This source did not publish a separate summary. Review SKILL.md before using the skill.
SKILL.md
Conducting Full-Scope Red Team Engagement
Overview
A full-scope red team engagement simulates real-world adversary behavior across all phases of the cyber kill chain — from initial reconnaissance through data exfiltration — to evaluate an organization's detection, prevention, and response capabilities. Unlike penetration testing, red team operations prioritize stealth, persistence, and objective-based scenarios that mimic advanced persistent threats (APTs).
When to Use
When conducting security assessments that involve conducting full scope red team engagement
When following incident response procedures for related security events
When performing scheduled security testing or auditing activities
When validating security controls through hands-on testing
Prerequisites
Written authorization (Rules of Engagement document) signed by executive leadership
Defined scope including in-scope/out-of-scope systems, escalation contacts, and emergency stop procedures
Threat intelligence on relevant adversary groups (e.g., APT29, FIN7, Lazarus Group)
Red team infrastructure: C2 servers, redirectors, phishing domains, payload development environment
Legal review confirming compliance with Computer Fraud and Abuse Act (CFAA) and local laws
Engagement Phases
Phase 1: Planning and Threat Modeling
Map the engagement to specific MITRE ATT&CK tactics and techniques based on the threat profile:
Kill Chain Phase
MITRE ATT&CK Tactic
Example Techniques
Reconnaissance
TA0043
T1593 Search Open Websites/Domains, T1589 Gather Victim Identity Info