red-team-tactics

Simulates attacker techniques to test defenses using MITRE ATT&CK phase mappings.

Updated Jan 22, 2026
One-click install
npx skills add https://github.com/Arbab1308/BrownlandBL-2 --skill red-team-tactics-arbab1308
Or copy as Structured Prompt for Agent
Please help me install this Agent Skill.
Skill: red-team-tactics
Source: https://github.com/Arbab1308/BrownlandBL-2/tree/main/.agent/skills/red-team-tactics
Command: npx skills add https://github.com/Arbab1308/BrownlandBL-2 --skill red-team-tactics-arbab1308

SYSTEM DOCUMENTATION & REQUIREMENTS

What problem does it solve?

Red team tactics principles help security teams simulate attacker techniques and assess defense readiness based on MITRE ATT&CK.

Core Features & Use Cases

  • Provides structured coverage of MITRE ATT&CK phases including reconnaissance, initial access, execution, persistence, defense evasion, credential access, discovery, lateral movement, collection, C2, exfiltration, and impact.
  • Supports threat modeling, security assessments, and reporting workflows to identify detection gaps and improvement opportunities.
  • Enables knowledge sharing and training by documenting realistic attack narratives aligned with MITRE framework.

Quick Start

Describe a starter red-team scenario mapped to MITRE ATT&CK phases to begin testing defenses.

Frequently Asked Questions about red-team-tactics

High-intent search queries and answers about installing and using this skill.

FAQPage Schema
How do I map red team tactics to MITRE ATT&CK phases for security assessments?

Red team tactics map to MITRE ATT&CK phases by simulating attacker techniques across reconnaissance, execution, persistence, defense evasion, and exfiltration. This structured mapping identifies detection gaps and improves overall defender readiness during security assessments.

What is defense evasion in threat modeling and how does it test detection capabilities?

Defense evasion in threat modeling involves simulating attacker techniques that bypass security controls to test detection capabilities. It provides structured MITRE ATT&CK mappings to identify visibility gaps and improve enterprise defense readiness against evasive threats.

Can I use this approach for detection engineering and enterprise risk assessment?

Yes, you can use red team simulation for detection engineering and enterprise risk assessment. It tests defenses across ATT&CK phases, providing structured reporting guidelines to identify improvement opportunities and validate detection coverage.

What's the best way to document realistic attack narratives aligned with MITRE ATT&CK?

The best way to document attack narratives aligned with MITRE ATT&CK is by mapping simulated techniques to specific phases like initial access, lateral movement, and impact. This enables knowledge sharing and training to improve defender readiness.

How to start a red team scenario mapped to MITRE ATT&CK phases for testing defenses?

Start a red team scenario mapped to MITRE ATT&CK by describing a simulated attack path covering reconnaissance, initial access, execution, and persistence. This structured approach identifies detection gaps and validates defense readiness across enterprise environments.