CGISecurity Logo
  • My experience coleading purple team

    I've been fortunate enough to manage a red team program for several years and since it's inception it has gone through many changes. What started out as adhoc engagements trying to see how far we could get/what problems we could find, turned into a mechanism to work more closely, and regularly with operations/it teams. More…

  • Joint blue team and red team exercises

    Having regular (probably monthly for most) red team engagements where the red teamers and incident response/monitoring teams sit in a room while the engagement occurs is a must. Everytime the red teamer executes a command that advances them, blue should be asked: If they detected it If not, could they have detected it? If unsure,…