red-team-tactics

Apply MITRE ATT&CK phases to plan red-team exercises.

Updated Jan 20, 2026
One-click install
npx skills add https://github.com/lchenrique/politron-ide --skill red-team-tactics-lchenrique
Or copy as Structured Prompt for Agent
Please help me install this Agent Skill.
Skill: red-team-tactics
Source: https://github.com/lchenrique/politron-ide/tree/main/.agent/skills/red-team-tactics
Command: npx skills add https://github.com/lchenrique/politron-ide --skill red-team-tactics-lchenrique

SYSTEM DOCUMENTATION & REQUIREMENTS

What problem does it solve?

This Skill helps security teams understand and practice adversary simulations by framing security testing around MITRE ATT&CK phases, enabling structured assessments.

Core Features & Use Cases

  • Modelled attack lifecycle: Covers reconnaissance, initial access, execution, persistence, privilege escalation, defense evasion, credential access, discovery, lateral movement, collection, C2, exfiltration, and impact.
  • Educational framing: Provides clear guidelines for threat modeling, red-team planning, and defense gap reporting.
  • Use Case: When preparing a tabletop or practical red-team exercise, this Skill guides the scenario design and evaluation criteria.

Quick Start

Describe a red-team scenario using MITRE ATT&CK phases for a simulated enterprise environment.

Frequently Asked Questions about red-team-tactics

High-intent search queries and answers about installing and using this skill.

FAQPage Schema
How do I simulate adversary attacks using MITRE ATT&CK phases for red-team exercises?

To simulate adversary attacks using MITRE ATT&CK, this Skill guides scenario design across the full attack lifecycle, from reconnaissance to impact, for structured enterprise testing without requiring external tooling.

What is adversary simulation in threat modeling and when do I need it?

Adversary simulation in threat modeling is the practice of emulating attacker behaviors to test defenses. You need it when preparing tabletop or practical red-team exercises to identify security gaps and evaluate defensive controls.

Can I use this red-team planning framework for tabletop exercises without external security tools?

Yes, you can use this framework for tabletop exercises without external security tools. It operates using structured prompts and standard defensive testing practices to deliver scenario design and evaluation criteria.

What's the best way to structure a red-team scenario covering the full enterprise attack lifecycle?

The best way to structure a red-team scenario is by mapping it to MITRE ATT&CK phases, covering reconnaissance, initial access, execution, persistence, privilege escalation, defense evasion, credential access, and lateral movement.

Does this adversary simulation approach cover defense evasion and lateral movement tactics?

Yes, this adversary simulation approach covers defense evasion and lateral movement tactics. It models the complete attack lifecycle including credential access, discovery, collection, command and control, exfiltration, and impact.

How do I report defense gaps discovered during red-team security testing?

To report defense gaps discovered during red-team security testing, this Skill provides educational framing and clear guidelines for evaluating defensive controls and documenting assessment results across simulated attack scenarios.