red-team-tactics

Simulate red-team tactics across MITRE ATT&CK phases for security assessments.

1|Updated Dec 19, 2025
One-click install
npx skills add https://github.com/fnsalinas/fnsalinas.github.io --skill red-team-tactics-fnsalinas
Or copy as Structured Prompt for Agent
Please help me install this Agent Skill.
Skill: red-team-tactics
Source: https://github.com/fnsalinas/fnsalinas.github.io/tree/main/.agent/skills/red-team-tactics
Command: npx skills add https://github.com/fnsalinas/fnsalinas.github.io --skill red-team-tactics-fnsalinas

SYSTEM DOCUMENTATION & REQUIREMENTS

What problem does it solve?

Adversary simulation guided by MITRE ATT&CK helps security teams validate defenses, improve detection, and accelerate incident response by providing a structured, repeatable approach to test security controls.

Core Features & Use Cases

  • MITRE-aligned attack phase planning and scenario development for controlled red-team exercises.
  • Detection validation, telemetry coverage, and incident-response readiness assessment across environments.
  • Ethical, scoped playbooks with clear reporting to drive remediation and security improvements.

Quick Start

Follow MITRE ATT&CK-based principles to simulate attacker steps and document detections.

Frequently Asked Questions about red-team-tactics

High-intent search queries and answers about installing and using this skill.

FAQPage Schema
How do I simulate red-team tactics using MITRE ATT&CK for security assessments?

To simulate red-team tactics using MITRE ATT&CK, you plan attack phases and develop controlled scenarios that evaluate detection and incident-response readiness within enterprise networks. This enforces ethical boundaries and structured reporting for remediation.

What is adversary simulation and when do I need it for cybersecurity risk assessment?

Adversary simulation is a structured approach to test security controls by mimicking attacker behaviors mapped to MITRE ATT&CK. You need it to validate defenses, improve detection coverage, and accelerate incident response during security assessments.

Can I use this for tabletop exercises and ongoing defender training?

Yes, you can apply this guidance to tabletop exercises and ongoing defender training. It provides structured, repeatable playbooks based on MITRE ATT&CK phases to validate detection capabilities and improve response readiness safely.

How do I ensure ethical boundaries and scoped execution during threat simulation?

To ensure ethical boundaries and scoped execution during threat simulation, you use enforced playbooks with clear reporting. This approach enables repeatable, safe assessments that drive security remediation without uncontrolled risks.

What's the best way to validate detection evasion capabilities against MITRE ATT&CK phases?

The best way to validate detection evasion capabilities is through MITRE-aligned attack phase planning. By simulating specific attacker steps, you assess telemetry coverage and identify gaps in your incident-response readiness.