@MDSecLabs will be running our Red Team Capability Training out in #BlackHatUSA26 again this year. This year the course features a big refresh, with a bunch of new additions on the latest evolving techniques!
Early bird discounts end this month! @BlackHatEvents
https://t.co/l3uAga4TS5
This year we're bringing our Adversary Simulation and Capability Development training to Asia for the first time with @BlackHatEvents#blackhatasia26 https://t.co/ipPoV0UwvJ
If you want some hands on red teaming and tool development training from seasoned experts (@_batsec_ ), the early bird pricing is now available!
i really do not understand this recent take that “socks is all you need”.
imo nothing highlights the difference in standards of what a ‘red team’ is than this.
the point is to use the necessary tradecraft to achieve the objectives, the client then advances their ability to detect this tradecraft and the cycle continues.
this type of exercise is mostly pointless unless the client already has a high level of maturity.
that’s why purple team exercises are more universal and offer the most benefit to organisations looking to start building their maturity level.
@BrandonTahedl We use Tailscale + GitHub for user/access management. LibreOffice, but rarely. Nothing for MDM, but there is Fleet MDM + Sandly Security.
@_EthicalChaos_@frodosobon@inversecos for sure, there is a lot of value and lessons that are learnt from perform an effective threat hunt. tracking a TAs pathway thru the network and identifying alternative c2 channels or persistence is not an easy task.
@_EthicalChaos_@frodosobon@inversecos yeh that’s true but a SOCs response to a detection is a whole new topic. this is why I like running a “detect and evict�� scenario at the end of an RT and raising the noise level massively. detection means nothing without eviction.
@_EthicalChaos_@frodosobon@inversecos agreed, but emulation is not a red team. if a client what to check if they would catch a TA employing the same TTPs someone else caught them using, then that’s fair. but it’s a purple team.