red-team-tactics

Explain red team operation principles and methodologies using the MITRE ATT&CK framework.

Updated Mar 7, 2026
One-click install
npx skills add https://github.com/devon87warren-afk/eboss-monorepo --skill red-team-tactics-devon87warren-afk
Or copy as Structured Prompt for Agent
Please help me install this Agent Skill.
Skill: red-team-tactics
Source: https://github.com/devon87warren-afk/eboss-monorepo/tree/main/apps/manager/.agent/skills/red-team-tactics
Command: npx skills add https://github.com/devon87warren-afk/eboss-monorepo --skill red-team-tactics-devon87warren-afk

SYSTEM DOCUMENTATION & REQUIREMENTS

What problem does it solve?

This Skill provides a comprehensive understanding of red team tactics, principles, and methodologies, enabling users to simulate adversary behavior for security testing and defense improvement.

Core Features & Use Cases

  • MITRE ATT&CK Framework: Detailed breakdown of attack phases and objectives.
  • Tactical Principles: Guidance on reconnaissance, initial access, privilege escalation, defense evasion, lateral movement, and more.
  • Reporting Standards: Best practices for documenting findings and identifying detection gaps.
  • Use Case: A security analyst can use this Skill to plan and execute a simulated phishing campaign, understanding the steps from initial access to data exfiltration and how to report on the effectiveness of existing security controls.

Quick Start

Explain the principles of defense evasion in red teaming.

Frequently Asked Questions about red-team-tactics

High-intent search queries and answers about installing and using this skill.

FAQPage Schema
What is adversary simulation in cybersecurity and how does it use the MITRE ATT&CK framework?

Adversary simulation mimics real-world threat actor behavior to test security controls. It uses the MITRE ATT&CK framework to map the attack lifecycle, from reconnaissance and initial access to lateral movement and data exfiltration, identifying detection gaps.

How do I execute privilege escalation techniques during a red team operation?

To execute privilege escalation during a red team operation, apply specific methodologies for Windows and Linux environments. These techniques elevate access levels after initial compromise, enabling deeper lateral movement and Active Directory attacks.

What are the best defense evasion strategies for penetration testing?

Effective defense evasion strategies for penetration testing involve tactics that bypass security controls without triggering alerts. This Skill details principles for remaining undetected while navigating the attack lifecycle during adversary simulation.

How should I structure red team reporting to identify security detection gaps?

Red team reporting should document findings and identify detection gaps by following best practices. It outlines the effectiveness of existing security controls against simulated attacks, providing actionable defense improvement insights.

Does this red team tactics guidance cover Active Directory attacks and lateral movement?

Yes, this red team tactics guidance covers Active Directory attacks and lateral movement methodologies. It provides tactical principles for navigating network environments and escalating privileges during adversary simulation.

What ethical boundaries apply to adversary simulation and penetration testing?

Adversary simulation must adhere to strict ethical boundaries and anti-patterns. This ensures penetration testing activities remain authorized, controlled, and focused on security defense improvement rather than actual system compromise.