I'll be speaking at @cackalackycon on May 19th! My talk is entitled "Everything You Never Wanted to Know About Red Teaming but Have Been Forced to Find Out" (h/t @mah3mm) and it's all about the side(s) of red teaming as a customer or practitioner they don't tell you about!
I wrote this to try to bring some reality to people trying to break into cyber. People will disagree with some (all) of it but hopefully somebody benefits from what I saw when I worked as a pentester.
https://t.co/LJaa7aA1Ty
I wrote this to try to bring some reality to people trying to break into cyber. People will disagree with some (all) of it but hopefully somebody benefits from what I saw when I worked as a pentester.
https://t.co/LJaa7aA1Ty
If you ever feel like you’re not leet enough, just read this and remember that someone ran a years-long APT targeting multiple countries off of shit they probably learned in their OSCP course
https://t.co/dG3brILcDl
@_1r15h_@Jhaddix lol if all you knew was western infosec news and threat intel, you’d think that hacking and APTs were purely a Russian/Chinese/DPRK/Iranian phenomenon and that none of the US or its allies ever did bad things with computers
@Jhaddix Also, just in regards to public APT reports: I suspect that the really advanced nation-state groups with the most cutting edge tradecraft aren’t getting caught yet, and if they are, that info is being kept close to the breast of LEOs and intel agencies 3/3
@Jhaddix And a part of that is selection bias: the companies that care enough to invest in a good SOC and do red/purple teams are harder to hack, so real world predators will go for the weaker/easier prey. The orgs that need red/purple the most are the ones not buying it! 2/n