Skip to main content

Red Team Operations

Red Teaming: Scenario-Based Testing

··1433 words·7 mins
This article explains Scenario-Based Testing (SBT) in detail, its benefits, tools and techniques used, and provides examples of how SBT can be used in Red Team Exercises to identify vulnerabilities and weaknesses in an organization’s security defenses.

Red team supply chain exercises: simulating what actually broke the world

··3130 words·15 mins
Part three of the Red Team Operations series. How operators simulate supply chain attacks on engagement, the canonical real-world case studies that justify the budget (SolarWinds, NotPetya, CCleaner, Kaseya, Codecov, 3CX, MOVEit, XZ Utils), the engagement-scoping considerations that make supply-chain testing different from regular red team work, and the defender controls (SBOM, signing, build provenance via SLSA, dependency review) that actually move the needle.

Red team exercises: the eight engagement shapes and the five-phase playbook

··3578 words·17 mins
An operator’s walkthrough of red team engagement types (network pentest, social engineering, physical, red-vs-blue, purple team, multiscenario, full spectrum, tabletop), the five-phase methodology that structures most engagements (recon, scanning, exploitation, post-exploitation, reporting), the actual tooling stack at each phase, and the case studies (DoD Cyber Flag, Verizon DBIR-derived attack-pattern data) worth grounding the work in.

The Adversary Mindset: A Working Guide to Red Team Operations

··2368 words·12 mins
A working operator’s view of red teaming versus pen testing, the Unified Kill Chain as a practical mental model rather than a theoretical framework, how modern C2 infrastructure is actually built (and why domain fronting isn’t the answer anymore), purple teaming as collaborative tuning, deconfliction with the white cell, and the operator-side OPSEC habits that decide whether you finish the engagement quietly.