red-team-tactics

Coordinate red-team planning and post-engagement reporting using MITRE ATT&CK.

Updated Jan 6, 2026
One-click install
npx skills add https://github.com/marablemarcel/Living-Lytics --skill red-team-tactics-marablemarcel
Or copy as Structured Prompt for Agent
Please help me install this Agent Skill.
Skill: red-team-tactics
Source: https://github.com/marablemarcel/Living-Lytics/tree/main/living-lytics/.agent/skills/red-team-tactics
Command: npx skills add https://github.com/marablemarcel/Living-Lytics --skill red-team-tactics-marablemarcel

SYSTEM DOCUMENTATION & REQUIREMENTS

What problem does it solve?

Enables security teams to plan, simulate, and report red-team activities in a structured, MITRE ATT&CK-aligned framework, reducing ambiguity and improving defense gaps identification.

Core Features & Use Cases

  • MITRE ATT&CK phased mapping and threat modeling to guide engagements
  • Ethical boundaries, reporting discipline, and post-engagement remediation guidance
  • Use cases include defense testing, incident rehearsal, and training blue-team responders

Quick Start

Provide an ATT&CK-aligned red-team plan for a defined environment and outline detection gaps.

Frequently Asked Questions about red-team-tactics

High-intent search queries and answers about installing and using this skill.

FAQPage Schema
How do I plan a red-team engagement using MITRE ATT&CK?

Structure red-team reporting by mapping simulated activities to MITRE ATT&CK phases. This aligns executed tactics with detection gaps and ethical boundaries, producing remediation recommendations for blue-team exercises and risk assessments.

What is MITRE ATT&CK phased threat modeling for security operations?

MITRE ATT&CK phased threat modeling maps simulated attacker behaviors across core phases like Lateral Movement and Credential Access. It provides security operations centers a structured framework to test detection coverage and rehearse incident responses.

How do I identify detection coverage gaps during a blue-team exercise?

Identify detection gaps by mapping simulated attack phases against current security monitoring capabilities. Evaluating attacker tactics like C2 and Lateral Movement against existing defenses highlights specific areas where detection visibility is missing.

Can I use this approach for training blue-team incident responders?

Yes, this approach trains blue-team responders through incident rehearsal and defense testing. It simulates phased attacker tactics within ethical boundaries, providing a structured model to evaluate and improve defensive response capabilities.

What are the ethical boundaries for attack simulation in risk assessments?

Ethical boundaries for attack simulation define strict operational limits during risk assessments to prevent unauthorized damage. The framework specifies guiding principles and anti-patterns, ensuring red-team engagements remain controlled and focused on defense strengthening.