This repository contains materials from the Purple Teaming Workshop conducted at OTCEP 2025 by the Attack Simulation Group (ASG).
Contains the complete slide deck used during the Purple Teaming Workshop.
Contains all the practical exercises and hands-on materials conducted during the workshop, including:
- Obfuscate a payload (PowerCat) with a given prompt
- Leveraging AI to converting a PowerShell payload into NodeJS
- Using AI to generate Splunk Search Processing Language (SPL) from Sigma Rules
- Using AI to improve on previously generated SPL query
Windows Defender Warning: The OTCEP25.zip file contains PowerCat payload that may be flagged as malicious by Windows Defender and other antivirus solutions.
Before extracting or using the contents of OTCEP25.zip, you must whitelist the entire folder where this repository is cloned to prevent Windows Defender from automatically deleting the files.
To whitelist the folder:
- Open Windows Security (Windows Defender)
- Go to Virus & threat protection
- Click on "Manage settings" under Virus & threat protection settings
- Click on "Add or remove exclusions"
- Add the full path to this repository folder as an exclusion
- Review the slides: Open
OTCEP 2025.pdfto understand the workshop concepts and methodology - Whitelist the folder: Follow the security notice above before proceeding
- Extract exercises: Safely extract
OTCEP25.zipto access the practical materials - Follow workshop guidelines: Use the materials responsibly and only in authorized testing environments
These materials are intended for educational and authorized security testing purposes only. Users are responsible for ensuring compliance with all applicable laws and organizational policies when using these tools and techniques.
Conducted by: Attack Simulation Group (ASG)
Event: OTCEP 2025
Workshop: Purple Teaming Workshop