redteam-orchestration

Automate red team network simulation engagements from reconnaissance to reporting.

Updated Apr 21, 2026
One-click install
npx skills add https://github.com/jayjpatel9717/kurukshetra --skill redteam-orchestration
Or copy as Structured Prompt for Agent
Please help me install this Agent Skill.
Skill: redteam-orchestration
Source: https://github.com/jayjpatel9717/kurukshetra/tree/main/squads/red-team/agents/parashurama/skills/redteam-orchestration
Command: npx skills add https://github.com/jayjpatel9717/kurukshetra --skill redteam-orchestration

SYSTEM DOCUMENTATION & REQUIREMENTS

💡 This Skill includes scripts (resource) and references (resource) components.

What problem does it solve?

This Skill automates the full lifecycle of red team network simulation engagements, from scope validation to final reporting, ensuring comprehensive and controlled security testing.

Core Features & Use Cases

  • Full Lifecycle Automation: Automates all phases of a red team engagement, including reconnaissance, initial access, lateral movement, and reporting.
  • Detection-First Philosophy: Ensures that the engagement operates in detection mode only, without any actual exploitation or lateral movement.
  • Specialist Agents: Utilizes GHATOTKACHA for network exploitation and INDRA for Active Directory enumeration and exploitation.
  • Customizable Workflows: Supports various engagement types such as AD Attack, Hybrid (AD+Net), External Network, and Internal Network.

Quick Start

Dispatch the redteam-orchestration skill to initiate a network simulation engagement on the target 'example.com'.

Frequently Asked Questions about redteam-orchestration

High-intent search queries and answers about installing and using this skill.

FAQPage Schema
How do I automate red team network simulation engagements end to end?

Red team network simulation engagements can be fully automated from reconnaissance and initial access to lateral movement and reporting by dispatching the redteam-orchestration skill to initiate the workflow on a target domain.

What is the detection mode philosophy in adversarial simulation?

Detection mode philosophy in adversarial simulation ensures the engagement operates strictly for detection without executing any actual exploitation or lateral movement, providing a controlled security testing environment.

Can I customize red team workflows for specific Active Directory attack scenarios?

Red team workflows can be customized for specific Active Directory attack scenarios using various engagement types such as AD Attack, Hybrid (AD+Net), External Network, and Internal Network configurations.

How does Active Directory enumeration work during network exploitation simulations?

Active Directory enumeration during network exploitation simulations operates by utilizing the INDRA specialist agent for AD enumeration, while the GHATOTKACHA agent handles network exploitation tasks across the engagement lifecycle.

Do I need to manually validate scope before starting an adversarial simulation?

Manual scope validation is not required before starting an adversarial simulation because the full lifecycle automation includes scope validation as the initial phase before proceeding to reconnaissance and access steps.

What are the limitations of using automated red team orchestration for security testing?

A key limitation of automated red team orchestration is its detection-first philosophy, meaning it cannot perform actual exploitation or lateral movement, restricting its use to simulation and detection validation only.

Related Skills