executing-red-team-engagement-planning

Plan red team engagements by defining scope, rules of engagement, and MITRE ATT&CK threat profiles.

1|1|Updated Apr 3, 2026
One-click install
npx skills add https://github.com/Yenn503/Net-Runners --skill executing-red-team-engagement-planning-yenn503
Or copy as Structured Prompt for Agent▼
Please help me install this Agent Skill.
Skill: executing-red-team-engagement-planning
Source: https://github.com/Yenn503/Net-Runners/tree/main/.netrunner/skills/lead/executing-red-team-engagement-planning
Command: npx skills add https://github.com/Yenn503/Net-Runners --skill executing-red-team-engagement-planning-yenn503

SYSTEM DOCUMENTATION & REQUIREMENTS

What problem does it solve? Red team engagements often fail due to unclear scope, missing legal authorization, or poor coordination with defenders. This Skill provides a structured methodology for planning authorized adversary simulations before any offensive testing begins, ensuring engagements are safe, legal, and aligned with real threats. ## Core Features & Use Cases - Scope and ROE Definition: Establish in-scope and out-of-scope assets, emergency stop procedures, communication plans, and legal authorization requirements. - Threat Profile Selection: Map relevant adversaries such as APT29, FIN7, or Lazarus Group to organizational risk using the MITRE ATT&CK framework. - Phased Planning Workflow: Follow four phases covering pre-engagement scoping, threat modeling, operational planning, and documentation with stakeholder approval. - Use Case: A security lead preparing an assumed-breach exercise uses this Skill to draft the Rules of Engagement, select APT29 TTPs mapped to the internal network, build a deconfliction matrix with the SOC, and produce an engagement brief for executive sign-off. ## Quick Start Ask the agent to draft a red team engagement plan for an assumed-breach exercise, including scope boundaries, rules of engagement, and a MITRE ATT&CK threat profile.

Frequently Asked Questions about executing-red-team-engagement-planning

High-intent search queries and answers about installing and using this skill.

FAQPage Schema
How do I plan a red team engagement?▼

Red team engagement planning follows four phases: pre-engagement scoping with stakeholders, threat modeling using MITRE ATT&CK, operational planning for infrastructure and OPSEC, and documentation with legal review and executive approval.

What should rules of engagement include for red teaming?▼

Rules of engagement should include scope definitions, restricted systems, communication and escalation channels, emergency stop procedures, legal authorization letters, data handling rules, and timelines with blackout windows.

How do I choose a threat profile with MITRE ATT&CK?▼

Use MITRE ATT&CK Navigator to map threat actors relevant to your sector, such as APT29 for government or FIN7 for finance. Then map their TTPs to your attack surface and define an emulation plan with specific technique IDs.

What is the difference between full scope and assumed breach engagements?▼

Full scope engagements simulate complete adversaries across physical, social, and cyber vectors against the entire organization. Assumed breach starts from an internal foothold and focuses on post-exploitation within the internal network.

What tools support red team engagement planning?▼

Common planning tools include MITRE ATT&CK Navigator for TTP mapping, VECTR for engagement tracking, PlexTrac for reporting, and SCYTHE for adversary emulation plan creation. Cobalt Strike or Nighthawk support C2 infrastructure design.

When should red team engagement planning not be skipped?▼

Planning should never be skipped for any offensive testing. Without signed authorization, defined scope, and deconfliction procedures, testing risks legal liability, business disruption, and SOC teams treating red team activity as real incidents.