red-team-tactics

Map attacker techniques and simulate the MITRE ATT&CK lifecycle for red-team exercises.

Updated Mar 18, 2026
One-click install
npx skills add https://github.com/raccioly/coach-gravity --skill red-team-tactics-raccioly
Or copy as Structured Prompt for Agent
Please help me install this Agent Skill.
Skill: red-team-tactics
Source: https://github.com/raccioly/coach-gravity/tree/main/content/starter-kit/skills/red-team-tactics
Command: npx skills add https://github.com/raccioly/coach-gravity --skill red-team-tactics-raccioly

SYSTEM DOCUMENTATION & REQUIREMENTS

What problem does it solve?

Security teams need structured guidance to understand and simulate attacker tactics and to improve detection and response capabilities.

Core Features & Use Cases

  • MITRE ATT&CK phase mapping and adversary simulation guidance.
  • Threat modeling, detection gap analysis, and incident response planning.
  • Use Case: Run a controlled red-team exercise to identify gaps across recon, initial access, execution, persistence, privilege escalation, defense evasion, and exfiltration.

Quick Start

Run a red-team scenario against a test environment using the ATT&CK reference to map techniques to detections.

Frequently Asked Questions about red-team-tactics

High-intent search queries and answers about installing and using this skill.

FAQPage Schema
How do I map attacker techniques using the MITRE ATT&CK framework for red-team exercises?

Map attacker techniques by simulating the full MITRE ATT&CK lifecycle to identify detection gaps. This guides red-team exercises across phases like initial access, execution, persistence, privilege escalation, defense evasion, and exfiltration.

What is the best way to simulate adversary tactics for threat modeling in enterprise networks?

Simulate adversary tactics by applying structured threat modeling against enterprise networks and cloud environments. This process identifies security gaps and improves detection and response capabilities across the attack lifecycle.

How do I perform a detection gap analysis using MITRE ATT&CK mappings?

Perform detection gap analysis by mapping simulated attacker techniques to your existing security controls. This reveals blind spots in your defenses and informs incident response planning across enterprise and cloud infrastructures.

Can I use this for incident response planning across cloud environments and enterprise networks?

Yes, incident response planning is supported across both enterprise networks and cloud environments. The skill provides structured guidance for evidence collection, risk assessment, and detection gap analysis to improve response capabilities.

Do I need defined reporting templates to run a red-team simulation?

Yes, a defined ATT&CK mapping, reporting templates, and guidance for evidence collection are required. These prerequisites ensure the red-team simulation accurately maps techniques to detections and produces actionable risk assessments.