red-team-tactics

Summarize red team tactics and attack lifecycle phases for security planning.

Updated Mar 30, 2026
One-click install
npx skills add https://github.com/pckienuit/GameDev1 --skill red-team-tactics-pckienuit
Or copy as Structured Prompt for Agent
Please help me install this Agent Skill.
Skill: red-team-tactics
Source: https://github.com/pckienuit/GameDev1/tree/main/.cursor-plugin/skills/red-team-tactics
Command: npx skills add https://github.com/pckienuit/GameDev1 --skill red-team-tactics-pckienuit

SYSTEM DOCUMENTATION & REQUIREMENTS

What problem does it solve?

This Skill helps security teams understand adversary behavior at a high level so they can plan simulations, improve detections, and communicate risk clearly.

Core Features & Use Cases

  • Attack Lifecycle Overview: Breaks down the MITRE ATT&CK-style phases from reconnaissance through exfiltration and impact.
  • Technique Mapping: Covers common tactics such as initial access, privilege escalation, defense evasion, credential access, and lateral movement.
  • Reporting and Ethics: Emphasizes documenting attack narratives, identifying detection gaps, and staying within authorized scope.
  • Use Case: Use this Skill when preparing a red team briefing, building a threat emulation plan, or translating offensive activity into defensive improvements.

Quick Start

Ask for a concise red team briefing that summarizes the attack lifecycle, key tactics, reporting priorities, and ethical boundaries for a specific scenario.

Frequently Asked Questions about red-team-tactics

High-intent search queries and answers about installing and using this skill.

FAQPage Schema
What are the key phases of the red team attack lifecycle?

The red team attack lifecycle includes reconnaissance, initial access, privilege escalation, defense evasion, credential access, lateral movement, exfiltration, and impact, mapped to the MITRE ATT&CK framework for clear phase-by-phase adversary simulation planning.

How do I map red team tactics to MITRE ATT&CK techniques for a briefing?

To map red team tactics to MITRE ATT&CK, summarize the attack lifecycle phase-by-phase, covering techniques like initial access and lateral movement. This approach translates offensive activity into defensive improvements, emphasizing detection gaps and ethical boundaries for authorized scope reporting.

Can I use this approach to identify detection gaps from adversary simulation?

Yes, adversary simulation identifies detection gaps by documenting the attack narrative across red team tactics like lateral movement and defense evasion. This concise analysis translates offensive behavior into defensive improvements within authorized ethical boundaries.

How do I build a threat emulation plan using red team tactics?

Build a threat emulation plan by outlining the MITRE ATT&CK attack lifecycle, from reconnaissance through impact. Incorporate specific red team tactics like privilege escalation and defense evasion, ensuring clear phase-by-phase structure and concise detection-gap analysis for defensive use.

What ethical boundaries should I follow during adversary simulation?

Adversary simulation requires staying within authorized scope, documenting attack narratives clearly, and focusing on defensive improvements. Ethical boundaries mandate that red team tactics like lateral movement and credential access are reported concisely to identify detection gaps without exceeding operational limits.