1 hour ago · 17 min read3447 words · Tech · hide · 0 comments

Here's a three part series I've written about the less sexy side of red teaming focused on explaining the important details that many tend to forget about when looking into red teaming or even approaching threat-led or regulated environments.Everyone wants to hear about the clever pivot or pwn or actions on objectives: the Kerberoastable service account that turned into domain admin, the misconfigured CI/CD pipeline that handed over cloud credentials, the phishing lure that bypassed MFA. However, nobody writes about the many weeks of planning that made any of that legal, safe, and actually worth doing or how the approach was taken.A Red Team Manager's job is mostly invisible and for good reason because the best laid plans should be seamless. It lives in test plans, risk registers, communications cadences, and awkward conversations about what's actually in scope and keeping the team on track. This post is about that work: the planning discipline that separates an engagement that…

No comments yet. Log in to reply on the Fediverse. Comments will appear here.