red-team-tactics

Analyze adversary tactics with MITRE ATT&CK for red-team exercises.

Updated Feb 12, 2026
One-click install
npx skills add https://github.com/AnvinX1/med-rag --skill red-team-tactics-anvinx1
Or copy as Structured Prompt for Agent
Please help me install this Agent Skill.
Skill: red-team-tactics
Source: https://github.com/AnvinX1/med-rag/tree/main/medical_genai_app/.agent/skills/red-team-tactics
Command: npx skills add https://github.com/AnvinX1/med-rag --skill red-team-tactics-anvinx1

SYSTEM DOCUMENTATION & REQUIREMENTS

What problem does it solve?

This skill provides a structured, MITRE ATT&CK-aligned framework to understand and simulate attacker tactics, enabling teams to identify gaps in defenses and improve detection and response capabilities.

Core Features & Use Cases

  • Threat-modeling and exercise design: Translate MITRE ATT&CK phases into actionable red-team exercise plans and blue-team tuning scenarios.
  • Training and capability assessment: Build training materials and evaluation criteria to strengthen security teams’ understanding of attack chains.
  • Use Case: Create a guided exercise that maps an attacker’s lifecycle to detection gaps and recommended mitigations for incident response planning.

Quick Start

Create an engaged red-team plan focusing on MITRE ATT&CK phases and post-exercise reporting instructions.

Frequently Asked Questions about red-team-tactics

High-intent search queries and answers about installing and using this skill.

FAQPage Schema
How do I map red-team exercises to MITRE ATT&CK tactics?

Map red-team exercises to MITRE ATT&CK by translating adversary tactics like reconnaissance, lateral movement, and exfiltration into actionable exercise plans. This structured framework identifies detection gaps and hardens network and endpoint defenses.

What is MITRE ATT&CK threat modeling for incident response?

MITRE ATT&CK threat modeling for incident response analyzes attacker lifecycle phases to pinpoint security posture weaknesses. It provides a structured framework to improve detection capabilities and guide mitigation strategies across networks and endpoints.

Can I use this framework for blue team defense training?

Yes, you can use this framework for blue team defense training by building evaluation criteria and training materials from simulated attack chains. It helps security teams understand adversary behavior and tune detection scenarios.

How to design a red-team plan covering privilege escalation and defense evasion?

Design a red-team plan by aligning exercise objectives with specific MITRE ATT&CK phases like privilege escalation and defense evasion. This translates adversary behaviors into guided exercises that reveal detection blind spots.

Does this MITRE ATT&CK skill require specific security tools or dependencies?

No specific security tools or dependencies are required. The skill operates independently to provide a structured MITRE ATT&CK-aligned framework for analyzing adversary tactics and generating post-exercise reporting guidance.