{"id":19914,"date":"2021-02-03T20:12:21","date_gmt":"2021-02-03T14:42:21","guid":{"rendered":"https:\/\/valeurbit.com\/blog\/?p=19914"},"modified":"2021-02-12T18:03:50","modified_gmt":"2021-02-12T12:33:50","slug":"red-team-teamwork-in-penetration-testing","status":"publish","type":"post","link":"https:\/\/valeurbit.com\/blog\/red-team-teamwork-in-penetration-testing\/","title":{"rendered":"Red Team: Teamwork In Penetration Testing"},"content":{"rendered":"\n<p>This article will review team interaction, tools and methodologies for conducting Red Team operations.&nbsp;The operations of the Red Team allow simulating the attack of a group of professional external intruders in the most naturalistic way to identify infrastructure vulnerabilities.<\/p>\n\n\n\n<h2 class=\"wp-block-heading\">Red Team vs Blue Team<\/h2>\n\n\n\n<p>The term Red Team comes from a military environment and defines a &#8220;friendly&#8221; attacking team.&nbsp;In contrast, there is a team of defenders &#8211; Blue Team.<\/p>\n\n\n\n<p>The difference between Red Team operations and the classic pentest is primarily in the rules of action and anticipation of the protected side.&nbsp;Also, in the &#8220;classic&#8221; penetration test, &#8220;white lists&#8221; are often used, restrictions on the time of work carried out, the level of interaction with the system.&nbsp;When conducting Red Team operations, there are practically no restrictions, a real attack on the infrastructure is carried out: from attacks of the outer perimeter, to attempts at physical access, to &#8220;hard&#8221; socio-technical techniques (not fixing a link, but, for example, a full-fledged reverse shell).<\/p>\n\n\n\n<p>The Blue Team&#8217;s task is to blindly protect the infrastructure: the defense team is not warned about an attack or its differences from real attackers &#8211; this is one of the best factors to test both defense systems and the ability of specialists to identify and block attacks, and subsequently investigate incidents.&nbsp;After the operation is completed, it is necessary to compare the worked out attack vectors with the recorded incidents to improve the infrastructure protection system.<\/p>\n\n\n\n<p>The Red Team approach is closest to a targeted attack &#8211; APT (Advanced Persistent Threat).&nbsp;The Red Team should consist of experienced professionals with extensive experience in both building IT \/ IS infrastructure and experience in compromising systems.<\/p>\n\n\n\n<p>What distinguishes Red Team operations:<\/p>\n\n\n\n<ul><li>Duration.&nbsp;Attacks can be carried out over several months.<\/li><li>Hardcore.&nbsp;Attackers can toughly influence the infrastructure, which can lead to the failure of some of the infrastructure components.<\/li><li>Lack of familiar penetration testing patterns.&nbsp;(Case from practice &#8211; during the bypass of the ACS system at one of the audit objects, the team carried out the removal of office equipment containing critical data outside the company &#8211; of course, in agreement with the work manager).<\/li><\/ul>\n\n\n\n<p>Red Team &#8211; attempts to gain access to the system by any means, including penetration testing;&nbsp;physical access;&nbsp;testing communication lines, wireless and radio frequency systems;&nbsp;testing employees through social engineering scenarios.<\/p>\n\n\n\n<p>The concept of Red Team Operations allows penetration testing work to be carried out as realistically as possible.<\/p>\n\n\n\n<h2 class=\"wp-block-heading\">Team approach<\/h2>\n\n\n\n<p>Red Team is similar to a military operation: targets or objects of attack, areas of responsibility and roles of team members are determined.&nbsp;Often, a Red Team team can be represented by an insider who transfers data from within the company, or performs auxiliary functions.<\/p>\n\n\n\n<p>A clear distribution of roles, systems of operational interaction and data analysis determine several roles of a&nbsp;<s>sniper, a medic<\/s>&nbsp;:<\/p>\n\n\n\n<ul><li>team leader &#8211; leadership;<\/li><li>operatives &#8211; active phase of the attack;<\/li><li>insiders &#8211; this role may not be present;<\/li><li>analysts &#8211; analysis and normalization of the received data.<\/li><\/ul>\n\n\n\n<h2 class=\"wp-block-heading\">Tools<\/h2>\n\n\n\n<p>The use of a particular toolkit in a particular case may be due to the specifics of a particular application or service and differs little from conventional penetration testing.&nbsp;When conducting Red Team operations, the question of team interaction and systematization of the results arises &#8211; these are reports of various analysis tools and vulnerabilities identified in manual mode &#8211; all this represents a huge amount of information in which something can be missed without proper order and a systematic approach important or &#8220;rake&#8221; possible duplicates.&nbsp;There is also a need to reduce reports and their normalization and reduction to a single form.<\/p>\n\n\n\n<p>Typically, Red Team operations cover rather large infrastructures that require the use of specialized tools:<\/p>\n\n\n\n<ul><li>Scanners and utilities for perimeter inventory, with the ability to separate work areas and aggregate results.<\/li><li>Data processing systems for penetration testing.<\/li><li>Using tools for analyzing and managing vulnerabilities.<\/li><li>Systems for conducting socio-technical campaigns.<\/li><\/ul>\n\n\n\n<h3 class=\"wp-block-heading\">Specialized software:<\/h3>\n\n\n\n<p><strong>Attention<\/strong><br><strong>Cobalt Strike<\/strong><br>Cobalt Strike is a penetration testing framework.&nbsp;This is an advanced analogue of Armitage, which in turn is a GUI add-on over the Metasploit Framework.&nbsp;An advanced embedded scripting language system allows for the most effective attacks.<\/p>\n\n\n\n<p><strong>Dradis<\/strong><br>The Dradis Framework is an open source platform for simplifying information security collaboration and reporting.&nbsp;Dradis is a standalone web application that centralizes information storage.&nbsp;There are two versions &#8211; Community Edition (free) and Professional Edition (from $ 59).&nbsp;The pro version has more functionality, including integration capabilities, reporting system, support (including priority support), available methodologies, etc.&nbsp;Expansion of functionality in the form of plugins \/ addons is possible.<\/p>\n\n\n\n<p><strong>Faraday IDE<\/strong><br>Faraday is the most powerful collaboration environment, true multiplayer penetration testing.&nbsp;Supports work in ArchAssault, Archlinux, Debian, Kali, OSX, Debian.&nbsp;Works in real time, instantly processing the results sent by one or another pentester.&nbsp;This framework is based on the concept of gamification, and specialists are given the opportunity to measure their skills in terms of the number and quality of fixed vulnerabilities.<\/p>\n\n\n\n<p><strong>Nessus<\/strong><br>One of the most popular vulnerability scanners developed by Tenable Network Security.&nbsp;Until 2005 it was free and open source software, and in 2008 a paid version of the product was released.<\/p>\n\n\n\n<p><strong>OpenVAS<\/strong><br>OpenVAS (Open Vulnerability Assessment System, the original name of GNessUs) is a framework consisting of several services and utilities that allows scanning hosts for vulnerabilities and managing vulnerabilities.<\/p>\n\n\n\n<p><strong>SE Toolkit<\/strong><br>Social Engineering Toolkit (set for social engineering), a classic multi-tool for conducting social engineering attacks.<\/p>\n\n\n\n<p><strong>GoPhish<\/strong><br>OpenSource phishing framework.&nbsp;Allows you to carry out massive phishing attacks.<\/p>\n\n\n\n<p><strong>Logstash \/ Elasticsearch \/ Kibana<\/strong><br>Solutions for a wide range of tasks for collecting, analyzing and storing data.<\/p>\n\n\n\n<hr class=\"wp-block-separator\"\/>\n\n\n\n<p>In the comments, I am ready to answer your questions, both on the software presented and on the Red Team operations.<\/p>\n","protected":false},"excerpt":{"rendered":"<p>This article will review team interaction, tools and methodologies for conducting Red Team operations.&nbsp;The operations of the Red Team allow simulating the attack of a group of professional external intruders in the most naturalistic way to identify infrastructure vulnerabilities. Red Team vs Blue Team The term Red Team comes from a military environment and defines&#8230;<\/p>\n","protected":false},"author":1,"featured_media":0,"comment_status":"closed","ping_status":"open","sticky":false,"template":"","format":"standard","meta":{"footnotes":""},"categories":[1],"tags":[],"yoast_head":"<!-- This site is optimized with the Yoast SEO plugin v16.5 - https:\/\/yoast.com\/wordpress\/plugins\/seo\/ -->\n<title>Red Team: Teamwork In Penetration Testing | ValeurBit Infosec<\/title>\n<meta name=\"robots\" content=\"index, follow, max-snippet:-1, max-image-preview:large, max-video-preview:-1\" \/>\n<link rel=\"canonical\" href=\"https:\/\/valeurbit.com\/blog\/red-team-teamwork-in-penetration-testing\/\" \/>\n<meta property=\"og:locale\" content=\"en_US\" \/>\n<meta property=\"og:type\" content=\"article\" \/>\n<meta property=\"og:title\" content=\"Red Team: Teamwork In Penetration Testing | ValeurBit Infosec\" \/>\n<meta property=\"og:description\" content=\"This article will review team interaction, tools and methodologies for conducting Red Team operations.&nbsp;The operations of the Red Team allow simulating the attack of a group of professional external intruders in the most naturalistic way to identify infrastructure vulnerabilities. Red Team vs Blue Team The term Red Team comes from a military environment and defines...\" \/>\n<meta property=\"og:url\" content=\"https:\/\/valeurbit.com\/blog\/red-team-teamwork-in-penetration-testing\/\" \/>\n<meta property=\"og:site_name\" content=\"ValeurBit Infosec\" \/>\n<meta property=\"article:publisher\" content=\"https:\/\/www.facebook.com\/valeurbitinfo\/\" \/>\n<meta property=\"article:published_time\" content=\"2021-02-03T14:42:21+00:00\" \/>\n<meta property=\"article:modified_time\" content=\"2021-02-12T12:33:50+00:00\" \/>\n<meta name=\"twitter:card\" content=\"summary_large_image\" \/>\n<meta name=\"twitter:creator\" content=\"@valeurbit\" \/>\n<meta name=\"twitter:site\" content=\"@valeurbit\" \/>\n<meta name=\"twitter:label1\" content=\"Est. reading time\" \/>\n\t<meta name=\"twitter:data1\" content=\"5 minutes\" \/>\n<script type=\"application\/ld+json\" class=\"yoast-schema-graph\">{\"@context\":\"https:\/\/schema.org\",\"@graph\":[{\"@type\":\"Organization\",\"@id\":\"https:\/\/valeurbit.com\/blog\/#organization\",\"name\":\"Valeurbit Infosec\",\"url\":\"https:\/\/valeurbit.com\/blog\/\",\"sameAs\":[\"https:\/\/www.facebook.com\/valeurbitinfo\/\",\"https:\/\/www.instagram.com\/valeurbit\",\"https:\/\/www.linkedin.com\/company\/valeurbit-infosec\/\",\"https:\/\/twitter.com\/valeurbit\"],\"logo\":{\"@type\":\"ImageObject\",\"@id\":\"https:\/\/valeurbit.com\/blog\/#logo\",\"inLanguage\":\"en-US\",\"url\":\"https:\/\/valeurbit.com\/blog\/wp-content\/uploads\/2021\/02\/Valeurbit-new-logo-center.png\",\"contentUrl\":\"https:\/\/valeurbit.com\/blog\/wp-content\/uploads\/2021\/02\/Valeurbit-new-logo-center.png\",\"width\":1080,\"height\":512,\"caption\":\"Valeurbit Infosec\"},\"image\":{\"@id\":\"https:\/\/valeurbit.com\/blog\/#logo\"}},{\"@type\":\"WebSite\",\"@id\":\"https:\/\/valeurbit.com\/blog\/#website\",\"url\":\"https:\/\/valeurbit.com\/blog\/\",\"name\":\"ValeurBit Infosec\",\"description\":\"Cyber Security Company\",\"publisher\":{\"@id\":\"https:\/\/valeurbit.com\/blog\/#organization\"},\"potentialAction\":[{\"@type\":\"SearchAction\",\"target\":\"https:\/\/valeurbit.com\/blog\/?s={search_term_string}\",\"query-input\":\"required name=search_term_string\"}],\"inLanguage\":\"en-US\"},{\"@type\":\"WebPage\",\"@id\":\"https:\/\/valeurbit.com\/blog\/red-team-teamwork-in-penetration-testing\/#webpage\",\"url\":\"https:\/\/valeurbit.com\/blog\/red-team-teamwork-in-penetration-testing\/\",\"name\":\"Red Team: Teamwork In Penetration Testing | ValeurBit Infosec\",\"isPartOf\":{\"@id\":\"https:\/\/valeurbit.com\/blog\/#website\"},\"datePublished\":\"2021-02-03T14:42:21+00:00\",\"dateModified\":\"2021-02-12T12:33:50+00:00\",\"breadcrumb\":{\"@id\":\"https:\/\/valeurbit.com\/blog\/red-team-teamwork-in-penetration-testing\/#breadcrumb\"},\"inLanguage\":\"en-US\",\"potentialAction\":[{\"@type\":\"ReadAction\",\"target\":[\"https:\/\/valeurbit.com\/blog\/red-team-teamwork-in-penetration-testing\/\"]}]},{\"@type\":\"BreadcrumbList\",\"@id\":\"https:\/\/valeurbit.com\/blog\/red-team-teamwork-in-penetration-testing\/#breadcrumb\",\"itemListElement\":[{\"@type\":\"ListItem\",\"position\":1,\"name\":\"Home\",\"item\":\"https:\/\/valeurbit.com\/blog\/\"},{\"@type\":\"ListItem\",\"position\":2,\"name\":\"Red Team: Teamwork In Penetration Testing\"}]},{\"@type\":\"Article\",\"@id\":\"https:\/\/valeurbit.com\/blog\/red-team-teamwork-in-penetration-testing\/#article\",\"isPartOf\":{\"@id\":\"https:\/\/valeurbit.com\/blog\/red-team-teamwork-in-penetration-testing\/#webpage\"},\"author\":{\"@id\":\"https:\/\/valeurbit.com\/blog\/#\/schema\/person\/df20c1cd317765fa8677a3056caeccfa\"},\"headline\":\"Red Team: Teamwork In Penetration Testing\",\"datePublished\":\"2021-02-03T14:42:21+00:00\",\"dateModified\":\"2021-02-12T12:33:50+00:00\",\"mainEntityOfPage\":{\"@id\":\"https:\/\/valeurbit.com\/blog\/red-team-teamwork-in-penetration-testing\/#webpage\"},\"wordCount\":982,\"publisher\":{\"@id\":\"https:\/\/valeurbit.com\/blog\/#organization\"},\"articleSection\":[\"Valeurbit\"],\"inLanguage\":\"en-US\"},{\"@type\":\"Person\",\"@id\":\"https:\/\/valeurbit.com\/blog\/#\/schema\/person\/df20c1cd317765fa8677a3056caeccfa\",\"name\":\"ValeurBit\",\"sameAs\":[\"https:\/\/valeurbit.com\/blog\"],\"url\":\"https:\/\/valeurbit.com\/blog\/author\/valeurbit\/\"}]}<\/script>\n<!-- \/ Yoast SEO plugin. -->","_links":{"self":[{"href":"https:\/\/valeurbit.com\/blog\/wp-json\/wp\/v2\/posts\/19914"}],"collection":[{"href":"https:\/\/valeurbit.com\/blog\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/valeurbit.com\/blog\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/valeurbit.com\/blog\/wp-json\/wp\/v2\/users\/1"}],"replies":[{"embeddable":true,"href":"https:\/\/valeurbit.com\/blog\/wp-json\/wp\/v2\/comments?post=19914"}],"version-history":[{"count":0,"href":"https:\/\/valeurbit.com\/blog\/wp-json\/wp\/v2\/posts\/19914\/revisions"}],"wp:attachment":[{"href":"https:\/\/valeurbit.com\/blog\/wp-json\/wp\/v2\/media?parent=19914"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/valeurbit.com\/blog\/wp-json\/wp\/v2\/categories?post=19914"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/valeurbit.com\/blog\/wp-json\/wp\/v2\/tags?post=19914"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}