offensive-sec

Generates MITRE ATT&CK-based red team guidance and checklists for authorized engagements.

Updated Jan 24, 2026
One-click install
npx skills add https://github.com/pikakit/agent-skills --skill offensive-sec
Or copy as Structured Prompt for Agent
Please help me install this Agent Skill.
Skill: offensive-sec
Source: https://github.com/pikakit/agent-skills/tree/main/.agent/skills/offensive-sec
Command: npx skills add https://github.com/pikakit/agent-skills --skill offensive-sec

SYSTEM DOCUMENTATION & REQUIREMENTS

What problem does it solve?

Structured MITRE ATT&CK phase guidance for authorized red team engagements, eliminating ad-hoc, inconsistent testing and helping defenders improve defenses.

Core Features & Use Cases

  • 13 MITRE ATT&CK phases guidance with threat-modeling and engagement planning
  • Four fixed initial access vectors and platform-specific privilege escalation checklists
  • Ethical boundaries enforcement, comprehensive reporting templates, and non-executable methodology for safe assessments

Quick Start

Run this skill to generate MITRE ATT&CK phase-based guidance for an authorized red-team engagement.

Frequently Asked Questions about offensive-sec

High-intent search queries and answers about installing and using this skill.

FAQPage Schema
How do I plan a red team engagement using MITRE ATT&CK phases?

Plan a red team engagement by mapping authorized targets to the 13 MITRE ATT&CK phases, applying threat modeling to select initial access vectors, and generating phase-specific checklists for privilege escalation and defense evasion.

What initial access vectors should I consider for an authorized pentest?

For an authorized pentest, evaluate four fixed initial access vectors provided by the methodology to determine the most viable entry point based on the target environment and threat modeling requirements.

Can I generate non-executable privilege escalation checklists for active directory attacks?

Yes, you can generate non-executable privilege escalation checklists tailored for active directory attacks, providing safe, methodology-driven guidance without executing any actual exploits on the target.

Does this red team methodology enforce ethical boundaries during engagement planning?

The red team methodology enforces ethical boundaries by providing a strictly non-executable framework, ensuring all phase-specific attack tactics and reporting guidance remain within authorized assessment limits.

What is the best way to structure red team reporting across MITRE phases?

The best way to structure red team reporting is to use comprehensive reporting templates that document findings and attack-phase tactics sequentially across the 13 MITRE ATT&CK phases.

Do I need executable exploit tools to use this red team guidance?

No, you do not need executable exploit tools because this methodology outputs non-executable, ethics-bound guidance, phase-specific checklists, and engagement planning for safe assessments.