red-team-tactics

Simulate adversary tactics using the MITRE ATT&CK framework.

Updated Jun 4, 2026
One-click install
npx skills add https://github.com/achmf/KostaHub --skill red-team-tactics-achmf
Or copy as Structured Prompt for Agent
Please help me install this Agent Skill.
Skill: red-team-tactics
Source: https://github.com/achmf/KostaHub/tree/main/.agent/skills/red-team-tactics
Command: npx skills add https://github.com/achmf/KostaHub --skill red-team-tactics-achmf

SYSTEM DOCUMENTATION & REQUIREMENTS

What problem does it solve?

This Skill provides a structured framework for understanding and simulating adversary behavior, helping security professionals identify gaps in their defensive posture and improve incident response.

Core Features & Use Cases

  • MITRE ATT&CK Mapping: Provides a clear breakdown of attack phases from reconnaissance to exfiltration.
  • Tactical Guidance: Offers specific checklists for privilege escalation, lateral movement, and defense evasion techniques.
  • Use Case: Use this Skill to conduct a tabletop exercise or a red team assessment to validate whether your current monitoring tools can detect specific lateral movement techniques like Pass-the-Hash.

Quick Start

Use the red-team-tactics skill to outline the defense evasion principles for a Windows environment.

Frequently Asked Questions about red-team-tactics

High-intent search queries and answers about installing and using this skill.

FAQPage Schema
How do I map adversary simulation tactics to the MITRE ATT&CK framework?

Map adversary simulation tactics by breaking down attack phases from reconnaissance to exfiltration using the MITRE ATT&CK framework. This provides a structured knowledge base to assess security controls across the entire attack lifecycle, including initial access and persistence.

What is the best way to document attack narratives and identify detection gaps?

Document attack narratives and identify detection gaps by simulating adversary behavior across the attack lifecycle. This approach validates whether current monitoring tools detect specific techniques, revealing critical weaknesses in enterprise defensive postures.

Can I use this for a tabletop exercise to validate lateral movement monitoring?

Yes, you can use this for tabletop exercises or red team assessments to validate monitoring tools. It offers tactical guidance and checklists for privilege escalation, lateral movement, and defense evasion to assess security controls.

How do I outline defense evasion principles for a Windows environment?

Outline defense evasion principles for a Windows environment using the provided tactical guidance and checklists. This facilitates structured adversary simulation to identify security control gaps and improve incident response readiness.

Does adversary simulation work without specific dependencies or components?

Yes, adversary simulation works without specific dependencies or components. It provides a comprehensive knowledge base for simulating adversary tactics based on the MITRE ATT&CK framework to assess security controls across the attack lifecycle.