Skip to content
Back to skills

Red Teaming

ASecurity

Emulate an adversary with MITRE ATT&CK, TIBER-style phases, and PWN tools.

  • 86 stars
  • 0 votes
  • 0 copies
  • 14 views
  • Added September 10, 2026
securitygogitapi

Works with

  • terminal
  • api

Security analysis

A100/100

Scanned September 10, 2026

npx -y skills add 0dayInc/pwn --skill red-teaming --agent claude-code

Installs into .claude/skills of the current project.

Are you the author of Red Teaming?

Add the live security badge to your README. It updates with every re-scan.

Security grade badge for Red Teaming
[![Security: A — Skills Directory](https://www.skillsdirectory.com/api/skills/0dayinc-red-teaming/badge)](https://www.skillsdirectory.com/skills/0dayinc-red-teaming)

More formats (shields.io, HTML) on the badges page. Keep it an A: scan every change in CI with Pro.

Download with Pro
SKILL.md
---
name: red-teaming
description: Emulate an adversary with MITRE ATT&CK, TIBER-style phases, and PWN tools.
license: MIT
allowed-tools: [pwn, terminal, extrospection]
metadata:
  bundled: true
  references:
    - https://attack.mitre.org/
    - https://www.ecb.europa.eu/paym/cyber-resilience/tiber-eu/html/index.en.html
    - https://www.crest-approved.org/
---

# Red Teaming

Use when the ask is adversary emulation, detection validation, or a
objective-based campaign - not a full-port pentest. Pentest = find
vulns. Red team = achieve a stated objective while mapping ATT&CK.

## When to use

- "red team", "assume breach", "purple team", "ATT&CK coverage"
- TIBER-EU / CBEST-shaped finance tests
- detect-and-respond exercises

## Methodologies

| Catalog | Role |
|---|---|
| MITRE ATT&CK | tactics/techniques for plan, execute, and report |
| Lockheed Martin Cyber Kill Chain | coarse campaign stages |
| TIBER-EU / CBEST | threat-intel-led, regulator-shaped red team |
| CREST | professional engagement hygiene |
| PTES | only for the exploit/post-ex slices |
| NIST SP 800-115 | evidence language if the customer is federal |

ATT&CK is the default label set. Kill Chain is the slide. TIBER is the
engagement wrapper when the customer named it.

## Tooling

- Intel: `PWN::Plugins::Shodan`, `Hunter`, `Github`, `IPInfo`
- Access: `NmapIt`, Burp, `TransparentBrowser`, `Metasploit`
- C2 / sessions: Metasploit sessions when asked; stay reversible
- Evidence: `PWN::Reports::*`, session JSONL, packet captures via
  `extro_packet` if granted

## Procedure

1. Objective + threat scenario (who, what crown jewel, success criteria).
2. Threat intel: techniques the scenario actually uses. Write an ATT&CK
   matrix for this op (not the whole enterprise).
3. Initial access path (or assumed-breach creds if that is the rules).
4. Execute only the techniques on the matrix. Record tactic, technique
   id, timestamp, detection (seen / not seen).
5. Stop at the objective or the agreed time box. No extra ransomware
   theatre.
6. Report: path, ATT&CK coverage, detections missed, fix owners.

## Pitfalls

- A noisy full nmap of the company is a pentest, not a red team.
- Do not invent a TIBER "white team" process the operator did not ask
  for. Follow the named targets.
- Purple team means show the defender the technique as you go.

## Verification

Written objective, ATT&CK technique list, at least one live action with
evidence, and a report that maps actions to technique ids.

Attribution

Is this your skill, or is something wrong with this listing? Request removal or report an issue. Author removals are honored within 72 hours.

Comments

Loading comments…