red-team-operations--engagement-planning

Featured

Authorized red team engagement planning, C2 architecture design, attack methodology, lateral movement strategy, OPSEC, and professional reporting

Data & Documents 409 stars 76 forks Updated 3 days ago MIT

Install

View on GitHub

Quality Score: 95/100

Stars 20%
87
Recency 20%
100
Frontmatter 20%
70
Documentation 15%
100
Issue Health 10%
80
License 10%
100
Description 5%
100

Skill Content

# Red Team Operations & Engagement Planning ## Purpose Enable Claude to assist authorized red team operators with engagement planning, C2 infrastructure design, attack methodology guidance, lateral movement strategy, OPSEC planning, and comprehensive reporting. Every workflow requires confirmed written authorization. > **CRITICAL — AUTHORIZATION GATE**: Red team assistance requires explicit authorization confirmation before proceeding. Claude will ask for authorization context and will not assist with active attack planning without it. > > **Authorized contexts:** > - Signed Statement of Work (SOW) or Rules of Engagement (ROE) > - Bug bounty program (confirm target is in-scope) > - Internal security testing (confirm organizational authority) > - CTF competition (confirm challenge platform and scope) > - Research in owned/isolated lab environment --- ## Activation Triggers This skill activates when the user asks about: - Planning a red team engagement or adversary simulation - Designing C2 infrastructure (redirectors, team servers, C2 profiles) - Active Directory attack paths (BloodHound, Kerberoasting, DCSync) - Lateral movement techniques for authorized engagements - Persistence mechanisms in red team context - Social engineering campaign planning (authorized) - Red team reporting and executive presentations - Tabletop exercises (TTX) design - Purple team collaboration - OPSEC planning for authorized operations --- ## Prerequisites ```bash pip install pyyaml request...

Details

Author
Masriyan
Repository
Masriyan/Claude-Code-CyberSecurity-Skill
Created
6 months ago
Last Updated
3 days ago
Language
Python
License
MIT

Bundled in these plugins

Similar Skills

Semantically similar based on skill content — not just same category

Data & Documents Featured

offensive-advanced-redteam

Comprehensive red team operations methodology covering full engagement lifecycle from planning through reporting. Addresses engagement scoping and rules of engagement negotiation, multi-tier C2 infrastructure design with redirectors and domain fronting, malleable traffic profiles and beacon tradecraft, OPSEC discipline including attribution avoidance and indicator management, EDR and AMSI evasion techniques using direct syscalls and unhooking, data collection with chain-of-custody controls, and structured reporting with purple team debrief workflows. Covers assumed-breach, external-to-internal, insider threat, and hybrid physical-cyber engagement scenarios with MITRE ATT&CK mapping throughout. Targets operators planning or executing adversary simulation engagements against mature defenders.

3,234 Updated 1 weeks ago
SnailSploit
AI & Automation Listed

red-team

Offensive security team skill providing methodology guidance for penetration testing and red team engagements. Invoked when users request penetration testing, reconnaissance, vulnerability analysis, exploitation methodology, social engineering, C2 infrastructure, or engagement reporting. Routes to 11 specialized agents covering the full MITRE ATT&CK kill chain. All engagements require red-lead scope authorization before any other agent. Follows PTES, OSSTMM, and ATT&CK methodology frameworks.

33 Updated 2 days ago
geekatron
Data & Documents Featured

purple-team--adversary-emulation

Collaborative purple-team operations — threat-informed adversary emulation planning (ATT&CK, CTID, Atomic Red Team, CALDERA), the detect-tune-validate loop, detection coverage measurement (DeTT&CT/Navigator), safe execution and deconfliction, and MTTD/coverage reporting

409 Updated 3 days ago
Masriyan