Purpose
Maintain reusable playbooks for Red Team exercises. Each playbook maps to ATT&CK/ATLAS techniques and can be invoked by name.
Playbook Structure
## [Playbook Name]
**Technique IDs:** T1566, ATLAS-T-001, ...
**Target:** [surface, e.g. trip export, rules files]
**Role:** Specialist | Technical Ninja
### Steps
1. [Action]
2. [Action]
3. [Action]
### Expected Blue Detection
- [What should fire]
### Artifacts
- [Scripts, payloads, file paths]
Standard Playbooks
| Playbook | Techniques | Target |
|---|
| Export flow | T1190, T1005 | Trip export, FileProvider |
| Rules backdoor | ATLAS-T-002, T1562 |