red-team-tactics

Guide red team tactics using the MITRE ATT&CK framework.

Updated Aug 5, 2025
One-click install
npx skills add https://github.com/lehuuhau1231/TechJobs --skill red-team-tactics-lehuuhau1231
Or copy as Structured Prompt for Agent
Please help me install this Agent Skill.
Skill: red-team-tactics
Source: https://github.com/lehuuhau1231/TechJobs/tree/main/tech-job-client/.agent/skills/red-team-tactics
Command: npx skills add https://github.com/lehuuhau1231/TechJobs --skill red-team-tactics-lehuuhau1231

SYSTEM DOCUMENTATION & REQUIREMENTS

💡 This Skill includes scripts (resource) and references (resource) components.

What problem does it solve?

This Skill provides a comprehensive guide to red team tactics based on the MITRE ATT&CK framework, helping security professionals understand and prepare for potential attacks.

Core Features & Use Cases

  • Red Team Principles: Offers an in-depth look into attack phases, detection evasion, and reporting.
  • Attack Phases: Explains the MITRE ATT&CK attack lifecycle and objectives for each phase.
  • Principles and Techniques: Discusses reconnaissance, initial access, privilege escalation, defense evasion, lateral movement, and more.
  • Active Directory Attacks: Special focus on Kerberoasting, AS-REP Roasting, DCSync, Golden Ticket, and other attack categories.
  • Reporting and Ethical Boundaries: Emphasizes documenting the attack narrative, detection gaps, and ethical considerations.

Quick Start

Use the red-team-tactics skill to understand the reconnaissance phase of a red team attack and its objectives.

Frequently Asked Questions about red-team-tactics

High-intent search queries and answers about installing and using this skill.

FAQPage Schema
What are the key phases of a red team attack simulation based on the MITRE ATT&CK framework?

Red team attack simulations based on the MITRE ATT&CK framework follow key phases including reconnaissance, initial access, privilege escalation, defense evasion, and lateral movement. Each phase has specific objectives to help security professionals understand attacker tactics.

How do I simulate Active Directory attacks like Kerberoasting and Golden Ticket for security testing?

To simulate Active Directory attacks for security testing, this Skill provides detailed guides on executing techniques like Kerberoasting, AS-REP Roasting, DCSync, and Golden Ticket attacks. These simulations help identify vulnerabilities within your Active Directory environment.

What techniques are used for detection evasion during a red team engagement?

Detection evasion during a red team engagement involves specific principles and techniques outlined in the MITRE ATT&CK framework. This Skill explains how attackers bypass security controls, allowing you to test and improve your organization's defense evasion detection capabilities.

How do I document and report red team attack narratives and detection gaps?

Documenting red team attack narratives and detection gaps requires focusing on ethical boundaries and reporting principles. This Skill emphasizes recording the attack lifecycle, identifying where defenses failed, and structuring the report to improve security postures.

Is this red team tactics guide suitable for understanding ethical boundaries in cybersecurity?

Yes, this red team tactics guide is suitable for understanding ethical boundaries in cybersecurity. It specifically emphasizes ethical considerations and boundaries during attack simulations to ensure security professionals conduct tests responsibly and safely.

Can I use this MITRE ATT&CK guide for privilege escalation and lateral movement testing?

Yes, you can use this MITRE ATT&CK guide for privilege escalation and lateral movement testing. It provides in-depth principles and techniques for these specific attack phases to help you simulate realistic threats and evaluate your network defenses.