Plans red team engagements by defining scope, rules of engagement (ROE), MITRE ATT&CK threat profiles, and operational timelines before attack testing.
npx claudepluginhub killvxk/cybersecurity-skills-zhThis skill uses the workspace's default tool permissions.
红队演练规划是在任何攻击测试开始之前,确定范围、目标、交战规则(ROE)、威胁模型选择和操作时间表的基础阶段。结构良好的演练计划确保红队模拟真实的对手行为,同时维持防止意外业务中断的安全护栏。
Plans red team engagements by defining scope, objectives, rules of engagement, threat models, and timelines before offensive security testing.
Guides red team engagement planning by defining scope, objectives, ROE, MITRE ATT&CK threat models, timelines, and deconfliction for authorized offensive testing.
Executes red team exercises simulating stealthy adversary attacks across full lifecycle from reconnaissance to exfiltration, testing detection and response. For red teaming, adversary emulation requests.
Share bugs, ideas, or general feedback.
红队演练规划是在任何攻击测试开始之前,确定范围、目标、交战规则(ROE)、威胁模型选择和操作时间表的基础阶段。结构良好的演练计划确保红队模拟真实的对手行为,同时维持防止意外业务中断的安全护栏。
| 类型 | 描述 | 范围 |
|---|---|---|
| 全范围 | 包含物理、社会和网络向量的完整对手模拟 | 整个组织 |
| 假设已入侵 | 从初始立足点开始,专注于后渗透 | 内部网络 |
| 基于目标 | 针对特定关键资产(如域管理员、PII 外泄) | 指定目标 |
| 紫队(Purple Team) | 与蓝队协作改进检测能力 | 特定控制措施 |
使用 MITRE ATT&CK Navigator 映射组织威胁,选择相关对手配置文件: