Skip to main content

conops-template

Concept of Operations document creation โ€” executive summary, threat actor profiling, attack narrative, kill chain design, communication plan, deconfliction.

Source facts

Repository
BitterSecurity/Decepticon
Last source activity
October 4, 2026 at 04:59
Detected SKILL.md language
English
Stars
5,666
Forks
1,067

Install options

The review-first prompt is selected by default. You can switch to a direct command or download a local copy.

Review the source files

Read SKILL.md and any companion files shown by SkillsMP before deciding whether to install.

File Explorer
2 files

Showing SKILL.md

SKILL.md
Source instructions ยท Read-only preview
name
conops-template
description
Concept of Operations document creation โ€” executive summary, threat actor profiling, attack narrative, kill chain design, communication plan, deconfliction.
allowed-tools
Read Write Edit
metadata
{"subdomain":"planning","when_to_use":"create CONOPS, design operation, threat model, plan attack","tags":"conops, kill-chain, threat-model, operation-design","upstream_ref":"Soundwave CONOPS template โ€” Concept of Operations document generator"}
# Concept of Operations (CONOPS) Generator The CONOPS bridges the legal RoE and the tactical OPPLAN. It must be **readable by a CEO** while containing **enough detail for operators**. ## When to Use - After `plan/roe.json` exists - User says "create CONOPS", "design the operation", "build threat model" - Before OPPLAN can be generated ## Prerequisites Read `plan/roe.json` first โ€” scope and boundaries constrain the CONOPS. See `../references/schema-quick-reference.md` for the `CONOPS`, `ThreatActor`, `KillChainPhase`, and `DeconflictionPlan` schema fields. ## Workflow ### Step 1: Interview the User Use the tier table and RoE Constraintโ†’Profile Implication table in `threat-profile/SKILL.md` to propose a threat profile. Ask the operator about material choices such as motivation, initial access, operation sequence, and success criteria when these are not already confirmed. **Question 1 โ€” Threat actor tier** (single-select, use `threat-profile` skill for detailed profiling): - a) Opportunistic external attacker (low) - b) Targeted cybercriminal (medium) - c) APT / nation-state (high) - d) Insider threat - e) Custom โ€” describe Use `threat-profile/references/adversary-archetypes.md` to propose **motivation** and **initial access vector**, then confirm them when they affect the operation. **Question 2 โ€” Success criteria** โ€” the crown-jewel / measurable win condition. Required; no default (every engagement needs an explicit end-state). **Agent-drafted, not asked:** - **Attack narrative** โ€” write the 2-3 sentence scenario yourself from RoE scope + tier + success criteria. This is the agent's job, not the operator's homework. - **Ultimate objectives** โ€” derive from success criteria; do not ask as a separate dimension. - ~~Communication plan~~ โ€” REMOVED. `CONOPS.communication_plan` is DEPRECATED (see SCHEMA_REFERENCE in soundwave.md); `ContactPlan` (contact-template skill) owns this now. Asking about it here duplicates a question and writes to a dead field. - **Deconfliction method** โ€” default to standard red-team markers/headers (see `deconfliction-template` reference) unless the operator's RoE/contact answers already flagged a SOC integration endpoint; do not spend a dedicated question on it. ### Step 2: Design Kill Chain Based on RoE scope + threat profile, select applicable phases. See `references/kill-chain-templates.md`. **Key rule**: Don't include phases outside RoE scope. Recon-only engagement โ†’ only `recon` phase. ### Step 3: Generate Documents 1. `plan/conops.json` โ€” matching `CONOPS` schema 2. `plan/deconfliction.json` โ€” matching `DeconflictionPlan` schema ### Step 4: Validate - Executive summary contains no jargon or tool names - Kill chain phases align with RoE scope - All MITRE ATT&CK technique IDs are valid - Timeline has concrete date ranges - At least 2 success criteria defined ## Generation Rules 1. **Executive summary = non-technical** โ€” no tool names, no jargon 2. **Threat actor TTPs must reference MITRE ATT&CK IDs** 3. **Kill chain scoped to RoE** โ€” no exploitation phase in recon-only engagement 4. **Timeline uses absolute dates** โ€” never relative 5. **Deconfliction defaults to standard red-team markers/headers** unless a SOC integration endpoint was already flagged; `communication_plan` is DEPRECATED โ€” write coordination details to `ContactPlan` instead
View on GitHub