Configurable role profile
Translate attack insight into durable product improvement.
Orange Team pathways bridge offensive discovery and engineering remediation. Practitioners analyse how an exploit worked, establish root cause rather than symptom, express the missing property as a requirement, guide a secure redesign, and verify that the change holds under retest. The measure of success is that the defect class does not return — so the work ends with a regression test and an updated control, not a closed ticket.
CLIP · Orange Team role profile
Illustrative view- 01 · Mission outcomeBridge offensive discovery and engineering remediation so weaknesses do not recur.
- 02 · CompetenciesExploit analysis · Root cause · Requirements · Secure redesign
- 03 · Exercise activityExploit-to-fix workshop
- 04 · EvidenceDefect trace from exploit to affected component
Team-colour terminology varies by organization
Mission intent
The role's purpose and its boundaries.
Bridge offensive discovery and engineering remediation so weaknesses do not recur.
Core competencies
What this pathway develops.
Competencies are versioned and mapped to organizational, NICE, relevant SKKNI or custom frameworks without duplicating the underlying evidence.
- 01Exploit analysis
- 02Root cause
- 03Requirements
- 04Secure redesign
- 05Verification
- 06Recurrence prevention
Learning pathway
Progressive difficulty, evidence at every step.
- 01FoundationStructured learning and prerequisites.
- 02Guided labSupervised practice with checkpoints.
- 03Team labCoordination and handoffs within the role.
- 04Integrated exerciseMulti-team scenario under exercise control.
- 05AssessmentObserved performance and assessor adjudication.
In sequence: Foundation knowledge leads into a guided laboratory, then a team laboratory, then an integrated multi-team exercise, and finally an assessment that produces competency evidence.
Representative scenarios
How the pathway is exercised.
Exploit-to-fix workshop
Tracing an exploited weakness to the design decision that permitted it.
Architecture redesign
Restructuring a component so an entire weakness class becomes unreachable.
Remediation verification
Confirming a fix holds under adversarial retest rather than unit tests alone.
Tools and environments
Capability categories, not a tool list.
Specific tooling is selected per deployment after security, licence and air-gap review. The categories below describe what the pathway needs to work.
- Shared analysis workspaces spanning offensive and engineering findings
- Threat modelling and architecture decision records
- Verification and regression environments
Evidence of competence
What observable behaviour supports readiness.
A readiness claim for this role must trace back to these artifacts. Evidence freshness is tracked separately from current competence, so an expired record never silently counts as a current one.
How readiness is calculated- Defect trace from exploit to affected component
- Design decision and its rationale
- Fix evidence with the requirement it satisfies
- Regression test covering the weakness class
- Updated control or standard
Collaboration
Upstream and downstream handoffs.
No role operates alone. These are the relationships that make this pathway useful to the wider mission.
Receives findings from Red Team and validated gaps from Purple Team
Hands implementable requirements to Yellow Team
Confirms with Blue Team that the change is observable in telemetry
Metrics
Operational and learning measures.
What the platform can measure for this role. Targets are baselined with each organization rather than claimed in advance.
- Vulnerability recurrence by class
- Time from finding to verified remediation
- Proportion of findings closed by design change rather than patch
Map your roles to CLIP.
We will work from your approved role definitions and competency framework, not from ours.