Chapter 1
- There are a wide range of objectives and goals for establishing a red team program. The following are some common ones:
1. Improve the performance of the blue team to successfully detect and recover from a breach.
2. Identify security and organizational deficiencies across the organization.
3. Improve security awareness and its culture across the organization.
4. Practice the remediation and eviction capabilities of the organization by emulating a real system compromise.
5. Help to further improve the understanding of offensive security across the organization and industry.
- An internal red team program can provide a variety of services to the organization, including, but not limited to, the following:
1. Perform penetration testing and traditional application-level security assessments.
2. Perform source code audits and code reviews.
3. Perform offensive security operations, including end-to-end breach emulations.
4. Develop a security training program and educating engineers...