red-team-tactics

Simulate adversaries to test defenses using MITRE ATT&CK phases.

Updated Jan 29, 2026
One-click install
npx skills add https://github.com/rahlplx/New-Smile-Savers --skill red-team-tactics-rahlplx
Or copy as Structured Prompt for Agent
Please help me install this Agent Skill.
Skill: red-team-tactics
Source: https://github.com/rahlplx/New-Smile-Savers/tree/main/smile-savers-site/.agent/skills/red-team-tactics
Command: npx skills add https://github.com/rahlplx/New-Smile-Savers --skill red-team-tactics-rahlplx

SYSTEM DOCUMENTATION & REQUIREMENTS

What problem does it solve?

Red team practitioners need a structured, evidence-based framework to simulate attacker behavior, evaluate defenses, and generate actionable reports.

Core Features & Use Cases

  • MITRE ATT&CK-aligned phases covering reconnaissance to impact for realistic simulations.
  • Detection-evasion awareness to test visibility and SOAR responses in controlled environments.
  • Reporting-ready outputs including narratives and gaps to drive defender improvements.

Quick Start

Execute a controlled red-team engagement against a test environment following MITRE ATT&CK phases to validate defenses.

Frequently Asked Questions about red-team-tactics

High-intent search queries and answers about installing and using this skill.

FAQPage Schema
How do I simulate adversaries to test defenses using MITRE ATT&CK?

Adversary simulation using MITRE ATT&CK involves executing structured attack phases from reconnaissance to impact. This process evaluates enterprise network defenses by replicating realistic attacker behavior within controlled environments.

What is detection evasion in red team engagements?

Detection evasion in red team engagements is the practice of bypassing security visibility and SOAR responses. It tests whether defenders can successfully identify and react to sophisticated attacker techniques during security assessments.

How do I structure red team reporting for defender improvements?

Red team reporting structures should include detailed attack narratives and identified security gaps. These reporting-ready outputs drive defender improvements by highlighting specific weaknesses discovered during adversary simulations.

Can I use adversary simulation for security training and incident simulations?

Yes, adversary simulation can be applied to security training and incident simulations across enterprise networks. It provides an evidence-based framework to evaluate defensive capabilities and generate actionable reports for participants.

What are the MITRE ATT&CK phases for a controlled red-team engagement?

The MITRE ATT&CK phases for a controlled red-team engagement cover the full attack lifecycle from reconnaissance to impact. These structured phases provide a framework to validate defenses within a test environment.