executing-red-team-exercise

Featured

Executes comprehensive red team exercises that simulate real-world adversary operations against an organization's people, processes, and technology. The red team operates with stealth as a primary objective, employing the full attack lifecycle from initial reconnaissance through objective completion while testing the organization's detection and response capabilities. This differs from penetration testing by focusing on adversary emulation rather than vulnerability identification. Activates for requests involving red team exercise, adversary simulation, adversary emulation, or full-scope offensive security assessment.

AI & Automation 12,642 stars 1468 forks Updated today Apache-2.0

Install

View on GitHub

Quality Score: 99/100

Stars 20%
100
Recency 20%
100
Frontmatter 20%
70
Documentation 15%
100
Issue Health 10%
50
License 10%
100
Description 5%
100

Skill Content

# Executing Red Team Exercise ## When to Use - Assessing an organization's ability to detect, respond to, and contain a realistic adversary operation - Testing the effectiveness of the security operations center (SOC), incident response team, and threat hunting capabilities - Validating security investments by simulating attacks that chain multiple vulnerabilities and techniques - Evaluating the organization's security posture against specific threat actors (nation-state, ransomware groups, insider threats) - Meeting regulatory requirements for adversary simulation (TIBER-EU, CBEST, AASE, iCAST) **Do not use** without executive-level authorization and a detailed Rules of Engagement document, against systems where disruption could affect safety or critical operations, or as a replacement for basic vulnerability management (fix known vulnerabilities first). ## Prerequisites - Executive-level written authorization with clearly defined objectives, scope, and off-limits systems - Red team command and control (C2) infrastructure: primary and backup C2 channels with domain fronting or redirectors - Operator workstations with OPSEC-hardened toolsets (Cobalt Strike, Sliver, Brute Ratel, or Mythic) - Threat intelligence on adversary groups relevant to the target organization for adversary emulation planning - Trusted agent (white cell) within the target organization who manages the exercise boundaries without alerting defenders - MITRE ATT&CK matrix for mapping planned and execute...

Details

Author
mukul975
Repository
mukul975/Anthropic-Cybersecurity-Skills
Created
3 months ago
Last Updated
today
Language
Python
License
Apache-2.0

Similar Skills

Semantically similar based on skill content — not just same category

AI & Automation Featured

executing-red-team-engagement-planning

Red team engagement planning is the foundational phase that defines scope, objectives, rules of engagement (ROE), threat model selection, and operational timelines before any offensive testing begins.

12,642 Updated today
mukul975
AI & Automation Featured

conducting-full-scope-red-team-engagement

Plan and execute a comprehensive red team engagement covering reconnaissance through post-exploitation using MITRE ATT&CK-aligned TTPs to evaluate an organization's detection and response capabilities.

12,642 Updated today
mukul975
AI & Automation Featured

performing-purple-team-exercise

Performs purple team exercises by coordinating red team adversary emulation with blue team detection validation using MITRE ATT&CK-mapped attack scenarios, real-time detection testing, and collaborative gap remediation. Use when SOC teams need to validate detection capabilities, improve analyst skills, and close detection gaps through structured offensive-defensive collaboration.

12,642 Updated today
mukul975
AI & Automation Listed

thinking-red-team

Deliberately attack your own plans, systems, and assumptions to find weaknesses before adversaries or reality does. Use for security review, architecture validation, plan stress-testing, and pre-launch preparation.

1 Updated today
babypochi06
AI & Automation Solid

red-team

Use when planning or executing authorized red team engagements, attack path analysis, or offensive security simulations. Covers MITRE ATT&CK kill-chain planning, technique scoring, choke point identification, OPSEC risk assessment, and crown jewel targeting.

16,642 Updated yesterday
alirezarezvani