red-team-tactics

Automate adversary-simulation planning and reporting with MITRE ATT&CK tactics.

Updated Jan 27, 2026
One-click install
npx skills add https://github.com/BrunoSantanaDeveloper/flyeelab-agent-kit --skill red-team-tactics-brunosantanadeveloper
Or copy as Structured Prompt for Agent
Please help me install this Agent Skill.
Skill: red-team-tactics
Source: https://github.com/BrunoSantanaDeveloper/flyeelab-agent-kit/tree/main/skills/red-team-tactics
Command: npx skills add https://github.com/BrunoSantanaDeveloper/flyeelab-agent-kit --skill red-team-tactics-brunosantanadeveloper

SYSTEM DOCUMENTATION & REQUIREMENTS

What problem does it solve?

Red Team Tactics helps security teams design adversary simulations aligned with the MITRE ATT&CK framework, enabling structured planning, execution, and reporting.

Core Features & Use Cases

  • MITRE ATT&CK phase mapping and threat-emulation workflows to reflect real-world attack sequences.
  • Guidance on detection evasion, safe practice, and ethical boundaries to minimize operational risk.
  • Comprehensive reporting templates that capture objectives, techniques used, detections, and remediation recommendations.

Quick Start

Describe a scoped red-team scenario and let the system generate a phased attack plan and debrief report.

Frequently Asked Questions about red-team-tactics

High-intent search queries and answers about installing and using this skill.

FAQPage Schema
How do I plan a red team exercise using the MITRE ATT&CK framework?

Threat emulation maps adversary behaviors to MITRE ATT&CK phases, allowing security teams to structure attack sequences. This approach ensures exercises accurately reflect real-world threats and test detection capabilities across the kill chain.

How do I generate a red team engagement report aligned to MITRE ATT&CK?

Post-engagement reporting outputs capture objectives, techniques used, detections triggered, and remediation recommendations. By aligning debrief reports to MITRE ATT&CK, security teams ensure structured documentation of adversary simulation results.

Does this approach include guidance on detection evasion for adversary simulation?

Detection evasion guidance is included to help simulate realistic adversary behaviors while maintaining safe practice and ethical boundaries. This minimizes operational risk during red-team exercises and ensures accurate testing of blue team capabilities.

Can I use this for threat emulation across different attack phases?

Structured phase mapping applies to threat-emulation workflows across different attack phases, reflecting real-world attack sequences. Security teams can simulate adversary behaviors from initial access through impact using MITRE ATT&CK-driven tactics.

What is the best way to structure adversary simulation planning?

Adversary-simulation planning is best structured by mapping scoped scenarios to MITRE ATT&CK-driven tactics. This approach automates the creation of phased attack plans, ensuring exercises follow realistic threat behaviors and structured execution.