red-team-tactics

Outline MITRE ATT&CK-based red-team tactics for adversary emulation.

8|Updated Feb 4, 2026
One-click install
npx skills add https://github.com/MisonL/Ling --skill red-team-tactics-misonl
Or copy as Structured Prompt for Agent
Please help me install this Agent Skill.
Skill: red-team-tactics
Source: https://github.com/MisonL/Ling/tree/main/.agents/skills/red-team-tactics
Command: npx skills add https://github.com/MisonL/Ling --skill red-team-tactics-misonl

SYSTEM DOCUMENTATION & REQUIREMENTS

What problem does it solve?

Security teams often struggle to model attacker behavior and communicate defensive gaps. This skill provides a structured framework based on MITRE ATT&CK to define red-team tactics, attacker goals, and the corresponding defensive checks.

Core Features & Use Cases

  • MITRE ATT&CK phase mapping for adversary emulation, covering Reconnaissance through Impact.
  • Clear phase objectives, techniques, and ethical guidelines to plan safe, authorized assessments.
  • Use cases include security assessments, threat-modeling exercises, and blue-team readiness training.

Quick Start

Review the MITRE ATT&CK matrix and draft a plan for your next authorized red-team exercise.

Frequently Asked Questions about red-team-tactics

High-intent search queries and answers about installing and using this skill.

FAQPage Schema
How do I plan red-team exercises using MITRE ATT&CK?

MITRE ATT&CK maps adversary emulation tactics across security phases from Reconnaissance to Impact, providing structured mappings and objective definitions to plan safe, authorized red-team exercises.

What is adversary simulation and how does threat emulation work?

Adversary simulation models attacker behavior to test defensive readiness, while threat emulation applies MITRE ATT&CK phase mappings to replicate specific attacker tactics from Recon to Impact during authorized assessments.

Can I use MITRE ATT&CK phase mapping for blue-team readiness training?

Yes, MITRE ATT&CK phase mapping supports blue-team readiness training by simulating attacker behavior, helping security teams identify defensive gaps and validate threat-modeling exercises across the attack lifecycle.

How do I define objectives for authorized security assessments?

Define objectives for authorized security assessments by mapping red-team tactics to MITRE ATT&CK phases, ensuring each simulated attacker goal from Recon to Impact includes ethical guidelines for safe testing.

What are the ethical guidelines for red-team adversary emulation?

Ethical guidelines for red-team adversary emulation ensure safe, authorized testing by defining boundaries for threat modeling and security assessments, preventing unauthorized impact during attacker behavior simulation.

Does this approach to red-team tactics require prior threat modeling experience?

No prior threat modeling experience is strictly required, as the framework provides structured MITRE ATT&CK phase mappings and objective definitions, though familiarity with adversary simulation enhances security assessment outcomes.