Home
Cybersecurity Blog
Cancel

Windows Local Persistence

Introduction Reasons why you’d want to establish persistence as QUICKY AS POSSIBLE including: 1. Re-exploitation isn't always possible: Some unstable exploits might kill the vulne...

Lay of the Land

Intro It is essential to be familiar with the environment where you have initial access to a compromised machine during a red team engagement. Therefore, performing recon and enumeration is a...

Enumeration

Introduction This room focuses on post-exploitation enumeration. In other words, we assume that we have successfully gained some form of access to a system. Moreover, we may have carried ...

Data Exfiltration

Introduction Cybercriminals use various internet attacks against companies for different purposes. In most cases, many of these attacks end in data breaches, where threat actors steal sensiti...

Weaponization

Intro Weaponization: Second stage of the Cyber Kill Chain model. The main purpose of this phase is to acquire initial access on the target machine through the use of malicious weapons t...

Red Team Threat Intel

Intro Threat Intelligence or Cyber Threat Intelligence(CTI) is the information, or TTPs attributed to an adversary, commonly used by defenders to aid in detection measures. The red cell can l...

Red Team OPSEC

Intro Operations Security (OPSEC) is a term coined by the US military. In the field of cybersec, let’s start with the definition provided by NIST: Systematic and proven process by...

Red Team Engagements

Intro The key to a successful engagement is well-coordinated planning and communication through all parties involved. Engagements: Tabletop exercises Adversary emulation Physical asses...

Phishing

Intro to Phishing Attacks Before you learn what phishing is, you’ll need to understand the term Social Engineering. Social Engineering : psychological manipulation of people into performing o...

Intro to C2

Intro Command and Control (C2) Frameworks are an essential part of both Red Teamers and Advanced Adversaries playbooks. They make it both easy to manage compromised devices during engagement and...