<?xml version="1.0" encoding="UTF-8"?><rss version="2.0"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:wfw="http://wellformedweb.org/CommentAPI/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	xmlns:atom="http://www.w3.org/2005/Atom"
	xmlns:sy="http://purl.org/rss/1.0/modules/syndication/"
	xmlns:slash="http://purl.org/rss/1.0/modules/slash/"
	>

<channel>
	<title>red team Archivy - Rolken</title>
	<atom:link href="https://rolken.cz/tag/red-team/feed/" rel="self" type="application/rss+xml" />
	<link>https://rolken.cz/tag/red-team/</link>
	<description>Cybersecurity company</description>
	<lastBuildDate>Wed, 31 Jul 2019 13:16:07 +0000</lastBuildDate>
	<language>en-US</language>
	<sy:updatePeriod>
	hourly	</sy:updatePeriod>
	<sy:updateFrequency>
	1	</sy:updateFrequency>
	<generator>https://wordpress.org/?v=6.9.4</generator>

<image>
	<url>https://rolken.cz/wp-content/uploads/2018/04/cropped-logo-3-1-32x32.png</url>
	<title>red team Archivy - Rolken</title>
	<link>https://rolken.cz/tag/red-team/</link>
	<width>32</width>
	<height>32</height>
</image> 
	<item>
		<title>Red team explained</title>
		<link>https://rolken.cz/red-team-explained/</link>
		
		<dc:creator><![CDATA[root]]></dc:creator>
		<pubDate>Thu, 23 May 2019 07:40:10 +0000</pubDate>
				<category><![CDATA[Red team]]></category>
		<category><![CDATA[red team]]></category>
		<guid isPermaLink="false">https://rolken.cz/?p=2697</guid>

					<description><![CDATA[<p>It became trend last two years to ask for&#160;red team assessment instead of security assessment, pentests or application tests. Somehow a red team became a fancy word for an&#160;external penetration test with&#160;social engineering on selected targets. We, in Rolken, are firm believers that security works and it&#8217;s easy but not simple. Since there are no<a href="https://rolken.cz/red-team-explained/">[...]</a></p>
<p>The post <a href="https://rolken.cz/red-team-explained/">Red team explained</a> appeared first on <a href="https://rolken.cz">Rolken</a>.</p>
]]></description>
										<content:encoded><![CDATA[<p>It became trend last two years to ask for&nbsp;<a href="https://rolken.cz/en/how-can-we-help/red-team/">red team assessment</a> instead of security assessment, pentests or <a href="https://rolken.cz/en/how-can-we-help/application-security/">application tests</a>. Somehow a red team became a fancy word for an<a href="https://rolken.cz/en/how-can-we-help/penetration-tests/">&nbsp;external penetration test</a> with&nbsp;<a href="https://rolken.cz/en/how-can-we-help/social-engineering/">social engineering</a> on selected targets. We, in Rolken, are firm believers that security works and it&#8217;s easy but not simple. Since there are no holy-cow-silver-bullet-solutions red teaming is not an example.&nbsp;</p>
<p>There are multiple reasons why you want to use red teaming but let&#8217;s curb the first enthusiasm and set a little bit of&nbsp;the expectations:</p>
<ul class="block-editor-rich-text__editable editor-rich-text__editable" role="textbox" contenteditable="true" aria-multiline="true" data-is-placeholder-visible="false" aria-label="Write list…" aria-autocomplete="list">
<li>there is <strong>no magic going to happen</strong> &#8211; a blue team and a red team have still to work security out and it is going to take time;</li>
<li>everyone is unique and it <strong>is</strong> <strong>not sufficient reason</strong> to do red teaming <strong>just</strong> <strong>because everyone is doing it</strong>;</li>
<li><strong>the bad red team is worse than no red team</strong> &#8211; starting with red teaming is more about culture than results. The bad red team is going to move your culture at least one year back.</li>
</ul>


<h3 class="wp-block-heading">When to use red team</h3>



<p>When you have basics done. These basics are: you have staff, you are able to monitor at least the network level, and you think you can respond to incidents. This carry you did at least these things:</p>



<ol class="wp-block-list"><li>an <a href="https://rolken.cz/how-can-we-help/asset-management/">asset inventory</a> and you understand your landscape (where are devices, which firmware your switches have, how many access points you are operating, how many unsupported windows XP you have etc.);</li><li>centralized logs and network monitoring;</li><li>you did basic hygiene &#8211; regular <a href="https://rolken.cz/how-can-we-help/vulnerability-assessment/">vulnerability scanning</a> and <a href="https://rolken.cz/how-can-we-help/penetration-tests/">penetration tests</a>;</li><li>and fixed pentests and vulnerability scans outcomes and documented what could not be fixed. And you are monitoring the weak points which can&#8217;t be fixed.</li></ol>



<p>You don&#8217;t need to have fancy tools like an anomaly monitoring, SIEM, security automation etc. In our experience, the motivated team of juniors with open source tools would give us way harder time than just one person with many fancy tools.</p>



<h3 class="wp-block-heading">How to use red team</h3>



<p>There is <strong>the sole purpose of a red team &#8211; to improve a blue team</strong>. It is like vaccination &#8211; if you want your immune cells able to react properly to a real adversary, you need to expose them to one in a controlled environment. Also, practice makes perfect and worst time to practice is during the <g class="gr_ gr_8 gr-alert gr_gramm gr_inline_cards gr_disable_anim_appear Grammar only-ins replaceWithoutSep" id="8" data-gr-id="8">real</g> crisis.</p>



<p>There is another important thing to consider and it is continuity. You want <strong>continual improvement of a blue team</strong> and to achieve the <g class="gr_ gr_5 gr-alert gr_gramm gr_inline_cards gr_disable_anim_appear Grammar only-ins replaceWithoutSep" id="5" data-gr-id="5">continual</g> improvement you need to <strong>do regular exercises</strong>.</p>



<blockquote class="wp-block-quote is-layout-flow wp-block-quote-is-layout-flow"><p><strong>Pro-tip:<br></strong> This is how you can differentiate between <g class="gr_ gr_225 gr-alert gr_gramm gr_inline_cards gr_disable_anim_appear Grammar only-ins replaceWithoutSep" id="225" data-gr-id="225">bad</g> and good red team. For bad one an objective is to hack you all the ways up and down. Good one focuses on the tested part and on skills transfer. During retrospectives, we often find the distribution of time is 40% testing, 20% recommendations, 40% skills transfer to the blue team.</p></blockquote>



<h3 class="wp-block-heading">What does it mean to win?</h3>



<p>Our approach is &#8220;if we win, we lose&#8221;. A side note: we almost always win. The good thing is we tend to win using a different approach compared to the last engagement. Our payloads from last time did not work? Very well! Physical security caught us? Good. Immediate detection of scanning? We are very happy.</p>



<p>If our tricks from the last exercise did not work it means we did our job well and a blue team have improved. Bonus for us: we have to improve too and make another clever way to overcome a blue team countermeasure.</p>



<p>Simply put, we are iterating together to moment when we have to say, sorry there is no way how we can attack you.</p>



<h3 class="wp-block-heading">In-house vs external?</h3>



<p>Let&#8217;s speak a little bit about quality. In red teaming there is a <g class="gr_ gr_6 gr-alert gr_gramm gr_inline_cards gr_disable_anim_appear Grammar only-ins replaceWithoutSep" id="6" data-gr-id="6">correlation</g> between quantity and quality in term <strong>there is no single person red team</strong> (that is why is it called team). Red team by definition is a team consisting <g class="gr_ gr_7 gr-alert gr_gramm gr_inline_cards gr_disable_anim_appear Grammar multiReplace" id="7" data-gr-id="7">from</g> people with various skills. From <a href="https://rolken.cz/how-can-we-help/application-security/">security assessment</a> via development, <a href="https://rolken.cz/how-can-we-help/social-engineering/">social engineering</a>, physical security to business analysis.</p>



<p>This means if you do not have a budget for at least 3-4 persons there is almost no point in making an internal one. Your blue team will benefit more from less interaction with a <g class="gr_ gr_5 gr-alert gr_gramm gr_inline_cards gr_disable_anim_appear Grammar only-ins replaceWithoutSep" id="5" data-gr-id="5">good</g> external party than from more interactions with a less skilled internal team.</p>



<p>It does not mean you should not have someone responsible for interaction with a red team and organisation of red teaming activities. But it could be a manager of a blue team &#8211; in the end, it is this role which strives excellence of his team. In our experience, we delivered the best results when on the other side was a technically competent project manager. Often it is pentester or security analyst with people and project management skills.</p>



<p>Decided to go for the internal one? Try to understand who you are hiring and what they are going to do. You can start by reading <a href="https://www.amazon.com/Rtfm-Red-Team-Field-Manual/dp/1494295504/ref=sr_1_1?keywords=red+team&amp;qid=1558597020&amp;s=gateway&amp;sr=8-1">Red Team Field Manual</a> and <a href="https://www.amazon.com/Blue-Team-Field-Manual-BTFM/dp/154101636X/ref=sr_1_5?keywords=red+team&amp;qid=1558597020&amp;s=gateway&amp;sr=8-5">Blue Team Field Manual</a> because <g class="gr_ gr_5 gr-alert gr_spell gr_inline_cards gr_disable_anim_appear ContextualSpelling ins-del multiReplace" id="5" data-gr-id="5">you&#8217;v</g> got to have defenders first.</p>



<h2 class="wp-block-heading">TL; DR</h2>



<p>Red teaming is <strong>less product or service and more cultural change</strong>. To embrace this cultural change you&#8217;ve got to know when and how to do it and understand nuances and motivations (what you want to achieve and what is on the market).</p>



<p>To succeed and implement red teaming into your organisation fix basics at first (<a href="https://rolken.cz/how-can-we-help/asset-management/">assets</a>, <a href="https://rolken.cz/how-can-we-help/vulnerability-assessment/">vulnerabilities</a>, <a href="https://rolken.cz/how-can-we-help/penetration-tests/"><g class="gr_ gr_4 gr-alert gr_spell gr_inline_cards gr_disable_anim_appear ContextualSpelling" id="4" data-gr-id="4">pentests</g></a> and countermeasures), communicate with a blue team and let them know you want to transfer skills from red to blue not test and catch them with pants down. Decide on the best approach &#8211; whether you have enough resources to build internal one or you are going for the external route.</p>
<p>The post <a href="https://rolken.cz/red-team-explained/">Red team explained</a> appeared first on <a href="https://rolken.cz">Rolken</a>.</p>
]]></content:encoded>
					
		
		
			</item>
		<item>
		<title>Why is a Red team usually more successful than a Blue team?</title>
		<link>https://rolken.cz/why-is-red-team-typically-more-sucessfull-then-blue-team/</link>
		
		<dc:creator><![CDATA[root]]></dc:creator>
		<pubDate>Tue, 26 Mar 2019 10:40:21 +0000</pubDate>
				<category><![CDATA[Red team]]></category>
		<category><![CDATA[asset management]]></category>
		<category><![CDATA[blue team]]></category>
		<category><![CDATA[incident response]]></category>
		<category><![CDATA[red team]]></category>
		<guid isPermaLink="false">https://rolken.cz/?p=2486</guid>

					<description><![CDATA[<p>Over the last ten years we performed more than one hundred red team assessments and only in three cases we failed to completely obtain protected assets, information or data. In general, as the red team, we are almost always on the winning side. But why? Are we so much smarter than the blue team? Or<a href="https://rolken.cz/why-is-red-team-typically-more-sucessfull-then-blue-team/">[...]</a></p>
<p>The post <a href="https://rolken.cz/why-is-red-team-typically-more-sucessfull-then-blue-team/">Why is a Red team usually more successful than a Blue team?</a> appeared first on <a href="https://rolken.cz">Rolken</a>.</p>
]]></description>
										<content:encoded><![CDATA[
<p>Over the last ten years we performed more than one hundred red team assessments and only in three cases we failed to completely obtain <a href="https://rolken.cz/how-can-we-help/asset-management/">protected assets</a>, information or data.</p>



<p>In general, as the red team, we are almost always on the winning side. But why? Are we so much smarter than the blue team? Or is it because to defend is harder than to attack?</p>



<p>To answer the question, why is the red team significantly more successful, we performed a short analysis of the asses<g class="gr_ gr_4 gr-alert gr_spell gr_inline_cards gr_disable_anim_appear ContextualSpelling ins-del multiReplace gr-progress sel" id="4" data-gr-id="4">s</g>ments aimed at assessing the difficulty of obtaining protected data. Based on the analysis, we present&nbsp;<strong>three basic, continual activities of the blue team&nbsp;</strong>that significantly reduces the red team&#8217;s success.</p>



<h3 class="wp-block-heading"><strong>Time for “spring clean-up” or do you know your assets? Red team does!</strong></h3>



<p>Even thought you would like to, it’s not necessary to immediately throw away all old apps and systems on long time forgotten servers. But, do a “clean-up” in your assets inventory.  We know, setting up new <a href="https://rolken.cz/how-can-we-help/vulnerability-assessment/">vulnerability scans</a> and finding new air gap vectors is more fun. However, this attack vector is complicated.  In a real world, we are going to find an old <a href="https://rolken.cz/how-can-we-help/application-security/">web application</a> purchased by the marketing department for a campaign finished three years ago and exploit it. It is always “the low hanging fruit” first. Remember we are doing for your improvement not a conference show case.</p>



<p><a href="https://rolken.cz/how-can-we-help/asset-management/">Asset inventory</a> is the most important basic line of defence. You need to know about every item you are protecting. Therefore, we recommend to set a basic, the most important target for the Blue team, <strong>to update the <a href="https://rolken.cz/how-can-we-help/asset-management/">asset inventory</a> every week</strong>. That is all. If your are doing this continuously, the attacker will not have an easy work, because with this measure you will eliminate &#8220;the lowest hanging fruit&#8221;.</p>



<h3 class="wp-block-heading"><strong>Curiosity is good or learn to detect the anomalies!</strong></h3>



<p>What is your detection capability? Yeah, we know, you probably have IDS and IPS, firewalls, correlation engine and all those cool stuff. But do you know how usually we got backconnect from the cracked machine? Meterpreter TCP. A bit more challenging is using OpenVPN on port 443 / TCP. Sometimes it is necessary to use a <g data-gr-id="11" id="11" class="gr_ gr_11 gr-alert gr_gramm gr_disable_anim_appear Grammar only-ins replaceWithoutSep">more</g> complicated approach, let&#8217;s say like Raspberry <g data-gr-id="9" id="9" class="gr_ gr_9 gr-alert gr_spell gr_disable_anim_appear ContextualSpelling ins-del">PI</g> with LTE modem. And occasionally we use sat link (OK, full disclosure here we wanted to try it, it&#8217;s was not really needed).</p>



<p>If you have properly set up an <a href="https://rolken.cz/how-can-we-help/asset-management/">asset management</a> and detection capability, you should uncover our activities immediately (because we had to put something into your network) &#8211; so no big deal.</p>



<p>To be able to detect anomalies, we recommend to set a simple target &#8211; <strong>always know everything about <a href="https://rolken.cz/how-can-we-help/incident-management/">egress traffic</a></strong>. Egress is more important than ingress because you can detect a successful attack <g class="gr_ gr_4 gr-alert gr_spell gr_inline_cards gr_disable_anim_appear ContextualSpelling ins-del" id="4" data-gr-id="4">in</g> the egress traffic.</p>



<h3 class="wp-block-heading"><strong>Practice makes perfect or train for incident response</strong></h3>



<p>When I had a role in the purple team, I had many interviews with blue and red team members. Funny thing, how much the red team and the blue team do not know each other. The blue team expects super-elite hackers who will use the never-seen techniques and tools. The red team expects that the blue team is able to detect an <g class="gr_ gr_9 gr-alert gr_gramm gr_inline_cards gr_disable_anim_appear Grammar only-ins doubleReplace replaceWithoutSep" id="9" data-gr-id="9">attack</g> in the style of &#8220;<a href="https://www.youtube.com/watch?v=PJqbivkm0Ms">Minority Report&#8221;</a>. None of these is true.</p>



<p>Practice makes perfect. Therefore, <strong>you should do periodic<a href="https://rolken.cz/how-can-we-help/incident-management/"> incident response </a>exercises</strong>. Do you know how much harder it would be for an attacker if your operator would be work with an analyst and upon detection there would be a clear list of actions and countermeasures?</p>



<p>In conclusion, I would like to share with you this tip from Twitter account  <a href="https://twitter.com/picardtips">Picard&#8217;s management tips (by the way, a great Twitter account, try it)</a>:<br></p>



<div class="wp-block-image"><figure class="aligncenter"><img fetchpriority="high" decoding="async" width="638" height="232" src="https://rolken.cz/wp-content/uploads/Screenshot-2019-03-26-at-11.16.05.png" alt="If you know how to manage incident red team is going to have hard time." class="wp-image-2488" srcset="https://rolken.cz/wp-content/uploads/Screenshot-2019-03-26-at-11.16.05.png 638w, https://rolken.cz/wp-content/uploads/Screenshot-2019-03-26-at-11.16.05-300x109.png 300w" sizes="(max-width: 638px) 100vw, 638px" /><figcaption>Run crisis drills when all is well. A real calamity is not a good time for training. </figcaption></figure></div>



<p>What do you think? <strong>We agree with Mr. Picard!</strong></p>
<p>The post <a href="https://rolken.cz/why-is-red-team-typically-more-sucessfull-then-blue-team/">Why is a Red team usually more successful than a Blue team?</a> appeared first on <a href="https://rolken.cz">Rolken</a>.</p>
]]></content:encoded>
					
		
		
			</item>
	</channel>
</rss>
