red-team-engagement

Plan and coordinate authorized red-team engagements with ATT&CK emulation and reporting.

345|47|Updated Mar 13, 2026
One-click install
npx skills add https://github.com/briiirussell/cybersecurity-skills --skill red-team-engagement
Or copy as Structured Prompt for Agent
Please help me install this Agent Skill.
Skill: red-team-engagement
Source: https://github.com/briiirussell/cybersecurity-skills/tree/main/skills/red-team-engagement
Command: npx skills add https://github.com/briiirussell/cybersecurity-skills --skill red-team-engagement

SYSTEM DOCUMENTATION & REQUIREMENTS

What problem does it solve?

It helps you plan, scope, and execute an authorized red-team engagement to validate whether your organization can detect, respond to, and contain adversary behavior—going beyond vulnerability discovery to test real defenses.

Core Features & Use Cases

  • Authorization-gated planning and execution: Requires explicit written authorization, defined scope, success criteria, and deconfliction contacts before any assistance proceeds.
  • Engagement lifecycle coverage: Guides pre-engagement scoping, recon/intelligence planning, ATT&CK-emulation execution, and structured debrief/reporting.
  • Assumed-breach and purple-team models: Supports externally scoped, assumed-breach, and purple-team workflows with appropriate emphasis on learning and detection coverage.
  • Dual-use safety boundaries: Refuses unauthorized targeting, discourages destructive activity by default, and uses synthetic markers instead of real customer-data exfiltration.

Quick Start

Use the red-team-engagement skill to create an engagement plan and RoE by describing your authorized target, in-scope assets, time window, assumed-breach starting point (if applicable), success criteria, and the deconfliction contact.

Frequently Asked Questions about red-team-engagement

High-intent search queries and answers about installing and using this skill.

FAQPage Schema
How do I plan an authorized red team engagement for adversary emulation?

To plan an authorized red team engagement, you must define explicit written authorization, scope, success criteria, and deconfliction contacts to validate detection and response capabilities against ATT&CK emulation scenarios.

What is the difference between a red team engagement and vulnerability discovery?

A red team engagement focuses on adversary emulation and validating whether your organization can detect, respond to, and contain threats, going beyond simple vulnerability discovery to test real defensive capabilities.

How do I create rules of engagement for an assumed-breach scenario?

Creating rules of engagement for an assumed-breach scenario requires defining the starting point, in-scope assets, time window, success criteria, and deconfliction contacts before executing any authorized testing.

Can I use this for purple team workflows to improve detection coverage?

Yes, purple team workflows are supported with an appropriate emphasis on learning, detection coverage, and collaborative validation of incident response capabilities during the engagement lifecycle.

How does deconfliction work during an ATT&CK emulation execution?

Deconfliction during ATT&CK emulation execution requires establishing specific contacts who can verify whether detected activity is part of the authorized test or an actual incident requiring response.

What are the limitations when handling evidence during a red team engagement?

Evidence handling limitations require using synthetic markers instead of real customer-data exfiltration, and the engagement refuses unauthorized targeting or destructive activity by default to maintain safety boundaries.