g3rt.com

Purple

dotgibson

One core, eight operating systems, two role layers.

  • Zsh
  • Neovim
  • tmux
  • Python
  • Bash
  • Docker

View the repository

repositories
13
operating systems
8
Python & Bash scripts
~370
paired detection entries
20+

The core (zsh, tmux, Neovim, git, starship, mise) is authored once and vendored into every per-OS repository with git subtree, so a tagged clone carries the exact core it was tested against. Eight platforms: macOS, Windows/WSL2, Kali, Arch, Fedora, openSUSE, Gentoo, and Alpine.

Two role layers sit on top. The offensive layer maps engagement phase to ATT&CK tactic to tooling, and enforces a rule-zero worth stating: the engagement bootstrap writes a scope file before anything else runs. Installing a tool is not permission to point it at anything.

The defensive layer is detection engineering plus a Dockerized hunt lab, with Python fixture generators that synthesize the traffic a detection is supposed to catch (DNS tunneling, DGA beaconing, ICMP tunneling, authentication coercion, cryptomining, reverse tunnels) so rules are validated against generated evidence rather than hope.

htpx ties the halves together: an ATT&CK-tagged corpus pairing each offensive technique with its detection, roughly 20 blue-side entries covering DCSync, Kerberoasting, golden tickets, ADCS abuse, and NTLM relay. The purple-team guidance is one line: detect on the invariant, not the IOC.

Details