red-team-tactics

Map attack phases to MITRE ATT&CK for authorized adversary simulations.

Updated Feb 19, 2026
One-click install
npx skills add https://github.com/jonnathan-ls/ai-context-kit --skill red-team-tactics-jonnathan-ls
Or copy as Structured Prompt for Agent
Please help me install this Agent Skill.
Skill: red-team-tactics
Source: https://github.com/jonnathan-ls/ai-context-kit/tree/main/skills/red-team-tactics
Command: npx skills add https://github.com/jonnathan-ls/ai-context-kit --skill red-team-tactics-jonnathan-ls

SYSTEM DOCUMENTATION & REQUIREMENTS

What problem does it solve?

This Skill provides structured red-team tactics guidance aligned to the MITRE ATT&CK framework to support authorized adversary simulations, exercises, and reports.

Core Features & Use Cases

  • MITRE ATT&CK phase mapping and attack lifecycle overview to guide planning and execution.
  • Ethical boundaries, scope control, and reporting guidelines to ensure responsible testing and clear outcomes.
  • Reproducible playbooks and checklists for scoping, execution, and debriefing across multiple engagement scenarios.

Quick Start

Describe an authorized red-team scenario using the MITRE ATT&CK framework to plan phases, detections, and reporting.

Frequently Asked Questions about red-team-tactics

High-intent search queries and answers about installing and using this skill.

FAQPage Schema
How do I map red-team attack phases to the MITRE ATT&CK framework?

Red-team attack phases map to MITRE ATT&CK by aligning reconnaissance, initial access, defense evasion, and lateral movement vectors with corresponding tactics and techniques to guide authorized adversary simulation planning and execution.

What ethical boundaries and scope controls apply to adversary simulations?

Adversary simulations require strict ethical boundaries and scope control to ensure responsible penetration testing, preventing unauthorized actions while maintaining clear, reproducible playbooks for scoping and debriefing engagements.

How should I structure reporting for a red-team engagement?

Red-team reporting should follow prescribed guidelines that map executed attack phases to MITRE ATT&CK techniques, documenting detections and mitigations evaluated during the authorized penetration testing or tabletop exercise.

Can this guidance be applied to tabletop exercises and penetration testing?

Yes, this guidance applies to both tabletop exercises and penetration testing, providing structured checklists and attack lifecycle overviews to help defenders evaluate their detections and mitigations against simulated threats.

What initial access vectors and defense evasion principles does this cover?

It enumerates specific reconnaissance and initial access vectors alongside detailed defense evasion and lateral movement principles, applying these to structured red-team tactics within the MITRE ATT&CK framework for authorized simulations.