-
The Red Team Engagement That Changed How I Think About Risk
There is one engagement in my career that genuinely changed how I think about cybersecurity risk. It was not the most sophisticated operation I have run. It was not the most expensive. It was the one that taught me the most. Here is what it was and what it taught me
-
What I Look For in a Red Team Report
Most red team reports are unreadable. The good ones are gold. Here is what makes the difference, in order, with the parts that most red teamers get wrong
-
Adversary Emulation vs Penetration Testing: Why the Distinction Matters
You paid €80,000 for a \"red team engagement.\" The report arrived with 47 findings, a 12-page executive summary, and a heat map of your network that looked like something out of a disaster movie
-
How to Write a Purple Team Report That Actually Gets Read
You ran a three-week purple team exercise. Your team worked hard. The red team executed a realistic adversary emulation. Your blue team detected some of it, missed most of it, and the gaps are clear. The debrief went…
-
Living Off the Land: Why the Best Attackers Don't Look Like Attackers
Volt Typhoon maintained access to critical infrastructure networks in the United States for at least five years. Microsoft, Mandiant, and the Five Eyes governments published the technical details in 2024. The…
-
How to Scope a Red Team Engagement That Tells You Something Real
Most red team engagements produce an impressive document and a set of \"critical findings\" that the security team could have predicted before the first phishing email was sent