red-team-tactics

Plan adversary simulations using MITRE ATT&CK aligned tactics.

8.1k|1.5k|Updated Jan 14, 2026
One-click install
npx skills add https://github.com/vudovn/antigravity-kit --skill red-team-tactics-vudovn
Or copy as Structured Prompt for Agent
Please help me install this Agent Skill.
Skill: red-team-tactics
Source: https://github.com/vudovn/antigravity-kit/tree/main/.agent/skills/red-team-tactics
Command: npx skills add https://github.com/vudovn/antigravity-kit --skill red-team-tactics-vudovn

SYSTEM DOCUMENTATION & REQUIREMENTS

What problem does it solve?

This Skill provides a structured primer on red-team tactics grounded in the MITRE ATT&CK framework to help security teams design realistic adversary simulations, improve detection, and enhance reporting.

Core Features & Use Cases

  • Framework-aligned guidance: details attack phases, from recon to impact, with emphasis on detection evasion and reporting.
  • Adversary simulation planning: helps craft scenarios to test defenses across multiple technique categories.
  • Use Case: simulate a typical ATT&CK lifecycle in a controlled lab to validate SIEM detections and response playbooks.

Quick Start

Run the red-team-tactics skill to review MITRE ATT&CK phase mapping and identify 3 techniques to test in your environment.

Frequently Asked Questions about red-team-tactics

High-intent search queries and answers about installing and using this skill.

FAQPage Schema
How do I plan adversary simulation scenarios using the MITRE ATT&CK framework?

Adversary simulation planning using MITRE ATT&CK involves mapping practical tactics to attack phases from recon to impact. This provides a structured guide to design realistic scenarios, test defenses, and validate SIEM detections across multiple technique categories.

What is the best way to structure red-team reporting for security assessments?

Red-team reporting for security assessments should align with MITRE ATT&CK phases to document adversary activity accurately. This approach structures findings by mapping simulated techniques to practical tactics, emphasizing detection evasion and actionable reporting recommendations.

Can I use this guidance to validate SIEM detections for specific ATT&CK techniques?

Yes, you can simulate a typical ATT&CK lifecycle in a controlled lab to validate SIEM detections. By mapping MITRE ATT&CK phases to practical tactics, you can identify and test specific techniques to ensure your response playbooks function correctly.

Does this cover detection evasion techniques across all attack phases?

Detection evasion is emphasized throughout the attack phases, from reconnaissance to impact. The guidance provides a structured primer detailing how to map MITRE ATT&CK phases to practical evasion tactics for realistic adversary simulations.

How do I map MITRE ATT&CK phases to practical red-team tactics?

Mapping ATT&CK phases to practical red-team tactics requires a structured guide covering the full attack lifecycle. This approach details each phase, from recon to impact, to help security teams design, simulate, and report on adversary activity.

When do I need threat modeling for adversary simulation exercises?

Threat modeling for adversary simulation is needed when designing realistic scenarios to test defenses across multiple technique categories. It helps craft controlled exercises to validate detection capabilities and improve response playbooks using MITRE ATT&CK alignment.