01Chain
- T1566.001Initial Access
- T1059.001Execution
- T1574.001Stealth
- T1685.001Defense Impairment
- T1219.002Command & Control
HANDS-ON LAB: SECURE AI AT RUNTIME WITH GHS & CROWDSTRIKE | Oct 13
REGISTER HEREIBM i CURRENCY DEBT WEBINAR | OCT 8
REGISTER HEREINTRODUCE AI WITHOUT REBUILDING YOUR IT ENVIRONMENT WEBINAR
GET THE RECORDINGON-DEMAND GOOGLE'S AGENTIC SECOPS WEBINAR
Watch RecordingWIZ CLOUD SECURITY BLUEPRINT WEBINAR
REGISTER HEREGlassHouse Systems Named A Great Place To Work! Read more
MITRE ATT&CK · Synthetic telemetry
Pick the tactics. TTXAgent builds the campaign and writes the Windows event logs to match — files on your machine, no agent, nothing touching your network.
Currently allowlisted. Every request is read by a person.
TTXAgentbuilding run E2B8502E
01Chain
02Event stream
03Validation
10 pass · 0 warn
04Run E2B8502E
AMBER-LANTERN
TTX-LAB-E2B8502E-WS0110.4.7.47
TTX-LAB-E2B8502E-DC0110.4.1.31
One run · E2B8502E
Four tactics requested, five resolved · ATT&CK v19.2 · 3,754 Sigma rules evaluated · ten checks passed
Atomic tests, attack ranges, BAS agents — every route to it starts with an environment you stand up, instrument, and run something hostile inside.
TTXAgent skips the environment. It writes what the intrusion would have left behind: the campaign, the process tree underneath it, and the Windows event log to match.
Building it yourself
and again for the next technique
With TTXAgent
01
Name the tactics. It resolves a chain ATT&CK actually permits, in the order an operator would run it.
02
Windows event XML with real process lineage: parent PIDs, process GUIDs, one logon session across every stage.
03
One folder. The exercise document, the event log, and the JSON behind both.
Fake telemetry falls apart the moment an analyst pivots on it. Every stage here inherits from the one before — real parent PIDs, real process GUIDs, one logon session.
Five stages, one process tree. Three of them never spawn anything — they act as pid 3508, so the remote-access beacon has a parent you can trace all the way back to the attachment.
It picks the technique and writes the sentence. Everything else is derived from them.
Anything that has to be internally consistent — hosts, PIDs, timestamps, tactic order — is computed and rendered from data. Technique names are read from the ATT&CK bundle on every call, never from model recall.
Every event carries the campaign's own hostname prefix, so it stays identifiable wherever the logs end up — including in a SIEM already full of your own traffic. Adversary addresses come from RFC 5737 and cannot route anywhere.
Loads into
Standard Windows event XML. If your SIEM reads Sysmon, it reads this.
Someone opening a run folder weeks later can tell what the campaign was, which ATT&CK and Sigma versions it was built against, and how to find it in the SIEM — without this tool installed.
Nine files, 527 KB. No database, no proprietary format.
Tests your content
Fire a rule against a full chain before it ships, not against one hand-written event.
Tests your process
Injects, discussion questions and facilitator notes ship in the document. Seventy-five minutes, already written.
Tests your people
New analysts pivot a real chain in your own SIEM, not in a vendor’s sandbox.
Tell us which tactics you want to exercise. We build the campaign, hand you the bundle, and walk your team through what the SOC caught.