redteam-intrusion-social

Plan and execute authorized social-engineering campaigns for red-team exercises.

1|1|Updated Apr 25, 2026
One-click install
npx skills add https://github.com/chenchunrun/onyx-soc --skill redteam-intrusion-social
Or copy as Structured Prompt for Agent▼
Please help me install this Agent Skill.
Skill: redteam-intrusion-social
Source: https://github.com/chenchunrun/onyx-soc/tree/main/skills/redteam-intrusion-social
Command: npx skills add https://github.com/chenchunrun/onyx-soc --skill redteam-intrusion-social

SYSTEM DOCUMENTATION & REQUIREMENTS

What problem does it solve?

社会工程学攻击策划与钓鱼内容构造的自动化与合规化执行,帮助授权红队演练高效且可控。

Core Features & Use Cases

  • 授权钓鱼演练: 设计、部署和评估钓鱼活动。
  • 社会工程内容生成: 快速创建逼真邮件、语音和短信场景。
  • 合规与记录: 确保书面授权、范围限定和报告的完整性。

Quick Start

请告知系统你要进行的授权红队社会工程演练场景,即可生成相应的钓鱼邮件和场景材料。

Frequently Asked Questions about redteam-intrusion-social

High-intent search queries and answers about installing and using this skill.

FAQPage Schema
How do I plan an authorized phishing campaign for a red-team exercise?▼

To plan an authorized phishing campaign, you must first obtain explicit written authorization and define scope boundaries. This skill automates social-engineering content generation and deployment for security awareness training and attacker emulation within those controlled limits.

What is social-engineering attacker emulation in security awareness training?▼

Social-engineering attacker emulation simulates real phishing scenarios to test organizational risk awareness. It involves generating realistic emails, voice, and SMS content to identify human vulnerabilities during authorized red-team exercises.

Can I generate phishing simulation emails without explicit written authorization?▼

You cannot generate or execute phishing simulations without explicit written authorization. This skill enforces strict compliance, requiring defined scope boundaries, data protection measures, and timely reporting to ensure authorized red-team activities remain legally controlled.

What is the best way to ensure compliance during organizational phishing simulations?▼

The best way to ensure compliance during phishing simulations is by enforcing strict scope boundaries and data protection protocols. This skill integrates compliance checks and reporting into the red-team workflow, maintaining complete records of authorized activities.

How do I create realistic social-engineering scenarios for red-team exercises?▼

To create realistic social-engineering scenarios, provide the system with your authorized red-team context. The skill then rapidly generates tailored phishing emails, voice, and SMS materials designed for your specific attacker emulation and training objectives.

Are there limitations on what I can target during a red-team social-engineering campaign?▼

Limitations on red-team social-engineering campaigns are defined by your explicit written authorization and scope boundaries. You must adhere to data protection requirements and restrict attacker emulation activities strictly to the approved organizational targets.