red-team-tactics

Explain Red Team attack phases and adversary simulation using the MITRE ATT&CK framework.

Updated Feb 28, 2026
One-click install
npx skills add https://github.com/lucasfdigital/Orchard --skill red-team-tactics-lucasfdigital
Or copy as Structured Prompt for Agent
Please help me install this Agent Skill.
Skill: red-team-tactics
Source: https://github.com/lucasfdigital/Orchard/tree/main/skills/red-team-tactics
Command: npx skills add https://github.com/lucasfdigital/Orchard --skill red-team-tactics-lucasfdigital

SYSTEM DOCUMENTATION & REQUIREMENTS

💡 This Skill includes references (resource) components.

What problem does it solve?

This Skill provides a comprehensive understanding of Red Team operations, enabling users to simulate adversary tactics effectively and identify security weaknesses.

Core Features & Use Cases

  • MITRE ATT&CK Framework: Detailed breakdown of attack phases and objectives.
  • Adversary Simulation: Principles for reconnaissance, initial access, execution, persistence, privilege escalation, defense evasion, and lateral movement.
  • Reporting & OpSec: Guidance on documenting findings and maintaining operational security.
  • Use Case: A security analyst can use this Skill to learn the methodologies behind advanced persistent threats (APTs) to better prepare their organization's defenses.

Quick Start

Explain the reconnaissance phase of the MITRE ATT&CK framework.

Frequently Asked Questions about red-team-tactics

High-intent search queries and answers about installing and using this skill.

FAQPage Schema
How do I simulate adversary tactics using the MITRE ATT&CK framework?

To simulate adversary tactics using the MITRE ATT&CK framework, you follow structured attack phases including reconnaissance, initial access, execution, and persistence to identify security weaknesses.

What are the key phases of red team operations for cybersecurity assessments?

Key red team operations phases include reconnaissance, initial access, defense evasion, privilege escalation, and lateral movement, providing principles to simulate advanced persistent threats.

How do red teams maintain operational security during adversary simulations?

Red teams maintain operational security during adversary simulations by following specific principles for defense evasion and utilizing reporting best practices to document findings without exposing methodologies.

Can I use this methodology to understand threat actor TTPs for security improvement?

Yes, you can use this methodology to understand threat actor TTPs. It breaks down attack phases and objectives, facilitating threat comprehension for security assessment and organizational defense improvement.

What is the best way to document findings from a red team engagement?

The best way to document red team engagement findings is to follow reporting best practices that detail the attack phases, adversary simulation techniques used, and identified security weaknesses.

Does adversary simulation cover privilege escalation and lateral movement techniques?

Yes, adversary simulation covers privilege escalation and lateral movement techniques. It provides principles for these phases alongside reconnaissance, initial access, execution, persistence, and defense evasion.