red-team-tactics

Coordinate structured red-team simulations across MITRE ATT&CK phases.

Updated Jan 21, 2026
One-click install
npx skills add https://github.com/ollieb89/orchestrator --skill red-team-tactics-ollieb89
Or copy as Structured Prompt for Agent
Please help me install this Agent Skill.
Skill: red-team-tactics
Source: https://github.com/ollieb89/orchestrator/tree/main/.cursor/skills/red-team-tactics
Command: npx skills add https://github.com/ollieb89/orchestrator --skill red-team-tactics-ollieb89

SYSTEM DOCUMENTATION & REQUIREMENTS

What problem does it solve?

Red team tactics principles help security teams identify and remediate gaps by mapping attacker behaviors to defenses.

Core Features & Use Cases

  • MITRE ATT&CK-aligned adversary-emulation guidance across multiple phases (reconnaissance, initial access, execution, persistence, privilege escalation, defense evasion, credential access, discovery, lateral movement, collection, command and control, exfiltration, and impact).
  • Ethical testing framework with scoped objectives, safety boundaries, and clear reporting for risk-free blue-team validation.
  • Threat modeling & detection: translate attacker techniques into detection rules and response playbooks for real-world scenarios.

Quick Start

Run a red-team exercise plan tailored to MITRE ATT&CK within your security program.

Frequently Asked Questions about red-team-tactics

High-intent search queries and answers about installing and using this skill.

FAQPage Schema
How do I simulate attacker behaviors to test my security defenses?

Red team simulations map attacker behaviors to your defenses to identify and remediate security gaps. By emulating adversaries across MITRE ATT&CK phases, you can safely test your detection rules, alerts, and response processes against real-world scenarios.

What is adversary emulation and how does it align with MITRE ATT&CK?

Adversary emulation is the practice of simulating attacker tactics and techniques to validate security defenses. This approach aligns with MITRE ATT&CK phases, spanning reconnaissance through impact, to safely test blue-team detection capabilities and response playbooks.

How do I plan a red team exercise with ethical boundaries and safety scoping?

Red team exercises require an ethical testing framework with scoped objectives and clear safety boundaries. This ensures risk-free blue-team validation while maintaining documented testing standards across all adversary simulation phases.

Can I use red team tactics to translate attacker techniques into detection rules?

Red team tactics help translate attacker techniques into actionable detection rules and response playbooks. By mapping threat modeling scenarios to your security program, you can effectively test alerts and improve real-world defense validation.

What is the best way to test defense evasion techniques during a security assessment?

Testing defense evasion concepts during adversary emulation reveals gaps in your security controls. By simulating these evasion techniques within an ethical framework, you can safely validate blue-team detections and strengthen your overall defense posture.