red-team-tactics

Explain red team tactics and adversary simulation using the MITRE ATT&CK framework.

Updated Jan 8, 2026
One-click install
npx skills add https://github.com/VoTruongDanh/AI_Cafe --skill red-team-tactics-votruongdanh
Or copy as Structured Prompt for Agent
Please help me install this Agent Skill.
Skill: red-team-tactics
Source: https://github.com/VoTruongDanh/AI_Cafe/tree/main/ai-service/.agent/skills/red-team-tactics
Command: npx skills add https://github.com/VoTruongDanh/AI_Cafe --skill red-team-tactics-votruongdanh

SYSTEM DOCUMENTATION & REQUIREMENTS

What problem does it solve?

This Skill provides a comprehensive understanding of red team tactics and principles, enabling users to simulate adversary behavior for security testing and defense improvement.

Core Features & Use Cases

  • MITRE ATT&CK Framework: Understand the lifecycle of an attack from reconnaissance to impact.
  • Tactical Principles: Learn about reconnaissance, initial access, privilege escalation, defense evasion, and lateral movement.
  • Active Directory Attacks: Explore common attack vectors within Active Directory environments.
  • Reporting & Ethics: Understand best practices for documenting findings and adhering to ethical boundaries.
  • Use Case: A security analyst can use this Skill to learn how to plan and execute a simulated phishing campaign, understanding the steps from initial access to privilege escalation and how to report findings effectively.

Quick Start

Explain the principles of defense evasion in red teaming.

Frequently Asked Questions about red-team-tactics

High-intent search queries and answers about installing and using this skill.

FAQPage Schema
What is adversary simulation and how does it map to the MITRE ATT&CK framework?

Adversary simulation replicates real-world attack behaviors to test security defenses, mapping tactics like reconnaissance, initial access, and lateral movement directly to the MITRE ATT&CK framework's lifecycle.

How do I execute privilege escalation and defense evasion tactics during red teaming?

Red teaming executes privilege escalation and defense evasion by applying specific adversary techniques to bypass security controls and elevate access, enabling deeper penetration into targeted systems.

Can I use this methodology to simulate Active Directory attacks?

Yes, this methodology explores common Active Directory attack vectors, allowing you to simulate adversary behavior and identify critical vulnerabilities within AD environments.

What are the ethical guidelines and reporting standards for adversary simulation?

Adversary simulation requires adhering to strict ethical boundaries and best practices for documenting findings, ensuring security testing is reported effectively and transparently.

How do I plan a simulated phishing campaign from initial access to impact?

Plan a simulated phishing campaign by following the attack lifecycle from initial access through privilege escalation, mapping each phase to adversary tactics to evaluate defensive strategies.

Does this approach focus on offensive tactics or improving defensive strategies?

This approach primarily details offensive red team tactics, but the ultimate goal is to facilitate understanding of security vulnerabilities and directly improve defensive strategies.