Engagement documentation is an extension of campaign planning where ideas and thoughts of campaign planning are officially documented. In this context, the term โ€œdocumentโ€ can be deceiving as some plans do not require proper documentation and can be as simple as an email; this will be covered later in this task.

In this task, we will cover a technical overview of the contents of each campaign plan prior to looking at the plans and documents themselves in upcoming tasks.

Engagement Plan:

ComponentPurpose
CONOPS (Concept of Operations)Non-technically written overview of how the red team meets client objectives and target the client.
Resource planIncludes timelines and information required for the red team to be successfulโ€”any resource requirements: personnel, hardware, cloud requirements.

Operations Plan:

ComponentPurpose
PersonnelInformation on employee requirements.
Stopping conditionsHow and why should the red team stop during the engagement.
RoE (optional)-
Technical requirementsWhat knowledge will the red team need to be successful.

Mission Plan:

ComponentPurpose
Command playbooks (optional)Exact commands and tools to run, including when, why, and how. Commonly seen in larger teams with many operators at varying skill levels.
Execution timesTimes to begin stages of engagement. Can optionally include exact times to execute tools and commands.
Responsibilities/rolesWho does what, when.

Remediation Plan (optional):

ComponentPurpose
ReportSummary of engagement details and report of findings.
Remediation/consultationHow will the client remediate findings? It can be included in the report or discussed in a meeting between the client and the red team.