From blue-team
Plan and run a purple-team exercise: collaboratively emulate specific ATT&CK techniques and measure whether detection and response actually work, then close the gaps. Use to validate defensive coverage against real adversary behavior. Authorized environments only.
How this skill is triggered — by the user, by Claude, or both
Slash command
/blue-team:purple-team-exerciseThe summary Claude sees in its skill listing — used to decide when to auto-load this skill
Measured evidence of which adversary techniques your defenses detect and respond to —
Measured evidence of which adversary techniques your defenses detect and respond to — and a prioritized set of fixes — produced collaboratively (red emulates, blue observes) rather than as a pass/fail contest.
threat-intelligence:threat-actor-profiling) and known coverage gaps
(detection-engineering:detection-coverage-review). Define success criteria.detection-engineering:detection-rule-development),
data-source onboarding, or runbook fixes; re-test to confirm closure.A results matrix: technique (ATT&CK) · emulation · telemetry? · detected? · responded?
· gap type · fix · retest status. Visualize as an ATT&CK heatmap
(security-diagramming) and report with security-reporting.
Purple teaming is collaborative measurement, not a competition — the win is closed gaps, not "red won." Keep emulations safe, authorized, and reversible. Re-test after fixes; an untested fix isn't a closed gap.
Creates, edits, and optimizes skills for Claude Code, including drafting, evaluating with test prompts, iterating on performance, and improving skill descriptions for better triggering accuracy.
npx claudepluginhub jassics/awesome-claude-security --plugin blue-team