red-team-tactics

Organize adversary simulation tactics and defensive reporting workflows for attack lifecycle analysis.

Updated Jun 17, 2026
One-click install
npx skills add https://github.com/JingyueCong/LatentRiskBench --skill red-team-tactics-jingyuecong
Or copy as Structured Prompt for Agent
Please help me install this Agent Skill.
Skill: red-team-tactics
Source: https://github.com/JingyueCong/LatentRiskBench/tree/main/latentriskbench/agent/skills/red-team-tactics
Command: npx skills add https://github.com/JingyueCong/LatentRiskBench --skill red-team-tactics-jingyuecong

SYSTEM DOCUMENTATION & REQUIREMENTS

What problem does it solve?

This Skill helps security teams understand adversary simulation methods and organize red team activities using structured attack lifecycle concepts without losing focus on defensive improvement.

Core Features & Use Cases

  • Attack Lifecycle Guidance: Covers reconnaissance, access, execution, persistence, evasion, discovery, and other adversary simulation phases based on MITRE ATT&CK concepts.
  • Assessment Frameworks: Provides principles for analyzing attack paths, documenting findings, and identifying detection gaps.
  • Use Case: A security analyst can use this Skill to structure a controlled red team assessment report by mapping observed behaviors to attack phases and defensive improvements.

Quick Start

Use the red-team-tactics skill to help organize a security assessment report using red team lifecycle principles.

Frequently Asked Questions about red-team-tactics

High-intent search queries and answers about installing and using this skill.

FAQPage Schema
How do I structure a red team assessment report using attack lifecycle principles?

Structure a red team assessment report by mapping observed adversary simulation behaviors to MITRE ATT&CK phases and identifying defensive detection gaps. This organizes findings from reconnaissance through evasion into actionable security improvements.

What is the MITRE ATT&CK framework's role in adversary simulation and threat modeling?

The MITRE ATT&CK framework provides structured knowledge for adversary simulation by defining attack lifecycle phases like reconnaissance, execution, and persistence. It maps observed behaviors to guide red team planning and threat modeling activities.

How do I analyze attack paths to identify detection gaps during a security assessment?

Analyze attack paths by documenting adversary simulation findings across execution and discovery phases, then mapping them against existing defenses. This identifies detection gaps and highlights required security assessment improvements.

Can I use red team methodology for defensive improvement without crossing ethical testing boundaries?

Red team methodology applies to defensive improvement through controlled adversary simulation, requiring structured knowledge of ethical testing boundaries. It organizes security reviews to analyze attack behaviors while maintaining strict ethical constraints.

What's the best way to organize red team planning activities for a cybersecurity assessment?

Organize red team planning by applying structured attack lifecycle concepts from reconnaissance to evasion. This methodology ensures adversary simulation activities cover all MITRE ATT&CK phases for comprehensive cybersecurity assessment coverage.

When do I need threat modeling for red team operations versus standard security reviews?

Threat modeling for red team operations is needed when conducting adversary simulation to analyze attack behaviors and identify detection gaps. It provides structured attack lifecycle analysis beyond standard security reviews by mapping MITRE ATT&CK phases.