Content
65%Weight 40%Scale 1-3Reviews the quality of instructions and guidance provided to agents. Good implementation is clear, handles edge cases, and produces reliable results.
The body is a rich, actionable adversary-emulation reference with concrete TTP/tool mappings and specific detection guidance, but it is monolithic and relies on an implicit rather than explicit, checkpointed workflow. Splitting bulk reference material into bundled files and tightening the overlapping intro/campaigns prose would improve the lower dimensions.
Suggestions
Move the exhaustive TTP-by-tactic enumeration, the malware/tooling table, and the source URL list into separate reference files (e.g., TTPS.md, TOOLING.md, SOURCES.md) linked from a concise overview, improving progressive disclosure.
Reframe the 'Emulation guidance' bullets as a numbered, phase-sequenced runbook with explicit validation checkpoints (e.g., verify payload executes and beacons before moving to persistence) to lift workflow clarity.
Trim the introductory paragraph and 'Notable campaigns' narratives to avoid restating attribution and targeting already detailed in dedicated sections.
| Dimension | Reasoning | Score |
|---|---|---|
Conciseness | The body is dense and specific with no basic-concept fluff, but the intro paragraph (line 14) and the 'Notable campaigns' narratives restate material expanded in later sections and could be tightened. | 2 / 3 |
Actionability | The 'Emulation guidance' section gives concrete, specific instructions with real parameters (lookalike Google/Naver/Kakao pages, GetAsyncKeyState at 50ms, 10-minute exfil intervals, specific staging paths and scheduled-task names), and the detection section lists specific hunt rules, satisfying actionable instruction-only guidance. | 3 / 3 |
Workflow Clarity | The emulation bullets follow an implicit kill-chain order (initial access → persistence → C2 → collection → exfiltration), but there is no explicit numbered runbook and no validation checkpoints between phases. | 2 / 3 |
Progressive Disclosure | The document is well-sectioned with clear headers and easy navigation, but it is a monolithic ~230-line single file with no bundle references, leaving bulk reference material (full TTP enumeration, malware table, 20+ source URLs) inline rather than split out. | 2 / 3 |
Total | 9 / 12 Passed |