red-team-tactics

Explain red team tactics and adversary simulation aligned with MITRE ATT&CK.

Updated Feb 6, 2026
One-click install
npx skills add https://github.com/ntuan2502/piggy --skill red-team-tactics-ntuan2502
Or copy as Structured Prompt for Agent
Please help me install this Agent Skill.
Skill: red-team-tactics
Source: https://github.com/ntuan2502/piggy/tree/main/.agent/skills/red-team-tactics
Command: npx skills add https://github.com/ntuan2502/piggy --skill red-team-tactics-ntuan2502

SYSTEM DOCUMENTATION & REQUIREMENTS

What problem does it solve?

This Skill provides a structured understanding of red team tactics and adversary simulation principles, enabling users to learn and apply advanced security testing methodologies.

Core Features & Use Cases

  • MITRE ATT&CK Framework: Detailed breakdown of attack lifecycle phases and objectives.
  • Tactical Principles: Guidance on reconnaissance, initial access, privilege escalation, defense evasion, lateral movement, and more.
  • Use Case: A security analyst can use this Skill to prepare for a penetration test by understanding the common phases and techniques an attacker might employ, and how to simulate them effectively.

Quick Start

Explain the principles of reconnaissance in red team tactics.

Frequently Asked Questions about red-team-tactics

High-intent search queries and answers about installing and using this skill.

FAQPage Schema
What is adversary simulation and how does it align with the MITRE ATT&CK framework?

Adversary simulation emulates advanced threat behaviors to test defenses. It maps directly to the MITRE ATT&CK framework by structuring attack lifecycle phases like reconnaissance, initial access, privilege escalation, and lateral movement into tactical objectives.

How do I prepare for a penetration test using red team tactics?

Prepare for penetration testing by mapping target environments to MITRE ATT&CK phases. Structure simulations around reconnaissance, initial access, defense evasion, and privilege escalation to emulate realistic adversary behaviors and identify security gaps.

What are the core phases of the attack lifecycle in cybersecurity?

The core attack lifecycle phases include reconnaissance, initial access, privilege escalation, defense evasion, and lateral movement. These phases structure red team operations and guide adversary simulation exercises.

Can I use this approach to understand defense evasion techniques?

Yes, you can learn defense evasion techniques through structured adversary simulation principles. It provides tactical guidance on how attackers bypass security controls during the attack lifecycle, aligned with the MITRE ATT&CK framework.

Do I need prior cybersecurity knowledge to understand red team tactics?

Prior cybersecurity knowledge is recommended. This material is tailored for security professionals and ethical hackers who need to understand advanced threat emulation and apply penetration testing methodologies effectively.