red-team-tactics

Simulate adversary techniques to assess network and endpoint defenses.

3|2|Updated Feb 27, 2026
One-click install
npx skills add https://github.com/grasberg/sofia --skill red-team-tactics-grasberg
Or copy as Structured Prompt for Agent
Please help me install this Agent Skill.
Skill: red-team-tactics
Source: https://github.com/grasberg/sofia/tree/main/cmd/sofia/internal/onboard/antigravity-kit/.agent/skills/red-team-tactics
Command: npx skills add https://github.com/grasberg/sofia --skill red-team-tactics-grasberg

SYSTEM DOCUMENTATION & REQUIREMENTS

What problem does it solve?

Adversary-simulation guidance helps security teams evaluate defenses by mapping attacker techniques to real-world scenarios.

Core Features & Use Cases

  • MITRE ATT&CK phase guidance for red-team exercises
  • Ethical boundaries and reporting templates for safe testing
  • Scenario design and outcome reporting for defense improvements

Quick Start

Outline a safe red-team exercise following MITRE ATT&CK phases to test detection and response.

Frequently Asked Questions about red-team-tactics

High-intent search queries and answers about installing and using this skill.

FAQPage Schema
How do I map red-team exercises to MITRE ATT&CK phases?

Red-team exercises map to MITRE ATT&CK phases by simulating adversary techniques across the kill chain to assess network and endpoint defenses. This mapping reveals detection gaps and response weaknesses in security assessments and training scenarios.

What ethical boundaries should I follow during adversary simulation?

Adversary simulation requires strict ethical boundaries to ensure safe testing. You must follow established reporting templates and guidelines that define scope, authorization, and safe execution to prevent unintended damage during red-team activities.

How do I design red-team scenarios to test defense evasion?

Red-team scenarios test defense evasion by applying specific attacker techniques designed to bypass security controls. Scenario design incorporates detection-evasion considerations to evaluate how well network and endpoint defenses identify stealthy threats.

Can I use adversary simulation for tabletop security exercises?

Adversary simulation is effective for tabletop security exercises and training. It provides structured scenarios based on MITRE ATT&CK phases that help teams practice threat detection and response without active network exploitation.

What is the best way to report red-team findings for defense improvements?

Reporting red-team findings requires structured templates that highlight detection gaps and response weaknesses. Effective outcome reporting maps observed adversary techniques to MITRE ATT&CK phases and provides actionable recommendations for defense improvements.