Red Team Frameworks & Methodologies

HackerSploit · Beginner ·🔐 Cybersecurity ·1y ago

Key Takeaways

The video introduces industry-standard frameworks and methodologies used by Red Teamers, such as MITRE ATT&CK and NIST Cybersecurity Framework, to plan and orchestrate successful Red Team operations.

Full Transcript

hey guys hack exploit here back again with another video and welcome back to the red team series uh in this video we're going to be continuing from where we left off in the previous video I do apologize for the delay in uploads but uh uh this video as well as the rest of the videos following this one will be uploaded in uh regular schedule or as per the regular schedule uh but with that being said uh what are we taking a look at in this video um in this video we're going to be exploring the various red team Frameworks or methodologies uh that are used as a sort of a guide um as a guideline or Baseline uh when performing red team operations and again this is not exclusive to penetration testing but uh you get the idea so we're going to be exploring you know the various Frameworks methodologies uh that are typically followed uh in terms of uh you know the process or the life cycle so you know if you think of a um you know if you think of penetration testing uh you have things like uh you know the uh penetration testing execution standard or pte uh which again can work uh in um in relation to Red teams but we're going to be exploring it a little bit more more and the objective here is to further uh understand or to further differentiate and distinguish uh you know a pentest from a red team operation and the methodologies will lend uh to that um or will lend to the explanation so uh you know before we do anything or we get started we need to understand red team engagements in terms of you know uh what we're doing um and what the objectives or um you know what the goals and objectives are and how you know uh how we take that how we go from a defined set of objectives with the Rules of Engagement uh and how we actually Implement that so a successful red team engagement begins with clearly defining the goals or objectives of the engagement with a client so very similar to appentice right um after which or once the objectives are agreed upon the red team is then tasked with planning and orchestrating the engagement or operation based on the predefined goals or objectives uh it's important to note that red team engagements uh or a red team engagement does not focus on the search you know for vulnerabilities and again that may seem a little bit confusing but uh if you look at it holistically whenever you're performing a r team operation your primary goal is not you know find vulnerabilities and then exploit them uh you know you're targeting the organization as a whole in terms of its uh you know uh the way it operates you know uh as well as you know the defensive uh capabilities or the detection and uh defense capabilities of the organization so you're taking a much more holistic approach uh what what that also means if I use an example uh is instead of focusing solely on systems or on uh you know computers let's say or servers you also start incorporating you know employees uh and you're trying uh you know going beyond the basic example of a fishing attack you're trying to assess whether you know um whether they are actually adhering to let's say some predefined standards or security policies around uh email security or you know downloading attachments if they if there is a security policy defined you're also trying to assess the response time or the incident response uh process um or at least the efficacy uh the efficacy of the process what that means is if the the organization you're performing the red team for or on has a blue team in place or a a sock you know Security operation Center you're trying to see uh how quickly or you know firstly if the sock can detect an attack in time and then secondly uh whether their response is proportionate or you know they able to um to defend against the attack um and the bottom line is that the results of the red team engagement or operation should highlight the blue team's ability to detect and defend against attacks and more importantly where improvements can be made which is why red team operations are typically performed you know every quarter or every um you know twice a year to not only assess the um you know the organization's ability to you know detect and defend against attacks but more so uh whether the blue team is actually improving or has improved from you know the previous operation with regards to you know uh the mistakes uh you identified or uh you know areas that you you were able to clearly see that you know the blue team needs to improve on uh so in addition to that as I explained in the previous video red team engagements or operations should also simulate or emulate new ttps and we'll get into ttps the ttps are an abbreviation for tactics techniques and procedures which is an abbreviation or a term or set of terms derived from the MIT attack framework so red team operations should also simulate or emulate new ttps for The Blue Team to learn how to detect and defend against so what this means is that you know the threat landscape is constantly evolving regardless of whether you're an organization of you know medium size or you're a large organization uh you know new AP groups or new new threat actors are constantly again using new ttps uh or you know they may uh you may see some uh advancements or some augmentations to their tradecraft and you need to keep the blue team uh on their tools or you need to keep them you know up to dat or aware of these new ttps and again that lends to the the whole uh cyclic process of improving their detection and uh defensive capabilities so what all of this means based on what I've just uh said here and you know the objectives laid out and agreed on what this means is that any successful red team engagement or operation will obviously require a structured methodological approach especially when you talk about adversary emulation or simulation which we'll actually be getting into um and uh it is therefore recommended uh you know if you and I know I'm going on a tangent here but if you remember what I covered in the previous video a lot of one of the misconceptions is that red team engagements or operations are very adhawk which means you know they there's no structureal methodology behind it but that couldn't be further from the truth uh What uh what usually leads people into thinking that it's quite random ad hoc and chaotic is the large scope or the very wide scope that you typically see red team operations have um what this means uh or what I'm trying to say here is that every red te operation requires an appropriate framework or methodology that you follow in terms of you know the methodological approach to stuff but also ensuring that uh you are uh staying within the bounds not just of the rules or not just uh the ones defined in the Rules of Engagement but uh you know using something that has worked previously uh so that you know you there's a sense of accountability um and this is very useful not just in during the execution phase of the red team operational campaign but also in structuring it beforehand so some frequent uh or frequently utilized red team Frameworks or methodologies include the Cyber kill Chain by loed Martin and of course the MIT attack framework now the M attack framework I know is not really a methodology that you can follow but it's really framework that um you know we'll actually be getting into in a separate video but is a framework that's been adopted by both the offensive side and the defensive side in cyber security and uh at you know at the most basic level offers a common speak or a common language between these two uh cyber Security Professionals or between these two groups and allows them to communicate things like um you know specific vulnerabilities or specific uh procedures and again if you're a little bit confused don't where it'll make sense so you know we have the Cyber kill Chain by loade Martin and we have the might attack framework which is a framework and then we have the unified uh cyber kill chain uh which uh is more so like a methodology or a process and um you can see that the Cyber kill chain here uh breaks down a red team operation again this can work for pen testing but it breaks it down into various phases so stage one or stages I should say stage one is all to do with reconnaissance some examp examples here are you know harvesting email addresses conference information just B very basic examples and then you have stage two which is where you now you're performing weaponization or this is the stage of weaponization where you're coupling exploits uh with back doors um into a deliverable payload another a better example is you know developing your uh let's say word uh your malicious word attachments or Word documents sorry uh that you'll use for initial access any payloads or uh any code that you're going to be using for initial access or even later uh you know during post exploitation and then you have stage three this is delivery so this is where you now deliver the weaponized bundle or payload to the victim via email web USB so that's where you know if you're performing uh fishing or you're using a spear fishing attachment this is this stage is all to do with you know uh setting up let's say your fishing framework uh or your fishing infrastructure in terms of domains emails the fishing um framework that you'll be using so something like goish uh and that encapsulates the whole process of now sending an email to your target uh and then of course you have exploitation uh which again can can include um Can involve the successful execution of your payload uh or your weaponized bundle as it were uh by the Target on the on a Target system and then exploitation sort of infers that you know gaining access to a system by means of either exploiting let's say an employee or a human being through social engineering or by exploiting a vulnerability in one of you know in a particular Target system so the objective here is uh you typically see this with apt groups the uh malicious document uh or file that let's say someone um in the Target organization downloads and opens or executes on this system usually doesn't have anything malicious on it uh from you know if you were to look at it objectively uh what that document if I use the example of a malicious document what it does is act as a dropper so it actually calls back uh to a command and control server and then you know um essentially downloads the stage um so if you think of it from your traditional Metasploit uh framework payload perspective uh the document acts as a stage uh as a Stager and then you know it downloads the stage uh only after the stage has been executed so once the document is open it it calls back downloads the stage which then uh either you know I wouldn't say gives the attacker reverse shell or gives the red team operator reverse shell but more importantly or more uh commonly you know um calls back to a command and control server and then you know further actions are taken which is why you now see um uh this is where you now see your you know command and control so so command and control channel is established uh and uh you know I've sort of skipped over installation of malware but that's where you have stuff like root kits Etc and then you have you know your actions on objectives so this is now where the attacker and again I'm looking at this from an adversarial perspective this is when the attacker either performs additional reconnaissance uh you know performs all the standard post exploitation stuff and then uh or post exploitation activi is and then you know action on objective essentially infers what were you know uh the attackers doing uh or performing actions that are in line with their original objectives so what was the objective of the threat group or AP group uh or why did they want to exploit or gain access to the this organization so you typically have um you know actions on objectives like uh some examples of actions on objectives are you know deploying ransomware deleting data exfiltrating data so on and so forth but as a red teamer you're not really going to be doing any of that that's typically where you stop or you draw the line there so you don't want to delete anything on an organization's uh you know within an organization's digital infrastructure you then have the M attack framework and I've just uh you know clipped a screenshot from the attack framework website and don't worry I'll be explaining this in the next video after this we'll actually be going through it in quite a bit of detail but the attack framework essentially breaks down uh each phase of an adver adversary's life cycle or the adversary's kill chain uh into tactics and each tactic contains techniques so you can see that at the top here these are all your tactics so you have initial access execution persistence privilege escalation defense evasion credential access so on and so forth all the way to impact so impact is the equivalent of actions on objectives in the U cyber kill chain uh by you know loed Martin just so that we're on the same page and then you can see under initial access it references the various techniques that are typically used by adversaries to gain initial access right and I've clipped off um you know the pre-engagement phase here but uh that'll actually make sense in the next video you can see the various ways that attackers typically gain access or initial access onto a system so you have spear fishing attachments exploiting a public facing application targeting external remote Services uh spear fishing links uh spear fishing via service trusted relationships valid accounts so on and so forth now if you compare the two and again I know that the attack framework or the MIT attack framework is a framework as the name suggests and the Cyber kill chain is exactly that sort of a uh cyber kill chain uh you can see that the MIT attack framework is quite popular as the most uh widely adopted framework by again not just red teamers but you know pentesters and also uh The Blue Team uh and again this will make sense as we progress ress but you can see the might the reason the M attack framework is much better is because it's much more comprehensive in um with regards to uh being uh being more detailed or sort of capturing or encapsulating a lot of the phases that for example the Cyber kill chain doesn't encapsulate or doesn't cover you know stuff like resource development or execution uh privilege escalation uh and you know one of the differences is that the attack framework actually outlines a lot of the post exploitation activity that's quite important um you know regardless of whether you're already if you analyze any um you know the tradecraft or the uh the attack cycle or the attack uh kill chain um of an AP group you'll typically see that a lot of their stuff or a lot of the key activity is you know post exploitation or is uh what you typically consider as activities performed after initial access so you know defense evasion uh credential access Discovery lateral movement collection command and control and then exfiltration and then impact right so hopefully that makes sense uh now that we've gotten this uh you know we're aware we gotten the introduction into the various red team Frameworks and methodologies at a high level in the next uh set of videos we're going to be taking a deep dive into the M attack framework or at least getting a practical view uh you know practical understanding or getting some practical experience with the framework um and then we'll also be exploring the MIT attack Navigator as a tool for planning uh red teim operations but I'll also show you how it can be used uh for reporting um as a way to communicate um you know the results of a red team operation to the blue team so that they can actually start making the improvements uh with that being said uh thank you very much uh for watching the video If you enjoyed it please leave a like down below if you have any feedback or questions please leave them in the comment section down below furthermore uh if you check the description section and the comment under this video you'll see uh that'll link you to a page on the hack exploit Forum where this um what whatever's been contained within the slides has been uh added or can be accessed in the form of um a post on the Forum and I've also provided you with access to the slides in PDF format uh on the Forum so just just check the description section of this video and other videos within this series or just check the first comment that's pinned to this video and you should see a link to that post uh The Forum is accessible on forum. Haack exploit. org if you want to visit it and I'll be using the Forum as a means of engaging with you guys so if you actually have any uh suggestions video suggestions any questions uh The Forum is a great place to actually uh quantify or to give uh you know some additional uh Credence to your questions you know the comments can be a bit difficult to keep track of uh but anyway with that being said that's going to be it for this video and I'll be seeing you in the next video [Music]

Original Description

Hey guys, HackerSploit here back again with another video. This video will introduce you to the various industry-standard frameworks and methodologies used by Red Teamers to plan and orchestrate successful Red Team operations. The slides and written version of this video can be accessed on the HackerSploit Forum: https://forum.hackersploit.org/t/red-team-frameworks-methodologies/9126 //PLATFORMS BLOG ►► https://bit.ly/3qjvSjK FORUM ►► https://bit.ly/39r2kcY ACADEMY ►► https://bit.ly/39CuORr //SOCIAL NETWORKS TWITTER ►► https://bit.ly/3sNKXfq DISCORD ►► https://bit.ly/3hkIDsK INSTAGRAM ►► https://bit.ly/3sP1Syh LINKEDIN ►► https://bit.ly/360qwlN PATREON ►► https://bit.ly/365iDLK MERCHANDISE ►► https://bit.ly/3c2jDEn //BOOKS Privilege Escalation Techniques ►► https://amzn.to/3ylCl33 Docker Security Essentials (FREE) ►► https://bit.ly/3pDcFuA //SUPPORT THE CHANNEL NordVPN Affiliate Link (73% Off) ►► https://bit.ly/3DEPbu5 Get $100 In Free Linode Credit ►► https://bit.ly/39mrvRM Get started with Intigriti: https://go.intigriti.com/hackersploit //CYBERTALK PODCAST Spotify ►► https://spoti.fi/3lP65jv Apple Podcasts ►► https://apple.co/3GsIPQo //WE VALUE YOUR FEEDBACK We hope you enjoyed the video and found value in the content. We value your feedback, If you have any questions or suggestions feel free to post them in the comments section or contact us directly via our social platforms. //THANK YOU! Thanks for watching! Благодарю за просмотр! Kiitos katsomisesta Danke fürs Zuschauen! 感谢您观看 Merci d'avoir regardé Obrigado por assistir دیکھنے کے لیے شکریہ देखने के लिए धन्यवाद Grazie per la visione Gracias por ver شكرا للمشاهدة ----------------------------------------------------------------------------------- #HackerSploit #cybersecurity
Watch on YouTube ↗ (saves to browser)
Sign in to unlock AI tutor explanation · ⚡30

Playlist

Uploads from HackerSploit · HackerSploit · 0 of 60

← Previous Next →
1 How To Install Kali Linux 2.0 On Virtual Box
How To Install Kali Linux 2.0 On Virtual Box
HackerSploit
2 100 Subscriber Q&A! - How I Learned Ethical Hacking
100 Subscriber Q&A! - How I Learned Ethical Hacking
HackerSploit
3 BlackArch Linux Review - Better Than Kali Linux?
BlackArch Linux Review - Better Than Kali Linux?
HackerSploit
4 How to Access the Deep Web Safely | Deep Web Starter Guide 1.0
How to Access the Deep Web Safely | Deep Web Starter Guide 1.0
HackerSploit
5 Wireshark Tutorial for Beginners - Installation
Wireshark Tutorial for Beginners - Installation
HackerSploit
6 Wireshark Tutorial for Beginners - Overview of the environment
Wireshark Tutorial for Beginners - Overview of the environment
HackerSploit
7 Wireshark Tutorial for Beginners - Capture options
Wireshark Tutorial for Beginners - Capture options
HackerSploit
8 Wireshark Tutorial for Beginners - Filters
Wireshark Tutorial for Beginners - Filters
HackerSploit
9 Complete Ethical Hacking Course - Become a Hacker Today - #1 Hacking Terminology
Complete Ethical Hacking Course - Become a Hacker Today - #1 Hacking Terminology
HackerSploit
10 Complete Ethical Hacking Course #2 - Installing Kali Linux
Complete Ethical Hacking Course #2 - Installing Kali Linux
HackerSploit
11 Parrot OS 3.5 Review | The Best Kali Linux Alternative
Parrot OS 3.5 Review | The Best Kali Linux Alternative
HackerSploit
12 Nmap Tutorial For Beginners - 1 - What is Nmap?
Nmap Tutorial For Beginners - 1 - What is Nmap?
HackerSploit
13 Katoolin | How To Install Pentesting Tools On Any Linux Distro
Katoolin | How To Install Pentesting Tools On Any Linux Distro
HackerSploit
14 Nmap Tutorial For Beginners - 2 - Advanced Scanning
Nmap Tutorial For Beginners - 2 - Advanced Scanning
HackerSploit
15 Nmap Tutorial For Beginners - 3 - Aggressive Scanning
Nmap Tutorial For Beginners - 3 - Aggressive Scanning
HackerSploit
16 Zenmap Tutorial For Beginners
Zenmap Tutorial For Beginners
HackerSploit
17 How To Setup Proxychains In Kali Linux - #1 - Stay Anonymous
How To Setup Proxychains In Kali Linux - #1 - Stay Anonymous
HackerSploit
18 How To Setup Proxychains In Kali Linux - #2 - Change Your IP
How To Setup Proxychains In Kali Linux - #2 - Change Your IP
HackerSploit
19 How To Change Mac Address In Kali Linux | Macchanger
How To Change Mac Address In Kali Linux | Macchanger
HackerSploit
20 How To Setup And Use anonsurf On Kali Linux | Stay Anonymous
How To Setup And Use anonsurf On Kali Linux | Stay Anonymous
HackerSploit
21 Ubuntu 17.04 "Zesty Zapus" Review - Bye Unity
Ubuntu 17.04 "Zesty Zapus" Review - Bye Unity
HackerSploit
22 VPN And DNS For Beginners | Kali Linux
VPN And DNS For Beginners | Kali Linux
HackerSploit
23 Tails OS Installation And Review - Access The Deep Web/Dark Net
Tails OS Installation And Review - Access The Deep Web/Dark Net
HackerSploit
24 Steganography Tutorial - Hide Messages In Images
Steganography Tutorial - Hide Messages In Images
HackerSploit
25 The Lazy Script - Kali Linux 2017.1 - Automate Penetration Testing!
The Lazy Script - Kali Linux 2017.1 - Automate Penetration Testing!
HackerSploit
26 Best Linux Distributions For Penetration Testing
Best Linux Distributions For Penetration Testing
HackerSploit
27 Netcat Tutorial - The Swiss Army Knife Of Networking - Reverse Shell
Netcat Tutorial - The Swiss Army Knife Of Networking - Reverse Shell
HackerSploit
28 Gaining Access - Web Server Hacking - Metasploitable - #1
Gaining Access - Web Server Hacking - Metasploitable - #1
HackerSploit
29 Web Server Hacking - FTP Backdoor Command Execution With Metasploit - #2
Web Server Hacking - FTP Backdoor Command Execution With Metasploit - #2
HackerSploit
30 How To Install Kali Linux On VMware  - Complete Guide 2018
How To Install Kali Linux On VMware - Complete Guide 2018
HackerSploit
31 Q&A #1 - Best Cyber-security Certifications?
Q&A #1 - Best Cyber-security Certifications?
HackerSploit
32 Terminator - Kali Linux - Multiple Terminals
Terminator - Kali Linux - Multiple Terminals
HackerSploit
33 Shodan Search Engine Tutorial - Access Routers,Servers,Webcams + Install CLI
Shodan Search Engine Tutorial - Access Routers,Servers,Webcams + Install CLI
HackerSploit
34 Q&A #2 - Mr Robot?
Q&A #2 - Mr Robot?
HackerSploit
35 Metasploit Community Web GUI  - Installation And Overview
Metasploit Community Web GUI - Installation And Overview
HackerSploit
36 Linux Expl0rer - Forensics Toolbox - Installation & Configuration
Linux Expl0rer - Forensics Toolbox - Installation & Configuration
HackerSploit
37 QuasarRAT - The Best Windows RAT? - Remote Administration Tool for Windows
QuasarRAT - The Best Windows RAT? - Remote Administration Tool for Windows
HackerSploit
38 Metasploit For Beginners - #1 - The Basics - Modules, Exploits & Payloads
Metasploit For Beginners - #1 - The Basics - Modules, Exploits & Payloads
HackerSploit
39 Metasploit For Beginners - #2 - Understanding Metasploit Modules
Metasploit For Beginners - #2 - Understanding Metasploit Modules
HackerSploit
40 Kali Linux Quick Tips - #1 - Adding a non-root user
Kali Linux Quick Tips - #1 - Adding a non-root user
HackerSploit
41 Metasploit For Beginners - #3 - Information Gathering - Auxiliary Scanners
Metasploit For Beginners - #3 - Information Gathering - Auxiliary Scanners
HackerSploit
42 Spectre Meltdown Vulnerability  - How To Check Your System
Spectre Meltdown Vulnerability - How To Check Your System
HackerSploit
43 Metasploit For Beginners - #4 - Basic Exploitation
Metasploit For Beginners - #4 - Basic Exploitation
HackerSploit
44 ARP Spoofing With arpspoof - MITM
ARP Spoofing With arpspoof - MITM
HackerSploit
45 WordPress Vulnerability Scanning With WPScan
WordPress Vulnerability Scanning With WPScan
HackerSploit
46 Generating A PHP Backdoor with weevely
Generating A PHP Backdoor with weevely
HackerSploit
47 Nikto Web Vulnerability Scanner - Web Penetration Testing - #1
Nikto Web Vulnerability Scanner - Web Penetration Testing - #1
HackerSploit
48 How To Install Kali Linux On Windows 10 - Windows Subsystem For Linux
How To Install Kali Linux On Windows 10 - Windows Subsystem For Linux
HackerSploit
49 Stacer - System Optimizer And Monitoring Tool For Linux
Stacer - System Optimizer And Monitoring Tool For Linux
HackerSploit
50 Kali Linux 2018.1 - Kernel Updates & Patches
Kali Linux 2018.1 - Kernel Updates & Patches
HackerSploit
51 MITM With Ettercap - ARP Poisoning
MITM With Ettercap - ARP Poisoning
HackerSploit
52 Password Cracking With John The Ripper - RAR/ZIP & Linux Passwords
Password Cracking With John The Ripper - RAR/ZIP & Linux Passwords
HackerSploit
53 How To Detect Rootkits On Kali Linux - chkrootkit & rkhunter
How To Detect Rootkits On Kali Linux - chkrootkit & rkhunter
HackerSploit
54 Channel Updates - How To Post Questions & Video Suggestions
Channel Updates - How To Post Questions & Video Suggestions
HackerSploit
55 Web App Penetration Testing - #1 - Setting Up Burp Suite
Web App Penetration Testing - #1 - Setting Up Burp Suite
HackerSploit
56 Web App Penetration Testing - #2 - Spidering & DVWA
Web App Penetration Testing - #2 - Spidering & DVWA
HackerSploit
57 Cl0neMast3r - GitHub Repository Cloning Tool
Cl0neMast3r - GitHub Repository Cloning Tool
HackerSploit
58 Kali Linux On Windows 10 Official - WSL - Installation & Configuration
Kali Linux On Windows 10 Official - WSL - Installation & Configuration
HackerSploit
59 DoS/DDoS Protection - How To Enable ICMP, UDP & TCP Flood Filtering
DoS/DDoS Protection - How To Enable ICMP, UDP & TCP Flood Filtering
HackerSploit
60 Web App Penetration Testing - #3 - Brute Force With Burp Suite
Web App Penetration Testing - #3 - Brute Force With Burp Suite
HackerSploit

The video covers the fundamentals of Red Team frameworks and methodologies, including industry-standard frameworks such as MITRE ATT&CK and NIST Cybersecurity Framework. Viewers will learn how to plan and orchestrate successful Red Team operations.

Key Takeaways
  1. Identify potential vulnerabilities
  2. Conduct threat modeling
  3. Develop a risk management plan
  4. Implement penetration testing
  5. Analyze results and develop recommendations
💡 Red Team operations require a thorough understanding of industry-standard frameworks and methodologies to effectively identify and exploit vulnerabilities.

Related AI Lessons

Up next
You Think Your Card Declined by Mistake? It Might Be a 2026 Scam
Tolulope Michael
Watch →