red-team-tactics

Map adversary techniques to MITRE ATT&CK phases for red-team simulations.

Updated Aug 30, 2024
One-click install
npx skills add https://github.com/jfrometa/esquizo --skill red-team-tactics-jfrometa
Or copy as Structured Prompt for Agent▼
Please help me install this Agent Skill.
Skill: red-team-tactics
Source: https://github.com/jfrometa/esquizo/tree/main/.agent/skills/red-team-tactics
Command: npx skills add https://github.com/jfrometa/esquizo --skill red-team-tactics-jfrometa

SYSTEM DOCUMENTATION & REQUIREMENTS

What problem does it solve?

This Skill maps adversary techniques to MITRE ATT&CK phases to help security teams assess and strengthen defenses.

Core Features & Use Cases

  • Adversary simulation playbooks aligned with MITRE ATT&CK phases
  • Threat-modeling guidance for red-team exercises and defense hardening
  • Clear reporting workflow to document findings and remediation steps

Quick Start

Use the red-team-tactics skill to generate a compact MITRE ATT&CK mapping for a simple environment.

Frequently Asked Questions about red-team-tactics

High-intent search queries and answers about installing and using this skill.

FAQPage Schema
How do I map adversary simulation techniques to MITRE ATT&CK phases?▼

You map adversary techniques to MITRE ATT&CK phases by using a structured playbook that aligns red-team simulation actions from recon to impact with the framework's categories, highlighting detection gaps and reporting requirements.

What is the best way to document red-team findings and remediation steps?▼

The best way to document red-team findings is using a narrative reporting template. This workflow maps executed adversary simulation techniques to MITRE ATT&CK phases, detailing detection gaps and required remediation steps for defense teams.

How does threat modeling help assess and strengthen security defenses?▼

Threat modeling helps assess and strengthen security defenses by simulating attacker behaviors across execution, persistence, privilege escalation, and defense evasion. Mapping these adversary techniques to MITRE ATT&CK phases reveals critical detection gaps.

Can I use this approach for red-team simulations across the entire attack lifecycle?▼

Yes, you can use this approach for red-team simulations across the entire attack lifecycle. It covers recon, initial access, execution, persistence, privilege escalation, defense evasion, credential access, discovery, lateral movement, collection, C2, exfiltration, and impact.

Do I need additional security operations tools to identify detection evasion gaps?▼

You do not need additional tools to identify detection evasion gaps initially. The Skill encodes a structured playbook with MITRE ATT&CK phases and defense-evasion techniques to highlight gaps and reporting requirements directly.