red-team-tactics

Guide red team operations using the MITRE ATT&CK framework.

Updated Feb 5, 2026
One-click install
npx skills add https://github.com/flybirdxx/RunningHub --skill red-team-tactics-flybirdxx
Or copy as Structured Prompt for Agent
Please help me install this Agent Skill.
Skill: red-team-tactics
Source: https://github.com/flybirdxx/RunningHub/tree/main/.gemini/skills/red-team-tactics
Command: npx skills add https://github.com/flybirdxx/RunningHub --skill red-team-tactics-flybirdxx

SYSTEM DOCUMENTATION & REQUIREMENTS

💡 This Skill includes scripts (resource) and references (resource) and assets (resource) components.

What problem does it solve?

This Skill provides a comprehensive guide to red team tactics based on the MITRE ATT&CK framework, helping users understand and simulate attacker behavior to improve their defenses.

Core Features & Use Cases

  • Red Team Tactics Principles: Offers a detailed explanation of the principles and phases of red team operations.
  • Attack Phases and Techniques: Provides insights into various attack phases, including reconnaissance, initial access, execution, persistence, and more.
  • Privilege Escalation and Defense Evasion: Discusses strategies for escalating privileges and evading detection mechanisms.
  • Lateral Movement and Data Collection: Covers techniques for moving laterally within a network and collecting data.
  • Active Directory Attacks: Explores specific attacks on Active Directory environments.
  • Reporting and Ethical Boundaries: Outlines principles for reporting and adhering to ethical boundaries in red team operations.

Quick Start

Use the red-team-tactics skill to learn about the MITRE ATT&CK framework and its application in red teaming.

Frequently Asked Questions about red-team-tactics

High-intent search queries and answers about installing and using this skill.

FAQPage Schema
What are the key phases of red team operations in attack simulation?

Red team operations follow phases including reconnaissance, initial access, execution, persistence, privilege escalation, defense evasion, lateral movement, and data collection to simulate attacker behavior.

How does the MITRE ATT&CK framework map to red teaming techniques?

The MITRE ATT&CK framework provides a structured matrix of adversary tactics and techniques, enabling red teamers to systematically plan attack simulations, execute specific behaviors, and map results to defensive gaps.

What techniques are used for privilege escalation and defense evasion in penetration testing?

Privilege escalation and defense evasion techniques involve strategies to gain higher-level permissions and bypass detection mechanisms, allowing red teamers to maintain access while avoiding security monitoring during penetration testing.

Can I use this guide for Active Directory attacks and lateral movement?

Yes, this guide explores specific attack techniques targeting Active Directory environments and covers methods for moving laterally within a network to simulate realistic internal threat scenarios.

What ethical boundaries should I follow during red team operations?

Red team operations must adhere to strict ethical boundaries, requiring clear authorization, scope limitations, and responsible reporting principles to ensure attack simulations improve defenses without causing harm.

Do I need prior cybersecurity experience to understand MITRE ATT&CK red team tactics?

This guide applies to cybersecurity professionals and red teamers, requiring foundational knowledge of penetration testing and network security to effectively understand and apply the attack simulation techniques.