red-team-tactics

Implement red team exercises aligned with the MITRE ATT&CK framework.

1|Updated Jun 23, 2026
One-click install
npx skills add https://github.com/phuonghx/aim-cli --skill red-team-tactics-phuonghx
Or copy as Structured Prompt for Agent
Please help me install this Agent Skill.
Skill: red-team-tactics
Source: https://github.com/phuonghx/aim-cli/tree/main/aim/templates/aim-agents/skills/red-team-tactics
Command: npx skills add https://github.com/phuonghx/aim-cli --skill red-team-tactics-phuonghx

SYSTEM DOCUMENTATION & REQUIREMENTS

💡 This Skill includes scripts (resource) and references (resource) components.

What problem does it solve?

This Skill provides a structured approach to red teaming by following the MITRE ATT&CK framework, helping organizations uncover detection gaps and enhance their security posture.

Core Features & Use Cases

  • ATT&CK Framework Alignment: Aligns red team exercises with the MITRE ATT&CK lifecycle, covering stages like reconnaissance, initial access, and lateral movement.
  • Objective-Based Scoping: Assists in defining objectives for red team exercises, ensuring minimal impact and focus on detection gaps.
  • Reporting and Analysis: Generates reports detailing the attack chain and the effectiveness of detection measures.

Quick Start

Use the red-team-tactics skill to initiate a penetration test with a focus on initial access via phishing.

Frequently Asked Questions about red-team-tactics

High-intent search queries and answers about installing and using this skill.

FAQPage Schema
How do I simulate adversary tactics using the MITRE ATT&CK framework for security validation?

To simulate adversary tactics using the MITRE ATT&CK framework, you align red teaming exercises across stages like reconnaissance, initial access, and lateral movement to validate security detection measures. This structured approach uncovers network gaps and enhances organizational posture.

What is the best way to scope a red team exercise to minimize operational impact?

The best way to scope a red team exercise is through objective-based scoping that defines specific targets for detecting security gaps while ensuring minimal operational impact. This focuses the adversary simulation strictly on validating defensive measures.

Can I use adversary simulation to test initial access techniques like phishing?

Yes, you can use adversary simulation to test initial access techniques like phishing. The framework supports simulating various attack vectors including execution, persistence, and privilege escalation to thoroughly evaluate your security controls.

Does red teaming following MITRE ATT&CK require prior authorization for penetration testing?

Yes, red teaming following MITRE ATT&CK requires explicit authorization before conducting sensitive operations. Proper authorization is mandatory to ensure the adversary simulation remains a legally compliant security validation exercise.

How do I generate reports detailing the attack chain and detection effectiveness?

You generate reports detailing the attack chain and detection effectiveness by analyzing the adversary simulation results across the MITRE ATT&CK lifecycle. The reporting feature maps executed techniques to identify specific security validation gaps.