Install any skill in seconds. Free to start, no credit card required.
Get Started Free →Red team tactics principles based on MITRE ATT&CK. Attack phases, detection evasion, reporting.
.claude/skills/lingxling-red-team-tactics/SKILL.md| Test case | Without → With | Effect | Δ tokens | Δ turns |
|---|---|---|---|---|
| case-14 | ✗→✓ | ▲ Improved | 10% | 0% |
| case-19 | ✗→✓ | ▲ Improved | 2% | 0% |
| case-10 | ✓→✗ | ▼ Worse | -3% | 0% |
| case-22 | ✓→✗ | ▼ Worse | 16% | 0% |
| case-06 | ✓→✓ | = Same ✓ | 44% | 0% |
> AUTHORIZED USE ONLY: Use this skill only for authorized security assessments, defensive validation, or controlled educational environments.
> Adversary simulation principles based on MITRE ATT&CK framework.
RECONNAISSANCE → INITIAL ACCESS → EXECUTION → PERSISTENCE
↓ ↓ ↓ ↓
PRIVILEGE ESC → DEFENSE EVASION → CRED ACCESS → DISCOVERY
↓ ↓ ↓ ↓
LATERAL MOVEMENT → COLLECTION → C2 → EXFILTRATION → IMPACT| Phase | Objective | |-------|-----------| | Recon | Map attack surface | | Initial Access | Get first foothold | | Execution | Run code on target | | Persistence | Survive reboots | | Privilege Escalation | Get admin/root | | Defense Evasion | Avoid detection | | Credential Access | Harvest credentials | | Discovery | Map internal network | | Lateral Movement | Spread to other systems | | Collection | Gather target data | | C2 | Maintain command channel | | Exfiltration | Extract data |
| Type | Trade-off | |------|-----------| | Passive | No target contact, limited info | | Active | Direct contact, more detection risk |
| Category | Value | |----------|-------| | Technology stack | Attack vector selection | | Employee info | Social engineering | | Network ranges | Scanning scope | | Third parties | Supply chain attack |
| Vector | When to Use | |--------|-------------| | Phishing | Human target, email access | | Public exploits | Vulnerable services exposed | | Valid credentials | Leaked or cracked | | Supply chain | Third-party access |
| Check | Opportunity | |-------|-------------| | Unquoted service paths | Write to path | | Weak service permissions | Modify service | | Token privileges | Abuse SeDebug, etc. | | Stored credentials | Harvest |
| Check | Opportunity | |-------|-------------| | SUID binaries | Execute as owner | | Sudo misconfiguration | Command execution | | Kernel vulnerabilities | Kernel exploits | | Cron jobs | Writable scripts |
| Technique | Purpose | |-----------|---------| | LOLBins | Use legitimate tools | | Obfuscation | Hide malicious code | | Timestomping | Hide file modifications | | Log clearing | Remove evidence |
| Type | Use | |------|-----| | Password | Standard auth | | Hash | Pass-the-hash | | Ticket | Pass-the-ticket | | Certificate | Certificate auth |
| Attack | Target | |--------|--------| | Kerberoasting | Service account passwords | | AS-REP Roasting | Accounts without pre-auth | | DCSync | Domain credentials | | Golden Ticket | Persistent domain access |
Document the full attack chain:
For each successful technique:
| ❌ Don't | ✅ Do | |----------|-------| | Rush to exploitation | Follow methodology | | Cause damage | Minimize impact | | Skip reporting | Document everything | | Ignore scope | Stay within boundaries |
> Remember: Red team simulates attackers to improve defenses, not to cause harm.
This skill is applicable to execute the workflow or actions described in the overview.
| Case | Status | Duration (ms) | Turns | Tokens | Tool calls | ||||||||
|---|---|---|---|---|---|---|---|---|---|---|---|---|---|
| Without | With | Δ | Without | With | Δ | Without | With | Δ | Without | With | Δ | ||
case-03 | fail→fail | 22,554 | 11,516 | -49% | 1 | 1 | 0% | 3,118 | 2,859 | -8% | 0 | 0 | — |
case-01 | fail→fail | 58,943 | 33,997 | -42% | 1 | 1 | 0% | 8,247 | 5,194 | -37% | 0 | 0 | — |
case-02 | fail→fail | 23,553 | 22,557 | -4% | 1 | 1 | 0% | 3,850 | 4,133 | +7% | 0 | 0 | — |
case-04 | fail→fail | 14,995 | 15,244 | +2% | 1 | 1 | 0% | 2,264 | 3,038 | +34% | 0 | 0 | — |
case-05 | fail→fail | 29,765 | 22,504 | -24% | 1 | 1 | 0% | 2,583 | 3,616 | +40% | 0 | 0 | — |
case-06 | pass→pass | 23,619 | 24,783 | +5% | 1 | 1 | 0% | 2,283 | 3,284 | +44% | 0 | 0 | — |
case-07 | fail→fail | 16,205 | 16,293 | +1% | 1 | 1 | 0% | 2,895 | 3,567 | +23% | 0 | 0 | — |
case-08 | pass→pass | 20,778 | 18,881 | -9% | 1 | 1 | 0% | 3,439 | 3,142 | -9% | 0 | 0 | — |
case-09 | pass→pass | 20,262 | 11,628 | -43% | 1 | 1 | 0% | 3,675 | 3,031 | -18% | 0 | 0 | — |
case-10 | pass→fail | 18,483 | 10,386 | -44% | 1 | 1 | 0% | 2,445 | 2,372 | -3% | 0 | 0 | — |
case-11 | pass→pass | 23,097 | 18,035 | -22% | 1 | 1 | 0% | 2,896 | 3,355 | +16% | 0 | 0 | — |
case-12 | fail→fail | 19,226 | 16,698 | -13% | 1 | 1 | 0% | 2,266 | 3,117 | +38% | 0 | 0 | — |
case-13 | pass→pass | 19,278 | 10,842 | -44% | 1 | 1 | 0% | 2,526 | 2,704 | +7% | 0 | 0 | — |
case-14 | fail→pass | 21,701 | 14,970 | -31% | 1 | 1 | 0% | 3,226 | 3,563 | +10% | 0 | 0 | — |
case-15 | pass→pass | 13,492 | 9,912 | -27% | 1 | 1 | 0% | 2,058 | 2,629 | +28% | 0 | 0 | — |
case-16 | pass→pass | 15,364 | 16,219 | +6% | 1 | 1 | 0% | 2,010 | 3,178 | +58% | 0 | 0 | — |
case-17 | pass→pass | 12,291 | 6,950 | -43% | 1 | 1 | 0% | 1,834 | 2,180 | +19% | 0 | 0 | — |
case-18 | pass→pass | 14,305 | 10,813 | -24% | 1 | 1 | 0% | 2,364 | 2,938 | +24% | 0 | 0 | — |
case-19 | fail→pass | 13,433 | 5,927 | -56% | 1 | 1 | 0% | 1,885 | 1,915 | +2% | 0 | 0 | — |
case-20 | pass→pass | 14,482 | 9,050 | -38% | 1 | 1 | 0% | 2,567 | 2,689 | +5% | 0 | 0 | — |
case-21 | pass→pass | 16,278 | 15,144 | -7% | 1 | 1 | 0% | 2,820 | 3,183 | +13% | 0 | 0 | — |
case-22 | pass→fail | 12,376 | 6,520 | -47% | 1 | 1 | 0% | 1,736 | 2,013 | +16% | 0 | 0 | — |
DecimalAI ran this skill against gemini-3.6-flash twice over the same eval suite — once with the skill loaded and once without — and compared the two runs case by case. 22 cases were attempted. The headline lift of 0 percentage points is the difference between those two pass rates over the 22 comparable cases. 2 cases got worse with the skill loaded, and they are included in that figure.
Without the skill loaded, the model failed this case. With it loaded, the same prompt on the same model passed. This is one improved case from the latest verified run; every case, including any that regressed, is in the table above.
Other measured skills in the registry, with their headline benchmark lift.