executing-red-team-engagement-planning

Plans red team engagements by defining scope, rules of engagement, and MITRE ATT&CK threat profiles.

954|172|Updated Mar 13, 2026
One-click install
npx skills add https://github.com/xalgord/xalgorix --skill executing-red-team-engagement-planning
Or copy as Structured Prompt for Agent
Please help me install this Agent Skill.
Skill: executing-red-team-engagement-planning
Source: https://github.com/xalgord/xalgorix/tree/main/internal/tools/skills/data/red-teaming/executing-red-team-engagement-planning
Command: npx skills add https://github.com/xalgord/xalgorix --skill executing-red-team-engagement-planning

SYSTEM DOCUMENTATION & REQUIREMENTS

What problem does it solve?

Red team engagements fail or cause business disruption when scope, authorization, and deconfliction are not defined before offensive testing begins. This Skill structures the planning phase so every engagement starts with signed authorization, explicit boundaries, and a tested emergency-stop procedure.

Core Features & Use Cases

  • Scope and ROE Definition: Produces explicit in-scope and out-of-scope asset lists, rules of engagement, communication plans, and emergency cessation procedures.
  • Threat Profile Selection: Maps adversary groups such as APT29, FIN7, and Lazarus to the organization's threat landscape using MITRE ATT&CK Navigator.
  • Deconfliction and Approval Workflow: Establishes SOC deconfliction matrices, legal authorization steps, and executive sign-off checkpoints.
  • Use Case: A security consultancy preparing a full-scope adversary simulation for a financial client uses this Skill to draft the ROE document, select a FIN7 threat profile, and brief operators before go-live.

Quick Start

Ask the AI to draft a red team engagement plan for a financial services organization including scope boundaries, rules of engagement, and a FIN7 threat profile mapped to MITRE ATT&CK techniques.

Frequently Asked Questions about executing-red-team-engagement-planning

High-intent search queries and answers about installing and using this skill.

FAQPage Schema
How do I plan a red team engagement?

Red team engagement planning follows four phases: pre-engagement scoping with stakeholders, threat modeling using MITRE ATT&CK, operational planning for infrastructure and OPSEC, and documentation with legal approval. The output is a signed rules of engagement document and an explicit scope definition.

What should rules of engagement include for red team testing?

Rules of engagement should include scope definitions, restricted systems, communication channels, emergency stop procedures with a code word, legal authorization letters, data handling rules, and timelines with blackout windows. Every operator must acknowledge the ROE in writing before testing begins.

How do I choose a threat profile with MITRE ATT&CK?

Select threat profiles by mapping adversary groups to the organization's actual threat landscape using MITRE ATT&CK Navigator. For example, FIN7 fits financial sector targets, while APT29 suits government and defense organizations. Mismatched profiles waste effort on irrelevant TTPs.

What is deconfliction in red team operations?

Deconfliction is a coordination channel between the red team and the organization's SOC or blue team that prevents red team activity from being escalated as a real incident. It requires a deconfliction matrix with named contacts established before the engagement starts.

What are common red team planning mistakes?

Common mistakes include implicit out-of-scope assumptions, untested emergency-stop procedures, missing signed authorization letters, unrealistic threat models, and scope creep during execution. A sound plan requires a signed ROE, explicit exclusions, and an end-to-end tested cessation procedure.