RG‑AE‑001 · Windows post‑compromise micro‑emulation
Scope & objective
A contained, authorized study of whether a realistic sequence of post‑compromise techniques is observed and understood by the detection stack. The objective is visibility and response validation, measured against a defined telemetry baseline.
Controlled workflow
Executed as a custom eight‑step CALDERA campaign in a controlled environment. Each step is mapped, time‑stamped against the evidence timeline, and tied to an observable artifact for validation.
Tools & telemetry
- MITRE Caldera (campaign operator)
- PowerShell Script Block Logging
- Sysmon telemetry
- Wazuh detection & alerting
Evidence‑backed findings
Campaign activity was correlated against the logging baseline to assess what the stack surfaced, what it missed, and where detection/response tuning is warranted. Findings and sanitized evidence are documented per step.
Architecture diagram — REDxGRIDxAEV / RG‑AE‑001
Limits & safe framing
This engagement does not demonstrate, and is not claimed to have achieved: initial access, persistence, credential theft, lateral movement, exfiltration, or production-system access. It is a bounded, authorized validation exercise.
The REDxGRIDxAEV repository is private. Full sanitized evidence and the write‑up are available on request.