aptpen.com OPS · ONLINE
scope_engagement →
◢ TOOLKIT AND TRADECRAFT

Access, instrumentation,
and in-house development.

// Every campaign arrives with current commercial license inventory, deep open-source toolchain fluency, and in-house tooling for the engagements that ask for it. Agentic harnesses extend the operator bench when an environment is too large for human pairs to reach end to end inside a campaign window. An operator stands behind every decision, and an audit trail stands behind every action.

§01 SIX CATEGORIES · ROTATING INVENTORY

What arrives with the work.

01
KIT.01

Commercial frameworks

Licensed and current on the major commercial command-and-control frameworks, plus the smaller specialty kits an engagement may call for. License inventory rides on our side of the engagement.

Cobalt Strike Brute Ratel Mythic Outflank
02
KIT.02

Open-source toolchains

Deep fluency in the standard offensive stack. We extend these tools when an engagement asks for it, and contribute patches back when the work improves the tool itself.

BloodHound certipy impacket NetExec evilginx sliver havoc
03
KIT.03

In-house implants

Operator-written loaders, beacons, and evasion routines for engagements where commercial kits are too widely fingerprinted. Built per campaign, burned at closeout.

Custom loaders BYOVD Signed binaries Memory-only
04
KIT.04

Agentic adversary emulation

We develop AI agents that execute named TTP chains under operator supervision. The harness lets one operator pair sustain breadth across a large environment, with every action logged for audit and every decision reviewed before it runs.

Operator-supervised TTP chains as policy Audit log per action
05
KIT.05

Red-team infrastructure

Dedicated redirectors, ephemeral domains, isolated C2, infrastructure-as-code stand-up. Every campaign runs on its own infrastructure, burned at closeout.

Dedicated C2 Ephemeral domains IaC stand-up
06
KIT.06

Wireless and physical kit

HID and iCLASS cloners, Proxmark, Wi-Fi Pineapple, SDR rigs, BLE and Zigbee analyzers, drop boxes, and the lock kit we carry for the engagements that ask for it.

Proxmark SDR BLE / Zigbee Drop boxes
§02 SPOTLIGHT · AGENTIC ADVERSARY EMULATION

Agentic exploits.

// A standalone capability we developed in 2025 and deploy on engagements where breadth would otherwise outrun the operator pair. The agent runs threat-actor TTP chains as policy, an operator sits supervisor on the chain, and every action lands in an audit log keyed to the engagement.

HOW IT WORKS

Policy, plan, supervise, audit.

The agent reads a TTP chain authored by the operator as the engagement plan and reasons about each step against the live environment. Operator supervision is enforced: every decision that crosses an ROE boundary holds for explicit human approval. The audit log records the prompt, the model output, the action taken, the resulting host state, and the operator who signed each gate.

  • TTP chain compiled from current ATT&CK plus actor playbook
  • Operator-set guardrails and stop conditions
  • Every action paired with a generated detection rule
  • Audit-log export on engagement close
WHERE IT FITS

Breadth across a large estate.

One operator pair can sustain breadth across thousands of endpoints, dozens of cloud accounts, or many tenants of a SaaS estate. The harness handles the parallel paths, the operator handles the decisions that matter. Output reads as if a larger team ran the campaign with the same opsec discipline.

  • Continuous engagements with large estates
  • Multi-tenant SaaS testing
  • Detection-engineering scale-out
  • Always paired with operator review
ROE AND SAFETY
The agent has read-only authority by default. Any action that modifies state, persists, or moves laterally crosses a gate that blocks for human approval. ROE-defined stop conditions, blackout windows, and out-of-scope assets are compiled into the policy engine before the campaign opens. The agent halts on a stop condition and surfaces the decision to the operator for review.
§03 CAMPAIGN INFRASTRUCTURE

Per-campaign infrastructure.

// Each engagement stands up its own infrastructure on a clean tenant, with no overlap between customers. Domains rotate every campaign, redirectors are dedicated, and the whole stack burns at closeout. Operators sign off on the build before the first beacon calls back.

PLANE.01

Redirector tier

CDN-fronted, geo-aware, rate-limited. Two redirectors per campaign minimum, more for high-opsec engagements.

PLANE.02

C2 tier

Isolated tenant, encrypted at rest, accessible only via operator hardware key. Logs ship in real time to engagement audit.

PLANE.03

Domain pool

Categorized domains aged for the campaign window, vetted against takedown signals, retired at closeout.

PLANE.04

IaC stand-up

Terraform plus Ansible. Reproducible build from a vault-signed engagement seed. Tear-down is one command.

Curious which parts of the kit fit your environment?

The scoping conversation walks through the toolkit choices that fit the campaign archetype and the threat model. Operators-only, no sales engineering loop.

open_intake →