⚠️ AUTHORIZED USE ONLY
This skill is for educational purposes or authorized security assessments only.
You must have explicit, written permission from the system owner before using this tool.
Misuse of this tool is illegal and strictly prohibited.
Mandatory confirmation gate
Before running any command that probes, exploits, changes, persists on, extracts data from, or attempts credential access against a target:
- Ask the user to state the exact target URL, IP, account, or resource.
- Ask the user to confirm written authorization and the permitted scope.
- Show the exact command(s) and explain their expected effect.
- Wait for explicit confirmation in the current conversation.
Without that confirmation, remain read-only and provide defensive guidance only. Prefer a sandbox, disposable VM, or controlled lab.
AUTHORIZED USE ONLY: Use this skill only for authorized security assessments, defensive validation, or controlled educational environments.
Red Team Tactics
Adversary simulation principles based on MITRE ATT&CK framework.
1. MITRE ATT&CK Phases
Attack Lifecycle
RECONNAISSANCE → INITIAL ACCESS → EXECUTION → PERSISTENCE
↓ ↓ ↓ ↓
PRIVILEGE ESC → DEFENSE EVASION → CRED ACCESS → DISCOVERY
↓ ↓ ↓ ↓
LATERAL MOVEMENT → COLLECTION → C2 → EXFILTRATION → IMPACT
Phase Objectives
| Phase |
Objective |
| Recon |
Map attack surface |
| Initial Access |
Get first foothold |
| Execution |
Run code on target |
| Persistence |
Survive reboots |
| Privilege Escalation |
Get admin/root |
| Defense Evasion |
Avoid detection |
| Credential Access |
Harvest credentials |
| Discovery |
Map internal network |
| Lateral Movement |
Spread to other systems |
| Collection |
Gather target data |
| C2 |
Maintain command channel |
| Exfiltration |
Extract data |
2. Reconnaissance Principles
Passive vs Active
| Type |
Trade-off |
| Passive |
No target contact, limited info |
| Active |
Direct contact, more detection risk |
Information Targets
| Category |
Value |
| Technology stack |
Attack vector selection |
| Employee info |
Social engineering |
| Network ranges |
Scanning scope |
| Third parties |
Supply chain attack |
3. Initial Access Vectors
Selection Criteria
| Vector |
When to Use |
| Phishing |
Human target, email access |
| Public exploits |
Vulnerable services exposed |
| Valid credentials |
Leaked or cracked |
| Supply chain |
Third-party access |
4. Privilege Escalation Principles
Windows Targets
| Check |
Opportunity |
| Unquoted service paths |
Write to path |
| Weak service permissions |
Modify service |
| Token privileges |
Abuse SeDebug, etc. |
| Stored credentials |
Harvest |
Linux Targets
| Check |
Opportunity |
| SUID binaries |
Execute as owner |
| Sudo misconfiguration |
Command execution |
| Kernel vulnerabilities |
Kernel exploits |
| Cron jobs |
Writable scripts |
5. Defense Evasion Principles
Key Techniques
| Technique |
Purpose |
| LOLBins |
Use legitimate tools |
| Obfuscation |
Hide malicious code |
| Timestomping |
Hide file modifications |
| Log clearing |
Remove evidence |
Operational Security
- Work during business hours
- Mimic legitimate traffic patterns
- Use encrypted channels
- Blend with normal behavior
6. Lateral Movement Principles
Credential Types
| Type |
Use |
| Password |
Standard auth |
| Hash |
Pass-the-hash |
| Ticket |
Pass-the-ticket |
| Certificate |
Certificate auth |
Movement Paths
- Admin shares
- Remote services (RDP, SSH, WinRM)
- Exploitation of internal services
7. Active Directory Attacks
Attack Categories
| Attack |
Target |
| Kerberoasting |
Service account passwords |
| AS-REP Roasting |
Accounts without pre-auth |
| DCSync |
Domain credentials |
| Golden Ticket |
Persistent domain access |
8. Reporting Principles
Attack Narrative
Document the full attack chain:
- How initial access was gained
- What techniques were used
- What objectives were achieved
- Where detection failed
Detection Gaps
For each successful technique:
- What should have detected it?
- Why didn't detection work?
- How to improve detection
9. Ethical Boundaries
Always
- Stay within scope
- Minimize impact
- Report immediately if real threat found
- Document all actions
Never
- Destroy production data
- Cause denial of service (unless scoped)
- Access beyond proof of concept
- Retain sensitive data
10. Anti-Patterns
| ❌ Don't |
✅ Do |
| Rush to exploitation |
Follow methodology |
| Cause damage |
Minimize impact |
| Skip reporting |
Document everything |
| Ignore scope |
Stay within boundaries |
Remember: Red team simulates attackers to improve defenses, not to cause harm.
When to Use
This skill is applicable to execute the workflow or actions described in the overview.
Limitations
- Use this skill only when the task clearly matches the scope described above.
- Do not treat the output as a substitute for environment-specific validation, testing, or expert review.
- Stop and ask for clarification if required inputs, permissions, safety boundaries, or success criteria are missing.
1---2name: red-team-tactics3description: Red team tactics principles based on MITRE ATT&CK. Attack phases, detection evasion, reporting.4---56> **⚠️ AUTHORIZED USE ONLY**7> This skill is for educational purposes or authorized security assessments only.8> You must have explicit, written permission from the system owner before using this tool.9> Misuse of this tool is illegal and strictly prohibited.1011> **Mandatory confirmation gate**12> Before running any command that probes, exploits, changes, persists on, extracts data from, or attempts credential access against a target:13> 1. Ask the user to state the exact target URL, IP, account, or resource.14> 2. Ask the user to confirm written authorization and the permitted scope.15> 3. Show the exact command(s) and explain their expected effect.16> 4. Wait for explicit confirmation in the current conversation.17>18> Without that confirmation, remain read-only and provide defensive guidance only. Prefer a sandbox, disposable VM, or controlled lab.1920> AUTHORIZED USE ONLY: Use this skill only for authorized security assessments, defensive validation, or controlled educational environments.2122# Red Team Tactics2324> Adversary simulation principles based on MITRE ATT&CK framework.2526---2728## 1. MITRE ATT&CK Phases2930### Attack Lifecycle3132```33RECONNAISSANCE → INITIAL ACCESS → EXECUTION → PERSISTENCE34 ↓ ↓ ↓ ↓35 PRIVILEGE ESC → DEFENSE EVASION → CRED ACCESS → DISCOVERY36 ↓ ↓ ↓ ↓37LATERAL MOVEMENT → COLLECTION → C2 → EXFILTRATION → IMPACT38```3940### Phase Objectives4142| Phase | Objective |43|-------|-----------|44| **Recon** | Map attack surface |45| **Initial Access** | Get first foothold |46| **Execution** | Run code on target |47| **Persistence** | Survive reboots |48| **Privilege Escalation** | Get admin/root |49| **Defense Evasion** | Avoid detection |50| **Credential Access** | Harvest credentials |51| **Discovery** | Map internal network |52| **Lateral Movement** | Spread to other systems |53| **Collection** | Gather target data |54| **C2** | Maintain command channel |55| **Exfiltration** | Extract data |5657---5859## 2. Reconnaissance Principles6061### Passive vs Active6263| Type | Trade-off |64|------|-----------|65| **Passive** | No target contact, limited info |66| **Active** | Direct contact, more detection risk |6768### Information Targets6970| Category | Value |71|----------|-------|72| Technology stack | Attack vector selection |73| Employee info | Social engineering |74| Network ranges | Scanning scope |75| Third parties | Supply chain attack |7677---7879## 3. Initial Access Vectors8081### Selection Criteria8283| Vector | When to Use |84|--------|-------------|85| **Phishing** | Human target, email access |86| **Public exploits** | Vulnerable services exposed |87| **Valid credentials** | Leaked or cracked |88| **Supply chain** | Third-party access |8990---9192## 4. Privilege Escalation Principles9394### Windows Targets9596| Check | Opportunity |97|-------|-------------|98| Unquoted service paths | Write to path |99| Weak service permissions | Modify service |100| Token privileges | Abuse SeDebug, etc. |101| Stored credentials | Harvest |102103### Linux Targets104105| Check | Opportunity |106|-------|-------------|107| SUID binaries | Execute as owner |108| Sudo misconfiguration | Command execution |109| Kernel vulnerabilities | Kernel exploits |110| Cron jobs | Writable scripts |111112---113114## 5. Defense Evasion Principles115116### Key Techniques117118| Technique | Purpose |119|-----------|---------|120| LOLBins | Use legitimate tools |121| Obfuscation | Hide malicious code |122| Timestomping | Hide file modifications |123| Log clearing | Remove evidence |124125### Operational Security126127- Work during business hours128- Mimic legitimate traffic patterns129- Use encrypted channels130- Blend with normal behavior131132---133134## 6. Lateral Movement Principles135136### Credential Types137138| Type | Use |139|------|-----|140| Password | Standard auth |141| Hash | Pass-the-hash |142| Ticket | Pass-the-ticket |143| Certificate | Certificate auth |144145### Movement Paths146147- Admin shares148- Remote services (RDP, SSH, WinRM)149- Exploitation of internal services150151---152153## 7. Active Directory Attacks154155### Attack Categories156157| Attack | Target |158|--------|--------|159| Kerberoasting | Service account passwords |160| AS-REP Roasting | Accounts without pre-auth |161| DCSync | Domain credentials |162| Golden Ticket | Persistent domain access |163164---165166## 8. Reporting Principles167168### Attack Narrative169170Document the full attack chain:1711. How initial access was gained1722. What techniques were used1733. What objectives were achieved1744. Where detection failed175176### Detection Gaps177178For each successful technique:179- What should have detected it?180- Why didn't detection work?181- How to improve detection182183---184185## 9. Ethical Boundaries186187### Always188189- Stay within scope190- Minimize impact191- Report immediately if real threat found192- Document all actions193194### Never195196- Destroy production data197- Cause denial of service (unless scoped)198- Access beyond proof of concept199- Retain sensitive data200201---202203## 10. Anti-Patterns204205| ❌ Don't | ✅ Do |206|----------|-------|207| Rush to exploitation | Follow methodology |208| Cause damage | Minimize impact |209| Skip reporting | Document everything |210| Ignore scope | Stay within boundaries |211212---213214> **Remember:** Red team simulates attackers to improve defenses, not to cause harm.215216## When to Use217This skill is applicable to execute the workflow or actions described in the overview.218219## Limitations220- Use this skill only when the task clearly matches the scope described above.221- Do not treat the output as a substitute for environment-specific validation, testing, or expert review.222- Stop and ask for clarification if required inputs, permissions, safety boundaries, or success criteria are missing.