What problem does it solve? Red team engagements often fail due to unclear scope, missing legal authorization, or poor coordination with defenders. This Skill provides a structured methodology for planning authorized adversary simulations before any offensive testing begins, ensuring engagements are safe, legal, and aligned with real threats. ## Core Features & Use Cases - Scope and ROE Definition: Establish in-scope and out-of-scope assets, emergency stop procedures, communication plans, and legal authorization requirements. - Threat Profile Selection: Map relevant adversaries such as APT29, FIN7, or Lazarus Group to organizational risk using the MITRE ATT&CK framework. - Phased Planning Workflow: Follow four phases covering pre-engagement scoping, threat modeling, operational planning, and documentation with stakeholder approval. - Use Case: A security lead preparing an assumed-breach exercise uses this Skill to draft the Rules of Engagement, select APT29 TTPs mapped to the internal network, build a deconfliction matrix with the SOC, and produce an engagement brief for executive sign-off. ## Quick Start Ask the agent to draft a red team engagement plan for an assumed-breach exercise, including scope boundaries, rules of engagement, and a MITRE ATT&CK threat profile.