Red Team OPSEC: High-Stealth Tradecraft and Controls
A kill-chain-ordered taxonomy of 127 malware techniques rated by detection resistance, mapped to the defensive controls that degrade each OPSEC tier, and an argument that the lowest-OPSEC technique achieving the objective is usually the correct one in a red team engagement.
The Missing Axis
Most technique references answer what exists. Very few answer how well a given technique survives contact with a modern EDR.
The second question is the one that matters in an engagement. Two techniques can achieve the same objective with detection probabilities an order of magnitude apart. The difference is rarely the technique itself; it is the telemetry it produces, the memory it touches, and the trust level it runs in.
OPSEC, in this context, is a design constraint rather than a score.
This article lays out a kill-chain-ordered taxonomy of 127 malware techniques, rated by detection resistance against current (late 2026) endpoint, cloud, and AI telemetry. It then maps those tiers to the controls that actually degrade them.
In a red team engagement, the lowest-OPSEC technique that achieves the objective is usually the correct one.
If a ★★☆☆☆ technique works, that is the finding. The client’s controls failed against commodity tradecraft. High-OPSEC techniques answer a different question: if the adversary is competent, does the control still hold?
How We Rate OPSEC
| Rating | Meaning |
|---|---|
| ★★★★★ | Structurally stealthy. Rarely detected even with mature telemetry. |
| ★★★★☆ | High stealth. Detected only by well-tuned, correlated detections. |
| ★★★☆☆ | Moderate. Commonly detected in mature environments. |
| ★★☆☆☆ | Low. Baseline-detected by most EDRs. |
| ★☆☆☆☆ | Trivial. Instant flag on modern EDR. |
Two clarifications apply here.
OPSEC is not operator tradecraft. A ★★★★★ technique in the hands of a careless operator still leaks attribution through build paths, reused XOR keys, default accounts, and clustered timestamps. Structural OPSEC and operator OPSEC are orthogonal axes.
Ratings decay. Reflective DLL injection was ★★★★★ in 2022. It is ★★★☆☆ today. Every tier in this article is relative to current detection maturity and will move.

2x2 matrix: Structural Stealth (x-axis) vs. Operational Stealth (y-axis), with technique clusters plotted.
The Taxonomy by Kill-Chain Tactic
1. Initial Access / Delivery
Delivery is the most commoditized and most monitored phase. Email gateways and download inspection have matured, so only the highest-trust paths remain top-tier.
| Technique | OPSEC | Notes |
|---|---|---|
| Supply chain compromise | ★★★★★ | Signed binary, trusted update path. |
| Signed binary proxy / LOLBins | ★★★★★ | msiexec, regsvr32, rundll32 with signed DLL. |
| Trojanised legitimate installer | ★★★★☆ | Signed outer, unsigned payload inside. |
| Spearphish → macro-less (LNK/ISO/OneNote) | ★★★★☆ | No Office macros; harder to detect statically. |
| DLL sideloading | ★★★★☆ | Signed host loads unsigned DLL. |
| IPFS-hosted payload retrieval | ★★★★☆ | Fake JPEGs on IPFS; resists takedown, bypasses domain reputation. |
| Multi-cloud fragment hosting | ★★★★☆ | Payload split across AWS S3, Azure Blob, GCS. |
| HTML smuggling | ★★★☆☆ | Payload assembled in browser; bypasses email gateways. |
| AutoIt wrapper chains | ★★★☆☆ | Three-layer AutoIt wrapper; XOR-encrypted intermediate payload. |
| Office macro (AMSI-bypassed) | ★★★☆☆ | Heavily signatured category. |
| Direct download via certutil/bitsadmin | ★★☆☆☆ | LOLBin but well-detected behaviorally. |
| Dropper EXE | ★★☆☆☆ | Easy to scan; needs strong obfuscation. |
Engagement note: delivery choice is usually dictated by the rules of engagement and the client’s actual exposure surface, not by OPSEC alone. A ★★★★★ supply chain path is meaningless if the engagement scope is a single workstation.
2. Execution
2.1 Execution Flow
| Technique | OPSEC | Notes |
|---|---|---|
| Call stack spoofing | ★★★★★ | Spoofed return chain, legitimate-looking stack. |
| Moonwalk++ | ★★★★★ | Bypasses CALL validation, module resolution, stack unwinding. |
| Indirect syscalls | ★★★★★ | Syscall from ntdll address range; bypasses userland hooks. |
| Direct syscalls | ★★★★☆ | Bypasses userland hooks but syscall from non-ntdll range. |
| Heaven’s Gate (32→64) | ★★★★☆ | Bypasses 32-bit hooks; unusual in 64-bit targets. |
| Fiber execution | ★★★★☆ | Shellcode runs in fiber; unusual execution context. |
| APC injection (early bird) | ★★★★☆ | Queued before main thread starts; clean call stack. |
| Thread hijacking | ★★★☆☆ | Suspend, modify RIP, resume; detectable via thread state. |
| CreateRemoteThread | ★★☆☆☆ | Classic, well-monitored. |
2.2 Process Injection
| Technique | OPSEC | Notes |
|---|---|---|
| Process Parameter Poisoning (P³) | ★★★★★ | No WriteProcessMemory, no VirtualAllocEx, no remote thread. |
| Module stomping into target | ★★★★★ | Target process, MEM_IMAGE, no private alloc. |
| Early bird APC | ★★★★☆ | Inject before main thread runs; clean context. |
| NtQueueApcThread-ex | ★★★★☆ | No CreateRemoteThread; kernel APC path. |
| Mapping injection (shared section) | ★★★★☆ | NtCreateSection + NtMapViewOfSection; no WriteProcessMemory. |
| TLS injection (CANONSTAGER) | ★★★★☆ | Uses TLS array; executes before entry point. |
| PoolParty / SharpParty | ★★★★☆ | Manipulates Windows thread pool worker factory. |
| SetWindowsHookEx | ★★★☆☆ | Forces DLL load into target; noisy. |
| WriteProcessMemory + CreateRemoteThread | ★★☆☆☆ | Classic, heavily monitored. |

Diagram of the canonical injection triad (allocate remote memory, write payload, create remote thread) with three bypass techniques overlaid, each eliminating a different leg: P³ (no allocate, no write, no thread), module stomping (writes to image-backed memory), TLS injection (no thread).
2.3 Shellcode Placement
| Technique | OPSEC | Notes |
|---|---|---|
| Stomped system DLL (MEM_IMAGE) | ★★★★★ | Backed by DLL path; VirtualQuery shows legit module. |
| Stomped copy-on-write DLL (NtCreateSection) | ★★★★★ | Private copy, still reports as image-backed. |
| VBS enclave (VTL1) shellcode placement | ★★★★★ | Shellcode hidden in VTL1; inaccessible to VTL0 EDR. |
| Spoofed section + nano-entropy pulses | ★★★★★ | No new thread; entropy signature ~0.5 bits/byte. |
| Stack (return-oriented) placement | ★★★★☆ | No alloc needed; size-constrained. |
.text section of loaded PE | ★★★★☆ | Overwrite unused padding/cave in existing module. |
| Heap of legitimate process | ★★★☆☆ | MEM_PRIVATE but no RX; needs separate exec primitive. |
| Private RW→RX alloc | ★★☆☆☆ | MEM_PRIVATE + EXECUTE, behavioral flag. |
| Private RWX alloc | ★☆☆☆☆ | Instant detection on modern EDR. |
3. Persistence
Persistence is academically under-studied relative to its operational use. A mid-2026 survey documented roughly 72 distinct Windows persistence mechanisms, yet only about 55% of malware samples are actually persistent.
| Technique | OPSEC | Notes |
|---|---|---|
| COM hijack (HKCU, no elevation) | ★★★★★ | No new files in System32, user-writable key. |
| Mandatory User Profile abuse (NTUSER.MAN) | ★★★★★ | Tampered hive loads into HKCU at logon; bypasses registry-API monitoring. |
| Bootkit / UEFI implant | ★★★★★ | Survives OS reinstall; very high complexity. |
| WMI subscription | ★★★★☆ | Fileless, survives reboots, runs as SYSTEM. |
| Scheduled task (XML, hidden) | ★★★★☆ | Blend with legitimate tasks, randomise name. |
| DLL sideload persistence | ★★★★☆ | Drop DLL next to auto-launched signed binary. |
| AMSI provider persistence | ★★★★☆ | Malicious AMSI provider DLL as COM server. |
| AppInit_DLLs | ★★★☆☆ | Loads into every GUI process; noisy. |
| Run key | ★★★☆☆ | Well-monitored but still works if payload is clean. |
| Service installation | ★★☆☆☆ | Requires elevation; heavily monitored. |
Engagement note: persistence is often the difference between a point-in-time finding and a sustained dwell-time assessment. If the objective is “can they stay,” persistence OPSEC is the central concern.
4. Privilege Escalation
| Technique | OPSEC | Notes |
|---|---|---|
| Token impersonation (existing token) | ★★★★★ | No new process, no exploit. |
| Named pipe impersonation | ★★★★☆ | Classic, still works, needs service interaction. |
| UAC bypass (CMSTPLUA/fodhelper) | ★★★★☆ | No prompt, auto-elevated COM object. |
| SeImpersonatePrivilege (potato variants) | ★★★★☆ | From service context; JuicyPotato still seen. |
| DLL hijack in privileged process | ★★★★☆ | Silent if DLL is clean. |
| SMB arbitrary port NTLM reflection | ★★★★☆ | Local NTLM reflection via alternative TCP port. |
| BYOVD (Bring Your Own Vulnerable Driver) | ★★★★☆ | Commodity EDR-killer; 54 tools, 35 signed drivers. |
| Kernel exploit | ★★★☆☆ | Noisy, crash risk, patch-dependent. |
| ShieldBreak (Defender LPE) | ★★★☆☆ | CVE-2026-69414; local user to SYSTEM on patched Windows. |
Sidebar: BYOVD’s shift. 2026 saw a niche technique become a commodity EDR-killer. Criminal marketplaces advertised BYOVD source code from late 2025, and ransomware operators adopted public PoCs within days. The technique is rated ★★★★☆ not because it is structurally undetectable, but because the supply of signed vulnerable drivers makes it operationally reliable.
5. Defense Evasion
5.1 Memory Evasion
| Technique | OPSEC | Notes |
|---|---|---|
| Module stomping | ★★★★★ | Overwrite .text of sacrificial DLL; MEM_IMAGE-backed. |
| Module overloading | ★★★★★ | Map fresh DLL copy, stomp it; image-backed. |
| Mirage (VBS enclave shellcode hiding) | ★★★★★ | Hides shellcode in VTL1; VTL0 EDR has limited visibility. |
| Sleep obfuscation (Ekko/Foliage/Cronos/Hypnus) | ★★★★★ | Encrypt payload during sleep windows. |
| Memory fluctuation (nano-entropy pulses) | ★★★★★ | Re-encryption drops entropy to ~0.5 bits/byte. |
| Phantom DLL hollowing | ★★★★☆ | Map DLL never loaded, hollow it. |
| Transacted hollowing | ★★★★☆ | TxF transaction hides writes from scanners. |
| Process hollowing | ★★★☆☆ | Unmaps legit image; VirtualQuery shows no path. |
| Reflective DLL injection | ★★★☆☆ | MEM_PRIVATE + RX, no backing; detectable. |
| Classic shellcode (VirtualAlloc RWX) | ★☆☆☆☆ | Instant flag on modern EDR. |
5.2 Hooks / Scanning Evasion
| Technique | OPSEC | Notes |
|---|---|---|
| Unhook ntdll (fresh map from disk) | ★★★★★ | Replace hooked ntdll with clean copy from file. |
| Encrypted payload at rest | ★★★★★ | No static signatures until execution. |
| EDR-Freeze (WerFaultSecure abuse) | ★★★★★ | Freezes EDR without terminating it. |
| Unhook via KnownDlls section | ★★★★☆ | Map from \KnownDlls\ntdll.dll, always clean. |
| AMSI patching | ★★★★☆ | Patch AmsiScanBuffer to return clean. |
| ETW patching | ★★★★☆ | Patch EtwEventWrite to suppress telemetry. |
| Sleep + jitter before exec | ★★★★☆ | Evades scan-on-execute timing heuristics. |
| PPL / handle stripping | ★★★☆☆ | Prevent EDR from opening handles to your process. |
6. Credential Access
| Technique | OPSEC | Notes |
|---|---|---|
| LSASS handle via existing handle duplication | ★★★★★ | No direct OpenProcess on lsass. |
| MiniDumpWriteDump via comsvcs.dll | ★★★★☆ | LOLBin; signed binary does the dump. |
| DCSync (if DA) | ★★★★☆ | No touching LSASS; replication protocol. |
| LSA secrets from registry | ★★★★☆ | SECURITY hive; offline extraction. |
| Kerberoasting | ★★★★☆ | Legitimate LDAP + TGS requests; hard to detect. |
| WerFaultSecure LSASS dump (PPL bypass) | ★★★★☆ | PPL WinTcb process reads LSASS even with RunAsPPL. |
| Internal Monologue (NTLM extraction) | ★★★★☆ | Recovers NTLM hashes without touching LSASS. |
| Netfilter / Password Filter / SSP DLL | ★★★★☆ | Captures cleartext before hashing. |
| Skeleton Key (domain controller) | ★★★☆☆ | Injects into LSASS on DC; heavily monitored. |
| Direct LSASS dump (ProcDump) | ★★☆☆☆ | Well-detected; LSASS access triggers alerts. |
| Mimikatz sekurlsa::logonpasswords | ★★☆☆☆ | Heavily signatured. |
This section shows the OPSEC spectrum within a single tactic most clearly. Handle duplication sits at ★★★★★, direct LSASS dumping at ★★☆☆☆, and both achieve the same objective.
7. Command and Control
| Technique | OPSEC | Notes |
|---|---|---|
| HTTPS over CDN (domain fronting) | ★★★★★ | Traffic looks like legitimate CDN. |
| Blockchain dead drops (EtherHiding) | ★★★★★ | C2 pointers in smart contracts; cannot be seized. |
| DNS over HTTPS (DoH) C2 | ★★★★★ | Encoded in DNS TXT records; exits via HTTPS. |
| Slack/Teams/OneDrive C2 | ★★★★★ | Legitimate cloud services, usually whitelisted. |
| AI-powered invisible C2 | ★★★★★ | AI shapes traffic/timing/encoding to mimic legitimate apps. |
| ICMP tunneling | ★★★★☆ | Often uninspected; needs raw socket. |
| HTTPS with valid cert + domain aging | ★★★★☆ | Aged domain, LE cert, mimics legit traffic. |
| Custom protocol over 443 | ★★★☆☆ | TLS but unusual JA3/JARM fingerprint. |
| Raw TCP reverse shell | ★★☆☆☆ | Unencrypted; easy to detect/block. |
| Meterpreter default | ★★☆☆☆ | Signatured protocol + shellcode. |
Structural shift. The move from domain-based C2 to chain-based C2, storing pointers in smart contracts rather than resolvable domains, decouples coordination from infrastructure defenders can seize. The malware itself is not more capable. The C2 layer is simply no longer takedown-able.
8. Cloud
Cloud OPSEC differs from endpoint OPSEC in one fundamental way: every action is an API call, and most clouds log API calls by default. CloudTrail, Azure Activity Log, GCP Audit Logs, and the M365 Unified Audit Log capture activity automatically. The detection question is not whether telemetry exists, but whether anyone is correlating it. Most estates forward cloud logs to a SIEM and never build detection logic on top of them.
A small number of techniques dominate real cloud intrusions. The table below covers the ones that matter most in practice, rated against a mature cloud logging pipeline with alerting.
| Technique | Phase | OPSEC | Notes |
|---|---|---|---|
| Valid Accounts (Cloud Accounts) | Initial Access | ★★★★★ | Legitimate credentials; blends with normal user activity. |
| Trusted Relationship | Initial Access | ★★★★☆ | Partner or vendor access; legitimate path into the tenant. |
| Additional Cloud Credentials | Persistence | ★★★★★ | Long-lived access keys; rarely reviewed after creation. |
| Modify Authentication Process (MFA) | Persistence | ★★★★★ | Registers attacker MFA method; invisible to the victim. |
| Implant Internal Image | Persistence | ★★★★☆ | Backdoored AMI or container; evades image scanning. |
| Additional Cloud Roles | Privilege Escalation | ★★★★★ | Role assignment abuse; blends with legitimate admin changes. |
| Cloud Instance Metadata API | Credential Access | ★★★★★ | Steals instance role credentials; no CloudTrail entry for the theft itself. |
| Cloud Secrets Management Stores | Credential Access | ★★★★★ | Vault secret reads; logged but rarely alerted. |
| Forge Web Credentials (SAML Tokens) | Credential Access | ★★★★★ | Golden SAML; no authentication event on the target IdP. |
| Unused/Unsupported Cloud Regions | Stealth | ★★★★★ | Operates in regions without logging or monitoring. |
| Hide Artifacts (Email Hiding Rules) | Stealth | ★★★★★ | Hides rules from the victim; no visible artifact. |
| Use Alternate Authentication Material | Lateral Movement | ★★★★☆ | Token or cookie reuse; evades password-based detection. |
| Transfer Data to Cloud Account | Exfiltration | ★★★★★ | Cross-account transfer; blends with normal data movement. |
| Resource Hijacking (Compute Hijacking) | Impact | ★★★★☆ | Crypto mining; detected via cost anomaly more than security. |
Container escape techniques (Docker Desktop, runc, NVIDIA Container Toolkit, Windows CExecSvc) are host-level primitives rather than cloud-API-level techniques. They do not map cleanly onto the MITRE ATT&CK Cloud Matrix, and are covered under the endpoint taxonomy where Escape to Host (T1611) applies.
Engagement note: cloud OPSEC is dominated by identity. The highest-rated techniques above all involve either legitimate credentials, native API calls, or trust relationships the environment already accepts. Detection investment should concentrate on identity-layer anomalies, not network-layer artifacts.
Detection note: cloud logs are high volume and low signal by default. A mature pipeline requires baseline modeling for each identity and service principal, alerting on deviations from that baseline rather than on individual API calls. The techniques rated ★★★★★ here are not invisible; they are indistinguishable from legitimate activity without that baseline.
9. AI / LLM-Driven Techniques
Two shifts are happening at once. First, AI is being used as an attack tool: LLM-driven metamorphic evasion, autonomous agent orchestration, and AI-assisted exploit development. Second, AI-enabled systems are themselves an attack surface: prompt injection, model poisoning, and RAG credential harvesting. Both matter for red team engagements, but they require different detection and control strategies.
A small number of MITRE ATLAS techniques dominate real-world AI-enabled intrusions. The table below covers the ones that matter most in practice, rated against a mature AI telemetry pipeline with alerting.
| Technique | ATLAS Phase | OPSEC | Notes |
|---|---|---|---|
| AI Supply Chain Compromise | Initial Access | ★★★★★ | Compromised model, dataset, or agent tool; trusted path into the environment. |
| LLM Prompt Injection (Indirect) | Execution | ★★★★★ | Payload delivered through retrieved content; no direct user interaction. |
| RAG Poisoning | Persistence | ★★★★★ | Poisoned retrieval content persists and influences every query that hits it. |
| Insert Backdoor Trigger | Persistence | ★★★★★ | Model-level backdoor that activates on a specific input pattern. |
| Poison AI Model | Persistence | ★★★★★ | Corrupts model weights or training data; survives redeployment. |
| AI Agent Tool Credential Harvesting | Credential Access | ★★★★★ | Extracts credentials from agent tool configurations. |
| Discover LLM System Information | Discovery | ★★★★★ | Extracts system prompts and model metadata. |
| Extract LLM System Prompt | Exfiltration | ★★★★★ | Recovers the system prompt; reveals guardrails and business logic. |
| Exfiltration via AI Inference API | Exfiltration | ★★★★★ | Encodes data in model queries; blends with normal API traffic. |
| Cost Harvesting (Excessive Queries) | Impact | ★★★★★ | Drives compute cost without affecting availability; financial impact. |
| Erode AI Model Integrity | Impact | ★★★★★ | Gradual degradation of model outputs; hard to attribute. |
| Autonomous Attack Orchestration | AI Attack Adaptation | ★★★★★ | Agent-driven attack chains; adapts without human intervention. |
| Autonomous Attack-Path Adaptation | AI Attack Adaptation | ★★★★★ | Agent selects alternate paths when blocked; bypasses static playbooks. |
| LLM Jailbreak | Privilege Escalation | ★★★★☆ | Bypasses guardrails; heavily researched and increasingly detected. |
| Escape to Host | Privilege Escalation | ★★★★☆ | AI agent escapes its sandbox; container or VM escape primitives apply. |
| Deepfake-Assisted Phishing | Initial Access | ★★★★☆ | Video or voice impersonation; bypasses awareness training. |
Engagement note: AI-specific techniques rarely operate in isolation. Prompt injection is a delivery mechanism; the objective is usually credential access or data exfiltration. RAG poisoning and model backdoors are persistence mechanisms that survive redeployment. When scoping an engagement against an AI-enabled target, treat the model and its retrieval pipeline as a data store with its own trust boundary, not as a black box.
Detection note: AI telemetry is immature. Most organizations log inference API calls but not prompt content, retrieval sources, or agent tool invocations. Detection requires instrumenting the AI pipeline itself, not just the cloud API layer. The techniques rated ★★★★★ here are not invisible; they are simply not logged at the fidelity required to distinguish them from normal operation.
What the Hierarchy Actually Tells Us
The top tier has moved. The highest-OPSEC techniques are no longer inject-and-execute primitives. They either avoid the detection triad structurally, hide in trust levels EDR cannot inspect (VTL1), or move C2 into infrastructure that cannot be seized.
The canonical injection triad is obsolete as a detection model. P³, TLS injection, module stomping, and Mirage each eliminate a different leg. Detection built on the triad’s co-occurrence will miss all four.
Detection logic itself is now a target. Moonwalk++ was built explicitly against published detection guidance. EDR-Freeze leaves the sensor running but unconscious, defeating both termination alerts and heartbeat monitoring.
Structural OPSEC and operator OPSEC diverge in practice. Formbook’s IPFS/AutoIt chain was structurally high-OPSEC but leaked build paths, default accounts, clustered timestamps, and static XOR key reuse. The technique was stealthy; the operator was not.
Cloud and AI extend the taxonomy, they do not replace it. Cloud techniques sit almost entirely in the identity layer. AI techniques sit almost entirely outside current telemetry. Both are additions to the classic endpoint kill chain, not substitutes for it.

Bar chart: tier distribution across all 127 techniques. 52 at ★★★★★, 48 at ★★★★☆, 15 at ★★★☆☆, 10 at ★★☆☆☆, 2 at ★☆☆☆☆.
Defensive Posture: The Controls That Break Each Tier
The taxonomy is only actionable if it maps to controls a client can implement.
Network Segregation and Microsegmentation
Degrades: C2, lateral movement, network-protocol credential access.
East-west inspection, VLAN/segment design that blocks SMB between workstation tiers, restricted RPC, and default-deny between zones. Segregation is the single highest-leverage control against post-compromise movement. It converts a single foothold into a contained one.
Egress Filtering
Degrades: C2 across all tiers.
Default-deny egress, DNS filtering, blocking direct-to-IP, blocking outbound on uncommon ports. To catch chain-based C2, monitor outbound JSON-RPC to public blockchain nodes rather than blocking blockchain traffic wholesale. Cloud egress controls and cross-account transfer monitoring also degrade cloud exfiltration.
Privileged Access Management
Degrades: privilege escalation, credential access, cloud identity abuse.
Tiered admin model, just-in-time elevation, credential vaulting, removal of standing Domain Admin, Protected Users group, LSA Protection, Credential Guard. In cloud environments, this extends to conditional access policies, workload identity federation, short-lived credentials, and elimination of long-lived access keys. PAM does not stop credential theft. It limits what stolen credentials unlock.
Endpoint Protection Tuning (EDR / XDR)
Degrades: memory evasion, injection, execution flow, hooks/scanning evasion.
Memory scanning at meaningful intervals, ASR rules, blocking unsigned DLL sideloading, kernel-level visibility, tamper protection, driver blocklisting for BYOVD, and monitoring for WerFaultSecure abuse and unexpected Offreg.dll loads.
SIEM and Detection Engineering
Degrades: everything, but only through correlation.
Process lineage over process names. Command-line anomaly detection. Call stack integrity monitoring. Memory protection change events. Registry hive file creation outside expected paths. Scheduled task XML inspection. ETW patch detection. Cloud baseline modeling for each identity and service principal. AI pipeline instrumentation for prompt and retrieval content.
Application Control
Degrades: delivery, execution, persistence.
WDAC, AppLocker, constraining script interpreters, and blocking known LOLBin abuse patterns.
Identity Controls
Degrades: credential access, privilege escalation, cloud persistence.
Phishing-resistant MFA, disabling NTLM where possible, gMSA for service accounts, and monitoring for Internal Monologue patterns. In cloud environments, this extends to disabling legacy authentication protocols, enforcing conditional access, and monitoring for MFA method registration events.

Control-to-tier heatmap. Rows: controls. Columns: kill-chain tactics. Cells colored by the highest OPSEC tier the control meaningfully degrades. Cloud is dominated by identity-layer controls; AI/LLM remains the widest gap.
Detection Gaps
No combination of the controls above reliably catches the following today:
- VTL1 abuse (Mirage-class)
- Blockchain dead drops
- LLM-generated metamorphic variants
- P³ injection
- Moonwalk++-class stack spoofing
- Indirect prompt injection against AI pipelines
- Cloud identity abuse via long-lived credentials in unmonitored regions
This list maps coverage rather than capability, and is the section most clients find actionable.
Engagement Implications
Start low, escalate deliberately. Begin with the lowest-OPSEC technique that could plausibly achieve the objective. If it works, the finding is stronger, not weaker. Escalate only when a lower tier is blocked, not when it is detected.
Separate “detected” from “blocked.” A ★★☆☆☆ technique that generates an alert but completes the objective is a detection-without-response finding. In practice, that finding is often more valuable than a stealth success.
Match tier to engagement question. Control validation uses low-to-mid OPSEC for broad coverage. Adversary emulation mirrors the target actor’s observed tier. Purple team walks the ladder deliberately and measures detection at each rung.
Report structural and operational failures separately. A control that fails against ★★☆☆☆ tradecraft is a posture gap. One that fails against ★★★★★ tradecraft is a detection engineering gap. These require different remediation owners.
Time-box OPSEC investment. Every tier increase costs engagement time. Document when the extra effort produced a materially different finding, and when it did not.
Closing
OPSEC is a spectrum, not a binary, and it is only meaningful when mapped to a specific defensive posture. The highest-OPSEC techniques today are not the ones most engagements need, but they define the ceiling of what current controls can see.
The controls that matter most are unglamorous: segregation, egress control, PAM, tuned EDR, identity hardening, and a SIEM with actual correlation logic. AI-assisted evasion and trust-level abuse are widening the gap between what mature estates can detect and what commodity estates can.
The goal of a red team engagement is not to be undetectable. It is to find out which controls fail, at which tier, and why.
Tower Vector publishes technical red team research. For engagement inquiries, contact us.
Related research:
References
-
MITRE ATT&CK Enterprise Matrix: Canonical adversary tactic and technique knowledge base.
https://attack.mitre.org/ -
Process Injection (T1055): Parent technique covering the injection triad and its sub-techniques.
https://attack.mitre.org/techniques/T1055/ -
OS Credential Dumping (T1003): Credential access, including LSASS memory extraction.
https://attack.mitre.org/techniques/T1003/ -
Impair Defenses (T1562): AMSI patching, ETW patching, and related evasion techniques.
https://attack.mitre.org/techniques/T1562/ -
Exploitation for Privilege Escalation (T1068): Covers BYOVD and kernel exploits.
https://attack.mitre.org/techniques/T1068/ -
Escape to Host (T1611): Container escape and virtualization breakout.
https://attack.mitre.org/techniques/T1611/ -
Web Service: Dead Drop Resolver (T1102.001): Maps to blockchain-based C2 coordination.
https://attack.mitre.org/techniques/T1102/001/ -
MITRE ATT&CK Cloud Matrix: Cloud platform tactics and techniques across Office Suite, Identity Provider, SaaS, and IaaS.
https://attack.mitre.org/matrices/enterprise/cloud/ -
MITRE ATT&CK Navigator: Compare technique coverage against defensive controls.
https://mitre-attack.github.io/attack-navigator/ -
MITRE ATLAS: Adversarial threat landscape for AI and LLM systems.
https://atlas.mitre.org/ -
Atomic Red Team: Test cases for validating detection coverage.
https://www.atomicredteam.io/ -
Sigma HQ: Vendor-neutral detection rules mapped to ATT&CK.
https://github.com/SigmaHQ/sigma -
Elastic Detection Rules: Open detection rules with ATT&CK mappings.
https://github.com/elastic/detection-rules