Token导航 LogoToken导航TokenDH.com
研究检索敏感数据github未标认证来源可访问许可证需确认审计异常

executing-red-team-exercise执行红队演习

Agent Skill

executing-red-team-exercise 用于查找、检索和筛选相关信息,适合在 Codex、Claude、Cursor、Gemini CLI 中需要根据关键词、任务场景或来源线索快速定位候选结果时使用。可结合来源仓库、安装命令和原始 README 继续核验具体用法。安装前建议确认权限范围、维护状态,以及是否会触发联网、命令执行或文件读写。

总安装

539

周安装

22

GitHub Stars

5,879

下载量

174
CodexClaudeCursorGemini CLI

安装说明

本站只整理中文说明和来源信息,不托管安装包,也不代用户安装。

GitHub

来源数

2

许可证

unknown

最后核验

2026-05-01

来源状态

来源可访问

安装方式

通过对话安装

复制提示词发给支持本地命令或 Skills 的 AI 助手,先确认命令和权限,再让它执行。

请帮我安装这个 Agent Skill:executing-red-team-exercise(执行红队演习)
来源仓库:https://github.com/mukul975/anthropic-cybersecurity-skills
仓库路径:skills/executing-red-team-exercise
安装命令:
npx skills add https://github.com/mukul975/anthropic-cybersecurity-skills --skill executing-red-team-exercise
安装前请先检查当前环境是否支持对应 CLI,并向我确认将要执行的命令、安装目录、联网范围和文件读写权限;确认后再执行。

命令行安装

复制命令到本机终端执行。该命令会通过 npx skills 从第三方来源获取 Skill;本站只展示命令,不托管安装包,也不自动执行。

skills.shnpx skills
npx skills add https://github.com/mukul975/anthropic-cybersecurity-skills --skill executing-red-team-exercise

简介

执行红队演习技能用于评估组织检测、响应和遏制真实攻击的能力。

  • 适合验证 SOC 效能、测试安全投资并满足监管要求。
  • 可针对特定威胁主体(如国家支持黑客)定制模拟攻击。
  • 安装前建议检查权限范围,避免触发不必要的系统变更或数据访问。
  • executing-red-team-exercise 属于研究检索类 Skill,可作为该场景下的辅助能力补充。

SKILL.md

Executing Red Team Exercise

When to Use

  • Assessing an organization's ability to detect, respond to, and contain a realistic adversary operation
  • Testing the effectiveness of the security operations center (SOC), incident response team, and threat hunting capabilities
  • Validating security investments by simulating attacks that chain multiple vulnerabilities and techniques
  • Evaluating the organization's security posture against specific threat actors (nation-state, ransomware groups, insider threats)
  • Meeting regulatory requirements for adversary simulation (TIBER-EU, CBEST, AASE, iCAST)

Do not use without executive-level authorization and a detailed Rules of Engagement document, against systems where disruption could affect safety or critical operations, or as a replacement for basic vulnerability management (fix known vulnerabilities first).

Prerequisites

  • Executive-level written authorization with clearly defined objectives, scope, and off-limits systems
  • Red team command and control (C2) infrastructure: primary and backup C2 channels with domain fronting or redirectors
  • Operator workstations with OPSEC-hardened toolsets (Cobalt Strike, Sliver, Brute Ratel, or Mythic)
  • Threat intelligence on adversary groups relevant to the target organization for adversary emulation planning
  • Trusted agent (white cell) within the target organization who manages the exercise boundaries without alerting defenders
  • MITRE ATT&CK matrix for mapping planned and executed techniques
Legal Notice: This skill is for authorized security testing and educational purposes only. Unauthorized use against systems you do not own or have written permission to test is illegal and may violate computer fraud laws.

Workflow

Step 1: Adversary Emulation Planning

Develop the operation plan based on a realistic threat model:

  • Threat actor selection: Select an adversary group relevant to the organization's industry. For financial services, emulate FIN7 or Lazarus Group. For healthcare, emulate APT41 or FIN12. Map the selected adversary's known TTPs from MITRE ATT&CK.
  • Objective definition: Define measurable objectives such as "Access customer financial data from the core banking system" or "Demonstrate ability to deploy ransomware across the domain"
  • Attack plan development: Create a step-by-step operation plan mapping each phase to ATT&CK tactics:

1. Initial Access (TA0001): Phishing, exploiting public-facing applications, or supply chain compromise 2. Execution (TA0002): PowerShell, scripting, exploitation for client execution 3. Persistence (TA0003): Scheduled tasks, registry modifications, implant deployment 4. Privilege Escalation (TA0004): Token impersonation, exploitation for privilege escalation 5. Defense Evasion (TA0005): Process injection, timestomping, indicator removal 6. Credential Access (TA0006): LSASS dumping, Kerberoasting, credential stuffing 7. Lateral Movement (TA0008): Remote services, pass-the-hash, remote desktop 8. Collection/Exfiltration (TA0009/TA0010): Data staging, exfiltration over C2

  • Deconfliction plan: Establish procedures for the white cell to distinguish red team activity from actual threats

Step 2: Infrastructure Preparation

Build OPSEC-hardened attack infrastructure:

  • C2 infrastructure: Deploy primary C2 server behind redirectors that filter Blue Team investigation traffic. Use domain fronting or legitimate cloud services (Azure CDN, CloudFront) to blend C2 traffic with normal web traffic.
  • Phishing infrastructure: Register aged domains (30+ days old), configure SPF/DKIM/DMARC, and build credential harvesting or payload delivery pages
  • Payload development: Create custom implants or configure C2 framework payloads with:

- AMSI bypass for PowerShell execution - ETW patching to evade security product telemetry - Sleep masking and memory encryption to defeat memory scanning - Signed binary proxy execution (rundll32, msbuild, regsvr32) for defense evasion

  • Staging infrastructure: Set up file hosting for second-stage payloads, exfiltration drop servers, and backup communication channels
  • OPSEC verification: Test the entire infrastructure against the same EDR/AV products deployed in the target environment before going live

Step 3: Initial Access

Gain initial foothold in the target environment:

  • Phishing campaign: Send targeted spear-phishing emails to selected employees with weaponized documents or credential harvesting links. Use pretexts based on OSINT gathered during reconnaissance.
  • External exploitation: Exploit vulnerabilities in internet-facing applications (VPN portals, web applications, email servers) identified during reconnaissance
  • Physical access: If in scope, attempt physical access to deploy network implants (LAN Turtle, Bash Bunny) or USB drops
  • Supply chain: If in scope, compromise a vendor or supplier relationship to gain indirect access
  • Upon successful initial access, establish the first C2 beacon and confirm communication with the C2 server. Immediately implement persistence (multiple mechanisms) to survive reboots and credential changes.

Step 4: Post-Exploitation and Objective Completion

Operate within the target environment while maintaining stealth:

  • Internal reconnaissance: Enumerate the domain, identify high-value targets, and map the network using BloodHound and internal scanning, with traffic designed to blend with normal administrative activity
  • Privilege escalation: Escalate from initial user to local admin, then to domain admin, using the least detectable techniques (Kerberoasting over pass-the-hash, living-off-the-land over custom tools)
  • Lateral movement: Move to target systems using legitimate protocols (RDP, WinRM, SMB) with stolen credentials. Vary techniques to test multiple detection signatures.
  • Defense evasion: Continuously adapt to avoid detection. If a technique triggers an alert, note the detection and switch to an alternative approach.
  • Objective execution: Complete the defined objectives (access target data, demonstrate ransomware staging, exfiltrate data) and document evidence of achievement
  • Detection timeline: Record timestamps for every technique executed to later compare against Blue Team's detection timeline

Step 5: Purple Team Integration and Reporting

Convert red team findings into defensive improvements:

  • Detection gap analysis: Compare the red team's technique timeline against the Blue Team's detection log. Identify which techniques were detected, which were missed, and the mean time to detect (MTTD) for each.
  • ATT&CK coverage mapping: Create an ATT&CK Navigator heatmap showing which techniques were tested and whether they were detected, missed, or partially detected
  • Purple team sessions: Conduct collaborative sessions where the red team reveals each technique step-by-step while the Blue Team identifies where detection should have occurred and writes new detection rules
  • Report: Deliver a comprehensive report including the operation narrative, technique-by-technique analysis with detection status, and prioritized recommendations for improving detection and response

Key Concepts

TermDefinition
Adversary EmulationSimulating the specific TTPs of a known threat actor to test defenses against realistic threats relevant to the organization
C2 (Command and Control)Infrastructure and communication channels used by the red team to remotely control implants deployed on compromised systems
OPSECOperational Security; practices employed by the red team to avoid detection by the defending team during the exercise
Domain FrontingA technique for hiding C2 traffic behind legitimate CDN domains to evade network-based detection and domain blocking
Purple TeamingCollaborative exercise where red and blue teams work together to improve detection by sharing attack techniques and defensive gaps
White CellThe trusted agent or exercise control group that manages the exercise, handles deconfliction, and mediates between red and blue teams
ImplantSoftware deployed by the red team on compromised systems to maintain access, execute commands, and facilitate lateral movement
MTTD/MTTRMean Time to Detect / Mean Time to Respond; metrics measuring how long it takes the defending team to identify and contain threats

Tools & Systems

  • Cobalt Strike: Commercial adversary simulation platform providing beacons, malleable C2 profiles, and post-exploitation capabilities
  • Sliver: Open-source C2 framework supporting multiple protocols (mTLS, WireGuard, HTTP/S, DNS) with cross-platform implants
  • MITRE ATT&CK Navigator: Tool for visualizing ATT&CK technique coverage, enabling comparison of planned vs. executed vs. detected techniques
  • Mythic: Open-source C2 framework with a modular agent architecture and web-based operator interface

Common Scenarios

Scenario: Adversary Emulation of FIN7 Against a Retail Company

Context: A national retail chain wants to test its defenses against FIN7, a financially motivated threat group known for targeting retail and hospitality organizations with point-of-sale malware, phishing, and data exfiltration.

Approach:

  1. Emulate FIN7 TTPs: spear-phishing with malicious document containing VBA macros that execute PowerShell
  2. Initial access achieved through spear-phishing a marketing employee; macro drops Cobalt Strike beacon using rundll32 proxy execution
  3. Internal reconnaissance with BloodHound reveals a path from the compromised user to a service account with access to the POS management server
  4. Kerberoast the service account, crack the password, and move laterally to the POS management system
  5. Demonstrate data access to cardholder data environment, staging simulated card data for exfiltration
  6. Exfiltrate staged data over DNS C2 channel to simulate data theft
  7. SOC detected the lateral movement at hour 47 but did not detect the initial phishing, macro execution, or Kerberoasting

Pitfalls:

  • Operating too aggressively and getting detected immediately, providing no value for testing Blue Team's advanced detection capabilities
  • Using exclusively custom tools instead of living-off-the-land techniques that real adversaries prefer
  • Not recording detailed timestamps for every action, making post-exercise analysis and detection gap mapping impossible
  • Failing to establish backup C2 channels, getting burned by a single detection, and losing access without completing objectives

Output Format

## Red Team Exercise Report - FIN7 Adversary Emulation

### Exercise Summary
**Duration**: November 4-22, 2025 (15 business days)
**Objective**: Access cardholder data environment and demonstrate data exfiltration capability
**Outcome**: OBJECTIVE ACHIEVED - Red team accessed POS management system and staged cardholder data for exfiltration

### ATT&CK Technique Coverage
| Technique | ID | Status | Detected? | MTTD |
|-----------|----|--------|-----------|------|
| Spear-Phishing Attachment | T1566.001 | Executed | No | - |
| Visual Basic Macro | T1059.005 | Executed | No | - |
| Process Injection | T1055 | Executed | No | - |
| Kerberoasting | T1558.003 | Executed | No | - |
| Remote Desktop Protocol | T1021.001 | Executed | YES | 47h |
| Data Staged | T1074 | Executed | No | - |
| Exfiltration Over C2 | T1041 | Executed | No | - |

### Detection Summary
- **Techniques Executed**: 14
- **Techniques Detected**: 3 (21.4%)
- **Mean Time to Detect**: 47 hours (for detected techniques)
- **Mean Time to Respond**: 4 hours (from detection to containment)

### Priority Recommendations
1. Deploy email detonation sandboxing for macro-enabled document analysis
2. Implement Kerberoasting detection via Windows Event ID 4769 monitoring
3. Enhance PowerShell logging (Script Block Logging, Module Logging)
4. Deploy memory-scanning EDR capability to detect process injection

适合场景

01

用户想查找某类 Agent Skill 时

02

需要根据任务场景推荐可安装能力包时

03

需要对比不同来源的安装命令和来源信息时

能力概览

能力 1

按任务关键词查找相关 Skills

能力 2

展示可复制的安装命令

能力 3

保留来源站点、仓库和原始说明,方便继续核验

能力 4

展示第三方安全扫描或审计结果

安装后应在对应宿主中按原始 README 的触发条件使用;具体调用方式请以来源页面和 README 为准。

平台分布

Codex

35.74%
按下载量换算62

Claude

30.44%
按下载量换算53

Cursor

19.52%
按下载量换算34

Gemini CLI

9.59%
按下载量换算17

安全审计

Gen Agent Trust Hub

通过

Socket

可疑

Snyk

未通过

权限和风险

敏感数据

该 Skill 可能接触密钥、Token、环境变量或敏感配置,应进入高风险复核队列,默认不自动发布。

安装前确认

本站仅展示第三方公开信息,不托管安装包,不提供自动安装或运行环境。安装前应自行审查源码、依赖和命令行为。来源安全扫描存在 warning/failed 结果,不能写成本站确认安全。当前只有一个来源,正式发布前建议补源仓库或其他目录站核验。

来源信息

继续浏览同类 Skills