#E1E4E8\"> </span><span style=\"--0:#79B8FF\">32</span><span style=\"--0:#E1E4E8\">)</span></div></div><div class=\"ec-line\"><div class=\"code\"><span style=\"--0:#79B8FF\">echo</span><span style=\"--0:#E1E4E8\"> </span><span style=\"--0:#9ECBFF\">&quot;macOS server token: </span><span style=\"--0:#E1E4E8\">$TOKEN</span><span style=\"--0:#9ECBFF\">&quot;</span></div></div><div class=\"ec-line\"><div class=\"code\">\n</div></div><div class=\"ec-line\"><div class=\"code\"><span style=\"--0:#99A0A6\"># Launch server</span></div></div><div class=\"ec-line\"><div class=\"code\">\n</div></div><div class=\"ec-line\"><div class=\"code\"><span style=\"--0:#F97583\">export</span><span style=\"--0:#E1E4E8\"> ART_MCP_TRANSPORT</span><span style=\"--0:#F97583\">=</span><span style=\"--0:#9ECBFF\">&quot;streamable-http&quot;</span></div></div><div class=\"ec-line\"><div class=\"code\"><span style=\"--0:#F97583\">export</span><span style=\"--0:#E1E4E8\"> ART_EXECUTION_ENABLED</span><span style=\"--0:#F97583\">=</span><span style=\"--0:#9ECBFF\">&quot;true&quot;</span></div></div><div class=\"ec-line\"><div class=\"code\"><span style=\"--0:#F97583\">export</span><span style=\"--0:#E1E4E8\"> ART_MCP_PORT</span><span style=\"--0:#F97583\">=</span><span style=\"--0:#9ECBFF\">&quot;8000&quot;</span></div></div><div class=\"ec-line\"><div class=\"code\"><span style=\"--0:#F97583\">export</span><span style=\"--0:#E1E4E8\"> ART_MCP_HOST</span><span style=\"--0:#F97583\">=</span><span style=\"--0:#9ECBFF\">&quot;0.0.0.0&quot;</span></div></div><div class=\"ec-line\"><div class=\"code\"><span style=\"--0:#F97583\">export</span><span style=\"--0:#E1E4E8\"> ART_AUTH_TOKEN</span><span style=\"--0:#F97583\">=</span><span style=\"--0:#9ECBFF\">&quot;</span><span style=\"--0:#E1E4E8\">$TOKEN</span><span style=\"--0:#9ECBFF\">&quot;</span></div></div><div class=\"ec-line\"><div class=\"code\">\n</div></div><div class=\"ec-line\"><div class=\"code\"><span style=\"--0:#B392F0\">uvx</span><span style=\"--0:#E1E4E8\"> </span><span style=\"--0:#9ECBFF\">atomic-red-team-mcp</span></div></div></code></pre></figure></div>\n<p>Verify whether the MCP servers are running.</p>\n<p><strong>Test each server</strong></p>\n<div class=\"expressive-code\"><figure class=\"frame is-terminal\"><figcaption class=\"header\"><span class=\"title\"></span><span class=\"sr-only\">Terminal window</span></figcaption><pre data-language=\"bash\" class=\"wrap\" style=\"--ecMaxLine:44ch\"><code><div class=\"ec-line\"><div class=\"code\"><span style=\"--0:#B392F0\">curl</span><span style=\"--0:#E1E4E8\"> </span><span style=\"--0:#9ECBFF\">http://10.2.20.14:8000/health</span><span style=\"--0:#E1E4E8\"> </span><span style=\"--0:#99A0A6\"># Windows</span></div></div><div class=\"ec-line\"><div class=\"code\"><span style=\"--0:#B392F0\">curl</span><span style=\"--0:#E1E4E8\"> </span><span style=\"--0:#9ECBFF\">http://10.2.20.15:8000/health</span><span style=\"--0:#E1E4E8\"> </span><span style=\"--0:#99A0A6\"># Linux</span></div></div><div class=\"ec-line\"><div class=\"code\"><span style=\"--0:#B392F0\">curl</span><span style=\"--0:#E1E4E8\"> </span><span style=\"--0:#9ECBFF\">http://10.2.20.16:8000/health</span><span style=\"--0:#E1E4E8\"> </span><span style=\"--0:#99A0A6\"># macOS</span></div></div></code></pre></figure></div>\n<blockquote>\n<p>Note: These commands are for initial setup and testing. For production use, implement proper service management with systemd, scheduled tasks, or launch daemons.</p>\n</blockquote>\n<h3 id=\"step-2-enable-unified-control\">Step 2: Enable Unified Control</h3>\n<p>Next, you’ll connect all servers to your AI assistant. Replace the bearer tokens in the configuration below with the tokens you saved from the previous step.</p>\n<div class=\"expressive-code\"><figure class=\"frame\"><figcaption class=\"header\"></figcaption><pre data-language=\"json\" class=\"wrap\" style=\"--ecMaxLine:49ch\"><code><div class=\"ec-line\"><div class=\"code\"><span style=\"--0:#E1E4E8\">{</span></div></div><div class=\"ec-line\" style=\"--ecIndent:2ch\"><div class=\"code\"><span class=\"indent\">  </span><span style=\"--0:#79B8FF\">&quot;mcpServers&quot;</span><span style=\"--0:#E1E4E8\">: {</span></div></div><div class=\"ec-line\" style=\"--ecIndent:4ch\"><div class=\"code\"><span class=\"indent\">    </span><span style=\"--0:#79B8FF\">&quot;atomic-windows&quot;</span><span style=\"--0:#E1E4E8\">: {</span></div></div><div class=\"ec-line\" style=\"--ecIndent:6ch\"><div class=\"code\"><span class=\"indent\">      </span><span style=\"--0:#79B8FF\">&quot;command&quot;</span><span style=\"--0:#E1E4E8\">: </span><span style=\"--0:#9ECBFF\">&quot;npx&quot;</span><span style=\"--0:#E1E4E8\">,</span></div></div><div class=\"ec-line\" style=\"--ecIndent:6ch\"><div class=\"code\"><span class=\"indent\">      </span><span style=\"--0:#79B8FF\">&quot;args&quot;</span><span style=\"--0:#E1E4E8\">: [</span></div></div><div class=\"ec-line\" style=\"--ecIndent:8ch\"><div class=\"code\"><span class=\"indent\">        </span><span style=\"--0:#9ECBFF\">&quot;-y&quot;</span><span style=\"--0:#E1E4E8\">,</span></div></div><div class=\"ec-line\" style=\"--ecIndent:8ch\"><div class=\"code\"><span class=\"indent\">        </span><span style=\"--0:#9ECBFF\">&quot;mcp-remote&quot;</span><span style=\"--0:#E1E4E8\">,</span></div></div><div class=\"ec-line\" style=\"--ecIndent:8ch\"><div class=\"code\"><span class=\"indent\">        </span><span style=\"--0:#9ECBFF\">&quot;http://10.2.20.14:8000/mcp&quot;</span><span style=\"--0:#E1E4E8\">,</span></div></div><div class=\"ec-line\" style=\"--ecIndent:8ch\"><div class=\"code\"><span class=\"indent\">        </span><span style=\"--0:#9ECBFF\">&quot;--header&quot;</span><span style=\"--0:#E1E4E8\">,</span></div></div><div class=\"ec-line\" style=\"--ecIndent:8ch\"><div class=\"code\"><span class=\"indent\">        </span><span style=\"--0:#9ECBFF\">&quot;Authorization: Bearer abc......windows&quot;</span><span style=\"--0:#E1E4E8\">,</span></div></div><div class=\"ec-line\" style=\"--ecIndent:8ch\"><div class=\"code\"><span class=\"indent\">        </span><span style=\"--0:#9ECBFF\">&quot;--allow-http&quot;</span></div></div><div class=\"ec-line\" style=\"--ecIndent:6ch\"><div class=\"code\"><span class=\"indent\"><span style=\"--0:#E1E4E8\">      </span></span><span style=\"--0:#E1E4E8\">]</span></div></div><div class=\"ec-line\" style=\"--ecIndent:4ch\"><div class=\"code\"><span class=\"indent\"><span style=\"--0:#E1E4E8\">    </span></span><span style=\"--0:#E1E4E8\">},</span></div></div><div class=\"ec-line\" style=\"--ecIndent:4ch\"><div class=\"code\"><span class=\"indent\">    </span><span style=\"--0:#79B8FF\">&quot;atomic-linux&quot;</span><span style=\"--0:#E1E4E8\">: {</span></div></div><div class=\"ec-line\" style=\"--ecIndent:6ch\"><div class=\"code\"><span class=\"indent\">      </span><span style=\"--0:#79B8FF\">&quot;command&quot;</span><span style=\"--0:#E1E4E8\">: </span><span style=\"--0:#9ECBFF\">&quot;npx&quot;</span><span style=\"--0:#E1E4E8\">,</span></div></div><div class=\"ec-line\" style=\"--ecIndent:6ch\"><div class=\"code\"><span class=\"indent\">      </span><span style=\"--0:#79B8FF\">&quot;args&quot;</span><span style=\"--0:#E1E4E8\">: [</span></div></div><div class=\"ec-line\" style=\"--ecIndent:8ch\"><div class=\"code\"><span class=\"indent\">        </span><span style=\"--0:#9ECBFF\">&quot;-y&quot;</span><span style=\"--0:#E1E4E8\">,</span></div></div><div class=\"ec-line\" style=\"--ecIndent:8ch\"><div class=\"code\"><span class=\"indent\">        </span><span style=\"--0:#9ECBFF\">&quot;mcp-remote&quot;</span><span style=\"--0:#E1E4E8\">,</span></div></div><div class=\"ec-line\" style=\"--ecIndent:8ch\"><div class=\"code\"><span class=\"indent\">        </span><span style=\"--0:#9ECBFF\">&quot;http://10.2.20.15:8000/mcp&quot;</span><span style=\"--0:#E1E4E8\">,</span></div></div><div class=\"ec-line\" style=\"--ecIndent:8ch\"><div class=\"code\"><span class=\"indent\">        </span><span style=\"--0:#9ECBFF\">&quot;--header&quot;</span><span style=\"--0:#E1E4E8\">,</span></div></div><div class=\"ec-line\" style=\"--ecIndent:8ch\"><div class=\"code\"><span class=\"indent\">        </span><span style=\"--0:#9ECBFF\">&quot;Authorization: Bearer def......linux&quot;</span><span style=\"--0:#E1E4E8\">,</span></div></div><div class=\"ec-line\" style=\"--ecIndent:8ch\"><div class=\"code\"><span class=\"indent\">        </span><span style=\"--0:#9ECBFF\">&quot;--allow-http&quot;</span></div></div><div class=\"ec-line\" style=\"--ecIndent:6ch\"><div class=\"code\"><span class=\"indent\"><span style=\"--0:#E1E4E8\">      </span></span><span style=\"--0:#E1E4E8\">]</span></div></div><div class=\"ec-line\" style=\"--ecIndent:4ch\"><div class=\"code\"><span class=\"indent\"><span style=\"--0:#E1E4E8\">    </span></span><span style=\"--0:#E1E4E8\">},</span></div></div><div class=\"ec-line\" style=\"--ecIndent:4ch\"><div class=\"code\"><span class=\"indent\">    </span><span style=\"--0:#79B8FF\">&quot;atomic-macos&quot;</span><span style=\"--0:#E1E4E8\">: {</span></div></div><div class=\"ec-line\" style=\"--ecIndent:6ch\"><div class=\"code\"><span class=\"indent\">      </span><span style=\"--0:#79B8FF\">&quot;command&quot;</span><span style=\"--0:#E1E4E8\">: </span><span style=\"--0:#9ECBFF\">&quot;npx&quot;</span><span style=\"--0:#E1E4E8\">,</span></div></div><div class=\"ec-line\" style=\"--ecIndent:6ch\"><div class=\"code\"><span class=\"indent\">      </span><span style=\"--0:#79B8FF\">&quot;args&quot;</span><span style=\"--0:#E1E4E8\">: [</span></div></div><div class=\"ec-line\" style=\"--ecIndent:8ch\"><div class=\"code\"><span class=\"indent\">        </span><span style=\"--0:#9ECBFF\">&quot;-y&quot;</span><span style=\"--0:#E1E4E8\">,</span></div></div><div class=\"ec-line\" style=\"--ecIndent:8ch\"><div class=\"code\"><span class=\"indent\">        </span><span style=\"--0:#9ECBFF\">&quot;mcp-remote&quot;</span><span style=\"--0:#E1E4E8\">,</span></div></div><div class=\"ec-line\" style=\"--ecIndent:8ch\"><div class=\"code\"><span class=\"indent\">        </span><span style=\"--0:#9ECBFF\">&quot;http://10.2.20.16:8000/mcp&quot;</span><span style=\"--0:#E1E4E8\">,</span></div></div><div class=\"ec-line\" style=\"--ecIndent:8ch\"><div class=\"code\"><span class=\"indent\">        </span><span style=\"--0:#9ECBFF\">&quot;--header&quot;</span><span style=\"--0:#E1E4E8\">,</span></div></div><div class=\"ec-line\" style=\"--ecIndent:8ch\"><div class=\"code\"><span class=\"indent\">        </span><span style=\"--0:#9ECBFF\">&quot;Authorization: Bearer ghi......macos&quot;</span><span style=\"--0:#E1E4E8\">,</span></div></div><div class=\"ec-line\" style=\"--ecIndent:8ch\"><div class=\"code\"><span class=\"indent\">        </span><span style=\"--0:#9ECBFF\">&quot;--allow-http&quot;</span></div></div><div class=\"ec-line\" style=\"--ecIndent:6ch\"><div class=\"code\"><span class=\"indent\"><span style=\"--0:#E1E4E8\">      </span></span><span style=\"--0:#E1E4E8\">]</span></div></div><div class=\"ec-line\" style=\"--ecIndent:4ch\"><div class=\"code\"><span class=\"indent\"><span style=\"--0:#E1E4E8\">    </span></span><span style=\"--0:#E1E4E8\">}</span></div></div><div class=\"ec-line\" style=\"--ecIndent:2ch\"><div class=\"code\"><span class=\"indent\"><span style=\"--0:#E1E4E8\">  </span></span><span style=\"--0:#E1E4E8\">}</span></div></div><div class=\"ec-line\"><div class=\"code\"><span style=\"--0:#E1E4E8\">}</span></div></div></code></pre></figure></div>\n<p>Restart your client, and Claude will have direct access to atomic testing capabilities across all three major operating systems.</p>\n<h2 id=\"multi-platform-attack-scenarios\">Multi-Platform Attack Scenarios</h2>\n<h3 id=\"scenario-1-run-persistence-atomics-across-all-platforms\">Scenario 1: Run Persistence atomics across all platforms</h3>\n<p>Imagine simulating an adversary who establishes persistence on Windows through registry manipulation, then moves to a Linux system using cron jobs:</p>\n<p>Execute registry persistence atomic test on atomic-windows server, then immediately follow up with a cron persistence test on atomic-linux server</p>\n<p>Claude coordinates both attacks:</p>\n<ul>\n<li><strong>Windows Phase:</strong> Executes T1547.001 (Registry Run Keys) on the Windows server</li>\n<li><strong>Linux Phase:</strong> Executes T1053.003 (Cron) on the Linux server</li>\n<li><strong>Reporting Phase:</strong> Provides consolidated output showing the complete attack chain</li>\n</ul>\n<p>Here is a sample output on what that would look like.</p>\n<div class=\"flex justify-center\"><p><img src=\"https://cyberbuff.dev/_astro/scenario1.CoyH11x3_Z1WvIVr.webp\" alt=\"Multiplatform Attack Scenario\" loading=\"lazy\" decoding=\"async\" width=\"916\" height=\"963\"></p></div>\n<h3 id=\"scenario-2-detection-rule-validation\">Scenario 2: Detection Rule Validation</h3>\n<p>Ever wondered how to efficiently execute atomic tests across Windows, Linux, and macOS—and get immediate validation results for your entire detection stack?</p>\n<p>For example: Want to assess your detection coverage against “Living off the tunnels” techniques? Run Cloudflare tunnel atomics on every major platform and instantly check whether your rules trigger the right alerts</p>\n<p>My detection rule targets Cloudflare tunnels. Find and execute Cloudflare tunnel atomics on atomic-windows, atomic-linux, and atomic-macos to validate detection coverage across platforms.</p>\n<p>After execution, query Splunk MCP and see whether there are any alerts for Cloudflare Tunnels.</p>\n<p>Claude will</p>\n<ol>\n<li><strong>Query</strong>: Queries and retrieves the atomic GUIDs for Cloudflare tunnel across all MCPs.</li>\n<li><strong>Execution</strong>: Automatically finds and executes the Cloudflare tunnel atomic across Windows, Linux, and macOS.</li>\n<li><strong>Detection</strong>: Checks Splunk MCP for any new Cloudflare alerts triggered by these activities.</li>\n<li><strong>Reporting</strong>: Summarizes the entire lifecycle of the attack, from execution all the way to detection outcomes.</li>\n</ol>\n<div class=\"flex justify-center\"><p><img src=\"https://cyberbuff.dev/_astro/scenario2.BB0NGJUf_Z1ux9p9.webp\" alt=\"Attack → Detection lifecycle\" loading=\"lazy\" decoding=\"async\" width=\"1371\" height=\"1295\"></p></div>\n<h3 id=\"scenario-3-threat-intelligence-to-multi-platform-playbook\">Scenario 3: Threat Intelligence to Multi-Platform Playbook</h3>\n<p>Remember those advanced prompts from Part 1? They become even more powerful with multiple platforms:</p>\n<p>Analyze this threat intelligence report and find platform-specific atomic tests. Execute Windows-specific TTPs on atomic-windows, Linux TTPs on atomic-linux, and macOS TTPs on atomic-macos. Provide a unified execution report.</p>\n<p>Claude will:</p>\n<ol>\n<li>Parse the threat intel for TTPs</li>\n<li>Map TTPs to platform-specific atomic tests</li>\n<li>Execute tests on appropriate platforms</li>\n<li>Generate a comprehensive multi-platform assessment</li>\n</ol>\n<div class=\"flex justify-center\"><p><img src=\"https://cyberbuff.dev/_astro/scenario3.BQCYpKEN_2kxt0p.webp\" alt=\"Threat Intelligence to Multi-Platform Playbook\" loading=\"lazy\" decoding=\"async\" width=\"797\" height=\"1061\"></p></div>\n<h2 id=\"whats-next\">What’s Next?</h2>\n<p>This enables several use cases:</p>\n<ul>\n<li>Automated kill chain execution across multiple platforms</li>\n<li>Purple team exercises with real-time coordination</li>\n<li>Threat hunting validation across heterogeneous networks</li>\n</ul>\n<details class=\"relative px-4 py-3 my-6 border-l-4 text-sm border-purple-500 bg-purple-950/5 [&amp;[open]>summary_svg:last-child]:rotate-180 [&amp;[open]>summary]:mb-3\" open><summary class=\"flex cursor-pointer items-center font-medium [&amp;::-webkit-details-marker]:hidden\"><svg width=\"1em\" height=\"1em\" viewBox=\"0 0 24 24\" class=\"mr-2 size-4 shrink-0 text-purple-300\" data-icon=\"lucide:message-square-warning\"><symbol id=\"ai:lucide:message-square-warning\"><path fill=\"none\" stroke=\"currentColor\" stroke-linecap=\"round\" stroke-linejoin=\"round\" stroke-width=\"2\" d=\"M22 17a2 2 0 0 1-2 2H6.828a2 2 0 0 0-1.414.586l-2.202 2.202A.71.71 0 0 1 2 21.286V5a2 2 0 0 1 2-2h16a2 2 0 0 1 2 2zm-10-2h.01M12 7v4\"/></symbol><use href=\"#ai:lucide:message-square-warning\"></use></svg><span class=\"font-medium mr-2 text-purple-300\">Important</span><svg width=\"1em\" height=\"1em\" viewBox=\"0 0 24 24\" class=\"ml-auto h-4 w-4 shrink-0 transition-transform duration-200 text-purple-300\" data-icon=\"lucide:chevron-down\"><symbol id=\"ai:lucide:chevron-down\"><path fill=\"none\" stroke=\"currentColor\" stroke-linecap=\"round\" stroke-linejoin=\"round\" stroke-width=\"2\" d=\"m6 9l6 6l6-6\"/></symbol><use href=\"#ai:lucide:chevron-down\"></use></svg></summary><div><p>With great power comes great responsibility. Use these capabilities in\nisolated, controlled environments, on systems you own or have explicit\npermission to test.</p></div></details>\n<p>This AI-powered orchestration approach opens up many possibilities, and I am curious about your experiences:</p>\n<ul>\n<li>Have you tried orchestrating security testing across multiple operating systems? What worked well, and what didn’t?</li>\n<li>What pain points have you faced with distributed testing or automating your security workflows? Are there specific bottlenecks that AI coordination could solve?</li>\n<li>Are there use cases, specific techniques, or atomic tests you’d like to see AI-powered orchestration handle better? What would make this approach more valuable for your team?</li>\n<li>Submit your toughest orchestration scenario. I’ll respond or feature solutions in future posts.</li>\n</ul>\n<h2 id=\"additional-resources\">Additional Resources</h2>\n<ul>\n<li><strong>Source code:</strong> <a href=\"https://github.com/cyberbuff/atomic-red-team-mcp\" rel=\"nofollow noreferrer noopener\" target=\"_blank\">GitHub</a></li>\n<li><strong>Bug Reports:</strong> <a href=\"https://github.com/cyberbuff/atomic-red-team-mcp/issues\" rel=\"nofollow noreferrer noopener\" target=\"_blank\">Create an issue</a></li>\n<li><strong>Questions:</strong> <a href=\"https://atomicredteam.slack.com/app_redirect?channel=U014WS6EU2Z\" rel=\"nofollow noreferrer noopener\" target=\"_blank\">Find me on Atomic Red Team Slack</a></li>\n<li><strong>Setup guide:</strong> See the <a href=\"https://github.com/cyberbuff/atomic-red-team-mcp/tree/main/docs/installation\" rel=\"nofollow noreferrer noopener\" target=\"_blank\">installation instructions</a></li>\n<li><strong>Advanced configuration:</strong> Check the <a href=\"https://github.com/cyberbuff/atomic-red-team-mcp/blob/main/docs/execution/multiple-mcp.md\" rel=\"nofollow noreferrer noopener\" target=\"_blank\">complete documentation</a> for production setup (service management, troubleshooting, and SSH tunneling)</li>\n</ul>",
      "date_published": "2025-11-04T00:00:00.000Z",
      "date_modified": "2025-11-04T00:00:00.000Z",
      "tags": [
        "Security",
        "Atomic Red Team",
        "MCP",
        "Adversary Emulation"
      ]
    },
    {
      "id": "https://cyberbuff.dev/blog/atomic-red-team-mcp",
      "url": "https://cyberbuff.dev/blog/atomic-red-team-mcp",
      "title": "Atomic Red Team MCP",
      "summary": "Use Atomic Red Team MCP server to create, query, and execute atomics from Atomic Red Team",
      "content_html": "<p>Hello everyone! 👋</p>\n<p>I’m excited to release the Atomic Red Team MCP Server - a tool that has transformed my adversary emulation workflow significantly. But before diving into the technical details, let me tell you why I built this.</p>\n<h2 id=\"️-the-problem-that-sparked-this-tool\">⚠️ The Problem That Sparked This Tool</h2>\n<p>As someone who regularly works with threat intelligence and detection engineering, I found myself repeating the same tedious process over and over.</p>\n<p>You probably know this pain too:</p>\n<p>You get threat intel about a new ransomware campaign. First, you spend 20 minutes sifting through atomic-red-team and others, searching for tests that match the TTPs. Half the time, the perfect test doesn’t exist. So you craft a custom test, validate the YAML syntax, execute it in your lab, debug why it failed, fix the test, run it again, and finally confirm it triggers your detection rules.</p>\n<p>What should be a 5-minute task turns into hours of manual work. There had to be a better way. This is where AI-powered automation changes everything.</p>\n<h2 id=\"-enter-ai-powered-adversary-emulation\">🤖 Enter AI-Powered Adversary Emulation</h2>\n<p>What if I could just ask my AI assistant to handle all of this? Instead of manually searching and creating tests, what if I could simply say:</p>\n<ul>\n<li>Find atomic tests for Conti ransomware techniques based on this threat intel report <code>threat-intel-report-here</code> → Get instant, relevant results</li>\n<li>Create a test to extract login credentials from Chrome browser → Get a validated, ready-to-execute atomic test</li>\n<li>Execute the atomic which creates a login item in macOS and show me the results → Get full execution output and analysis</li>\n</ul>\n<p>The Atomic Red Team MCP Server makes exactly this possible. It brings 1500+ atomic tests directly into Claude, VSCode, Cursor, and other AI assistants, transforming security testing from manual grunt work into natural conversations, reducing multi-hour processes to minutes.</p>",
      "image": "https://cyberbuff.dev/_astro/banner.BmR21x4n.png",
      "date_published": "2025-10-31T00:00:00.000Z",
      "date_modified": "2025-10-31T00:00:00.000Z",
      "tags": [
        "Security",
        "Atomic Red Team",
        "MCP",
        "Adversary Emulation"
      ]
    },
    {
      "id": "https://cyberbuff.dev/blog/atomic-red-team-mcp/claude-becomes-the-apt",
      "url": "https://cyberbuff.dev/blog/atomic-red-team-mcp/claude-becomes-the-apt",
      "title": "Claude becomes the APT",
      "summary": "Breaking Things with Atomic Red Team MCP because manual exploitation is so last decade",
      "content_html": "<h2 id=\"-what-is-mcp\">💭 What Is MCP?</h2>\n<p>Model Context Protocol (MCP) allows AI assistants like Claude to directly interact with external tools and databases instead of relying on copy-paste workflows between systems. Before MCP, you’d search GitHub for atomic tests, copy YAML to Claude, get responses, then manually transfer everything back to your terminal - essentially acting as a human API bridge.</p>\n<p>With MCP, Claude can directly query atomic test databases, validate YAML syntax, and execute commands within the same conversation context. It’s like giving your AI assistant API access to your security toolchain rather than making it work through you as a proxy. This eliminates the context-switching overhead that kills productivity in security workflows.</p>\n<h2 id=\"-key-features\">✨ Key Features</h2>\n<ul>\n<li>🔍 Search 1500+ atomic tests by technique ID, name, or platform</li>\n<li>⚡ Create new tests with AI assistance following best practices</li>\n<li>✅ Validate created atomic test against YAML schemas</li>\n<li>🎯 Execute tests in controlled environments (optional, disabled by default)</li>\n</ul>\n<h2 id=\"-real-world-scenarios\">⚡ Real World Scenarios</h2>\n<p>Ready for some practical magic? Here’s what becomes possible:</p>\n<h3 id=\"scenario-1-threat-intel-analysis\">Scenario 1: Threat Intel Analysis</h3>\n<p>You receive a threat report about the new macOS Stealer. You need to test your defenses.</p>\n<p>Try this:</p>\n<details class=\"relative px-4 py-3 my-6 border-l-4 text-sm border-emerald-500 bg-emerald-950/5 [&amp;[open]>summary_svg:last-child]:rotate-180 [&amp;[open]>summary]:mb-3\" open><summary class=\"flex cursor-pointer items-center font-medium [&amp;::-webkit-details-marker]:hidden\"><svg width=\"1em\" height=\"1em\" viewBox=\"0 0 24 24\" class=\"mr-2 size-4 shrink-0 text-emerald-300\" data-icon=\"lucide:code\"><symbol id=\"ai:lucide:code\"><path fill=\"none\" stroke=\"currentColor\" stroke-linecap=\"round\" stroke-linejoin=\"round\" stroke-width=\"2\" d=\"m16 18l6-6l-6-6M8 6l-6 6l6 6\"/></symbol><use href=\"#ai:lucide:code\"></use></svg><span class=\"font-medium mr-2 text-emerald-300\">Example</span><svg width=\"1em\" height=\"1em\" viewBox=\"0 0 24 24\" class=\"ml-auto h-4 w-4 shrink-0 transition-transform duration-200 text-emerald-300\" data-icon=\"lucide:chevron-down\"><symbol id=\"ai:lucide:chevron-down\"><path fill=\"none\" stroke=\"currentColor\" stroke-linecap=\"round\" stroke-linejoin=\"round\" stroke-width=\"2\" d=\"m6 9l6 6l6-6\"/></symbol><use href=\"#ai:lucide:chevron-down\"></use></svg></summary><div><p>Analyze the threat intelligence report at <code>threat-intel-report-link-here</code>. First, identify all TTPs mentioned in the report and cross-reference them against the existing Atomic Red Team library to find matching atomic tests. For any TTPs that don’t have corresponding atomics, generate new atomic tests. Finally, compile everything into a structured playbook YAML file with entries formatted as:</p><div class=\"expressive-code\"><figure class=\"frame\"><figcaption class=\"header\"></figcaption><pre data-language=\"yaml\" class=\"wrap\" style=\"--ecMaxLine:51ch\"><code><div class=\"ec-line\"><div class=\"code\"><span style=\"--0:#E1E4E8\">- </span><span style=\"--0:#85E89D\">auto_generated_guid</span><span style=\"--0:#E1E4E8\">: </span><span style=\"--0:#9ECBFF\">abcdef-abcd-abcd-abcd-abcdef</span></div></div><div class=\"ec-line\" style=\"--ecIndent:2ch\"><div class=\"code\"><span class=\"indent\">  </span><span style=\"--0:#85E89D\">name</span><span style=\"--0:#E1E4E8\">: </span><span style=\"--0:#9ECBFF\">Atomic Test name 1</span></div></div><div class=\"ec-line\" style=\"--ecIndent:2ch\"><div class=\"code\"><span class=\"indent\">  </span><span style=\"--0:#85E89D\">technique_id</span><span style=\"--0:#E1E4E8\">: </span><span style=\"--0:#9ECBFF\">T1000</span></div></div><div class=\"ec-line\"><div class=\"code\">\n</div></div><div class=\"ec-line\"><div class=\"code\"><span style=\"--0:#E1E4E8\">- </span><span style=\"--0:#85E89D\">auto_generated_guid</span><span style=\"--0:#E1E4E8\">: </span><span style=\"--0:#9ECBFF\">abcdef-abcd-abcd-abcd-abcdef</span></div></div><div class=\"ec-line\" style=\"--ecIndent:2ch\"><div class=\"code\"><span class=\"indent\">  </span><span style=\"--0:#85E89D\">name</span><span style=\"--0:#E1E4E8\">: </span><span style=\"--0:#9ECBFF\">Atomic Test name 2</span></div></div><div class=\"ec-line\" style=\"--ecIndent:2ch\"><div class=\"code\"><span class=\"indent\">  </span><span style=\"--0:#85E89D\">technique_id</span><span style=\"--0:#E1E4E8\">: </span><span style=\"--0:#9ECBFF\">T1000</span></div></div></code></pre></figure></div></div></details>\n<div class=\"flex justify-center\"><p><img src=\"https://cyberbuff.dev/_astro/scenario1.Bb6yZPYi_Z1rDeq2.webp\" alt=\"Threat Intel Analysis\" loading=\"lazy\" decoding=\"async\" width=\"964\" height=\"1456\"></p></div>\n<p>Behind the scenes, the AI assistant will</p>\n<ul>\n<li>Extract TTPs and attack techniques from the report</li>\n<li>Search the atomic library for existing coverage</li>\n<li>Generate new tests for missing techniques using actual malware commands</li>\n<li>Validate all YAML syntax automatically</li>\n<li>Compile everything into a ready-to-execute playbook</li>\n</ul>\n<p>Traditional approach: 45+ minutes, with MCP: 5-10 minutes</p>\n<h3 id=\"scenario-2-detection-rule-validation\">Scenario 2: Detection Rule Validation</h3>\n<p>Your team deployed a new detection rule targeting Cloudflare tunnel abuse - a technique increasingly used by threat actors for persistence and C2 communication.</p>\n<details class=\"relative px-4 py-3 my-6 border-l-4 text-sm border-emerald-500 bg-emerald-950/5 [&amp;[open]>summary_svg:last-child]:rotate-180 [&amp;[open]>summary]:mb-3\" open><summary class=\"flex cursor-pointer items-center font-medium [&amp;::-webkit-details-marker]:hidden\"><svg width=\"1em\" height=\"1em\" viewBox=\"0 0 24 24\" class=\"mr-2 size-4 shrink-0 text-emerald-300\" data-icon=\"lucide:code\"><use href=\"#ai:lucide:code\"></use></svg><span class=\"font-medium mr-2 text-emerald-300\">Example</span><svg width=\"1em\" height=\"1em\" viewBox=\"0 0 24 24\" class=\"ml-auto h-4 w-4 shrink-0 transition-transform duration-200 text-emerald-300\" data-icon=\"lucide:chevron-down\"><use href=\"#ai:lucide:chevron-down\"></use></svg></summary><div><p>I need to test my ‘Cloudflared Tunnel Execution’ detection rule that flags\ncloudflared tool usage for maintaining persistence. Find existing atomic tests\nthat would trigger this, or create a new test using techniques from\n<a href=\"https://lottunnels.github.io/lottunnels/Binaries/cloudflared/\" rel=\"nofollow noreferrer noopener\" target=\"_blank\">https://lottunnels.github.io/lottunnels/Binaries/cloudflared/</a></p></div></details>\n<p>What your AI assistant delivers:</p>\n<ul>\n<li>Searches atomic red team library for cloudflared-related tests</li>\n<li>Analyzes the provided documentation for attack patterns</li>\n<li>Creates a new atomic test if it doesn’t already exist</li>\n<li>Outputs validated, contribution-ready YAML</li>\n<li>(Optional) Chain with SIEM/SOAR MCP integrations for automated validation. Check out Claude found the APT by Michael Haag for a real-world Splunk MCP example.</li>\n</ul>\n<div class=\"flex justify-center\"><p><img src=\"https://cyberbuff.dev/_astro/scenario2.BqznR0r9_1Mb73v.webp\" alt=\"Detection Rule Validation\" loading=\"lazy\" decoding=\"async\" width=\"991\" height=\"1487\"></p></div>\n<p><strong>Traditional approach</strong>: 30+ minutes, with MCP: 3-5 minutes</p>\n<h2 id=\"️-troubleshooting\">🛠️ Troubleshooting</h2>\n<p>AI not recognizing your requests? Add “using atomic-red-team MCP” to your prompt. If issues persist, start a fresh chat conversation.</p>\n<h2 id=\"-limitations\">🚧 Limitations</h2>\n<ul>\n<li>Complex multi-stage campaigns may need manual breakdown.</li>\n<li>Environment-specific payloads require custom modification.</li>\n<li>Generated tests may need tuning for your specific infrastructure.</li>\n<li>If generated tests seem off-target, include specific threat intel reports or attack documentation in your prompt for better accuracy.</li>\n</ul>\n<h2 id=\"-ready-to-streamline-your-security-testing\">🎉 Ready to streamline your security testing?</h2>\n<ul>\n<li><strong>Source code:</strong> <a href=\"https://github.com/cyberbuff/atomic-red-team-mcp\" rel=\"nofollow noreferrer noopener\" target=\"_blank\">GitHub</a></li>\n<li><strong>Install in 5 minutes:</strong> <a href=\"https://github.com/cyberbuff/atomic-red-team-mcp?tab=readme-ov-file#platform-specific-guides\" rel=\"nofollow noreferrer noopener\" target=\"_blank\">Installation Guide</a></li>\n<li><strong>Try your first query:</strong> “Show me all osascript tests”</li>\n<li><strong>Found a bug?</strong> <a href=\"https://github.com/cyberbuff/atomic-red-team-mcp/issues\" rel=\"nofollow noreferrer noopener\" target=\"_blank\">Create an issue</a></li>\n<li><strong>Questions?</strong> Find me on <a href=\"https://atomicredteam.slack.com/app_redirect?channel=U014WS6EU2Z\" rel=\"nofollow noreferrer noopener\" target=\"_blank\">Atomic Red Team Slack</a></li>\n<li><strong>Ready to see the magic happen?</strong> Check out Atomics on a Friday for a live demo of the tool on <a href=\"https://youtu.be/nSuCkEFHwR0\" rel=\"nofollow noreferrer noopener\" target=\"_blank\">YouTube</a></li>\n</ul>\n<p><a href=\"https://www.youtube.com/watch?v=nSuCkEFHwR0\"><img src=\"https://i.ytimg.com/vi/nSuCkEFHwR0/hqdefault.jpg\" alt=\"Watch the video on YouTube\" /></a></p>\n<p>Give it a try!</p>\n<p>Coming next: <a href=\"https://cyberbuff.dev/blog/atomic-red-team-mcp/claude-becomes-c2\">Run Atomic Red Team MCPs across Windows, Linux, and macOS with centralized AI assistant control</a></p>\n<p>Note: Huge thanks to <a href=\"https://x.com/M_haggis\" rel=\"nofollow noreferrer noopener\" target=\"_blank\">Michael Haag</a> for the inspiration with his “Claude found the APT” work - I’m totally borrowing his clever naming convention for “Claude becomes the APT.”</p>",
      "date_published": "2025-10-31T00:00:00.000Z",
      "date_modified": "2025-10-31T00:00:00.000Z",
      "tags": [
        "Security",
        "Atomic Red Team",
        "MCP",
        "Adversary Emulation"
      ]
    }
  ]
}