Claude Cursor opencode Skill

red-team-tactics

Red team tactics principles based on MITRE ATT&CK. Attack phases, detection evasion, reporting.

LLM Mart · 0 points · 0 views 0 listing impressions 0 install-command copies
Virus-scanned Reviewed automatically before listing.

Full trust report

Download vodailocz-kilo-kit-mcp-skills_security_red-team-tactics-0448e6c.zip · 2 KB
Part of vodailocz/kilo-kit-mcp — 142 skills

Install

skills CLI npx skills add https://github.com/VoDaiLocz/kilo-kit-mcp/tree/main/skills/security/red-team-tactics
Claude Code claude plugin marketplace add https://llmmart.ai/marketplace.json && claude plugin install vodailocz-kilo-kit-mcp@llmmart
Git git clone https://github.com/VoDaiLocz/kilo-kit-mcp.git

The skills CLI installs just this skill, for any of its supported agents. Claude Code installs the whole vodailocz/kilo-kit-mcp collection as a plugin from our marketplace. Git is the plain clone.

Skill manifest

Red Team Tactics

Adversary simulation principles based on MITRE ATT&CK framework.


1. MITRE ATT&CK Phases

Attack Lifecycle

RECONNAISSANCE → INITIAL ACCESS → EXECUTION → PERSISTENCE
       ↓              ↓              ↓            ↓
   PRIVILEGE ESC → DEFENSE EVASION → CRED ACCESS → DISCOVERY
       ↓              ↓              ↓            ↓
LATERAL MOVEMENT → COLLECTION → C2 → EXFILTRATION → IMPACT

Phase Objectives

Phase Objective
Recon Map attack surface
Initial Access Get first foothold
Execution Run code on target
Persistence Survive reboots
Privilege Escalation Get admin/root
Defense Evasion Avoid detection
Credential Access Harvest credentials
Discovery Map internal network
Lateral Movement Spread to other systems
Collection Gather target data
C2 Maintain command channel
Exfiltration Extract data

2. Reconnaissance Principles

Passive vs Active

Type Trade-off
Passive No target contact, limited info
Active Direct contact, more detection risk

Information Targets

Category Value
Technology stack Attack vector selection
Employee info Social engineering
Network ranges Scanning scope
Third parties Supply chain attack

3. Initial Access Vectors

Selection Criteria

Vector When to Use
Phishing Human target, email access
Public exploits Vulnerable services exposed
Valid credentials Leaked or cracked
Supply chain Third-party access

4. Privilege Escalation Principles

Windows Targets

Check Opportunity
Unquoted service paths Write to path
Weak service permissions Modify service
Token privileges Abuse SeDebug, etc.
Stored credentials Harvest

Linux Targets

Check Opportunity
SUID binaries Execute as owner
Sudo misconfiguration Command execution
Kernel vulnerabilities Kernel exploits
Cron jobs Writable scripts

5. Defense Evasion Principles

Key Techniques

Technique Purpose
LOLBins Use legitimate tools
Obfuscation Hide malicious code
Timestomping Hide file modifications
Log clearing Remove evidence

Operational Security

  • Work during business hours
  • Mimic legitimate traffic patterns
  • Use encrypted channels
  • Blend with normal behavior

6. Lateral Movement Principles

Credential Types

Type Use
Password Standard auth
Hash Pass-the-hash
Ticket Pass-the-ticket
Certificate Certificate auth

Movement Paths

  • Admin shares
  • Remote services (RDP, SSH, WinRM)
  • Exploitation of internal services

7. Active Directory Attacks

Attack Categories

Attack Target
Kerberoasting Service account passwords
AS-REP Roasting Accounts without pre-auth
DCSync Domain credentials
Golden Ticket Persistent domain access

8. Reporting Principles

Attack Narrative

Document the full attack chain:

  1. How initial access was gained
  2. What techniques were used
  3. What objectives were achieved
  4. Where detection failed

Detection Gaps

For each successful technique:

  • What should have detected it?
  • Why didn't detection work?
  • How to improve detection

9. Ethical Boundaries

Always

  • Stay within scope
  • Minimize impact
  • Report immediately if real threat found
  • Document all actions

Never

  • Destroy production data
  • Cause denial of service (unless scoped)
  • Access beyond proof of concept
  • Retain sensitive data

10. Anti-Patterns

❌ Don't ✅ Do
Rush to exploitation Follow methodology
Cause damage Minimize impact
Skip reporting Document everything
Ignore scope Stay within boundaries

Remember: Red team simulates attackers to improve defenses, not to cause harm.

Files (kilo-kit-mcp)
  • SKILL.md 4.3 KB
    ---
    name: red-team-tactics
    description: Red team tactics principles based on MITRE ATT&CK. Attack phases, detection evasion, reporting.
    allowed-tools: Read, Glob, Grep
    ---
    
    # Red Team Tactics
    
    > Adversary simulation principles based on MITRE ATT&CK framework.
    
    ---
    
    ## 1. MITRE ATT&CK Phases
    
    ### Attack Lifecycle
    
    ```
    RECONNAISSANCE → INITIAL ACCESS → EXECUTION → PERSISTENCE
           ↓              ↓              ↓            ↓
       PRIVILEGE ESC → DEFENSE EVASION → CRED ACCESS → DISCOVERY
           ↓              ↓              ↓            ↓
    LATERAL MOVEMENT → COLLECTION → C2 → EXFILTRATION → IMPACT
    ```
    
    ### Phase Objectives
    
    | Phase | Objective |
    |-------|-----------|
    | **Recon** | Map attack surface |
    | **Initial Access** | Get first foothold |
    | **Execution** | Run code on target |
    | **Persistence** | Survive reboots |
    | **Privilege Escalation** | Get admin/root |
    | **Defense Evasion** | Avoid detection |
    | **Credential Access** | Harvest credentials |
    | **Discovery** | Map internal network |
    | **Lateral Movement** | Spread to other systems |
    | **Collection** | Gather target data |
    | **C2** | Maintain command channel |
    | **Exfiltration** | Extract data |
    
    ---
    
    ## 2. Reconnaissance Principles
    
    ### Passive vs Active
    
    | Type | Trade-off |
    |------|-----------|
    | **Passive** | No target contact, limited info |
    | **Active** | Direct contact, more detection risk |
    
    ### Information Targets
    
    | Category | Value |
    |----------|-------|
    | Technology stack | Attack vector selection |
    | Employee info | Social engineering |
    | Network ranges | Scanning scope |
    | Third parties | Supply chain attack |
    
    ---
    
    ## 3. Initial Access Vectors
    
    ### Selection Criteria
    
    | Vector | When to Use |
    |--------|-------------|
    | **Phishing** | Human target, email access |
    | **Public exploits** | Vulnerable services exposed |
    | **Valid credentials** | Leaked or cracked |
    | **Supply chain** | Third-party access |
    
    ---
    
    ## 4. Privilege Escalation Principles
    
    ### Windows Targets
    
    | Check | Opportunity |
    |-------|-------------|
    | Unquoted service paths | Write to path |
    | Weak service permissions | Modify service |
    | Token privileges | Abuse SeDebug, etc. |
    | Stored credentials | Harvest |
    
    ### Linux Targets
    
    | Check | Opportunity |
    |-------|-------------|
    | SUID binaries | Execute as owner |
    | Sudo misconfiguration | Command execution |
    | Kernel vulnerabilities | Kernel exploits |
    | Cron jobs | Writable scripts |
    
    ---
    
    ## 5. Defense Evasion Principles
    
    ### Key Techniques
    
    | Technique | Purpose |
    |-----------|---------|
    | LOLBins | Use legitimate tools |
    | Obfuscation | Hide malicious code |
    | Timestomping | Hide file modifications |
    | Log clearing | Remove evidence |
    
    ### Operational Security
    
    - Work during business hours
    - Mimic legitimate traffic patterns
    - Use encrypted channels
    - Blend with normal behavior
    
    ---
    
    ## 6. Lateral Movement Principles
    
    ### Credential Types
    
    | Type | Use |
    |------|-----|
    | Password | Standard auth |
    | Hash | Pass-the-hash |
    | Ticket | Pass-the-ticket |
    | Certificate | Certificate auth |
    
    ### Movement Paths
    
    - Admin shares
    - Remote services (RDP, SSH, WinRM)
    - Exploitation of internal services
    
    ---
    
    ## 7. Active Directory Attacks
    
    ### Attack Categories
    
    | Attack | Target |
    |--------|--------|
    | Kerberoasting | Service account passwords |
    | AS-REP Roasting | Accounts without pre-auth |
    | DCSync | Domain credentials |
    | Golden Ticket | Persistent domain access |
    
    ---
    
    ## 8. Reporting Principles
    
    ### Attack Narrative
    
    Document the full attack chain:
    1. How initial access was gained
    2. What techniques were used
    3. What objectives were achieved
    4. Where detection failed
    
    ### Detection Gaps
    
    For each successful technique:
    - What should have detected it?
    - Why didn't detection work?
    - How to improve detection
    
    ---
    
    ## 9. Ethical Boundaries
    
    ### Always
    
    - Stay within scope
    - Minimize impact
    - Report immediately if real threat found
    - Document all actions
    
    ### Never
    
    - Destroy production data
    - Cause denial of service (unless scoped)
    - Access beyond proof of concept
    - Retain sensitive data
    
    ---
    
    ## 10. Anti-Patterns
    
    | ❌ Don't | ✅ Do |
    |----------|-------|
    | Rush to exploitation | Follow methodology |
    | Cause damage | Minimize impact |
    | Skip reporting | Document everything |
    | Ignore scope | Stay within boundaries |
    
    ---
    
    > **Remember:** Red team simulates attackers to improve defenses, not to cause harm.
    

Comments (0)

Sign in to join the conversation.

No comments yet.

Reviews (0)

No reviews yet.

Related