red-team

Plan authorized red-team engagements with kill-chain ordered attack plans.

Updated Apr 16, 2026
One-click install
npx skills add https://github.com/devCharuzu/philfida-taskmanage --skill red-team-devcharuzu
Or copy as Structured Prompt for Agent
Please help me install this Agent Skill.
Skill: red-team
Source: https://github.com/devCharuzu/philfida-taskmanage/tree/main/.windsurf/skills/red-team
Command: npx skills add https://github.com/devCharuzu/philfida-taskmanage --skill red-team-devcharuzu

SYSTEM DOCUMENTATION & REQUIREMENTS

💡 This Skill includes scripts (resource) and references (resource) components.

What problem does it solve?

Plans authorized red-team engagements using structured attack planning to align techniques, risk, and crown jewels with governance.

Core Features & Use Cases

  • Engagement Planner Tool: builds a scored, kill-chain ordered plan from technique selection, access level, and crown jewel targets.
  • Kill-Chain Phase Methodology: organizes techniques into eight phases to guide execution.
  • Technique Scoring and Prioritization: rates techniques by detection risk and prerequisites to rank paths.
  • Choke Point Analysis: identifies high-leverage techniques that influence multiple paths to crown jewels.
  • OPSEC Risk Assessment: catalogs and contextualizes operational security risks and mitigations.
  • Crown Jewel Targeting: defines high-value assets to determine success criteria.
  • Attack Path Methodology: analyzes routes from starting access to crown jewels with scoring.
  • Workflows: provides quick scoping and multi-week engagement workflows.
  • Anti-Patterns: highlights governance and safety missteps to avoid.
  • Cross-References: links to related defensive and risk-management skills.

Quick Start

Execute the engagement planner with your technique set and ensure RoE authorization to generate a plan.

Frequently Asked Questions about red-team

High-intent search queries and answers about installing and using this skill.

FAQPage Schema
How do I plan a red-team engagement using MITRE ATT&CK techniques?

Plan red-team engagements by selecting MITRE ATT&CK techniques, ordering them into kill-chain phases, and scoring paths based on detection risk and prerequisites to target crown jewels.

What is choke point analysis in red-team attack path methodology?

Choke point analysis identifies high-leverage MITRE ATT&CK techniques that influence multiple attack paths, maximizing access to crown jewel targets across different access levels.

How do I assess OPSEC risks when scoping authorized red-team operations?

Assess OPSEC risks by cataloging operational security threats and contextualizing mitigations during engagement planning, ensuring techniques align with governance and Rules of Engagement authorization.

Can I estimate engagement duration based on technique prerequisites?

Engagement planning generates duration estimates by evaluating technique prerequisites and detection risk scores, structuring multi-week workflows from initial access to crown jewel targeting.

What are common anti-patterns to avoid during red-team engagement planning?

Red-team engagement planning highlights governance and safety missteps to avoid, ensuring structured attack plans satisfy functional requirements without compromising operational security or authorization scope.

Does this red-team planner support multi-week engagement workflows?

The engagement planner supports both quick scoping and multi-week engagement workflows, generating actionable outputs for stakeholders from technique selection to kill-chain ordered execution plans.