What problem does it solve?
Planning and executing an authorized red team engagement requires coordinating infrastructure, C2 tradecraft, evasion techniques, OPSEC discipline, and structured reporting, and mistakes in any phase create legal exposure or premature detection.
Core Features & Use Cases
- Engagement Planning and ROE: Defines scope, rules of engagement, deconfliction procedures, and legal authorization requirements before any offensive action.
- Tiered C2 Infrastructure: Covers domain aging, redirectors with traffic filtering, malleable C2 profiles, sleep/jitter tuning, and fallback channels mapped to MITRE ATT&CK.
- Evasion and OPSEC: Documents AMSI bypass, ETW patching, direct syscalls, unhooking, LOLBin usage, indicator management, and cleanup procedures.
- Use Case: An operator preparing an assumed-breach engagement uses this Skill to design a three-tier C2 architecture, configure a Microsoft 365-themed malleable profile, and produce an ATT&CK-mapped report with a purple team debrief plan.
Quick Start
Ask Claude to plan a red team engagement infrastructure with redirectors, malleable C2 profiles, and an OPSEC checklist for an authorized assumed-breach scenario.