Skip to content

UI & Navigation

Arpan Sarkar edited this page Jun 27, 2025 · 9 revisions

Halberd provides four main views for conducting security testing and analysis in cloud environments. Each view serves a distinct purpose in your security testing workflow:

  1. Attack
  2. Automator
  3. Analyse
  4. Agent

Attack View

The core testing interface where you execute individual attack techniques against cloud targets.

Key Features:

  • Multi-Cloud Support: Dedicated tabs for Entra ID, M365, Azure, and AWS
  • MITRE ATT&CK Integration: Techniques organized by MITRE tactics
  • Dynamic Access Management: Real-time access status and credentials management
  • Flexible Configuration: Customizable parameters for each technique
  • Immediate Feedback: Structured output display with formatted results
  • Playbook Integration: Add techniques directly to playbooks for automation

Common Uses:

  • Running individual attack techniques
  • Testing specific security controls
  • Exploratory security testing
  • Validating security configurations

Automator View

The automation hub for creating and managing attack sequences through playbooks.

Key Features:

  • Visual Playbook Builder: Graphical creation of attack sequences
  • Scheduling: Automated execution of playbooks
  • Import/Export: Share and reuse playbooks
  • Execution Controls: Manage playbook runs and view results
  • Step Configuration: Customize each step's parameters and timing

Common Uses:

  • Automating complex attack chains
  • Red team engagement automation
  • Regular security testing
  • Incident simulation

Analyse View

A comprehensive dashboard for analyzing testing results and gaining insights.

Key Features:

  • Attack Timeline: Chronological view of all executions
  • Success Metrics: Analysis of technique success rates
  • Coverage Analysis: Understanding of testing coverage
  • MITRE Mapping: Alignment with MITRE tactics and techniques
  • Export Capabilities: Generate detailed reports

Common Uses:

  • Reviewing testing coverage
  • Identifying successful attack paths
  • Generating reports
  • Tracking testing progress

Agent View

An advanced AI agent that allows red teaming in natural language.

Key Features:

  • Discover, configure & execute techniques: Describe attack objective and discover techniques. Ask agent to configure and execute techniques
  • Plan attacks: Create executable test plans directly from natural language
  • Document support: Understand new attacks directly from a document and automatically create Halberd playbooks from it
  • Analyze and report: Understand technique outputs better and generate custom reports using AI

Remember: Always ensure you have proper authorization before conducting any security testing in cloud environments.

Clone this wiki locally