redteam-intrusion-social

Plan and execute authorized social-engineering campaigns for red-team exercises.

1|1|Updated Apr 25, 2026
One-click install
npx skills add https://github.com/chenchunrun/onyx-soc --skill redteam-intrusion-social
Or copy as Structured Prompt for Agent
Please help me install this Agent Skill.
Skill: redteam-intrusion-social
Source: https://github.com/chenchunrun/onyx-soc/tree/main/skills/redteam-intrusion-social
Command: npx skills add https://github.com/chenchunrun/onyx-soc --skill redteam-intrusion-social

SYSTEM DOCUMENTATION & REQUIREMENTS

What problem does it solve?

社会工程学攻击策划与钓鱼内容构造的自动化与合规化执行,帮助授权红队演练高效且可控。

Core Features & Use Cases

  • 授权钓鱼演练: 设计、部署和评估钓鱼活动。
  • 社会工程内容生成: 快速创建逼真邮件、语音和短信场景。
  • 合规与记录: 确保书面授权、范围限定和报告的完整性。

Quick Start

请告知系统你要进行的授权红队社会工程演练场景,即可生成相应的钓鱼邮件和场景材料。

Frequently Asked Questions about redteam-intrusion-social

High-intent search queries and answers about installing and using this skill.

FAQPage Schema
How do I plan an authorized phishing campaign for a red-team exercise?

To plan an authorized phishing campaign, you must first obtain explicit written authorization and define scope boundaries. This skill automates social-engineering content generation and deployment for security awareness training and attacker emulation within those controlled limits.

What is social-engineering attacker emulation in security awareness training?

Social-engineering attacker emulation simulates real phishing scenarios to test organizational risk awareness. It involves generating realistic emails, voice, and SMS content to identify human vulnerabilities during authorized red-team exercises.

Can I generate phishing simulation emails without explicit written authorization?

You cannot generate or execute phishing simulations without explicit written authorization. This skill enforces strict compliance, requiring defined scope boundaries, data protection measures, and timely reporting to ensure authorized red-team activities remain legally controlled.

What is the best way to ensure compliance during organizational phishing simulations?

The best way to ensure compliance during phishing simulations is by enforcing strict scope boundaries and data protection protocols. This skill integrates compliance checks and reporting into the red-team workflow, maintaining complete records of authorized activities.

How do I create realistic social-engineering scenarios for red-team exercises?

To create realistic social-engineering scenarios, provide the system with your authorized red-team context. The skill then rapidly generates tailored phishing emails, voice, and SMS materials designed for your specific attacker emulation and training objectives.

Are there limitations on what I can target during a red-team social-engineering campaign?

Limitations on red-team social-engineering campaigns are defined by your explicit written authorization and scope boundaries. You must adhere to data protection requirements and restrict attacker emulation activities strictly to the approved organizational targets.