red-team-operations

Translate approved campaign plans into operational steps across Cyber Kill Chain phases.

3|3|Updated Mar 8, 2026
One-click install
npx skills add https://github.com/jaskaranhundal/usap-skills --skill red-team-operations
Or copy as Structured Prompt for Agent
Please help me install this Agent Skill.
Skill: red-team-operations
Source: https://github.com/jaskaranhundal/usap-skills/tree/main/red-team/red-team-operations
Command: npx skills add https://github.com/jaskaranhundal/usap-skills --skill red-team-operations

SYSTEM DOCUMENTATION & REQUIREMENTS

💡 This Skill includes scripts (resource) and references (resource) and assets (resource) components.

What problem does it solve?

This Skill automates the execution of complex red team operations, translating campaign plans into discrete, actionable steps across the Cyber Kill Chain while enforcing strict operational security and authorization controls.

Core Features & Use Cases

  • Adversary Simulation Execution: Translates approved campaign plans into operational steps for reconnaissance, weaponization, delivery, exploitation, installation, C2, and actions on objectives.
  • Operational Security (OPSEC) Management: Enforces strict OPSEC constraints, including C2 infrastructure design, kill switch procedures, and IOC minimization.
  • Use Case: A validated campaign plan from red-team-planner is received, detailing objectives to demonstrate lateral movement to a domain controller. This Skill will plan and execute the necessary steps, including C2 setup, lateral movement path selection, and exfiltration staging, all while adhering to defined OPSEC and authorization requirements.

Quick Start

Use the red-team-operations skill to plan the reconnaissance phase for campaign RT-2026-Q1-001.

Frequently Asked Questions about red-team-operations

High-intent search queries and answers about installing and using this skill.

FAQPage Schema
How do I execute adversary simulation steps across the Cyber Kill Chain?

Adversary simulation execution translates approved campaign plans into discrete operational steps across all seven Cyber Kill Chain phases, managing reconnaissance, weaponization, delivery, exploitation, installation, C2, and actions on objectives.

How does this skill manage operational security and C2 infrastructure setup?

Operational security management enforces strict OPSEC constraints during adversary simulation, including C2 infrastructure design, kill switch procedures, IOC minimization, and pre-operation IOC management to maintain stealth throughout the campaign.

Do I need human approval tokens and MITRE ATT&CK technique IDs to run red team operations?

Yes, red team operations require human approval tokens and MITRE ATT&CK technique IDs for execution directives, ensuring authorized control over lateral movement path selection and exfiltration staging activities.

What is the best way to plan lateral movement to a domain controller during a red team campaign?

Lateral movement path selection is planned by translating validated campaign objectives into discrete operational steps, mapping techniques across the Cyber Kill Chain while adhering to defined OPSEC and authorization requirements.

Can I use this skill to plan the reconnaissance phase for a specific red team campaign?

Yes, you can use this skill to plan the reconnaissance phase for specific campaigns such as RT-2026-Q1-001, translating approved campaign plans into actionable operational steps with OPSEC constraints applied.

What are the limitations when staging exfiltration during adversary simulation?

Exfiltration staging is constrained by enforced OPSEC requirements and IOC minimization protocols, requiring human approval tokens before executing actions on objectives to maintain operational security throughout the process.