conducting-full-scope-red-team-engagement

Plans and executes full-scope red team engagements using MITRE ATT&CK-aligned TTPs.

954|172|Updated Mar 13, 2026
One-click install
npx skills add https://github.com/xalgord/xalgorix --skill conducting-full-scope-red-team-engagement
Or copy as Structured Prompt for Agent
Please help me install this Agent Skill.
Skill: conducting-full-scope-red-team-engagement
Source: https://github.com/xalgord/xalgorix/tree/main/internal/tools/skills/data/red-teaming/conducting-full-scope-red-team-engagement
Command: npx skills add https://github.com/xalgord/xalgorix --skill conducting-full-scope-red-team-engagement

SYSTEM DOCUMENTATION & REQUIREMENTS

What problem does it solve?

Security teams need to validate whether their detection and response capabilities actually work against realistic adversary behavior, but ad-hoc penetration tests often miss stealth, persistence, and objective-based scenarios that real APT actors use.

Core Features & Use Cases

  • End-to-End Engagement Methodology: Covers all phases from OSINT reconnaissance and initial access through lateral movement, exfiltration, and reporting, mapped to MITRE ATT&CK tactics and techniques.
  • Operational Guidance with Real Commands: Provides concrete commands for tools like Amass, theHarvester, GoPhish, Rubeus, Impacket, and C2 frameworks such as Havoc and Sliver.
  • Detection Gap Measurement: Defines metrics like MTTD, MTTR, TTP coverage, and dwell time, plus purple team recommendations for closing detection gaps.
  • Use Case: A red team operator planning an authorized engagement against a corporate Active Directory environment uses this Skill to structure the operation, select ATT&CK techniques per phase, timestamp evidence, and produce a report with a detection gap analysis for the SOC.

Quick Start

Ask the AI to plan a full-scope red team engagement against an authorized target environment, mapping each phase to MITRE ATT&CK techniques and defining measurable objectives.

Frequently Asked Questions about conducting-full-scope-red-team-engagement

High-intent search queries and answers about installing and using this skill.

FAQPage Schema
How do I plan a full-scope red team engagement?

Start with a signed Rules of Engagement document defining scope, objectives, and emergency stop procedures. Then map each kill chain phase to MITRE ATT&CK tactics, build C2 infrastructure, execute reconnaissance through exfiltration, and report with a detection gap analysis.

What is the difference between red teaming and penetration testing?

Red team operations prioritize stealth, persistence, and objective-based scenarios that mimic APTs, while penetration testing focuses on finding and exploiting vulnerabilities broadly. Red teams measure the SOC's detection and response, not just exploitable flaws.

Which C2 frameworks does this red team methodology support?

The methodology references Havoc, Cobalt Strike, Sliver, Mythic, and Brute Ratel C4 as command and control frameworks. It also covers supporting tools like Metasploit, Impacket, CrackMapExec, Rubeus, and Mimikatz for post-exploitation.

What authorization is required before starting a red team engagement?

A written Rules of Engagement document signed by executive leadership is required, defining in-scope and out-of-scope systems, escalation contacts, and emergency stop procedures. Legal review confirming compliance with laws like the CFAA is also a stated prerequisite.

How is red team engagement success measured?

Success is measured with metrics including Mean Time to Detect, Mean Time to Respond, TTP coverage percentage, objective achievement rate, and dwell time. Objectives count as achieved only when concrete evidence, such as Domain Admin membership or exfiltrated file hashes, is observed.

What should I do when phishing initial access fails during an engagement?

Treat phishing failure as a phase setback, not an engagement failure. Pivot to the pre-agreed assumed-breach grant defined in the Rules of Engagement instead of exhausting the operation window on additional lure attempts.