This Memorial Day, please take a minute and stand in silence. Remember those that payed the ultimate price so we can live a good life.

Let's all stop what we do at 11 AM. Stand still for 1 minute. Say thank you to all the men and women that gave it all.


"The defender’s metrics signify the defender’s focus, a feature the savvy red team will seek to exploit to the education and benefit of the defender (who may in turn seek to exploit this dynamic)."

-- Red Team Journal: The Red Teamer’s Go-To Move #4: Understand and Exploit Metrics

Note: this is a must read article. Like always, our friends at rhe Red Team Journal have the best insights into the world of red teaming.

2015’s Red Team Tradecraft | Raphael Mudge

"There is a theory which states that if ever anyone discovers exactly what the Universe is for and why it is here, it will instantly disappear and be replaced by something even more bizarre and inexplicable. There is another theory which states that this has already happened.”

― Douglas Adams, The Restaurant at the End of the Universe

Raphael starts his post with this quote by Douglas Adams. I think he managed to capture with the quote the challenge you face as a Red Teamer.

Go read the post. There are some good tips splinkled in there.

Understanding the Positive Outcomes of Red Teaming | RSA Blog

The advantages of employing a red team are several, but generally the most important one is providing a shift in perspective. Too often, whether it is when putting together a new budget, selecting a software application, building out a data center, or making a multitude of other decisions, we tend to fall into ingrained ways of thinking and deciding. This is especially true in organizations, where we can fall into that organizational mindset or are highly dependent upon standard operating procedures. A good red team can step outside that mindset and bring a different perspective to a plan, system, or security process that can often get overlooked.

A simple article that describes what a red team is. Easy read.


"An amazing thing, the human brain. Capable of understanding incredibly complex and intricate concepts. Yet at times unable to recognize the obvious and simple."




The Red Teamer’s Top Ten Books | OODA Loop

If might expect a red teamer’s top ten list of books to feature volumes on coding, hacking, and pentesting, you’re going to be surprised. In my view, the overarching principles of red teaming exist independent of any specific domain of application. Hence, my theme here is timeless patterns of cross-domain thinking, very much in line with the Red Team Journal Red Teaming Law #32 (“The Target”): “No matter what the nature of the game, the red team’s ultimate target should always be the opponent’s mind. Everything else is just technique.”

A great article (and a great list) at OODA Loop written by Mark Mateski.


"All advantage goes to the offense in cyber. It just does. On the defensive side, you have to say 'I must defend all 100,000 machines, all 50,000 employees.' The offensive side thinks, 'I only need to break into one and I'm on the inside.'"

--Kevin Mandia

This is one of the key reason for Red Teaming. Act, don't react.