red-team

Plan authorized red-team engagements with scored MITRE ATT&CK kill-chain attack plans.

Updated Apr 9, 2026
One-click install
npx skills add https://github.com/Patasse97/claude-skills --skill red-team-patasse97
Or copy as Structured Prompt for Agent
Please help me install this Agent Skill.
Skill: red-team
Source: https://github.com/Patasse97/claude-skills/tree/main/engineering-team/red-team
Command: npx skills add https://github.com/Patasse97/claude-skills --skill red-team-patasse97

SYSTEM DOCUMENTATION & REQUIREMENTS

💡 This Skill includes scripts (resource) and references (resource) components.

What problem does it solve?

Structured red-team planning provides a repeatable methodology to design and execute authorized adversary simulations, enabling accurate assessment of detection, response, and control effectiveness in a controlled environment.

Core Features & Use Cases

  • Engagement Planner Tool: builds scored, kill-chain ordered attack plans from MITRE ATT&CK techniques and crown jewel targets.
  • Kill-Chain Phase Methodology: organizes techniques into eight phases to guide stepwise execution and measurement.
  • Technique Scoring & OPSEC: scores techniques by detection risk and effort, identifies choke points, and surfaces OPSEC considerations for safe execution.
  • Cross-References & Workflows: aligns red-team activities with threat-detection and incident-response workflows to validate defenses.

Quick Start

Obtain signed Rules of Engagement and run the planner with your chosen techniques to generate an engagement plan.

Frequently Asked Questions about red-team

High-intent search queries and answers about installing and using this skill.

FAQPage Schema
How do I plan authorized red-team simulations using MITRE ATT&CK techniques?

Red-team simulations require a structured methodology to build scored, kill-chain ordered attack plans from MITRE ATT&CK techniques against crown jewel targets. You generate a reproducible engagement plan by mapping selected techniques to validate detection and response effectiveness.

What's the best way to structure attack-path analysis for threat emulation?

Structuring attack-path analysis involves organizing techniques into eight kill-chain phases for stepwise execution. This methodology surfaces OPSEC considerations and identifies choke points to safely validate defenses. It guides the measurement of control effectiveness throughout the engagement.

Does this red-team engagement planner require signed Rules of Engagement?

Yes, authorized red-team engagements require signed Rules of Engagement before execution. You must obtain signed RoE and define your scope, then run the planner with chosen techniques to generate the engagement plan safely and legally.

Can I score MITRE ATT&CK techniques by detection risk and effort?

Yes, you can score MITRE ATT&CK techniques by detection risk and effort to prioritize execution. Technique scoring identifies OPSEC considerations and choke points, ensuring safe execution while validating threat detection and incident response workflows.

How do red-team activities align with incident-response and threat-detection workflows?

Red-team activities align with incident-response and threat-detection workflows through cross-referencing during engagement planning. This validates defense controls by measuring detection and response effectiveness against the simulated kill-chain execution within the defined scope.