Abstract
Proposed herein is an automated adversary-emulation (red-team) system that executes techniques mapped to the MITRE Adversarial Tactics, Techniques, and Common Knowledge (ATT&CK) framework through a live execution engine and adapts in real time based on whether each technique is detected by the target's defenses. The system combines three elements: a standardized agent context protocol used as an orchestration bus that exposes shared execution state and callable tools to role-specialized reasoning agents; real-time ingestion of endpoint detection and response (EDR), security information and event management (SIEM), and intrusion detection system (IDS) signals as structured inputs to agent reasoning; and detection-conditional, autonomous substitution of functionally equivalent evasion-variant techniques when a technique is detected. Together, these elements form a closed observe-reason-act-adapt loop that emulates how an adaptive human adversary switches techniques to remain undetected and yields a measurable reduction in detection rate relative to static, pre-scripted execution.
Creative Commons License

This work is licensed under a Creative Commons Attribution 4.0 License.
Recommended Citation
Singh, Amit, "DETECTION-CONDITIONAL MULTI-AGENT ADVERSARY EMULATION WITH AUTONOMOUS EVASION-VARIANT TECHNIQUE SUBSTITUTION", Technical Disclosure Commons, ()
https://www.tdcommons.org/dpubs_series/11239