orchestration
Atlas orchestrator patterns — delegation, state management, adaptive re-planning, context handoff protocols.
التثبيت باستخدام Codex أو Claude انسخ هذا Prompt والصقه في Codex أو Claude أو مساعد آخر ليراجع صفحة Skill ويثبّتها لك.
القائمة
Atlas orchestrator patterns — delegation, state management, adaptive re-planning, context handoff protocols.
التثبيت باستخدام Codex أو Claude انسخ هذا Prompt والصقه في Codex أو Claude أو مساعد آخر ليراجع صفحة Skill ويثبّتها لك.
استنادا إلى تصنيف SOC المهني
Benchmark mode marker — engagement objective is flag capture. Generic engagement rules apply unchanged.
Exploit Active Directory Certificate Services ESC1 — vulnerable template allows arbitrary SAN, enabling user impersonation up to domain admin.
BloodHound ingestion + canonical Cypher queries for AD attack-path enumeration. Run after collector dumps zip; promotes findings into the knowledge graph.
NetExec (CrackMapExec successor) — unified SMB/LDAP/MSSQL/WinRM/RDP/SSH/FTP/VNC protocol auth + post-auth modules. 200+ modules incl. BloodHound auto-ingest, ESC1-15 scanning, PrintNightmare, LDAP relay.
Active Directory attack lane — BloodHound ingestion, Kerberoasting, ADCS ESC scanning, DCSync, LAPS extraction.
Red team engagement lifecycle management — initiation, phase transitions, go/no-go gates, deconfliction, emergency procedures, completion.
| name | orchestration |
| description | Atlas orchestrator patterns — delegation, state management, adaptive re-planning, context handoff protocols. |
| allowed-tools | Read |
| metadata | {"subdomain":"orchestration","when_to_use":"delegate, orchestrate, next objective, blocked, re-plan, hand off, engagement state, status update, parallel execution","tags":"orchestration, delegation, state-management, re-planning, context-handoff","mitre_attack":[]} |
Every task() delegation MUST include:
recon/, exploit/)task(
description="""
OBJECTIVE: {objective_id} — {title}
PHASE: {phase}
SCOPE:
- IN: {in_scope_targets}
- OUT: {out_of_scope_targets}
CONTEXT FROM PREVIOUS PHASES:
{relevant_findings_summary}
LESSONS LEARNED:
{known_gotchas}
ACCEPTANCE CRITERIA:
- [ ] {criterion_1}
- [ ] {criterion_2}
Save all results to {phase}/
""",
subagent_type="{agent_name}"
)
| Objective Phase | Sub-Agent | When to Use |
|---|---|---|
| Planning | soundwave | Missing roe.json/conops.json/deconfliction.json, or documents need updating |
| Recon | recon | Subdomain/port/service enumeration, OSINT, cloud/web recon |
| Exploitation | exploit | Initial access: SQLi, SSTI, AD attacks, credential exploitation |
| Post-Exploitation | postexploit | After foothold: cred dump, privesc, lateral movement, C2 |
Delegate independent tasks simultaneously for efficiency:
# Independent targets — run in parallel
task(description="Recon subnet 10.0.0.0/24...", subagent_type="recon")
task(description="Recon subnet 10.0.1.0/24...", subagent_type="recon")
# DO NOT parallelize dependent tasks:
# ✗ Exploit before recon completes
# ✗ PostExploit before foothold established
./
├── roe.json # Immutable scope boundaries (read every iteration)
├── conops.json # Operation concept
├── deconfliction.json # Deconfliction identifiers and procedures
├── opplan.json # Objective tracker (update status after each sub-agent)
├── findings/ # Per-finding Markdown files, created lazily
├── lessons_learned.md # Failed approaches + what worked
└── .ralph_state.json # Loop iteration counter + completion flags
passed, blocked, in_progress)findings/FIND-{NNN}.md only when a real finding existsfindings/FIND-*.md entries each iteration (keep only relevant excerpts)Execute this IN ORDER after every recon task() completes. No exceptions.
1. Read recon/SUMMARY.md
├── Missing or empty? → Rule 13 crash protocol (retry once, then BLOCKED)
└── Present → continue
2. Contains RECON_HANDOFF / CRITICAL/HIGH finding / captured session?
├── YES → dispatch task("exploit", ...) IMMEDIATELY (Rule 19)
│ Pass: exact vector, URL, param, session tokens, challenge tags
└── NO (RECON_BUDGET_EXHAUSTED / LOW/INFO only) → continue
3. RECON_BUDGET_EXHAUSTED with zero confirmed vulns?
├── Unvisited surface remains? → focused second recon turn on that surface
└── No unvisited surface → update_objective(status="blocked",
reason="recon exhausted: no confirmed vuln class")
Rule: Step 2 YES has NO exceptions. Do not do "one more recon probe" first.
1. Document failure:
- WHY it failed (specific error, defense mechanism, missing prerequisite)
- WHAT was attempted (tools, techniques, targets)
→ Append to lessons_learned.md
2. Assess alternatives:
- Different attack vector from findings?
- Lower-risk approach?
- Skip and return later after more intel?
3. Decision:
IF alternative exists → delegate new task with adjusted approach
IF prerequisite missing → re-order objectives (e.g., need more recon)
IF no path forward → mark BLOCKED with explanation, move to next objective
The OPPLAN defines priority order, but you may deviate when:
Always document re-ordering decisions in lessons_learned.md.
Report structured status:
| Objective | Phase | Sub-Agent | Result | Key Findings |
|---|---|---|---|---|
| OBJ-001 | Recon | recon | PASSED | 12 subdomains, AD on 10.0.0.5 |
Before each delegation, briefly state:
Maintain running status after each iteration:
Engagement: {name}
Progress: {passed}/{total} objectives
Current: OBJ-003 (Exploit phase)
Blocked: OBJ-002 (WAF blocking SQLi — will retry after credential access)
Next: OBJ-004 (PostExploit — pending OBJ-003 completion)
When all objectives are done: