Introduction To Red Teaming
Key Takeaways
Introduction to Red Teaming, its origins, and differences from Penetration Testing, covering roles and responsibilities within a red team.
Full Transcript
hey guys hackers BL here back again with another video Welcome Back to the red team Essentials series that again i' started a while back and uh in this particular video I'm going to be giving you a proper formal introduction to teaming uh one of the um uh one of the areas that was lacking in the red team essential series was a proper formal introduction along with um an explanation or a breakdown of how uh red teams work uh with regards to uh not only uh the operations themselves and you know the types of operations but also uh you know the organization um of a red team um you know when you're talking about for examp example uh The Operators um the red team lead Etc so uh in this video uh we're going to be getting this formal introduction now uh there's a couple of things that I want to mention before we get started uh uh the first thing is related to a question you might be asking yourself and that is um you know what's the importance of this uh you know I you probably have an understanding of red teaming um and don't worry by the end of this video you'll see why this is important uh another reason this is important is because uh these set of introductory videos or the red team videos that I'll be releasing this week or soon to follow after this video will set the stage for all of the red team related stuff we'll be you know exploring so you know ad pen testing C2 Frameworks so on and so forth so this is going to be very important now with that being said let's uh not waste any time and let let's get started so what is red teaming uh red teing really can be thought of as the process of emulating the tactics techniques and procedures also known as ttps of real world threats or AP groups and the goal here is to measure the effectiveness and resilience of Defenders or The Blue Team uh the employees of an organization their processes and of course the underlying technology uh that that organization is running um whether it be you know standard uh software or operating systems but also the Security Solutions so the underlying goal or motive of redeeming is to get a better more holistic understanding of an organization's ability to detect and defend against adversarial ttps so uh I'll explain how this differs from standard pen testing and why I'm emphasizing you know real world adversaries and you know that's really the Crux of red teaming if you come to think of it or if youve ever been part of a red team now you know a red team does not need to be or a red team operation does not need to be limited to you know performing adversary emulation or simulation um and that's the uh you know the Nuance that I'm going to be uh going through in a few seconds so where did the idea of red teaming or a red team come from well redeeming is a practice that was adopted from the military whereby military units are tasked to operate as adversaries and are required to simulate or emulate um attack techniques or you know adversarial trade Craft um in order to assess the abilities of the defending team so uh within the military you know primarily the United States military this um exercise was developed where you know uh divisions or units were were separated into you know the offensive and the defensive and the objective of the offensive side not not always the case but in most cases is to emulate you know the tradecraft of an adversary that they could potentially face and the objective here is to assess whether the defensive uh capabilities of you know within that military unit or that uh particular Battalion uh as an example uh you know assess the abilities of that Battalion to defend against you know a real world attack um and of course if you contextualize it in the context of cyber security what you're doing uh in a Rim operation as said in some cases or actually I should say in most cases is you're trying to actually get a realistic holistic ideas to whether the organization can actually uh defend um defend against a real world adversary so the deviation from pent test will become apparent in a few seconds so this process provides an organization with valuable information on their blue team's abilities or you know their defensive capabilities and more importantly it outlines where detection and defense controls or mechanisms can be improved so the the organization gets a realistic view of what an attack would look like and the potential impact of this attack uh and again the red team is emulating or will try and simulate a real world adversary that the organization might uh face or you know that the organization might be targeted by uh you know due to various factors whether that be the geographic location of the organization the sector that it operates in uh and of course we'll be going through a lot of this as we proceed within this series but this is very important to understand so I have a very simple diagram here that sort of outlines uh if youve ever if you've ever performed a pen test before uh you can see immediately from this diagram that um and this is an example of a red team operation this diagram sort of encapsulates uh the difference really clearly now if it's not uh apparently if it's not clear yet don't worry this will make sense but you can see uh you know we have the target organizations uh Network or infrastructure here and here we have the attack or the red team as it were and you can see there's you know multiple ways in um you know through the firewall and you know in terms of post exploitation you're not um your objective and this is where the first deviation begins to appear your objective is not to you know just um extend your uh the level of access you have on the target organizations Network you're also going to do quite a few things like for example uh if you're performing a rim operation or more specifically an adversary emulation campaign and you're emulating let's say particular AP group then you're also going to need to perform uh or to factor in stealth uh evasion as well as C2 uh exfiltration and demonstrate some form of impact now when I say some form of impact I don't mean uh that in red team operations you'll typically be required to install or uh execute Ransom where on the target uh infrastructure that's of course uh not good and I would not recommend you do that uh for obvious reasons but your objective is to show the organization uh What uh is likely to happen you know in the event of a of an attack but in this case the attack or the realism of the attack is contextualized by the fact that the red team operation is either emulating a particular real world adversary or AP group or is at least adapting some of their tradecraft or ttps so moving on um you know given the perceived nature and scope of a red team operation it is typically misconstrued as an unplanned unorganized ad hoc pentest so generally speaking you know at first glance this is what you typically you know consider a red team operation to be an ad hoc test in that uh you know there's no real structure as to what the uh initial axis Vector is or there's no real systematic approach to how you get in um but as you'll soon see this is uh this couldn't be farther from the truth and obviously I had to throw in some uh some memes here to uh to better or to better communicate the message but you can see that you know when you uh in this particular Meme and I apologize for explaining it even though it's quite self-explanatory uh you know frequent question you ask or pentester would ask a red Deemer is how the hell did you get in and the red team will have quite a few answers depending obviously on the nature of the operation or their skill level I should say uh but in order for us to understand red teeming and what the difference is we need to go back to you know the birth of security assessments or you know what pent tests were called uh before we called them pent tests or you know before Cy cber security was properly defined as it is today um so we need to understand you know the various types of security assessments that um are commonly used or have been commonly used by organizations what their objectives are and how they differ and the objectives will really clarify the difference so from an offensive perspective organizations have typically used various security assessments to get an understanding of their current threat surface risk uh potential business impact and of course defense uh or detection and defensive capabilities so the point I'm trying to make in this slide is based on my own experience and uh you know what I've done throughout my career you rarely see anyone starting off in the red team uh moving into the red team is sort of a procedural uh process that uh requires you to go through various phases uh so you know you start off with you not necessarily you know Standard Security assessments or uh but you typically start off as a pentester and then develop your skills uh you know extend your understanding of uh adversarial tradecraft uh ttps tooling ex you know uh malware development resource development I should say uh red team infrastructure opsc and then you know you transition into uh the red team so you know the most basic security assessment uh that you're probably aware of is a vulnerability assessment or vulnerability scan as it were so vulnerability assessments are the most common form of preventative security right the primary objective with vulnerability assessments or scans is to scan all workstations and digital Assets in order to identify vulnerabilities and misconfigurations now this provides an organization with a clearer picture of their threat surface and of course the security posture this information helps a company determine whether uh where they should focus their patching and Remediation effort so if you've ever used a vulnerability scan before like openvas or nesses or even qualis uh what you're doing or what this uh level of security or system of security is all about is just telling you uh what systems or software you need to patch based on what is publicly uh what has been publicly disclosed in terms of vulnerabilities right uh it doesn't really protect you from zero days but in terms of how companies use vulnerability scans and assessments is primarily to give them an idea of the you know the security posture and where they should focus their patching uh and Remediation effort so you know should they patch a uh low um low severity vulnerability or the high one it's pretty clear that it's the high one but it goes uh you know uh there's multiple um abstractions or not abstractions there's multiple um additional layers that need to be considered here so for example uh should you patch a medium um medium severity vulnerability or a vulnerability with a CF CVSs score of let's say 6. uh 6 OR7 uh or one that has a CVSs score of eight uh the distinction or you know the decision making is not really about patching the one with the highest severity first but also factoring in things like uh you know the infrastructure um or you know uh the actual um uh the actual asset the vulnerability is being is affecting so for example if you if if you had the vulnerability uh on a service or a system you know within let's say uh the the company's headquarters or you know one of their business critical uh Cloud environments and uh that one had let's say a CVSs score of six and the other one that had a CVSs score of eight is running in one of their Dev environments which one do you patch first obviously you'll go for the one uh that uh you know we'll have the highest impact uh not just uh out of the uh not just derived from the CVSs score of the vulnerability itself but the potential impact of the vulnerability or the exploitation of the vulnerability in terms of the impact to the organization so vulnerability assessments are very useful in reducing the attack surface but fall short in extrapolating the organizational risk of identified vulnerabilities and of course it doesn't factor in things like uh you know initial access uh um as well as zero days so you can see that it's a pretty cyclic process in that you have um vulnerability identification there's analysis risk assessment and then remediation and then you know it's a cyclic process so fairly simple to understand and then of course we have the infamous pen test or penetration testing as it were so penetration testing and of course I apologize for defining it but this is very important penetration testing is the process of identifying and attemp and attempting to exploit vulnerabilities On Target systems uh penetration tests improve on vulnerability assessments or scans by verifying the potential impact of a vulnerability so again using the example of the vulnerability scan uh you really cannot calculate or determine the potential impact of vulnerability regardless of its score uh until you have successfully exploited it to actually prove that a it can be exploited and B this is what the impact will be so pent tests are essentially an augmentation and again uh you guys can slam me in the comments but uh what you're doing is you know there's obvious additions to the process but uh your primary objective is to find vulnerabilities regardless as you know whether you know they um you're dealing with a zero day misconfigurations Etc uh but your primary objective to again demonstrate um to demonstrate impact is to successfully exploit the vulnerability or a misconfiguration and prove to the organization that has hired you that hey this is what is possible uh and this is the potential impact of exploiting this vulnerability so penetration testing also goes beyond initial access or exploitation and involves uh performing various post exploitation activities so not only are you you know exploiting a vulnerability but you're then showing the organization what exactly is possible um you know if an attacker leveraged or exploited the vulnerability um you know to gain initial access or what is possible after the fact so you know if you're talking about an ad environment and you gain initial access uh you know how far can you move laterally within the uh Target organization's network uh can you elevate privileges so on and so forth so the standard post exploitation uh life cycle now uh just building on what I've just said here the primary objective of a penetration test is to identif exploit vulnerabilities in Target systems as I've already stated in order to measure the risk associated with the exploitation of the target uh of the targets attack surface or the organization's attack surface now penetration tests provide an organization with a much more accurate understanding of how potential of how a Potential Threat could gain access to the environment and provides valuable information on where detection and defense capabilities need to be improved penetration tests however are quite limited with uh with regards to their ability to emulate or simulate a real threat actor primarily because of the scope uh no this is not completely uh you know this is not inclusive of um this is not uh you know totally inclusive of uh why they're limited but uh one of the reasons that um penetration tests are uh one of the reasons why they're so limited in terms of uh you know giving the organization an accurate idea of what is possible is primarily down to their scope now I'm not saying that red team operations don't have a scope but bear with me so penetration test can either be Black Box white box or you know gray box and one of the things you'll realize is that they're quite loud what I mean by that is organizations or companies still treat pentest as sort of augmented forms of vulnerability scans in in that and again this is very rarely the case but you'll typically see that you know you work out a timetable or a schedule as to when you'll be performing the pent test uh so that you don't uh affect or impact business critical services or infrastructure you don't uh interrupt uh employees so on and so forth and you can obviously tell that this is where the realism is taken out of the equation so at the red team you're essentially told hey uh and again I know this is not always the case but you're told hey show us what exactly is possible uh again there's obviously some limitations around what you can do within the environment if you gain initial access but yeah you know you can perform your operation at any time uh and that's very important because that's what real attackers do real attackers don't work uh you know um they don't work with the timetable or agree on the terms of the engagement or the attack with the organization so given that the goal of atist is to identify an exploit V abilities in Target systems uh risk is typically measured and is limited to the workstations or assets or digital infrastructure within the pre-defined and agreed upon scope and does not Encompass critical aspects of an organization especially from a security perspective like employees Defenders if the organization has a blue team or defenders in place and of course the organization's processes when I talk about processes what I'm referring to here is you know for example what do uh how does an organization deal with a threat or an incident is there an incident response plan uh you know is is there a containment plan so on and so forth so you're testing uh for example how quick an organization responds uh to an attack if you know uh if it's been alerted by The Blue Team that's just one example but I'm sure you get the idea now this is an example of a pentesting uh Rules of Engagement um quotation that I just pulled out and this sort of gives you an idea as to what you typically see and why this can't really tell an organization especially one that's under constant uh you know attack or you know uh is facing a Potential Threat you'll see why this is really this really can't tell or can't paint an accurate picture of what an organization um you know of how an organization or the organizations capability or abilities to again detect and defend against Real World attacks so you can see that it says over here during the engagement the following rules must be adhered to any deviations must be determined and approved by change management than the steering committee so activities that may potentially or potentially result in a denial of service condition that's fairly obvious or fairly uh familiar fairly typical I should say uh you know service interruption or otherwise General annoyance are prohibited now of course I know some of you in the comments will be ready to uh you probably already typing it out that this is not representative of all pentest and you're right but this is at least in my experience representative of most of most pentests right the other thing is the scope so you can see this engagement is considered full scope with a following Network exclusion so they're saying it's full scope but then adding exclusion so you can sort of see the double speak here already and when you say full scope if you're a red teamer then you may be asking are we allowed to target employees uh you know via fishing uh emails or uh fishing campaigns you know that's obviously not the case uh you can see that you you have to have uh status meetings um you know in this case uh you know daily 10:00 a.m. and 3 p.m. via the approved channels the approved testing window this is really annoying Monday Wednesday Friday Saturday Sunday 12:00 a.m. to 5:00 a.m. so when no employees in the office are you really getting an accurate picture of of an organization's um you know ability to defend itself against uh an a real world attack probably not yeah right and then Port scanning is allowed with the following exclusion uh exclusion so you can scan uh FTP uh SSH um you know web service port 80443 SMB 8080 and of course 8443 so you starting to get the idea uh activities that may result in the Locking of accounts are considered unethical and will result in a case uh in case forwarding uh to the Ethics Line so Brute Force you know you're going to be fairly limited uh testers will at no time perform a happy dance or resort to celebrating so you sort of get the idea now and again this uh Meme here sort of sums it up I'm not attacking pentests in fact again I've performed many pentests and and they're very very important I'm just trying to distinguish between pain tests and Red Team operations and this distinction is very important because again as I said the typical uh Layman would uh or even pentester would consider red team operation at first glance to be an ad hoc pen test without you know these rules of engagement so given the underlying objective penetration testers usually do not have to worry about for example tripping alerts or evading detection as as a result penetration testers are typically noisy and loud and real world threats are not so you uh again just using what I've described here uh or putting it into context you can sort of understand now what organizations are likely to use red team operations or red team engagements as opposed to pentests these are going to be organizations or companies that are under constant threat uh by real world adversaries now we'll dive into the reasons as to why you know an organization might be under threat and how to you know identify the threat actor or AP group to emulate in order to again test the organization to see if they can actually detect and defend against that real world threat that you're emulating or that AP group for example but we'll get into that later so a traditional pentest and again the key word here is traditional a traditional pentest is likely to ignore attack vectors like social engineering and of course physical intrusions or physical attacks which again uh in you can disregard physical intrusions in the case of AP groups but these are very common uh you know ttps uh used by real world adversaries or threats and of course penetration testers must abide by strict rules of engagement and the predefined scope in certain cases the organization may also Whit list the penetration testers attack infrastructure and in certain case uh in certain cases the defense and detection mechanisms may be relax the bottom line is that as you know uh in certain cases pen tests can become very formal exercises where you're also or even allowed to you know plug in your attack infrastructure uh into the organization's Network and uh you know the any potential restrictions uh may be removed so it takes away from giving the organization a realistic and that's the key word here realistic uh view uh and more importantly holistic so all-encompassing to the best of a red team um you know to the best of a red team's abilities um yeah so doesn't really give the organization a clear or accurate uh view um of you know whether they can actually you know withstand an attack or you know detect uh and defend against a real Attack so why red team so if it isn't obvious already as to you know the differences between a red team operation and a pentest and you know what organizations or entities are likely to choose one over the other and when they're likely to choose one over the other um if that isn't obvious already then let me dive in a little bit more so red teaming firstly allows you to assess and measure the effectiveness and resilience of employees so you're going Beyond just digital infrastructure and you know the standard SC hope you typically expect you're now including employees their ability to again uh you know detect you know fishing attack social engineering so on and so forth uh you're also testing the Defenders if the organization has one and if they are performing a red team operation or they have hired you to to perform uh a red team operation against them they mo most likely have a Defenders or a blue team or you know a sock and of course you're also testing processes which I've explained uh and you're testing all of the is to see how the organization as a whole uh deals with an attack a real world attack I should say uh secondly uh red teaming is very useful in measuring the blue team's ability to detect and defend against adversaries and this is where you now get into the territory of purple teaming where these exercises are frequently set up uh you know the purple Team sets up exercises uh between the red team and The Blue Team uh to uh again con uh to constantly or frequently uh test a blue team's ability to again detect and defend against adversaries real world adversaries but the objective here is to also is to also uh test the blue team against new and upcoming threats as well as tradecraft malwe Etc but to ensure that you know their skill level is maintained or they're you know frequently kept on their toes uh another another reason why red team oper ations are so important for certain organizations or entities is because it can really be used to train the blue team uh in the sense that you're now giving the blue team an opportunity to actually experience what a real world attack looks like again to the best of the red team's ability to emulate a particular adversary so Defenders as organizations are now discovering require frequent training and practice in order to be effective um and this is where you're not only testing just the The Blue Team but also the processes so the you know the blue team or the Defenders processes with regards to decision making critical thinking effective communication Etc and of course uh the company as a whole but more specifically The Blue Team or the Defenders get exposure to real world threats um you know AP groups and their corresponding ttps tradecraft and of course malware so they actually understand or get to experience what it is uh what a real Attack feels like or what it looks like and I know that again we the red team is performing emulation or simulation so it's not exactly 100% accurate but it's way better than you know uh performing Port scans and uh operating from an assumed breach perspective as you typically have with pent tests um and now that brings us to the essential terminology now this is arguably one of the most important slides in this video because this uh this terminology will be frequently used during this series and I'll not be defining uh or I'll be primarily using the abbreviations uh assuming that you're aware of them so obviously you have ttps which is derived from the MIT attack framework which we'll actually be exploring uh in the next video but ttps uh stand for tactics techniques and procedures don't worry I'll explain ttps in the next video uh you then have tradecraft uh tradecraft refers to techniques and procedures used by an attack or you know an adversary in this case a red team uh during an attack campaign so in terms of where trade craft becomes applicable it's it becomes it becomes applicable when you're talking about adverse ulation or when you're analyzing or performing threat Intelligence on let's say particular adversary threat group or AP group and tradecraft represents commonalities or um uh no I wouldn't say Comm alties it essentially represents or defines or can be defined as you know what this thread group ad uh what a particular thread group adversary or AP group for that matter what they typically do in terms of the attacks so do they are there any patterns that we're seeing so for initial access are they using a particular you know a particular initial access Vector um across uh all of their publicly disclosed uh uh hacks or attacks that they've been involved in or have uh you know have actually uh been attributed to them you're trying to find uh you know you're trying to find commonalities or um patterns in terms of what they do not just limited to the ttps but also when they do or run particular attacks or uh when they run particular techniques or sub techniques uh of the attack life cycle so uh you know do they exfiltrate data of a shorter amount of time uh over a long uh you know a longer period of time uh do they typically uh install any back doors uh any rootkits stuff like that um you then have uh red team specific terminology like oplog uh this is very important and I'll I'll actually share some templates with you uh if you have performed a pen test you may not have used an OP or a system uh actually I'll take that back you probably have done it because again every pentester takes notes or logs of all the actions they have been doing or all the commands they've been executing on a Target environment if you haven't been doing that please start doing it and again I'll share the tools and resources that can again make that easier for you but operator logs are the records generated by Red Team operators during an engagement these logs have specific and required fields that must be captured what an operator log is or an OP log is pretty much a spreadsheet in most cases where you as the red team operator and I'll explain the difference between an operator and a lead uh the red team operator logs whatever commands they're executing or whatever they're doing uh when they did it the time stamp is very important so that this information can then be passed along to the red team lead when you know they're generating the report or developing the report but is also important because it acts as a form of accountability uh where you can say that I did this at this time and I didn't do this because again I would have logged it and most C2 Frameworks as you have probably realized at least some of the good ones uh perform this logging automatically because again you know operators May delete uh if they're doing it manually they may delete some of the commands they've run if for example it ca if it causes destruction or downtime to the organization or you know a piece of its infrastructure you then have C2 which refers to command and control C2 uh is a broad term that uh you know in the the context of red team operations when used in this particular way refers to the C2 infrastructure or the communication Channel as it were not really the framework and then of course you have exfiltration which is the process of extracting um information or data from the target system through a covert channel in most cases covert but really through a C2 Channel you then have ioc this is more so relevant to the Defenders and that is the indicator of compromise so these are artifact s that uh again are used to identify versial activity or uh again represent a particular activity uh on a system or a network and they're then attributed to you know let's say malicious uh activity uh you then have opsc which is operational security this in the context of a red team operation I'm not talking about it broadly is uh you know what the blue team can observe and is used to minimize exposure so you might be a little bit confused cuz you may be aware of obsc and what it means you know let's say on the internet as an individual but in the context of a red team operation it's really controlling as an operator it it's really controlling what the blue team can see so you know evading detection limiting the artifacts you create on a system uh you know removing any potentially identifiable information from you know malware or payloads you may be generating Etc you then have operational impact now uh operational impact in the context of a red team operation is the effect or the effect of an objective driven action within a Target environment so uh before you actually you know perform or do anything as an operator you obviously uh need to be aware of operational impact what that means is what's the effect of running a particular command what's the uh impact of running mimic hats as an example that's a stupid example but you get my point you then have situational awareness which again something that is not always understood but very very important actually separates uh you know a a good or I would say a bad red team Opera from a good one so um you know this can be considered a phase but let me just explain it as I have here so this is a phase of a red team operation that you know it's local enumeration but the again the The Operators who do this well uh really are determinance a key determinance in the overall success of a red team operation because they'll guide the other operators who may be doing stuff like post exploitation or uh exfiltration or stuff like that uh but uh you know the uh this is the that phase where you're gathering information on the targets uh not just the the the actual systems you've compromised and the network or you know an ad environment but also when people are logging onto computers uh you know what sort of security or defense Solutions have been implemented uh so on and so forth and then of course you have CTI which is uh cyber threat intelligence uh this refers to information that's collected aggregated analyzed and interpreted to provide the context for decision-making processes regarding threats we'll dive into threat intelligence in in its own series especially when we get into adverse ulation uh which we'll actually be exploring uh quite soon actually probably this week but uh now I want to dive into some key uh you know the final sections of this video so let's take a look at the types of red team engagements and this is very very very important so when we talk about uh the types of red team engagements and yes there are types which is why I was a bit Cy with my definition or uh you know um how some of you may have uh construed me uh or how you may have Mis misunderstood my definition of a rim operation as only being restricted to adverse rul it isn't obviously but these are the typical uh types of Rim engagements that you'll typically see or operations I should say but uh you have your full simulation so this is uh where you simulate a threat or an adversary's attack flow uh in comparison to and we'll talk about the difference between adversary simulation and emulation but this is where again when we talk about simulation uh you're not really adhering to or sticking to the uh the actual ttps of a known threat actor or AP group uh you probably are making adaptations to the emulation or simulation plan I should say where you're taking a few ttps or trade craft from one threat uh and a few from another or this is what you can consider a standard red team operation or an augmented form of a pentest where the scope is uh pretty wide or pretty large in terms of the fact that you know you can now perform uh you can target employees of course there are restrictions put on this and we'll get into that but you get the idea you then have adverse regulation which again as you probably can tell I'm a huge fan of and I'll actually be taking you through I will be actually uh going through it using some really really cool Labs on Cyber ranges uh so do stay tuned for that but um this is where you emulate or mimic an adversary or an AP group's uh ttps or tactics techniques and procedures with little or no deviation from you know the the known publicly known and attributed ttps of that particular threat uh threat group adversary or AP group you then have assumed breach uh so this is also quite common where it's typically thought of as a model where instead of you know performing the initial access phase of a red teim operation you pretty much Start um you know you you start from the point of uh you start from the point assuming you've already gained initial access so that means that you obviously uh you know you either connect directly to the Target uh environments or the the organization's Network or you have let's say a jump box set up for you and uh that can be very useful for companies that don't want you to do all the external stuff first or try and gain access first but just show that the organization what's possible if an attacker is successfully able to breach U or gain access to the uh the organization's Network or infrastructure so that can be very useful in certain cases you then have tabletop exercises which are not really considered your traditional red team engagement but fall under red teaming uh this is a simulation on o you know an over the table simulation where scenarios um you know attack scenarios uh breach scenarios are discussed between the red and blue teams to evaluate how they would theoretically respond to certain threats now this goes beyond just the red and blue teams you'll typically see tabletop exercises being performed uh you know between uh the red team uh or a senior member of the red team and for example the CAO of uh the organiz ization or you know the executives and you're trying to assess how they they would deal with a potential intrusion uh you know in terms of the best steps to take uh or the next steps to take uh whether they're doing it efficiently are they making any mistakes because again different types of attacks or different types of breaches require different types of responses uh from management uh as you already know so those are the types and then now finally we have the red team roles and responsibilities so uh whenever and again this is fairly generalized whenever you're you know performing a red team or if you've ever if you are a red teamer you know that you you have your red cell uh which comprises of red team operators you can think of red team operators as pentesters uh who uh and I'll explain why they're called operators now and then you have the red team lead um you can disregard you know the white cell and the engagement control group and Observers but then of course on the organization side you have the blue cell which comprises of you know the blue team where you have your sock analyst or what you'd call Blue Team operators uh trusted agent if required and a blue team lead uh so you know we'll not dive into that right now I'm just focused on the red team side or the Red Cell side so let's take a look and understand what these uh you know these categorizations are in terms of um in terms of roles so the Red Cell so this is the group that plays uh you know the op for or opposing force during red versus blue exercises or during a red team operation so a red cell is the uh essentially refers to the components that make up the offensive portion of a red team engagement that simulates the Strategic and tactical responses of a given Target or simply put emulates a particular adversary or simulates an adversary and the red cell is typically comprised of red team leads and operators and is commonly referred to as you know a red team instead of a red cell there you are if you ever see that term that's what red cell is referring to it's just referring to the red team uh you then have the blue cell this is the opposite the opposite side of red and it is all the components defending a Target Network or organization the blue cell is typically comprised of blue team members Defenders internal staff and an organization's management and then you have the white cell the white cell is important and I'll explain why so in certain cases when performing red team operations and you know red team operations for organizations that have a blue team um this is where the white cell would make sense but the white cell is an um can be thought of as a referee uh and their job is to control uh the red team operation in terms of uh you know for example communicating to the red team that hey the defend ERS are uh you know the Defenders the the the Defenders are doing really well they've been able to identify this information about the attack they've attributed it you know so on and so forth um and uh you know they serve as the referee between the red team activities and the Defenders responses during an engagement and they control the engagement environment on network and of course they monitor adherence to the the Roe and the white cell is typically um put there by the organiz ation itself you can think of it as a trusted uh individual who takes no sides but just ensures that things are uh proceeding uh correctly with no damage to the actual you know to to the organization's Network or data and again um uh just acting as a referee if that makes sense uh moving on uh defining a little uh defining the roles within the red cell or the red team we obviously have the red team lead so this individual or this role uh serves as the operational and administrative lead for the red team the key word there is operational I I should say administrative but they are two key words operational and administrative uh so you know this individual Acts or serves as the operational and and administrative lead for the red team they conduct the engagement budget and resource management for the red team they provide oversight and guidance for engagements capabilities and Technologies they Ensure adherence to all laws regulation policies and of course the Rules of Engagement you in certain cases if the team is quite large you also have the red team assistant lead now this individual or this role you know essentially involves assisting the team lead with overseeing engagement operations and operators and can also assist in writing engagement plans and documentation if needed now you'll actually see the importance of all of these responsibilities that the red team lead or the team assistant lead uh you know typically performs or is responsible for in the next video but you then have your operators which is us or your pentesters uh the these are the individuals actually doing the stuff now what you'll typically see as opposed to a pentest I I shouldn't say as opposed to a pentest but within well defined or structured uh red teams or red cells you have uh various operators doing various Things based on their special ities or their skills so for example one one operator will be responsible for post exploitation on an ad environment right another would probably be uh probably has skills in uh you know for example persistence and setting up in maintaining a uh C2 Communication channel uh you get the idea but you know the red team operator complies with all red team requirements under the direction of the red team lead uh they are the operation exe um executors of the engagement and they pretty much applied red team dtps to the engagement and they provide technical research and capabilities to the red team they obviously uh because they're the ones doing stuff or the operational executors of the engagement they keep detail logs during each phase of the engagement and as I said in well defined and organized red teams uh different operators are doing different things the reason this is the case is because you don't want uh different operator stepping or duplicating efforts or doing stuff that you know someone else could be doing and uh you know creating that conflict there or essentially interfering with each other all right so I think that was a very good introduction to Red teaming hopefully you came out of this video a little bit smarter and wiser uh regarding uh red teaming and if you did that was exactly the objective so now that we you know got this formal introduction to Red teaming we can actually begin proceed leading forward so um the next video or I should say videos will uh be walking through you know the red team Frameworks and methodologies uh various uh planning and uh reporting templates as well as the operator logs uh and much more and then we'll move into the Practical side of red teaming or the area that you know I've been really excited to get dug um into and that is of course adversary emulation ad pen testing resource development malware development Etc but with that being said if you found value in this video please leave a like down below if you have any questions or comments or feedback please leave them in the comment section uh down below and I will be seeing you in the next video [Music]
Original Description
Hey guys, HackerSploit here back again with another video. This video will introduce you to red teaming, and explain its origins and adoption in offensive cybersecurity. You will also learn about the key differences between Red Teaming and Penetration Testing. You will also be introduced to the various roles and responsibilities within a red team, including the red team operator and red team lead. Whether you're a beginner or looking to deepen your knowledge, this video provides a comprehensive overview to get you started on your red teaming journey.
//PLATFORMS
BLOG ►► https://bit.ly/3qjvSjK
FORUM ►► https://bit.ly/39r2kcY
ACADEMY ►► https://bit.ly/39CuORr
//SOCIAL NETWORKS
TWITTER ►► https://bit.ly/3sNKXfq
DISCORD ►► https://bit.ly/3hkIDsK
INSTAGRAM ►► https://bit.ly/3sP1Syh
LINKEDIN ►► https://bit.ly/360qwlN
PATREON ►► https://bit.ly/365iDLK
MERCHANDISE ►► https://bit.ly/3c2jDEn
//BOOKS
Privilege Escalation Techniques ►► https://amzn.to/3ylCl33
Docker Security Essentials (FREE) ►► https://bit.ly/3pDcFuA
//SUPPORT THE CHANNEL
NordVPN Affiliate Link (73% Off) ►► https://bit.ly/3DEPbu5
Get $100 In Free Linode Credit ►► https://bit.ly/39mrvRM
Get started with Intigriti: https://go.intigriti.com/hackersploit
//CYBERTALK PODCAST
Spotify ►► https://spoti.fi/3lP65jv
Apple Podcasts ►► https://apple.co/3GsIPQo
//WE VALUE YOUR FEEDBACK
We hope you enjoyed the video and found value in the content. We value your feedback, If you have any questions or suggestions feel free to post them in the comments section or contact us directly via our social platforms.
//THANK YOU!
Thanks for watching!
Благодарю за просмотр!
Kiitos katsomisesta
Danke fürs Zuschauen!
感谢您观看
Merci d'avoir regardé
Obrigado por assistir
دیکھنے کے لیے شکریہ
देखने के लिए धन्यवाद
Grazie per la visione
Gracias por ver
شكرا للمشاهدة
-----------------------------------------------------------------------------------
#HackerSploit #cybersecurity
Watch on YouTube ↗
(saves to browser)
Sign in to unlock AI tutor explanation · ⚡30
Playlist
Uploads from HackerSploit · HackerSploit · 0 of 60
← Previous
Next →
1
2
3
4
5
6
7
8
9
10
11
12
13
14
15
16
17
18
19
20
21
22
23
24
25
26
27
28
29
30
31
32
33
34
35
36
37
38
39
40
41
42
43
44
45
46
47
48
49
50
51
52
53
54
55
56
57
58
59
60
How To Install Kali Linux 2.0 On Virtual Box
HackerSploit
100 Subscriber Q&A! - How I Learned Ethical Hacking
HackerSploit
BlackArch Linux Review - Better Than Kali Linux?
HackerSploit
How to Access the Deep Web Safely | Deep Web Starter Guide 1.0
HackerSploit
Wireshark Tutorial for Beginners - Installation
HackerSploit
Wireshark Tutorial for Beginners - Overview of the environment
HackerSploit
Wireshark Tutorial for Beginners - Capture options
HackerSploit
Wireshark Tutorial for Beginners - Filters
HackerSploit
Complete Ethical Hacking Course - Become a Hacker Today - #1 Hacking Terminology
HackerSploit
Complete Ethical Hacking Course #2 - Installing Kali Linux
HackerSploit
Parrot OS 3.5 Review | The Best Kali Linux Alternative
HackerSploit
Nmap Tutorial For Beginners - 1 - What is Nmap?
HackerSploit
Katoolin | How To Install Pentesting Tools On Any Linux Distro
HackerSploit
Nmap Tutorial For Beginners - 2 - Advanced Scanning
HackerSploit
Nmap Tutorial For Beginners - 3 - Aggressive Scanning
HackerSploit
Zenmap Tutorial For Beginners
HackerSploit
How To Setup Proxychains In Kali Linux - #1 - Stay Anonymous
HackerSploit
How To Setup Proxychains In Kali Linux - #2 - Change Your IP
HackerSploit
How To Change Mac Address In Kali Linux | Macchanger
HackerSploit
How To Setup And Use anonsurf On Kali Linux | Stay Anonymous
HackerSploit
Ubuntu 17.04 "Zesty Zapus" Review - Bye Unity
HackerSploit
VPN And DNS For Beginners | Kali Linux
HackerSploit
Tails OS Installation And Review - Access The Deep Web/Dark Net
HackerSploit
Steganography Tutorial - Hide Messages In Images
HackerSploit
The Lazy Script - Kali Linux 2017.1 - Automate Penetration Testing!
HackerSploit
Best Linux Distributions For Penetration Testing
HackerSploit
Netcat Tutorial - The Swiss Army Knife Of Networking - Reverse Shell
HackerSploit
Gaining Access - Web Server Hacking - Metasploitable - #1
HackerSploit
Web Server Hacking - FTP Backdoor Command Execution With Metasploit - #2
HackerSploit
How To Install Kali Linux On VMware - Complete Guide 2018
HackerSploit
Q&A #1 - Best Cyber-security Certifications?
HackerSploit
Terminator - Kali Linux - Multiple Terminals
HackerSploit
Shodan Search Engine Tutorial - Access Routers,Servers,Webcams + Install CLI
HackerSploit
Q&A #2 - Mr Robot?
HackerSploit
Metasploit Community Web GUI - Installation And Overview
HackerSploit
Linux Expl0rer - Forensics Toolbox - Installation & Configuration
HackerSploit
QuasarRAT - The Best Windows RAT? - Remote Administration Tool for Windows
HackerSploit
Metasploit For Beginners - #1 - The Basics - Modules, Exploits & Payloads
HackerSploit
Metasploit For Beginners - #2 - Understanding Metasploit Modules
HackerSploit
Kali Linux Quick Tips - #1 - Adding a non-root user
HackerSploit
Metasploit For Beginners - #3 - Information Gathering - Auxiliary Scanners
HackerSploit
Spectre Meltdown Vulnerability - How To Check Your System
HackerSploit
Metasploit For Beginners - #4 - Basic Exploitation
HackerSploit
ARP Spoofing With arpspoof - MITM
HackerSploit
WordPress Vulnerability Scanning With WPScan
HackerSploit
Generating A PHP Backdoor with weevely
HackerSploit
Nikto Web Vulnerability Scanner - Web Penetration Testing - #1
HackerSploit
How To Install Kali Linux On Windows 10 - Windows Subsystem For Linux
HackerSploit
Stacer - System Optimizer And Monitoring Tool For Linux
HackerSploit
Kali Linux 2018.1 - Kernel Updates & Patches
HackerSploit
MITM With Ettercap - ARP Poisoning
HackerSploit
Password Cracking With John The Ripper - RAR/ZIP & Linux Passwords
HackerSploit
How To Detect Rootkits On Kali Linux - chkrootkit & rkhunter
HackerSploit
Channel Updates - How To Post Questions & Video Suggestions
HackerSploit
Web App Penetration Testing - #1 - Setting Up Burp Suite
HackerSploit
Web App Penetration Testing - #2 - Spidering & DVWA
HackerSploit
Cl0neMast3r - GitHub Repository Cloning Tool
HackerSploit
Kali Linux On Windows 10 Official - WSL - Installation & Configuration
HackerSploit
DoS/DDoS Protection - How To Enable ICMP, UDP & TCP Flood Filtering
HackerSploit
Web App Penetration Testing - #3 - Brute Force With Burp Suite
HackerSploit
More on: Security Basics
View skill →Related Reads
📰
📰
📰
📰
Your HIPAA Posture, in Version Control
Medium · Cybersecurity
What is gobuster?
Medium · Programming
Web3 Development Surges Amidst Critical Supply Chain Malware Threats and Bearish Sentiment
Dev.to AI
Lab: SQL injection UNION attack, retrieving multiple values in a single column
Medium · Cybersecurity
🎓
Tutor Explanation
DeepCamp AI