red-team-tactics

Plan red-team adversary simulations aligned with MITRE ATT&CK phases.

Updated Jan 24, 2026
One-click install
npx skills add https://github.com/lehoangphuc747/anki-lms-demo --skill red-team-tactics-lehoangphuc747
Or copy as Structured Prompt for Agent
Please help me install this Agent Skill.
Skill: red-team-tactics
Source: https://github.com/lehoangphuc747/anki-lms-demo/tree/main/.agent/skills/red-team-tactics
Command: npx skills add https://github.com/lehoangphuc747/anki-lms-demo --skill red-team-tactics-lehoangphuc747

SYSTEM DOCUMENTATION & REQUIREMENTS

What problem does it solve?

Red team adversary simulations guided by MITRE ATT&CK help security teams assess and improve their defenses without real-world harm.

Core Features & Use Cases

  • Phase-aligned adversary simulation framework based on MITRE ATT&CK.
  • Guidance on reconnaissance, initial access, execution, persistence, defense evasion, credential access, discovery, lateral movement, collection, C2, exfiltration, and reporting.
  • Use Case: Plan and execute controlled red-team exercises to identify detection gaps, validate response playbooks, and train defenders.

Quick Start

Describe a controlled red-team scenario aligned to MITRE ATT&CK to begin a defensive exercise.

Frequently Asked Questions about red-team-tactics

High-intent search queries and answers about installing and using this skill.

FAQPage Schema
What is a red team adversary simulation based on MITRE ATT&CK?

A red team adversary simulation based on MITRE ATT&CK is a controlled security testing exercise that mimics real-world attackers to safely assess enterprise network defenses, identify detection gaps, and validate incident response playbooks.

How do I plan a red team exercise aligned with MITRE ATT&CK phases?

To plan a red team exercise, map simulated attacker actions to MITRE ATT&CK phases like reconnaissance, initial access, persistence, defense evasion, and lateral movement, using structured reporting templates for post-exercise analysis.

Can I use adversary simulation frameworks for incident response planning?

Yes, adversary simulation frameworks are highly applicable for incident response planning. They help validate existing response playbooks by safely emulating threat modeling scenarios and testing defender reactions across enterprise networks.

Does this red team framework provide guidance on detection evasion?

Yes, the framework provides specific guidance on defense evasion techniques during simulated attacks, allowing security teams to accurately test detection capabilities and identify blind spots in their monitoring infrastructure.

What is the best way to structure threat modeling for enterprise security testing?

The best way to structure threat modeling for security testing is aligning adversary simulation phases with the MITRE ATT&CK framework, covering execution, credential access, collection, and exfiltration to comprehensively evaluate defensive postures.

When should I use MITRE ATT&CK for security testing instead of other approaches?

You should use MITRE ATT&CK for security testing when you need a structured, phase-aligned adversary simulation to uncover specific detection gaps, train defenders, and validate incident response procedures without causing real-world harm.