Welcome to my 2023 Irreverant Red Team TTP Wrap Up (Trends, Trolls, Predictions)
It's likely some of these will ruffle feathers, but hackers break things right? 😁
🧵👇
Are you building an internal Red Team? Do you want to know how to set goals and provide guidance to gauge the maturity of your Red Team? Look no further! Check out "The Matrix" - a model that provides guidance and sets goals for Red Team maturity.
https://t.co/HoIlnnX82p
Good blog on measuring your offensive security maturity: https://t.co/S04xKAk2ca
If you want something a little deeper, check out the Red Team Maturity Model: https://t.co/JPLL8xvZ78
We cover the different roles, measuring, and maturing your red team program in #SEC565
At @SpecterOps, @leidy_tector and I focus on maturing detection engineering teams. This blog explores our methodology for prioritizing the detection engineering backlog. https://t.co/XQqn7Qh8RN
Confused by the @dotMudge whistleblow. When you are hired to lead security at a company, you are undoubtedly going to inherit problems like described in the article. It’s your job to lead through constant improvement to a better, more secure place & reduce risk. It’s hard work.
🧵Sure this is bad but it's also on par with the average state of cybersecurity in the vast majority of organizations.
Yet every time a report like this hits the press we're all taken aghast? Why?
https://t.co/0SfeVEnbfi
I'm happy to share the results of months of research on code injection, process tampering, and their detection! 🥳
Here you'll find technique categorization, a dive into the underlying OS mechanisms, sample demos, detection suggestions, and much more:
https://t.co/KZyI0PKlPz
I released a new version of the detection engineering maturity matrix at https://t.co/SotN9bQBJR.
This update adds sub-categories to make the matrix more consumable and includes a few content updates.
@Voulnet@TechBrunchFR@subtee@0xdabbad00 Thanks @Voulnet!! Something like https://t.co/C8aCFzC0ny in GCP would be https://t.co/pxD4zgGShw or what I would look at is https://t.co/0CudgNd1Jw & https://t.co/NTX1SvZi77
Most or all red teams offer assumed breach after a fixed amount of time these days. The downside to having entire blue team involved is unrealistic responses to low level alerts or things that happen along the way https://t.co/XZELVqvkxQ
A couple recent tweets from various people about everyone wanting to be a red teamer. It's a really interesting time if you're red teaming clients who actually need it. There is a constant requirement to be on top of EDR products/detections that could change daily.
@HackingLZ@techspence@klrgrz Reminds me of this. We make the rules, we act as umpire, then act shocked when the blue team doesn't want to play. https://t.co/K2gqWnzWn7
@subTee It's as if we've been making the rules for our own game and taking the role of umpire, then acting surprised when the blue team doesn't show up.
https://t.co/K2gqWnzWn7