API Reference: Red Team Engagement Planning
MITRE ATT&CK Framework
Tactics (Enterprise)
| ID |
Tactic |
| TA0043 |
Reconnaissance |
| TA0042 |
Resource Development |
| TA0001 |
Initial Access |
| TA0002 |
Execution |
| TA0003 |
Persistence |
| TA0004 |
Privilege Escalation |
| TA0005 |
Defense Evasion |
| TA0006 |
Credential Access |
| TA0007 |
Discovery |
| TA0008 |
Lateral Movement |
| TA0009 |
Collection |
| TA0011 |
Command and Control |
| TA0010 |
Exfiltration |
| TA0040 |
Impact |
ATT&CK Navigator API
Red Team Tools API References
Cobalt Strike — Teamserver
GoPhish — Campaign API
BloodHound — Data Collection
Engagement Plan Structure
Key Sections
| Section |
Content |
| Scope |
IP ranges, domains, systems in/out |
| Rules of Engagement |
Authorization, boundaries |
| Objectives |
Goals mapped to business risk |
| Scenarios |
Attack paths and techniques |
| Timeline |
Phases with milestones |
| Communication |
Deconfliction, reporting |
| Data Handling |
Encryption, retention, destruction |
PTES (Penetration Testing Execution Standard)
Phases
- Pre-engagement Interactions
- Intelligence Gathering
- Threat Modeling
- Vulnerability Analysis
- Exploitation
- Post-Exploitation
- Reporting
Report Template Fields
| Field |
Description |
| Executive Summary |
Business impact overview |
| Scope & Methodology |
What was tested and how |
| Findings |
Vulnerabilities with CVSS scores |
| Attack Narrative |
Timeline of red team actions |
| Detection Gaps |
What blue team missed |
| Recommendations |
Prioritized remediation |