red-team-tactics

Map adversary techniques to MITRE ATT&CK phases for red-team simulations.

Updated Aug 30, 2024
One-click install
npx skills add https://github.com/jfrometa/esquizo --skill red-team-tactics-jfrometa
Or copy as Structured Prompt for Agent
Please help me install this Agent Skill.
Skill: red-team-tactics
Source: https://github.com/jfrometa/esquizo/tree/main/.agent/skills/red-team-tactics
Command: npx skills add https://github.com/jfrometa/esquizo --skill red-team-tactics-jfrometa

SYSTEM DOCUMENTATION & REQUIREMENTS

What problem does it solve?

This Skill maps adversary techniques to MITRE ATT&CK phases to help security teams assess and strengthen defenses.

Core Features & Use Cases

  • Adversary simulation playbooks aligned with MITRE ATT&CK phases
  • Threat-modeling guidance for red-team exercises and defense hardening
  • Clear reporting workflow to document findings and remediation steps

Quick Start

Use the red-team-tactics skill to generate a compact MITRE ATT&CK mapping for a simple environment.

Frequently Asked Questions about red-team-tactics

High-intent search queries and answers about installing and using this skill.

FAQPage Schema
How do I map adversary simulation techniques to MITRE ATT&CK phases?

You map adversary techniques to MITRE ATT&CK phases by using a structured playbook that aligns red-team simulation actions from recon to impact with the framework's categories, highlighting detection gaps and reporting requirements.

What is the best way to document red-team findings and remediation steps?

The best way to document red-team findings is using a narrative reporting template. This workflow maps executed adversary simulation techniques to MITRE ATT&CK phases, detailing detection gaps and required remediation steps for defense teams.

How does threat modeling help assess and strengthen security defenses?

Threat modeling helps assess and strengthen security defenses by simulating attacker behaviors across execution, persistence, privilege escalation, and defense evasion. Mapping these adversary techniques to MITRE ATT&CK phases reveals critical detection gaps.

Can I use this approach for red-team simulations across the entire attack lifecycle?

Yes, you can use this approach for red-team simulations across the entire attack lifecycle. It covers recon, initial access, execution, persistence, privilege escalation, defense evasion, credential access, discovery, lateral movement, collection, C2, exfiltration, and impact.

Do I need additional security operations tools to identify detection evasion gaps?

You do not need additional tools to identify detection evasion gaps initially. The Skill encodes a structured playbook with MITRE ATT&CK phases and defense-evasion techniques to highlight gaps and reporting requirements directly.