Red Team Tactics

SkillAI & models

red-team-tactics is a skill that teaches an AI agent red team attack techniques and defense-evasion methods using the MITRE ATT&CK framework. It covers attack phases, detection evasion, and reporting, so the agent can help with offensive security work grounded in a standard framework.

Use Red Team Tactics in Claude, ChatGPT or Ahel Desktop

Free. Sign in, add Red Team Tactics and connect your AI. About a minute.

Also: Claude Code · Cursor · Codex

Then ask your AI: use the Red Team Tactics skill

Details

Instructions available. Your AI can read the instructions. Execution depends on the setup they require.

Have an agent setup that supports loading skills.

Red Team TacticsStart free

What your AI can do with it

  • Explains red team attack techniques organized by MITRE ATT&CK phases
  • Describes detection evasion methods used by attackers
  • Structures offensive security work around the MITRE ATT&CK framework
  • Supports reporting on red team tactics and findings

Getting started

  1. Have an agent setup that supports loading skills.
  2. Add the red-team-tactics skill to the agent's available skills.
  3. Ask the agent about attack phases, evasion methods, or reporting to use the skill.

What this skill tells your AI

The instructions your AI receives, as published by davila7/claude-code-templates in cli-tool/components/skills/security/red-team-tactics/SKILL.md and read by ahel’s review.

Adversary simulation principles based on MITRE ATT&CK framework.


1. MITRE ATT&CK Phases

Attack Lifecycle

RECONNAISSANCE → INITIAL ACCESS → EXECUTION → PERSISTENCE
       ↓              ↓              ↓            ↓
   PRIVILEGE ESC → DEFENSE EVASION → CRED ACCESS → DISCOVERY
       ↓              ↓              ↓            ↓
LATERAL MOVEMENT → COLLECTION → C2 → EXFILTRATION → IMPACT

Phase Objectives

PhaseObjective
ReconMap attack surface
Initial AccessGet first foothold
ExecutionRun code on target
PersistenceSurvive reboots
Privilege EscalationGet admin/root
Defense EvasionAvoid detection
Credential AccessHarvest credentials
DiscoveryMap internal network
Lateral MovementSpread to other systems
CollectionGather target data
C2Maintain command channel
ExfiltrationExtract data

2. Reconnaissance Principles

Passive vs Active

TypeTrade-off
PassiveNo target contact, limited info
ActiveDirect contact, more detection risk

Information Targets

CategoryValue
Technology stackAttack vector selection
Employee infoSocial engineering
Network rangesScanning scope
Third partiesSupply chain attack

3. Initial Access Vectors

Selection Criteria

VectorWhen to Use
PhishingHuman target, email access
Public exploitsVulnerable services exposed
Valid credentialsLeaked or cracked
Supply chainThird-party access

4. Privilege Escalation Principles

Windows Targets

CheckOpportunity
Unquoted service pathsWrite to path
Weak service permissionsModify service
Token privilegesAbuse SeDebug, etc.
Stored credentialsHarvest

Linux Targets

CheckOpportunity
SUID binariesExecute as owner
Sudo misconfigurationCommand execution
Kernel vulnerabilitiesKernel exploits
Cron jobsWritable scripts

5. Defense Evasion Principles

Key Techniques

TechniquePurpose
LOLBinsUse legitimate tools
ObfuscationHide malicious code
TimestompingHide file modifications
Log clearingRemove evidence

Operational Security

  • Work during business hours
  • Mimic legitimate traffic patterns
  • Use encrypted channels
  • Blend with normal behavior

6. Lateral Movement Principles

Credential Types

TypeUse
PasswordStandard auth
HashPass-the-hash
TicketPass-the-ticket
CertificateCertificate auth

Movement Paths

  • Admin shares
  • Remote services (RDP, SSH, WinRM)
  • Exploitation of internal services

7. Active Directory Attacks

Attack Categories

AttackTarget
KerberoastingService account passwords
AS-REP RoastingAccounts without pre-auth
DCSyncDomain credentials
Golden TicketPersistent domain access

8. Reporting Principles

Attack Narrative

Document the full attack chain:

  1. How initial access was gained
  2. What techniques were used
  3. What objectives were achieved
  4. Where detection failed

Detection Gaps

For each successful technique:

  • What should have detected it?
  • Why didn't detection work?
  • How to improve detection

9. Ethical Boundaries

Always

  • Stay within scope
  • Minimize impact
  • Report immediately if real threat found
  • Document all actions

Never

  • Destroy production data
  • Cause denial of service (unless scoped)
  • Access beyond proof of concept
  • Retain sensitive data

10. Anti-Patterns

❌ Don't✅ Do
Rush to exploitationFollow methodology
Cause damageMinimize impact
Skip reportingDocument everything
Ignore scopeStay within boundaries

Remember: Red team simulates attackers to improve defenses, not to cause harm.

Signals

GitHub stars
32k
Forks
4k
Last commit
Oct 2026

Questions

What framework does it use?
It is based on MITRE ATT&CK, a standard framework for describing attack phases and techniques.
Does it cover detection evasion?
Yes, it includes defense-evasion methods alongside attack phases and reporting.
Who is it for?
People using an AI agent for offensive security or red team work who want the agent to follow established tactics.
Advanced
Item type
skill
Key
red-team-tactics
Source
github.com/davila7/claude-code-templates