← Projects
Private platform · never public

Emulate the attack. Measure the defense.

GothamCity is my private adversary-emulation platform. It turns threat profiles and ATT&CK techniques into controlled campaigns, keeps execution context visible, and shows exactly where defensive coverage held—or where the operator still has a blind spot.

500ATT&CK techniques indexed
277Atomic mappings available
56LOLBAS-enriched techniques
Operator console

Coverage that explains itself.

This synthetic preview mirrors a local, agent-free validation run. All fourteen techniques completed in simulation; nine were marked as detected, leaving five explicit gaps for review.

GothamCity / coverageRansomware readiness · safe simulationno live agent
Techniques14executed
Detected09defensive signals
Blind spots05operator review
Detection rate64%synthetic result
Kill-chain coverageDetection by tactic
completed simulation
Execution100%
covered
Credential access67%
review remaining evidence
Discovery67%
review remaining evidence
Collection100%
covered
Impact0%
detection gap
simulation is evidence context—not a live execution claimsynthetic labels · target-free dataset
Verified product surfaces

Real screens. Sanitized data.

These images were captured from the local Docker build. The account area and environment details are excluded; the remaining content uses built-in threat profiles and a target-free simulation.

Campaign lifecycle

Plan, execute, challenge, repeat.

GothamCity keeps campaign composition and defensive interpretation in one loop, without pretending that a queued command and a verified endpoint execution are the same event.

01

Compose with context

Start from actor profiles or focused templates, then narrow the plan by platform, tactic, prerequisites, cleanup needs, and risk—not by a flat list of technique IDs.

02

Make execution honest

Staged, simulated, queued, dispatched, and agent-executed states stay distinct. The console shows the assigned agent and execution mode so a simulation never masquerades as endpoint proof.

03

Measure what defended

Results roll into tactic-level coverage, ATT&CK Navigator output, Sigma-oriented analysis, and a repeatable retest path. Undetected activity remains a named gap, not a buried log line.

Execution boundary

A control plane with visible limits.

The platform is designed for authorized labs and purple-team work. Its public page describes the decision model while operational components remain private.

GothamCity owns

  • Threat-profile, template, and technique-based campaign planning
  • Atomic Red Team and LOLBAS execution context with cleanup metadata
  • Explicit simulated-versus-live agent state and campaign history
  • Detection coverage, blind-spot review, reporting, and retest workflow

GothamCity does not claim

  • A simulated result proves a command ran on a real endpoint
  • An ATT&CK mapping alone proves detection quality or impact
  • A registered agent authorizes activity outside an approved scope
  • The private repository, deployment, or operator payloads are public