red-team-tactics

Map attacker techniques to MITRE ATT&CK phases for red-team exercises.

5|2|Updated Mar 1, 2026
One-click install
npx skills add https://github.com/umairinayat/Specter-AI --skill red-team-tactics-umairinayat
Or copy as Structured Prompt for Agent
Please help me install this Agent Skill.
Skill: red-team-tactics
Source: https://github.com/umairinayat/Specter-AI/tree/main/.agent/skills/red-team-tactics
Command: npx skills add https://github.com/umairinayat/Specter-AI --skill red-team-tactics-umairinayat

SYSTEM DOCUMENTATION & REQUIREMENTS

What problem does it solve?

Provides structured principles and guidance for conducting red-team simulations aligned with the MITRE ATT&CK framework, helping defenders improve detection and response.

Core Features & Use Cases

  • MITRE-aligned Phases: covers Reconnaissance, Initial Access, Execution, Persistence, Privilege Escalation, Defense Evasion, Credential Access, Discovery, Lateral Movement, Collection, C2, Exfiltration, and Impact for comprehensive exercise planning.
  • Ethical Security Guidance: emphasizes scoped testing, reporting, and strict ethical considerations to prevent unintended harm.
  • Use Case: security teams plan and execute controlled red-team exercises to identify detection gaps and improve incident response.

Quick Start

Run a guided red-team planning session against a test environment following MITRE ATT&CK mapping.

Frequently Asked Questions about red-team-tactics

High-intent search queries and answers about installing and using this skill.

FAQPage Schema
How do I map red-team exercises to the MITRE ATT&CK framework?

Mapping red-team exercises to MITRE ATT&CK involves simulating attacker techniques across phases like reconnaissance, initial access, and exfiltration. This structured mapping guides controlled testing to identify detection gaps and strengthen defensive readiness.

What ethical boundaries should I follow during red-team security testing?

Ethical red-team security testing requires strict scoping, defined reporting expectations, and controlled environments to prevent unintended harm. These boundaries ensure realistic threat emulation while maintaining safe engagement limits during the simulation.

Can I use MITRE ATT&CK mapping for defense evasion and privilege escalation simulations?

MITRE ATT&CK mapping covers defense evasion, privilege escalation, credential access, and lateral movement for comprehensive threat emulation. You can apply these tactics to simulate realistic attacker behaviors and test your environment's detection capabilities.

How do I plan a red-team engagement to identify incident response gaps?

Planning a red-team engagement involves mapping simulated techniques across attack phases from initial access to impact. This structured exercise evaluates your incident response capabilities by revealing detection gaps and improving defensive readiness.

What is threat emulation and when do I need it for security testing?

Threat emulation is the simulation of attacker techniques using frameworks like MITRE ATT&CK to test defensive readiness. You need it when security teams must identify detection gaps, validate controls, and improve incident response through controlled exercises.