adversary-emulation

Simulate cyber attacks using ATT&CK framework-based scenarios for red team exercises.

6|Updated May 30, 2026
One-click install
npx skills add https://github.com/jassics/awesome-claude-security --skill adversary-emulation
Or copy as Structured Prompt for Agent
Please help me install this Agent Skill.
Skill: adversary-emulation
Source: https://github.com/jassics/awesome-claude-security/tree/main/plugins/red-team/skills/adversary-emulation
Command: npx skills add https://github.com/jassics/awesome-claude-security --skill adversary-emulation

SYSTEM DOCUMENTATION & REQUIREMENTS

💡 This Skill includes scripts (resource) components.

What problem does it solve?

This Skill helps security professionals plan and execute an adversary-emulation engagement, mimicking the tactics, techniques, and procedures (TTPs) of real-world threat actors.

Core Features & Use Cases

  • Threat Actor Emulation: Choose a relevant threat actor and emulate their attack methods.
  • ATT&CK Mapped Plan: Build an attack plan that aligns with the adversary's behavior across the attack lifecycle.
  • Objective-Based Engagement: Define specific objectives for the simulation, such as accessing sensitive data or bypassing security controls.
  • Detection & Response Assessment: Measure the effectiveness of your organization's detection and response mechanisms.

Quick Start

Start the adversary-emulation skill by setting the objective: /adversary-emulation:set-objective "Access network resources"

Frequently Asked Questions about adversary-emulation

High-intent search queries and answers about installing and using this skill.

FAQPage Schema
How do I simulate a cyberattack for a red team assessment?

An adversary emulation engagement mimics the tactics, techniques, and procedures of real-world threat actors mapped to the ATT&CK framework. It helps security professionals measure the effectiveness of organizational detection and response mechanisms against realistic attacks.

How do I build an attack plan mapped to a specific threat actor?

To build an attack plan, select a relevant threat actor and map their known behaviors to ATT&CK framework techniques across the attack lifecycle. You then define specific engagement objectives, such as bypassing security controls or accessing sensitive data, to guide the simulation.

What skills do I need to perform adversary emulation?

You need scripting and system interaction skills to emulate attacker behaviors and evaluate security measures. The process is designed for security analysts who plan and execute red team exercises to assess organizational security controls.

Can I set custom objectives for a red team simulation?

Yes, you can define objective-based engagements by setting specific goals like accessing network resources or bypassing security controls. This allows the simulated attack to focus on evaluating targeted detection and response capabilities within your environment.

When should I use adversary emulation over a standard security assessment?

Use adversary emulation when you need to assess detection and response capabilities against specific threat actor profiles rather than performing general vulnerability scanning. It provides a realistic cyberattack simulation mapped to ATT&CK techniques to evaluate actual defense mechanisms.

Related Skills