red-team-tactics

Plan red team exercises using MITRE ATT&CK tactics and techniques.

2|Updated Jan 29, 2026
One-click install
npx skills add https://github.com/Tai-ch0802/skills-bundle --skill red-team-tactics-tai-ch0802
Or copy as Structured Prompt for Agent
Please help me install this Agent Skill.
Skill: red-team-tactics
Source: https://github.com/Tai-ch0802/skills-bundle/tree/main/i18n/zh-TW/red-team-tactics
Command: npx skills add https://github.com/Tai-ch0802/skills-bundle --skill red-team-tactics-tai-ch0802

SYSTEM DOCUMENTATION & REQUIREMENTS

💡 This Skill includes references (resource) components.

What problem does it solve?

This Skill provides a structured framework for understanding and executing red team operations, based on the MITRE ATT&CK matrix, to identify and improve an organization's defensive capabilities.

Core Features & Use Cases

  • Adversary Emulation: Understand and apply principles of adversary simulation aligned with the MITRE ATT&CK framework.
  • Attack Lifecycle Mapping: Learn the stages of an attack, from reconnaissance to impact, and the tactics used within each.
  • Defense Evasion & Privilege Escalation: Explore techniques adversaries use to bypass defenses and gain higher privileges.
  • Reporting & Improvement: Focus on documenting attack chains and identifying detection gaps for security enhancement.
  • Use Case: A security analyst can use this Skill to plan and execute a simulated phishing campaign, understanding the steps from initial access to potential data exfiltration, and then report on how defenses could be strengthened.

Quick Start

Use the red-team-tactics skill to outline the steps for a reconnaissance phase in an adversary simulation.

Frequently Asked Questions about red-team-tactics

High-intent search queries and answers about installing and using this skill.

FAQPage Schema
How do I plan red team exercises using the MITRE ATT&CK framework?

Red team exercises using the MITRE ATT&CK framework involve mapping adversary simulation across attack stages, from reconnaissance to impact. This Skill outlines specific tactics and procedures for planning and executing these operations to identify defensive gaps.

What techniques are used for defense evasion in adversary simulation?

Defense evasion in adversary simulation involves techniques adversaries use to bypass security defenses during an attack. This Skill provides principles for understanding and applying these evasion methods alongside privilege escalation tactics within the attack lifecycle.

How do I map the attack lifecycle from initial access to lateral movement?

Mapping the attack lifecycle requires detailing specific tactics for reconnaissance, initial access, privilege escalation, lateral movement, and impact. This Skill structures these stages based on the MITRE ATT&CK matrix to emulate real adversary behavior.

Can I use this adversary simulation framework for planning a phishing campaign?

Yes, you can use this adversary simulation framework to plan a simulated phishing campaign. It helps you understand the steps from initial access to potential data exfiltration and provides principles for reporting on how defenses could be strengthened.

What is the best way to document attack chains and identify detection gaps?

The best way to document attack chains and identify detection gaps is through structured reporting focused on security enhancement. This Skill emphasizes documenting the attack lifecycle and identifying defensive blind spots uncovered during red team operations.

Does adversary simulation require prerequisite knowledge of penetration testing?

Adversary simulation is designed for cybersecurity professionals, requiring a foundational understanding of penetration testing and adversary tactics. This Skill applies these principles to help users execute red team exercises and improve organizational defensive capabilities.