red-team-tactics

Summarize red-team tactics using the MITRE ATT&CK framework.

Updated Dec 28, 2025
One-click install
npx skills add https://github.com/oalansilva/crypto --skill red-team-tactics-oalansilva
Or copy as Structured Prompt for Agent
Please help me install this Agent Skill.
Skill: red-team-tactics
Source: https://github.com/oalansilva/crypto/tree/main/.agent/skills/red-team-tactics
Command: npx skills add https://github.com/oalansilva/crypto --skill red-team-tactics-oalansilva

SYSTEM DOCUMENTATION & REQUIREMENTS

What problem does it solve?

Red-team tactics principles based on the MITRE ATT&CK framework provide a structured lens for understanding attacker techniques, improving threat modeling, and guiding defender strategies.

Core Features & Use Cases

  • Attack lifecycle mapping across MITRE phases (Reconnaissance, Initial Access, Execution, Persistence, Privilege Escalation, Defense Evasion, Credential Access, Discovery, Lateral Movement, Collection, C2, Exfiltration, Impact).
  • Practical guidance on detection evasion, adversary simulation ethics, reporting for governance, and risk-aware testing.
  • Use cases for security teams conducting tabletop exercises, red-team planning, security control validation, and threat-hunting programs.

Quick Start

Analyze a hypothetical enterprise environment and generate a threat-model summary highlighting ATT&CK phases and recommended defenses.

Frequently Asked Questions about red-team-tactics

High-intent search queries and answers about installing and using this skill.

FAQPage Schema
How do I map red-team tactics to MITRE ATT&CK phases for threat modeling?

Map red-team tactics to MITRE ATT&CK phases by analyzing the attack lifecycle from Reconnaissance to Impact. This threat-modeling approach structures adversary techniques into distinct phases, highlighting defense-evasion considerations and recommended defenses to improve your security posture.

What is adversary simulation ethics and why is it important for security assessments?

Adversary simulation ethics define the risk-aware testing boundaries and reporting standards required during red-team planning. Following these ethical boundaries ensures security assessments validate detection engineering without disrupting enterprise network operations or violating governance policies.

How do I plan a red-team exercise for enterprise network security control validation?

Plan a red-team exercise by generating a threat-model summary that maps simulated adversary techniques across MITRE ATT&CK phases. This validates security controls, guides threat-hunting programs, and ensures detection evasion considerations and reporting standards are followed across the enterprise network.

Can I use MITRE ATT&CK framework for detection engineering and threat hunting?

Yes, you can use the MITRE ATT&CK framework for detection engineering and threat hunting programs. It provides a structured lens for understanding attacker techniques, mapping the attack lifecycle, and guiding defender strategies to strengthen your overall security posture.

What are the limitations of using red-team tactics summaries for security posture improvement?

Red-team tactics summaries provide structured threat-modeling guidance but require strict adherence to ethical boundaries and risk-aware testing. They simulate adversaries to strengthen defenses but do not replace active security assessments or continuous detection engineering across enterprise networks.