Planning Red Team Operations | Scope, ROE & Reporting
Key Takeaways
This video by HackerSploit outlines the process of planning and orchestrating Red Team operations, covering topics such as scope, Rules of Engagement (ROE), and reporting, with a focus on cybersecurity and red team operations. The video provides guidance on defining objectives and scope, creating a ROE document, and developing a red team methodology, as well as tools and resources for red team operations, including the MITRE ATT&CK framework and proxy chains.
Full Transcript
hey guys hack exploit here back again with another video Welcome Back to the red team series uh in this video we're going to be taking a look at uh the process of uh planning red team engagements and we're going to be exploring quite a few things one of which is the Rules of Engagement and some templates uh that you can use as a basis not just of understanding what uh you know the rules of engagement typically are uh but also uh some report templates it'll give you an idea as to what uh results um are supposed to look like what you know report uh looks like uh but the uh primary objective of this video is to give you a proper understanding of uh what the um you know the process of planning red team engagements operations looks like um and you know what info or what some of the critical uh aspects or uh elements are with regards to you know planning uh for these operations so uh the first starting point as you know if you are a pentester is the scope and objectives right so defining red team engagement goals can be difficult and tedious primarily because there needs to be a synthesis between the red team and the client now this is uh quite relevant or more important in the context of um uh of red teams more so than it is uh when you know you're when you're performing a pentest the reason that is so is quite obvious as I've mentioned previously in this series and in the preceding videos leading up to this video red team operations are seen as ad hoc and random however as we've seen uh what makes them appear this way is the fact that the scope can be quite large making it uh you know quite complex and consequently uh this complexity begins right as you're defining the scope and objectives or rather I should say uh extrapolating the scope from the objectives that the the company or your the client has uh essentially communicated now what that means is firstly uh you know the client needs to communicate what their ultimate objectives are so why are they hiring you uh to perform the red team operation what that means is what do they want to know whenever you're performing a pen test or a red team operation or any security assessment of any kind what you're selling to the client is the report and the report needs to answer questions the questions are again can be extrapolated from the objectives or are directly related to the objectives so we'll get into some examples of what companies typically or what organiz uh what objectives organizations typically lay out out uh but the the tricky bit is from those objectives we obviously extrapolate some sort of scope so for example if the organization says uh we want to know what our external threat surface looks like in terms of you know our publicly exposed assets or servers that are you know publicly accessible well from that point you can sort of see why the scope becomes important more so in this particular case because then the first question that anyone would ask or a red team lead would ask or even a pentest is okay could you explain or Define what you mean by publicly exposed assets uh and at that point they would say well our website the client would say our website is off uh you know you you you can't um touch the websites or these particular apis or these particular domains or subdomains you get the idea now the reason this is difficult in the context of red team operations and I used a very simpl simplistic example there is because if you're talking about a proper red team operation or adversary emulation campaign you're obviously going to be doing a lot of things or your scope is going to be very wide with regards to the activities you're performing so uh the bottom line is that you really need to ensure that the client understands um or you and the client understand what is uh what the scope is or what you can or cannot do uh with regards to you know the types of attacks you can run so on and so forth so this is especially true for organizations new to Red teaming uh whether you're on the delivery or receiving end of a red team engagement the solid goals must be decided uh and agreed upon to have a successful red team engagement and that's a very good point there um you know if there is a dichotomy or misunderstanding uh you know when the objectives and the scope are being defined uh especially in relation to the client if they have different objectives or they wanted something completely different or had a different idea as to what the outcomes are regardless of the results and then you know you go ahead and do something else and the report you know again is not what they're looking for or tells them very little about what they're focused on that can be quite uh problematic and again if you want to have a successful red team engagement and what I Define as successful is answering the questions that the client wants answered so for example can we defend against this AP group or you know an AP group with the following ttps can is our blue team able to again detect and defend against these types of attacks uh you know is our organizations suceptible to fishing uh campaigns or to fishing attacks are are our employees following the security policies stuff like that right and so in the report if you don't answer these questions and you go on different tangents talking about how some servers have this vulnerability and they can be exploited therefore so on and so forth you get the idea it's not answering the question so you need to have a you know a uh there needs to be a synthesis uh between you and the client in terms of you know what they want answered so when analyzing a client's desired objectives one key factor to consider is the depth and nature of the engagement Now red team engagements can typically be categorized Into You Know full simulation or an extended pentest which is a standard R teim operation or adverse rul right now the type of Engagement to utilize and the corresponding methodology used will L depend on the objectives defined by the client once objectives have been defined engagement plans will need to be set up to further expand on the specifics of the engagement so the company tells you these are objectives you then say okay if these are your objectives you then come up with the engagement plan extrapolated from the objectives and you say based on what you laid out as the objectives this is what we have come up with please tell us whether this is in alignment not only with the objectives but fits within the scope that you have defined if they have defined it yet or the engagement plans will end up defining the scope with a few minor adjustments um another key factor to consider as I said is the engagement scope the scope of the um the scope of an engagement will depend on the target infrastructure as well as you know the client's requirements uh and these are very esoteric as you know if you're a pent tester so the scope outlines what you can or cannot do or can or cannot Target and what you can or cannot use in terms of tools or software um and the scope is always defined by the client and should be strictly adhered to now that's not always the case in terms of definition as I said in certain cases it could be a collective uh definition where you come up with the engagement Plans extrapolated by the objectives the organization laid out and you say okay based on this this is what the scope should be or you know what scope did you have in mind and then you can come up with a synthesized scope that encapsulates uh you know the client's objectives and also encapsulates the engagement um the engagement plans so again it's not always the case that they'll be defined um you know uh before the fact uh but uh yeah there's something you need to keep in mind now you may be asking well what are some of these ex uh these objectives can you give us some examples Alexis well yes I can so these are some examples of objectives you typically see uh specifically in the case of red team operations so the first one is identify the system is configurations and network weaknesses very broad as you can see uh they might be a little bit specific and say focus on external public facing system so from that objective you're then able to say ah okay so based on this you can Define the scope and then come up with the engagement plan or the plan for the red team operation you communicate it with the client they agree on it the Rules of Engagement is defined so on and so forth another example of an objective is to determine the effectiveness of endpoint detection and response systems that's again quite wide in terms of uh or quite Broad in terms of what they're asking you but you can see that in the report they want to know whether the endpoint detection and response systems or the EDR systems that they may be recently installed are working or or are effective um and then you would come up with a plan and say well based on that we can try maybe some we can come up with a rim operation that focuses on uh uh that essentially assesses the edrs capabilities another example of an objective is to evaluate the overall security posture and response so that can be further extrapolated or broken down into the seam and detection measures remediation segmentation of DMZ and internal servers and of course another example is to evaluate the impact of data exposure and exfiltration where they're essentially telling you can you show us you know what exactly is possible in terms of you know whether if an attacker was or a threat actor or an AP group was to breach our organization what could they um expose or what data could they exfiltrate all things considered so you get the idea um now when we talk about the rules of Eng engagement again if you're a pentest you should be very very familiar with this also known as the Roe The Rules of Engagement establish the responsibility relationship and guidelines between the red team the network owner the system owner and any stakeholders required for engagement execution the Roe documents the target information approvals threat implementation activities and issues required to staff coordinate and execute engagements with within the target environment so in since it essentially lays out the responsibility the relationship and the guidelines between the red team the network owner or network administrator or system administrator the system owner uh and any other stakeholders like maybe you know project manager for that particular operation Etc and the docu uh the Roe documents the you know information about the target um any approvals that need to be put in place you know before the uh operation is uh commenced uh that needs to be signed by relevant stakeholders uh the threat implementation what that means is what is your engagement plan what are you going to do all the activities uh and all the issues required to staff so you know the members of your red team um who is responsible for what the coordination between the two the communication not only between or in between the members of the red team or the red team operators but also communication frequent communication between you uh if you were the red team lead uh and the client to provide them with updates etc etc so it's a very important document now uh you know building onto that it also outlines the scope and objectives of the engagement so that is clearly stated uh and uh the Roe establishes the responsibility relationship and guidelines between as I've already said the red team Network owner the system owner stakeholders Etc and we've already gone through that now the body of the Roe document should have the following information the methodology being used or the methodology that was followed but ideally of course the methodology that's being used a high level description of the types of activities that may be executed so the attack um kill chain or what your attack will look like in terms of ttps the sequence of the uh the activities the types of hardware and software that may be employed if they are if you know if Hardware is going to be employed that needs to be stated in terms of software you want to State what attack tools or INF structure will be used uh so for example cobal strike uh so on and so forth um there's another important thing a recommended deconfliction process essentially a process that outlines you know the uh the process and procedures for communicating uh certain events uh communicating updates and of course deconfliction and then of course the rules and responsibilities of each functional group more specifically within your own red team amongst the red team operators so who is responsible for what who is responsible for initial access who is responsible for exfiltration so on and so forth uh the identification and references to appropriate legal requirements so this is where you have your uh your guidelines or your standards like you know whether the there any compliance or regulatory uh requirements that need to be factored in so if the companies are you know dealing with uh you know their customers financial information or you know credit card details you'll obviously see p PCI there you also have hyper socks Etc so again the ROE should show you know uh references to specific legal requirements that set the basis for what you can and cannot do uh and finally uh but not again um uh finally but not conclusively a legal responsibility disclaimer this is a federally again depending on the country you operate in a federally mandate requirements for the red team to report certain findings so this is in reference to you know if you find any um let's say x-rated content or any not x-rated but you know content of a certain nature that is illegal your responsibility to report it to the relevant authorities uh and that again is goes both ways communication uh you're you're again communicating and disclaiming this to the client that hey if we find anything that's illegal we are uh legally required to disclose it U so just something that you need to keep in mind now when it comes down to planning red team operations um as I've already stated uh you know this can be quite difficult and is uh is true for organizations new to Red teaming organizations that are you know uh getting their first red team operations uh orchestrated so whether you're on the delivery or receiving end of a red team engagement a solid plan must be laid out now the red team engagement planning can be broken down into four primary types you have your engagement plan so this outlines the technical requirements of the red team so conops uh you know the resource requirements and uh of course the timelines I've already explained conops in the in introduction to Red teing video so you can refer to that that's why I stated uh in that video the essential terminology you then have your operations plan this is quite simple to understand this uh essentially a detailed version of the engagement plan with the roles and responsibilities for each operator you then have the mission plan so this is uh the execution plan this States who will do what what commands or what ttps or techniques or sub techniques will be executed when they are to be executed and the operator responsible for executing a specific Tech essentially what this means is hey Mr operator 1 you are going to be responsible for privilege escalation these are the ttps that you should um that you're going to be responsible for executing or I should say techniques or sub techniques and you must adhere to them and not go uh outside of this um then of course you have your remediation plan this outlines the next phase of the engagement once the operation is done or concluded and that's of course the report uh reporting and Remediation so uh to conclude this video I want to give you some really cool resources uh the links to which will be um actually added in the description section of this video uh but what I'm going to be highlighting are um some sample red team Rules of Engagement and Reporting uh documents or templates that can again uh verify or validate what I've explained in the slides but also serve as um a basis for you to again get a better understanding of red team operations uh right from the planning phase all the way to you know the execution or reporting and Remediation phase so just going to switch over and uh I'll see you in a couple of seconds all right so I'm back in my browser and one of the resources I want to share with you and uh again you can use it as a guide is red team. guide It's a website called red team. guide so the URL is just red team. guide link uh will be in the description section uh the Red Team guide is a really cool resource that's based on a book that I highly recommend you check out or get called red team development and operation operations which is a practical guide to Red Team operations uh so this book has a this complimentary website um you know uh that you know it offers you this complimentary website which is free you don't need to buy the book to access this uh but it essentially has guides that you can refer to um and one or a couple of them are going to be for example if you take a look at um uh the references uh templates and presentations you're going to have your your um templates here so you have your operator log so your operator log is a spreadsheet typically that's given to every red team operator that uh they use to outline all the activities they've done or that they've performed on the target system on the target environment this is very useful and it's timestamped so that at the end of the day you have accountability as to who did what when they did it and what the resultant uh what the result of that action was uh you then have The Rules of Engagement uh example document here and then the red team report example um so those are the templates you can also take a look at the checklist and planning um so you know in terms of uh you can see this uh this set of checklist is intended to be a start to uh help and plan build each red team each design may have additional requirements used this is a starting point and modify as you see fit so this is a checklist uh you red team development checklist list where you determine the required Knowledge and Skills uh develop the roles and responsibilities guide develop a red team methodology or adapt one develop TTP guidance for engagement so that's when you're developing your red team and then you have your red team engagement checklist so before you start a red any red team you go through this checklist we use one that's quite similar so you start with your Rules of Engagement is there an event communication plan uh is the diff deconfliction process being distributed to all stakeholders all relevant parties uh entry point method is the scope defined the goals and objectives uh the target restrictions the target infrastructure any approvals that are required uh scenario development if there is you know if you're performing um adverse emulation operational impact planning so the impact of your operations on the target organization's digital infrastructure or the organization as a whole develop the threat profiles uh plan and uh you know plan the threat infrastructure which may be required especially if you're performing threat uh or adverse regulation you know acquire infrastructure so on and so forth and then you have your execution checklist so the daily completion and rollup confirmation uh every oper uh is every operator capturing their logs or logging their activity our screenshots being captured our system changes being captured um you know there's a daily or twice daily mandatory internal RT sitrep I've already explained what sitrep is an update uh um you know the update the real time attack diagram which outlines where you are in terms of the attack kill chain and then the culmination this is the red uh you know checklist for the culmination so engagement close out uh roll up data roll back system changes if any were made validate the data has been collected outline the critical attack diagram or the attack um uh you know the the attack flow or the attack kill chain as it were the technical review Tech cont Tech so this is you the red team lead uh with the red team operators uh sharing notes um and then of course the executive brief and then of course you have reporting where you have the draft attack narrative uh the dra the draft observation and findings finalize the attack diagram and then finalize the report um and now you can take a look at the Rules of Engagement here so this pretty much contains what I specified there and you can take a look if you go back to the references templates and presentations page uh we can start off with the operator log I'm just going to download these three documents uh I'll disregard the CSV cuz I like an Excel template these are completely safe by the way you can uh you can take my word for that as of recording this video if something happens in the future uh obviously if you're downloading any documents do so in a sandbox or virtual environment but I'll just download them and I'll we'll start off with the operator log and I'll explain what it is which I've already done but uh how it's used all right so we're starting off with the operator log um you can see it's very simple spreadsheet uh that just contains a log of all your activities so uh left here you have your date time stamp date and time time stamp that uh allows you to specify when you started an activity when you stopped the source IP so if you're running this from a you know command and control infrastructure uh what the IP is the destination IP or the IP address of the target system the destination Port if any the destination system uh the host name that is the pivot IP if there is a pivot point uh the pivot Port uh the URL if relevant the tool or app that you run pertinent to this action or activity the command you run so in this case proxy chains um you know we're essentially using proxy chains uh to proxy through um maybe the Pivot Point here it looks like and you can see the description or the reason why you did this was to test the ability for foothold to communicate with internal server so yes indeed you're using proxy chains to again proxy through the pivot point or the pivot system uh then the output you can see Port 80 was open so the result was successful communication whether the you know was there any system modification or modification as a result of running a particular uh of running this particular action or this particular task um no there wasn't comments very useful access to the Target service via foothold one and then the operator name here so this is very important during a red team operation uh and of course I know there's many other tools automation tools you can use to log your activity uh you know everyone has their own uh uh has their own tools but when I started when I was building my red team um I started with a spreadsheet and again very very useful you can't uh deny the efficacy of uh you know just how useful a spreadsheet can end up being especially when you don't have uh you know uh you know the funding to get some of the third party commercial software that uh again is used specifically for or by Red teams that's not an excuse but the spreadsheet is always uh uh you know is always there if you need it and this is arguably one of the best operator log templates that I've seen so that's the operator log as I said as you continue to do different things you provide your you know start time end time and all the other data here and at the end of the day you again have an update call uh you know between yourself other members of the red team or the operators in the red team lead just to assess what was done uh whether there any impacts uh so on and so forth and of course to ensure that you're on track with the red team operation uh with regards to its timeline so that's the operator log let me switch over to the Rules of Engagement all right so this is the Rules of Engagement document template um that I downloaded um and you can see how this works so you know this is just a standard template you have your client name the date and then you have your executive summary what the objectives are as we discussed and you can see the disclaimer here the signing of the Roe constitutes acknowledgement and approval of the customer system owner and red team of the red uh and the red team of the red team's authorities and the red teams here is referring to the actual name of your organization in a execution of the engagement and then explicit restrictions where you know restrictions are specified explicitly and agreed upon the authorized Target space which is pretty much your scope and then the activities that you'll be performing in terms of tactics and this is where the uh the MIT attack framework comes into play and more importantly if you remember in the slides I mentioned that you also specify the methodology or you know the nomenclature you're using and in most cases you'll typically use the attack framework as a base is or as you know essentially as as the nomenclature uh for defining your um your activi so you know you could say the in terms of tactics reconnaissance uh initial access uh privilege escalation you can dive a little bit deeper into the uh techniques or sub techniques and each of those tactics over here you have your table of contents fairly self-explanatory um you can see here the now you we actually Define The Rules of Engagement what they mean uh references here specifying any references the scope the definitions of the scope so sorry not the definitions of the scope but rather the definitions so Rules of Engagement and support agreement so uh this is where you essentially State I um I love red teams Inc has been agreed to has been agreed upon to conduct a red team engagement and supporting red team activities this document provides the ground rules for planning executing and Reporting the engagement you then provide a short description of the services requested and information about the requesting entity the following systems networks and or assets will be included so the list of business organization systems and networks included all software and Hardware included as a Target during the engagement uh and then of course the objectives so the engagement is designed to you specify the objectives this means the system must um uh you know the systems within the scope in alignment with the objective will be tested assessed evaluated or stressed or stress tested as it were uh for the red team an open network will be utilized and open network is defined as a network with access to the internet so you actually Define what you'll be using how you'll be using it you know cutting a long story short how you'll be conducting this engagement operation um and you need to do it very clearly so that after the fact there's no legal dispute regarding hey you guys didn't tell us you do this or that you know so on and so forth and then you specify the responsibilities of the customer and then right over here there will be a complete and open coordination with all stakeholders required for the engagement execution stakeholders are the parties represented by the signatories of the this document and you can see just how uh fine um or how fine grain and granular The Rules of Engagement needs to be from a legal perspective in that you actually need to Define uh what each term means and by signing it or by you signing it and the client signing it they agree not only to what you've defined technically in relation to the engagement or the operation but also the nomenclature used uh so for example stakeholders once the client signs it then the definition of stakeholders are exactly what is stated here uh the red team activities are limited to the Target of Engagement Red Team Tools and activities may be intrusive but will not intentionally disrupt Services outside the authorizations of these rules of engagement and then you specify here uh the red team will provide updates uh as follows uh you specify the uh you know the update types the conditions uh the you know date and time Etc if that is to be agreed upon and then the customer or the client will um and then you specify the responsibilities or you know provide the red team administrative facilities and support uh for all red team personnel as necessary to conduct the engagement if it's on site Provide support uh with network and resources for conducting the engagement including adequate workspace acqu facility so this is where you lay out what you require once the client signs it again they're uh they're legally obligated to um again uh you know provide you with this whatever is agreed upon here and likewise whatever you uh what whatever responsibilities you are binded to you will need to you know comply with them moving on uh you can see if I just proceed a little bit uh bit into here um there we are so the sensitive information reporting vulnerabilities discovered during the engagement that present an immediate risk to life limb or eyesight will be reported promptly to the the person um the point of contact uh to enable immediate response or action representatives of the signatories of the this Roe will receive the following notification as uh uh as appropriate uh incidental Discovery and this is what is referring to you're talking about um you know reporting of certain stuff to the legal authorities incidental discovery of information that relates to Serious crimes such as sabotage threats or plans to commit offenses that threaten life or could cause significant damage to loss or customer property and which does not present an immediate risk will be reported to the applicable local authorities for Action the red team reporting is otherwise conducted in a way that does not attribute information or particular in uh a particular activity to an individual that means um within the report you can say that employee XY Z or John Doe um responded or opened up various fishing emails and downloaded attachments it needs to be um uh it cannot be personal you cannot include any you know um individual information uh and this goes this is both ways in this case it's referring to uh you know the operator's detail so moving on red te activities may not be conducted in support of law enforcement or criminal investigation purposes um moving on CES operation processes so this are stipulates the uh uh you know the the process follow in ter you know if there is uh if you know the if you get to the point where operations need to be seized so the red team will suspend activity upon detection of computer anomalies that could be potentially that could potentially be unauthorized intrusions into Target of environment uh networks the red team will suspend activity when unintentional information as described above is uh encountered and until the appropriate reporting is taken place information usage deconfliction very important all detected information assurance incidents whether real world or alleged red team activity should immediately be reported using normal incident reporting processes the customer or system owner if there's a difference between the two point of contact may contact the red team's point of contact to determine if discovered activities are the result of the red team and then of course the deliverables so the red team will provide an engagement summary presentation for the target of Engagement Representatives at the completion of the engagement the red team will provide a written summary of the engagement results to the uh POC or you know point of contact uh representative within 30 days following the completion of the test so this is very important is where where you say what you're going to deliver and when you're going to deliver it after completion of the operation then of course you have your Roe Pro um provisions and then the requirements restrictions and Authority uh which again you can go through there's the ground rules here so the this section identifies specific cific rules associated with the execution of this event um uh you know that that uh can be broken down into network operations uh Cloud operations physical engagement so all the following areas are are off limits to the red team Personnel including transient movement due to potential loss of life so if you're doing a physical engagement uh then the the the the client can specify hey you guys can do what you want but you can't enter this office or that uh particular ular area or the um you can't enter this particular room so on and so forth you know the same can be done uh in terms of provisioning or specifying you know restrictions to buildings or premises so on and so forth and then of course there's the resolution of issues or points of contact so in the event that any issues uh may occur or develop which are not covered by this Roe will be resolved mutually with all stakeholders you have the CIO representative uh the title full name phone number email you get the idea um if there is a white cell lead by the way I already explained this so refer to the introduction video if you would like to know about the the different roles and responsibilities within a red team uh in conjunction with the client but here you have the red team lead and the red team technical lead um and then of course authorization approval and there needs to be signing from everyone and then of of course you have the appendix here which specifies the target environment the authorized you know all all that good stuff and then the points of contact here engagement director The Trusted agent the whiter lead emergency contact the red team lead and then in the appendix uh c section c you have the Ry methodology so this is where you outline the methodology that uh you know you're going to use and again this where you can now align it with uh Frameworks like the M attack framework where you can use the the name of tactics um in this case that's not the case because you can have exploitation uh in the M attack framework you typically have initial access and then here post exploitation you specify what you're going to be doing in terms of techniques or sub techniques so identifying domain User Group memberships identifying the IP space so you know local enumeration and then persistence so no privilege escalation here actually that looks like it falls under exploitation uh and then of course lateral movement continued enumeration and then you lay out um you know uh impact here um and then you have your engagement objective so hopefully this makes sense now the final section the threat profile this is when you're performing adversary emulation so as part of the red team engagement I or we the your organization uh the you know red team Inc uh will be replicating the ttps associated with the group known as let's say apt29 this threat has been known to exploit and attack the systems and networks servicing the transactional records customer order database and XYZ of organization similar to so the threat profile in this case when you're performing adverse ulation you typically will select an AP group that again aligns or has been known to Target your client or the client you're performing the red team operation for in terms of geographic location the industry the client operates in so you know uh if the if the client is operating let's say in North America and is a financial services company then you'd find AP groups that Target those types of organizations or those types of companies in that uh AP groups that Target North American companies but more importantly that Target um companies in the financial sector that offer Financial Services of a certain kind that allows you to give the organization or the client a realistic holistic view of what what they're likely to face based on uh you know AP groups or the uh the um the adversarial ttps that AP groups who Target that particular geographic region and industry or type of companies utilize uh so you know you're not using ttps of an AP group that targets companies in Southeast Asia because again that might not be entirely too realistic unless that particular apt group targets countries in East Asia in addition to uh to companies in North Amer America uh but there we are you go ahead and specify the ttps you'll be emulating you can be a little bit more detailed I typically include you know the M attack Navigator layer here or an image of it that uh you know AIDS in U in explaining what exactly will be doing uh but yeah that is the Rules of Engagement all right so the final thing we'll touch on um based on uh red team the red team guides website is the reporting template again a link to all of these templates and as well as the red team guides website by the way a huge shout out to them will be in the description section for you to peruse yourself at your own time but this is an example of what a red team uh typical I would say it's it's generic but uh what a red team report would look like um and you'll be able to tell if you're a pentester what the differences are between a red team report and a pent testing report they're fairly similar uh but here you have your executive summary um where you specif again executive summary is exactly that it's a summary for you know the SE Suite um level within the client you know essentially summarizes right over here the goals included the following uh the observations um and then of course the summary of goals and objectives achieved uh moving on you have your table of contents the methodology and goals where you now dive a little bit uh or you you know make this a little bit more detailed or you know layout now with a with a lot more detail what you did so scenario and scope uh so this is where you specify and remember I talked about the types of red team operations in the introductory video uh this is where you specify the scenario so the red team engagement or the type of red team operation you're performing so the red team engagement was based on the assumed breach model so in this case there's no initial access within um your operation you're again just going to assume or you're going to get um the the client May provide you provision or you may connect let's say a jump box in the Target organization's Network where you're assuming that you know you have already breached the organization uh in this case utilizing external command and control a coordinating fishing attack was used to begin the test and involved the support of a trusted agent within the organization you're performing the red team operation for the coordinated fish was followed by a fishing attack against Real World users who did not have any knowledge of the engagement the approach of the assumed model allows the test to begin quickly and later use access gain from the fishing attack to validate actions the scope is defined there and then you have your miscellaneous stuff in here and then the attack narrative this is the attack diagram I was referring to where you outline uh visually the you always use a diagram or a flowchart but you essentially explain you can see here each of these phases has a numbering or sequencing so step one was targeting workstations you can see it's says the attack narrative the following section outlines the sequence of events and highlights the key points during the engagement so work stations were targeted first um or the initial attack where you know the execution of the C2 agent credential harvesting attempting or attempt to move laterally to the client workstations this is highlighted in green which means it worked uh or rather it didn't uh you can look at the color coding so ah green is unsuccessful red is successful so again you can see that color according is going to be uh you know up to you and your team but it should be stated in the Legend So now that I looked at the legend if I was an executive of the client um for whom this red team operation was performed for I can start to understand what's going on so uh step one maintaining C2 access two is lateral movement uh three lateral movement privilege escalation four is backup dat X filtration and in this case uh the execution of the C2 agent was successful credential harvesting was successful attempt to move laterally to servers was successful and the technique here was the SMB name pipe connection that was the pivot technique this brought us to servers uh where uh you know the execution of the SMB name pipe C2 agent was successful in this case I think uh the Havoc C2 framework was used credential harvesting was successful where we gained uh clear text passwords of multiple domain accounts however attempting to move laterally to client workstations did not seem to work the techniques we tried out were uh we you know we were we were unable to connect for whatever reason um and then of course you can proceed on and uh you know explore uh you know you can explore whether extration was successful in this case does not look like it was successful so this diagram just tells the organization or your client this is what we did in alignment with what we agreed on this is what worked what didn't for the techniques or sub techniques that worked this is what it led us to um or this is what we're able to do with that and uh yeah so fairly simple and then of course you provide a description of each critical step uh this is your standard um you know your pen testing where you report your vulnerabilities or your POC proof of concept uh where you outline the vulnerabilities you found um how it can be replicated so on and so forth and any other references uh any other tools you used but in this case you pretty much outline it as a critical step it's entirely up to you how you want to format it but that's how it is and then observations and recommendations um which is self-explanatory so there we are that is uh that brings us to the end of this video the objective of this video as I stated earlier on or in the beginning of the video was to uh give you an introduction into the process of planning a r team uh operation and walk you through the process of you know laying out the objectives uh the scope Rules of Engagement and then you know moving on to the actual engagement itself and some resources there that being the operator log and finally the reporting and I've given you example of what this looks like uh with that being said that's going to be it for this video If you like this video for value in it please leave a like down below if you have any questions or suggestions please leave them in the comment section if you want to continue the conversation with regards to this video or other videos within the red team series a link to the thread or category on the hackers exploit Forum available or accessible on forum. hack.org uh has been added to the description section of this video as well as the pinned comment in the comment section so you can refer to it if again you wanted a documented version of this video with a link to all the resources which again are already in the description section but if you wanted something written you can do so there if you want to continue the conversation regarding these videos and if you have any important questions The Forum is the right place to look ah with that being said uh that was quite a mouthful but that brings us to the end of the video as I said and now we'll be moving to the more practical stuff namely adversary emulation so the this brings us to the end of the slides or the videos that have an excessive amount of theoretical information and now we'll get to put everything we've learned um or now that we have the fundamentals with regards to Red teaming we're now able to move into stuff like adversary emulation and actually perform a red team operation so that's going to be it and I'll be seeing you in the next video stay safe [Music]
Original Description
Hey guys, HackerSploit here back again with another video. This video outlines the process of planning and orchestrating Red Team operations.
This video also outlines various Red Team resources, guides, and templates to plan and orchestrate a successful Red Team Operation.
//LINKS & RESOURCES
REDTEAM.GUIDE: https://redteam.guide/
The slides and written version of this video can be accessed on the HackerSploit Forum: https://forum.hackersploit.org/t/introduction-to-the-mitre-att-ck-framework/9127
//HACKERSPLOIT PLATFORMS
BLOG ►► https://bit.ly/3qjvSjK
FORUM ►► https://bit.ly/39r2kcY
ACADEMY ►► https://bit.ly/39CuORr
//SOCIAL NETWORKS
TWITTER ►► https://bit.ly/3sNKXfq
INSTAGRAM ►► https://bit.ly/3sP1Syh
LINKEDIN ►► https://bit.ly/360qwlN
PATREON ►► https://bit.ly/365iDLK
MERCHANDISE ►► https://bit.ly/3c2jDEn
//BOOKS
Privilege Escalation Techniques ►► https://amzn.to/3ylCl33
Docker Security Essentials (FREE) ►► https://bit.ly/3pDcFuA
//SUPPORT THE CHANNEL
NordVPN Affiliate Link (73% Off) ►► https://bit.ly/3DEPbu5
Get $100 In Free Linode Credit ►► https://bit.ly/39mrvRM
Get started with Intigriti ►► https://go.intigriti.com/hackersploit
//CYBERTALK PODCAST
Spotify ►► https://spoti.fi/3lP65jv
Apple Podcasts ►► https://apple.co/3GsIPQo
//WE VALUE YOUR FEEDBACK
We hope you enjoyed the video and found value in the content. We value your feedback, If you have any questions or suggestions feel free to post them in the comments section or contact us directly via our social platforms.
//THANK YOU!
Thanks for watching!
Благодарю за просмотр!
Kiitos katsomisesta
Danke fürs Zuschauen!
感谢您观看
Merci d'avoir regardé
Obrigado por assistir
دیکھنے کے لیے شکریہ
देखने के लिए धन्यवाद
Grazie per la visione
Gracias por ver
شكرا للمشاهدة
-----------------------------------------------------------------------------------
#HackerSploit #cybersecurity #redteam #hacker
Watch on YouTube ↗
(saves to browser)
Sign in to unlock AI tutor explanation · ⚡30
Playlist
Uploads from HackerSploit · HackerSploit · 0 of 60
← Previous
Next →
1
2
3
4
5
6
7
8
9
10
11
12
13
14
15
16
17
18
19
20
21
22
23
24
25
26
27
28
29
30
31
32
33
34
35
36
37
38
39
40
41
42
43
44
45
46
47
48
49
50
51
52
53
54
55
56
57
58
59
60
How To Install Kali Linux 2.0 On Virtual Box
HackerSploit
100 Subscriber Q&A! - How I Learned Ethical Hacking
HackerSploit
BlackArch Linux Review - Better Than Kali Linux?
HackerSploit
How to Access the Deep Web Safely | Deep Web Starter Guide 1.0
HackerSploit
Wireshark Tutorial for Beginners - Installation
HackerSploit
Wireshark Tutorial for Beginners - Overview of the environment
HackerSploit
Wireshark Tutorial for Beginners - Capture options
HackerSploit
Wireshark Tutorial for Beginners - Filters
HackerSploit
Complete Ethical Hacking Course - Become a Hacker Today - #1 Hacking Terminology
HackerSploit
Complete Ethical Hacking Course #2 - Installing Kali Linux
HackerSploit
Parrot OS 3.5 Review | The Best Kali Linux Alternative
HackerSploit
Nmap Tutorial For Beginners - 1 - What is Nmap?
HackerSploit
Katoolin | How To Install Pentesting Tools On Any Linux Distro
HackerSploit
Nmap Tutorial For Beginners - 2 - Advanced Scanning
HackerSploit
Nmap Tutorial For Beginners - 3 - Aggressive Scanning
HackerSploit
Zenmap Tutorial For Beginners
HackerSploit
How To Setup Proxychains In Kali Linux - #1 - Stay Anonymous
HackerSploit
How To Setup Proxychains In Kali Linux - #2 - Change Your IP
HackerSploit
How To Change Mac Address In Kali Linux | Macchanger
HackerSploit
How To Setup And Use anonsurf On Kali Linux | Stay Anonymous
HackerSploit
Ubuntu 17.04 "Zesty Zapus" Review - Bye Unity
HackerSploit
VPN And DNS For Beginners | Kali Linux
HackerSploit
Tails OS Installation And Review - Access The Deep Web/Dark Net
HackerSploit
Steganography Tutorial - Hide Messages In Images
HackerSploit
The Lazy Script - Kali Linux 2017.1 - Automate Penetration Testing!
HackerSploit
Best Linux Distributions For Penetration Testing
HackerSploit
Netcat Tutorial - The Swiss Army Knife Of Networking - Reverse Shell
HackerSploit
Gaining Access - Web Server Hacking - Metasploitable - #1
HackerSploit
Web Server Hacking - FTP Backdoor Command Execution With Metasploit - #2
HackerSploit
How To Install Kali Linux On VMware - Complete Guide 2018
HackerSploit
Q&A #1 - Best Cyber-security Certifications?
HackerSploit
Terminator - Kali Linux - Multiple Terminals
HackerSploit
Shodan Search Engine Tutorial - Access Routers,Servers,Webcams + Install CLI
HackerSploit
Q&A #2 - Mr Robot?
HackerSploit
Metasploit Community Web GUI - Installation And Overview
HackerSploit
Linux Expl0rer - Forensics Toolbox - Installation & Configuration
HackerSploit
QuasarRAT - The Best Windows RAT? - Remote Administration Tool for Windows
HackerSploit
Metasploit For Beginners - #1 - The Basics - Modules, Exploits & Payloads
HackerSploit
Metasploit For Beginners - #2 - Understanding Metasploit Modules
HackerSploit
Kali Linux Quick Tips - #1 - Adding a non-root user
HackerSploit
Metasploit For Beginners - #3 - Information Gathering - Auxiliary Scanners
HackerSploit
Spectre Meltdown Vulnerability - How To Check Your System
HackerSploit
Metasploit For Beginners - #4 - Basic Exploitation
HackerSploit
ARP Spoofing With arpspoof - MITM
HackerSploit
WordPress Vulnerability Scanning With WPScan
HackerSploit
Generating A PHP Backdoor with weevely
HackerSploit
Nikto Web Vulnerability Scanner - Web Penetration Testing - #1
HackerSploit
How To Install Kali Linux On Windows 10 - Windows Subsystem For Linux
HackerSploit
Stacer - System Optimizer And Monitoring Tool For Linux
HackerSploit
Kali Linux 2018.1 - Kernel Updates & Patches
HackerSploit
MITM With Ettercap - ARP Poisoning
HackerSploit
Password Cracking With John The Ripper - RAR/ZIP & Linux Passwords
HackerSploit
How To Detect Rootkits On Kali Linux - chkrootkit & rkhunter
HackerSploit
Channel Updates - How To Post Questions & Video Suggestions
HackerSploit
Web App Penetration Testing - #1 - Setting Up Burp Suite
HackerSploit
Web App Penetration Testing - #2 - Spidering & DVWA
HackerSploit
Cl0neMast3r - GitHub Repository Cloning Tool
HackerSploit
Kali Linux On Windows 10 Official - WSL - Installation & Configuration
HackerSploit
DoS/DDoS Protection - How To Enable ICMP, UDP & TCP Flood Filtering
HackerSploit
Web App Penetration Testing - #3 - Brute Force With Burp Suite
HackerSploit
More on: Security Basics
View skill →Related Reads
📰
📰
📰
📰
Blank Identifier: Idiomatic Go or Vulnerability Trap?
Medium · Cybersecurity
Kinetix Browser Review: The Ultimate Solution for Fast, Secure, and Private Web Surfing
Medium · Machine Learning
How to Group and Batch Vulnerability Fixes to Save Engineering Time
Dev.to · InstaSLA
10 Skills Every Cyber Security Professional Needs in 2026
Medium · Cybersecurity
🎓
Tutor Explanation
DeepCamp AI