Red team operations

Red team operations

The difference between “I can pop a shell” and “I can run a covert operation for a month against a target with EDR and a SOC”. Most of red team is opsec discipline, not novel exploits.

Prereqs

  • Comfortable shell user across Windows and Linux.
  • active-directory stage 2.
  • Comfort writing C# / C / Nim / Rust for tradecraft tooling.

Stage 1 — opsec and tradecraft mental model

Stage 2 — Windows evasion primitives

Stage 3 — running an operation

References