From red-team
Plan and run an objectives-based adversary-emulation engagement: select a relevant threat actor, build an ATT&CK-mapped emulation plan across the attack lifecycle, execute within rules of engagement, and assess detection/response. Use for full-scope red-team work. Strictly authorized engagements only.
How this skill is triggered — by the user, by Claude, or both
Slash command
/red-team:adversary-emulationThe summary Claude sees in its skill listing — used to decide when to auto-load this skill
A realistic, objectives-based engagement that emulates a chosen adversary's TTPs to
A realistic, objectives-based engagement that emulates a chosen adversary's TTPs to reach a defined objective — producing both offensive findings and an honest measure of the blue team's detection and response.
threat-intelligence:threat-actor-profiling) and define the objective (e.g.
"access crown-jewel data X"). Realism comes from emulating a real actor's TTPs.osint (footprinting, exposure, people) to find a realistic entry.network-security. Operate
with appropriate stealth where authorized, but never outside scope and never
destructively. Log every action with timestamps for deconfliction.An engagement report: objective & outcome · adversary emulated · ATT&CK technique
timeline (executed vs. detected vs. responded) · attack path
(security-diagramming:attack-tree) · findings · detection/response gaps ·
recommendations. Use security-reporting. Feed gaps to detection-engineering and
run a blue-team:purple-team-exercise to close them.
Red teaming measures outcomes and detection, not vulnerability count — the deliverable is "could a realistic adversary achieve X, and would we have caught them?" Stay rigorously within RoE: authorized, non-destructive, deconflicted, and logged. The highest value is collaborative (purple) — emulate, measure, then help the defenders close the gaps.
Creates, edits, and optimizes skills for Claude Code, including drafting, evaluating with test prompts, iterating on performance, and improving skill descriptions for better triggering accuracy.
npx claudepluginhub jassics/awesome-claude-security --plugin red-team