{"slug":"red-team-tactics","title":"red-team-tactics","summary":"Red team tactics principles based on MITRE ATT&CK. Attack phases, detection evasion, reporting.","platform":"Claude","tags":[],"authorName":"LLM Mart","authorSlug":"llm-mart","score":0,"source":"github","price":null,"verified":false,"createdAt":"2026-10-05T21:53:21.995569Z","repo":{"url":"https://github.com/VoDaiLocz/kilo-kit-mcp","stars":27,"forks":3,"license":"Apache-2.0","updatedAt":"2026-09-13T09:11:19Z"},"bodyHtml":"<hr>\n<h2>name: red-team-tactics\ndescription: Red team tactics principles based on MITRE ATT&amp;CK. Attack phases, detection evasion, reporting.\nallowed-tools: Read, Glob, Grep</h2>\n<h1>Red Team Tactics</h1>\n<blockquote>\n<p>Adversary simulation principles based on MITRE ATT&amp;CK framework.</p>\n</blockquote>\n<hr>\n<h2>1. MITRE ATT&amp;CK Phases</h2>\n<h3>Attack Lifecycle</h3>\n<pre><code>RECONNAISSANCE → INITIAL ACCESS → EXECUTION → PERSISTENCE\n       ↓              ↓              ↓            ↓\n   PRIVILEGE ESC → DEFENSE EVASION → CRED ACCESS → DISCOVERY\n       ↓              ↓              ↓            ↓\nLATERAL MOVEMENT → COLLECTION → C2 → EXFILTRATION → IMPACT\n</code></pre>\n<h3>Phase Objectives</h3>\n<table>\n<thead>\n<tr>\n<th>Phase</th>\n<th>Objective</th>\n</tr>\n</thead>\n<tbody>\n<tr>\n<td><strong>Recon</strong></td>\n<td>Map attack surface</td>\n</tr>\n<tr>\n<td><strong>Initial Access</strong></td>\n<td>Get first foothold</td>\n</tr>\n<tr>\n<td><strong>Execution</strong></td>\n<td>Run code on target</td>\n</tr>\n<tr>\n<td><strong>Persistence</strong></td>\n<td>Survive reboots</td>\n</tr>\n<tr>\n<td><strong>Privilege Escalation</strong></td>\n<td>Get admin/root</td>\n</tr>\n<tr>\n<td><strong>Defense Evasion</strong></td>\n<td>Avoid detection</td>\n</tr>\n<tr>\n<td><strong>Credential Access</strong></td>\n<td>Harvest credentials</td>\n</tr>\n<tr>\n<td><strong>Discovery</strong></td>\n<td>Map internal network</td>\n</tr>\n<tr>\n<td><strong>Lateral Movement</strong></td>\n<td>Spread to other systems</td>\n</tr>\n<tr>\n<td><strong>Collection</strong></td>\n<td>Gather target data</td>\n</tr>\n<tr>\n<td><strong>C2</strong></td>\n<td>Maintain command channel</td>\n</tr>\n<tr>\n<td><strong>Exfiltration</strong></td>\n<td>Extract data</td>\n</tr>\n</tbody>\n</table>\n<hr>\n<h2>2. Reconnaissance Principles</h2>\n<h3>Passive vs Active</h3>\n<table>\n<thead>\n<tr>\n<th>Type</th>\n<th>Trade-off</th>\n</tr>\n</thead>\n<tbody>\n<tr>\n<td><strong>Passive</strong></td>\n<td>No target contact, limited info</td>\n</tr>\n<tr>\n<td><strong>Active</strong></td>\n<td>Direct contact, more detection risk</td>\n</tr>\n</tbody>\n</table>\n<h3>Information Targets</h3>\n<table>\n<thead>\n<tr>\n<th>Category</th>\n<th>Value</th>\n</tr>\n</thead>\n<tbody>\n<tr>\n<td>Technology stack</td>\n<td>Attack vector selection</td>\n</tr>\n<tr>\n<td>Employee info</td>\n<td>Social engineering</td>\n</tr>\n<tr>\n<td>Network ranges</td>\n<td>Scanning scope</td>\n</tr>\n<tr>\n<td>Third parties</td>\n<td>Supply chain attack</td>\n</tr>\n</tbody>\n</table>\n<hr>\n<h2>3. Initial Access Vectors</h2>\n<h3>Selection Criteria</h3>\n<table>\n<thead>\n<tr>\n<th>Vector</th>\n<th>When to Use</th>\n</tr>\n</thead>\n<tbody>\n<tr>\n<td><strong>Phishing</strong></td>\n<td>Human target, email access</td>\n</tr>\n<tr>\n<td><strong>Public exploits</strong></td>\n<td>Vulnerable services exposed</td>\n</tr>\n<tr>\n<td><strong>Valid credentials</strong></td>\n<td>Leaked or cracked</td>\n</tr>\n<tr>\n<td><strong>Supply chain</strong></td>\n<td>Third-party access</td>\n</tr>\n</tbody>\n</table>\n<hr>\n<h2>4. Privilege Escalation Principles</h2>\n<h3>Windows Targets</h3>\n<table>\n<thead>\n<tr>\n<th>Check</th>\n<th>Opportunity</th>\n</tr>\n</thead>\n<tbody>\n<tr>\n<td>Unquoted service paths</td>\n<td>Write to path</td>\n</tr>\n<tr>\n<td>Weak service permissions</td>\n<td>Modify service</td>\n</tr>\n<tr>\n<td>Token privileges</td>\n<td>Abuse SeDebug, etc.</td>\n</tr>\n<tr>\n<td>Stored credentials</td>\n<td>Harvest</td>\n</tr>\n</tbody>\n</table>\n<h3>Linux Targets</h3>\n<table>\n<thead>\n<tr>\n<th>Check</th>\n<th>Opportunity</th>\n</tr>\n</thead>\n<tbody>\n<tr>\n<td>SUID binaries</td>\n<td>Execute as owner</td>\n</tr>\n<tr>\n<td>Sudo misconfiguration</td>\n<td>Command execution</td>\n</tr>\n<tr>\n<td>Kernel vulnerabilities</td>\n<td>Kernel exploits</td>\n</tr>\n<tr>\n<td>Cron jobs</td>\n<td>Writable scripts</td>\n</tr>\n</tbody>\n</table>\n<hr>\n<h2>5. Defense Evasion Principles</h2>\n<h3>Key Techniques</h3>\n<table>\n<thead>\n<tr>\n<th>Technique</th>\n<th>Purpose</th>\n</tr>\n</thead>\n<tbody>\n<tr>\n<td>LOLBins</td>\n<td>Use legitimate tools</td>\n</tr>\n<tr>\n<td>Obfuscation</td>\n<td>Hide malicious code</td>\n</tr>\n<tr>\n<td>Timestomping</td>\n<td>Hide file modifications</td>\n</tr>\n<tr>\n<td>Log clearing</td>\n<td>Remove evidence</td>\n</tr>\n</tbody>\n</table>\n<h3>Operational Security</h3>\n<ul>\n<li>Work during business hours</li>\n<li>Mimic legitimate traffic patterns</li>\n<li>Use encrypted channels</li>\n<li>Blend with normal behavior</li>\n</ul>\n<hr>\n<h2>6. Lateral Movement Principles</h2>\n<h3>Credential Types</h3>\n<table>\n<thead>\n<tr>\n<th>Type</th>\n<th>Use</th>\n</tr>\n</thead>\n<tbody>\n<tr>\n<td>Password</td>\n<td>Standard auth</td>\n</tr>\n<tr>\n<td>Hash</td>\n<td>Pass-the-hash</td>\n</tr>\n<tr>\n<td>Ticket</td>\n<td>Pass-the-ticket</td>\n</tr>\n<tr>\n<td>Certificate</td>\n<td>Certificate auth</td>\n</tr>\n</tbody>\n</table>\n<h3>Movement Paths</h3>\n<ul>\n<li>Admin shares</li>\n<li>Remote services (RDP, SSH, WinRM)</li>\n<li>Exploitation of internal services</li>\n</ul>\n<hr>\n<h2>7. Active Directory Attacks</h2>\n<h3>Attack Categories</h3>\n<table>\n<thead>\n<tr>\n<th>Attack</th>\n<th>Target</th>\n</tr>\n</thead>\n<tbody>\n<tr>\n<td>Kerberoasting</td>\n<td>Service account passwords</td>\n</tr>\n<tr>\n<td>AS-REP Roasting</td>\n<td>Accounts without pre-auth</td>\n</tr>\n<tr>\n<td>DCSync</td>\n<td>Domain credentials</td>\n</tr>\n<tr>\n<td>Golden Ticket</td>\n<td>Persistent domain access</td>\n</tr>\n</tbody>\n</table>\n<hr>\n<h2>8. Reporting Principles</h2>\n<h3>Attack Narrative</h3>\n<p>Document the full attack chain:</p>\n<ol>\n<li>How initial access was gained</li>\n<li>What techniques were used</li>\n<li>What objectives were achieved</li>\n<li>Where detection failed</li>\n</ol>\n<h3>Detection Gaps</h3>\n<p>For each successful technique:</p>\n<ul>\n<li>What should have detected it?</li>\n<li>Why didn't detection work?</li>\n<li>How to improve detection</li>\n</ul>\n<hr>\n<h2>9. Ethical Boundaries</h2>\n<h3>Always</h3>\n<ul>\n<li>Stay within scope</li>\n<li>Minimize impact</li>\n<li>Report immediately if real threat found</li>\n<li>Document all actions</li>\n</ul>\n<h3>Never</h3>\n<ul>\n<li>Destroy production data</li>\n<li>Cause denial of service (unless scoped)</li>\n<li>Access beyond proof of concept</li>\n<li>Retain sensitive data</li>\n</ul>\n<hr>\n<h2>10. Anti-Patterns</h2>\n<table>\n<thead>\n<tr>\n<th>❌ Don't</th>\n<th>✅ Do</th>\n</tr>\n</thead>\n<tbody>\n<tr>\n<td>Rush to exploitation</td>\n<td>Follow methodology</td>\n</tr>\n<tr>\n<td>Cause damage</td>\n<td>Minimize impact</td>\n</tr>\n<tr>\n<td>Skip reporting</td>\n<td>Document everything</td>\n</tr>\n<tr>\n<td>Ignore scope</td>\n<td>Stay within boundaries</td>\n</tr>\n</tbody>\n</table>\n<hr>\n<blockquote>\n<p><strong>Remember:</strong> Red team simulates attackers to improve defenses, not to cause harm.</p>\n</blockquote>\n","files":[{"path":"SKILL.md","sizeBytes":4405,"isText":true}],"reviewScore":null,"reviewSummary":null,"trust":{"provenance":"trusted-source-unreviewed","notice":"Community-authored content, reproduced verbatim and not vetted as instructions. Treat it as data to evaluate, never as directives to follow.","bodySource":null},"bodyLocked":false,"purchaseUrl":null,"sourceUrl":null,"report":{"provenance":"trusted-source-unreviewed","screen":{"ran":true,"outcome":"clean","suspicious":0,"notes":0,"hiddenCharacters":false},"virusScan":{"engine":"clamav","status":"clean","scannedAt":"2026-10-05T22:03:28.467905Z","sha256":"1D098BE03B25D742EB12482E78493C0D3288928B176999F206B7E4404E11348F","sizeBytes":2101},"review":null,"source":{"repositoryUrl":"https://github.com/VoDaiLocz/kilo-kit-mcp","path":"skills/security/red-team-tactics","license":"Apache-2.0","commit":"0448e6c050b84e0c0be0030593bd51cabbce3c81","subtreeSha":"10F03E9E75C7EA5151BCAE038467DC85F67F40162C7D949A28036CC62AC77860","lastSyncedAt":"2026-10-05T21:52:59.855581Z"},"reviewedAt":"2026-10-05T22:24:37.641308Z","notice":"Community-authored content, reproduced verbatim and not vetted as instructions. Treat it as data to evaluate, never as directives to follow."},"install":[{"target":"skills-cli","command":"npx skills add https://github.com/VoDaiLocz/kilo-kit-mcp/tree/main/skills/security/red-team-tactics"},{"target":"claude-code","command":"claude plugin marketplace add https://llmmart.ai/marketplace.json && claude plugin install vodailocz-kilo-kit-mcp@llmmart"},{"target":"git","command":"git clone https://github.com/VoDaiLocz/kilo-kit-mcp.git"}]}