Skill detail
red-team
Security engineering specialty.
Inspect before use
Automated review checks relevance, not safety or endorsement. Read the source instructions before using this skill.
SKILL.md
The saved excerpt is a snapshot from review. The external source remains the complete and most current version.
--- name: "red-team" description: "Use when planning or executing authorized red team engagements, attack path analysis, or offensive security simulations. Covers MITRE ATT&CK kill-chain planning, technique scoring, choke point identification, OPSEC risk assessment, and crown jewel targeting." --- # Red Team Red team engagement planning and attack path analysis skill for authorized offensive security simulations. This is NOT vulnerability scanning (see security-pen-testing) or incident response (see incident-response) — this is about structured adversary simulation to test detection, response, and control effectiveness. --- ## Table of Contents - [Overview](#overview) - [Engagement Planner Tool](#engagement-planner-tool) - [Kill-Chain Phase Methodology](#kill-chain-phase-methodology) - [Technique Scoring and Prioritization](#technique-scoring-and-prioritization) - [Choke Point Analysis](#choke-point-analysis) - [OPSEC Risk Assessment](#opsec-risk-assessment) - [Crown Jewel Targeting](#crown-jewel-targeting) - [Attack Path Methodology](#attack-path-methodology) - [Workflows](#workflows) - [Anti-Patterns](#anti-patterns) - [Cross-References](#cross-references) --- ## Overview ### What This Skill Does This skill provides the methodology and tooling for **red team engagement planning** — building structured attack plans from MITRE ATT&CK technique selection, access level, and crown jewel targets. It scores techniques by effort and detection risk, assembles kill-chain phases, identifies choke points, and flags OPSEC risks. ### Distinction from Other Security Skills | Skill | Focus | Approach | |-------|-------|----------| | **red-team** (this) | Adversary simulation | Offensive — structured attack planning and execution | | security-pen-testing | Vulnerability discovery | Offensive — systematic exploitation of specific weaknesses | | threat-detection | Finding attacker activity | Proactive — detect TTPs in telemetry | | incident-response | Active incident management | Reactive — contain and investigate confirmed incidents | ### Authorization Requirement **All red team activities described here require written authorization.** This includes a signed Rules of Engagement (RoE) document, defined scope, and explicit executive approval. The `engagement_planner.py` tool will not generate output without the `--authorized` flag. Unauthorized use of these techniques is illegal under the CFAA, Computer Misuse Act, and equivalent laws worldwide. --- ## Engagement Planner Tool The `engagement_planner.py` tool builds a scored, kill-chain-ordered attack plan from technique selection, access level, and crown jewel targets. ```bash # Basic engagement plan — external access, specific techniques python3 scripts/engagement_planner.py \ --techniques T1059,T1078,T1003 \ --access-level external \ --authorized --json # Internal network access with crown jewel targeting python3 scripts/engagement_planner.py \ --techniques T1059,T1078,T1021,T1550,T1003 \ --access-level internal \ --crown-jewels "Database,Active Directory,Payment Systems" \ --authorized --json # Credentialed (assumed breach) scenario with scale python3 scripts/engagement_planner.py \ --techniques T1059,T1078,T1021,T1550,T1003,T1486,T1048 \ --access-level credentialed \ --crown-jewels "Domain Controller,S3 Data Lake" \ --target-count 50 \ --authorized --json # List all 29 supported MITRE ATT&CK techniques python3 scripts/engagement_planner.py --list-techniques ``` ### Access Level Definitions | Level | Starting Position | Techniques Available | |-------|------------------|----------------------| | external | No internal access — internet only | External-facing techniques only (T1190, T1566, etc.) | | internal | Network foothold — no credentials | Internal recon + lateral movement prep | | credentialed | Valid credentials obtained | Full kill chain including priv-esc, lateral movement, impact | ### Exit Codes | Code | Meaning | |------|---------|Read the full source on GitHub (opens external page)