red-team-tactics

Plan MITRE ATT&CK-aligned red-team simulations with scoped ethical guidelines.

Updated Jan 12, 2026
One-click install
npx skills add https://github.com/BenWork17/VeXeViet --skill red-team-tactics-benwork17
Or copy as Structured Prompt for Agent
Please help me install this Agent Skill.
Skill: red-team-tactics
Source: https://github.com/BenWork17/VeXeViet/tree/main/.agent/skills/red-team-tactics
Command: npx skills add https://github.com/BenWork17/VeXeViet --skill red-team-tactics-benwork17

SYSTEM DOCUMENTATION & REQUIREMENTS

What problem does it solve?

Solves the problem of planning and executing adversary simulations using MITRE ATT&CK, providing structured guidance for detection evasion concepts and comprehensive reporting.

Core Features & Use Cases

  • Lifecycle mapping: Aligns security exercises to MITRE ATT&CK phases from recon to exfiltration.
  • Tactics overview: Covers reconnaissance, initial access, execution, persistence, privilege escalation, defense evasion, credential access, discovery, lateral movement, collection, C2, exfiltration, and impact.
  • Ethical guidelines & reporting: Emphasizes scoped testing, responsible disclosure, documentation, and post-engagement evaluation.

Quick Start

Outline a MITRE ATT&CK-aligned red-team engagement plan for a mid-size enterprise.

Frequently Asked Questions about red-team-tactics

High-intent search queries and answers about installing and using this skill.

FAQPage Schema
How do I plan a MITRE ATT&CK-aligned red team engagement for an enterprise network?

Plan a MITRE ATT&CK-aligned red team engagement by mapping simulation phases from reconnaissance to exfiltration, ensuring strict scope enforcement and ethical boundaries throughout the exercise. This provides structured guidance for enterprise networks and hybrid architectures.

What MITRE ATT&CK tactics should a red team simulation cover?

A red team simulation should cover reconnaissance, initial access, execution, persistence, privilege escalation, defense evasion, credential access, discovery, lateral movement, collection, C2, exfiltration, and impact. These adversary simulation tactics align directly with MITRE ATT&CK lifecycle phases.

Can I use adversary simulation techniques in cloud environments?

Yes, adversary simulation techniques apply across cloud environments, enterprise networks, and hybrid architectures. The simulation guidance enforces strict safety, reproducibility, and evidence-based outcomes regardless of the target infrastructure.

What ethical boundaries apply to penetration testing and red team exercises?

Ethical boundaries for penetration testing and red team exercises require strict scope adherence, responsible disclosure, comprehensive documentation, and post-engagement evaluation. These guidelines ensure security assessments remain safe, measurable, and reproducible.

What's the best way to structure red team reporting after a security assessment?

The best way to structure red team reporting focuses on evidence-based outcomes, documentation of scoped testing activities, and post-engagement evaluation. This ensures comprehensive reporting requirements are met for security assessments.

Why do red team simulations require strict scope and safety enforcement?

Red team simulations require strict scope and safety enforcement to maintain ethical boundaries, ensure reproducibility, and guarantee evidence-based outcomes during adversary simulation. This prevents unauthorized impact during security assessments.