Importing¶
To support interoperability between PurpleOps instances and open-source frameworks, the following assessment import methods are supported.
Note
Only Admin and Red users can perform these functions.
Testcase(s) from Template¶
Opens a modal table populated with testcases from Atomic Red Team and any provided custom templates as specified in configuration.
Mitre ATT&CK Navigator Layer¶
Imports testcases from MITRE ATT&CK Navigator exports (layer controls --> download layer as json). This allows for the speedy creation of assessments based on e.g. a given threat actor. For instance, to create a PurpleOps assessment based off the Lazarus Group:
- Visit the MITRE ATT&CK Navigator
Create New Layer-->Create a new empty layer-->Enterpriseselection controls-->search & multiselectThreat Groups-->Lazarus Group-->selecttechnique controls-->background color-->select colorlayer controls-->download layer as json
- In PurpleOps
Import-->Mitre ATT&CK Navigator Layer-->Upload .json
Campaign Template¶
Import a suite of testcases generated using Export --> Campaign Template.
Entire Assessment¶
Imports an entire assessment generated using Export --> Entire Assessment, populating:
- Assessment metadata (e.g.
nameanddescription) - Testcases
- Testcase data
- Evidence files
Allows for full portability between PurpleOps instances!