********** Red team ********** .. contents:: Table of contents Introduction ============= For more information about the purposes of this site view the `about`_ page. This page is meant to provide the neccessary info pertaining to Red Team activities occured in the 7th semester, the minor. For more information relating to the context of why this page exists visit the `personal learning plan`_. .. _about: /about.html .. _personal learning plan: /personal%20learning%20plan.html Learning focuses ================ In order to shape the upcoming curriculum, I've chosen various learning focuses for the blue team side. These are work in progress, and have to be developed out further. ------------- .. sidebar:: Red-teaming .. image:: security.svg Category ^^^^^^^^^ | In the tables below the category tab depicts the nature of the skill concercning the listed task. | The duration is not something I came up with; it is derived from the Personal Learning Plan assignment template. | Additionally to the standard, I've expanded with a custom table with tasks I came up with. - T = Technical skills - N = Non-technical skills - R = Research & development skills - P = Professional skills Learning tasks --------------- +----------------------------------------------------+----------+----------+-------------+--------+ | Task summary | Category | Duration | Requirement | Status | +====================================================+==========+==========+=============+========+ | Follow the workshops related to hacking & red team | T | 0.5day | Should | Done | +----------------------------------------------------+----------+----------+-------------+--------+ | Study pen testing methodologies and practices | T+P | 2days | Must | Done | +----------------------------------------------------+----------+----------+-------------+--------+ | Take part of the Red v. Blue team | T+N | 1days | Must | Done | +----------------------------------------------------+----------+----------+-------------+--------+ | Own one of the Linux based machines on Htb | T+N | 2-3days | Must | Done | +----------------------------------------------------+----------+----------+-------------+--------+ | Own one of the Windows based machines on Htb | T+N | 2-3days | Must | Done | +----------------------------------------------------+----------+----------+-------------+--------+ | Learn how reverse engineering works | T | 2-3days | Should | Open | +----------------------------------------------------+----------+----------+-------------+--------+ | Pick a lock | T | 1day | Should | Done | +----------------------------------------------------+----------+----------+-------------+--------+ | Experiment with phishing tools in a contained lab | T | 1day | Should | Open | +----------------------------------------------------+----------+----------+-------------+--------+ | Visit building with a red team perspective | N | 1day | Should | Cancl. | +----------------------------------------------------+----------+----------+-------------+--------+ | Learn how cryptography works | T | 2-3days | Could | Open | +----------------------------------------------------+----------+----------+-------------+--------+ Research & development tasks ----------------------------- +-----------------------------------------------------+----------+----------+-------------+--------+ | Task summary | Category | Duration | Requirement | Status | +=====================================================+==========+==========+=============+========+ | Visit seminars related to developments in red team | R | 1day | Should | Done | +-----------------------------------------------------+----------+----------+-------------+--------+ | Organize/join a session to analyze new vuln. | T+P | 2days | Must | Cancl. | +-----------------------------------------------------+----------+----------+-------------+--------+ | Set-up environment for pen testing and red teaming. | T | 2days | Must | Done | +-----------------------------------------------------+----------+----------+-------------+--------+ | Develop a dropbox that can be used in red team | R+T | 3days | Should | Open | +-----------------------------------------------------+----------+----------+-------------+--------+ | Research covert channels and set-up one | R+T | 2days | Should | Open | +-----------------------------------------------------+----------+----------+-------------+--------+ | Research typical and known vulnerabilities in cloud | R+T | 2-3days | Should | Done | +-----------------------------------------------------+----------+----------+-------------+--------+ Professional application tasks ------------------------------- +---------------------------------------------------+----------+----------+-------------+--------+ | Task summary | Category | Duration | Requirement | Status | +===================================================+==========+==========+=============+========+ | Acquire Red-team pentest with a PiE and report | P+T+N | 4days | Must | Done | +---------------------------------------------------+----------+----------+-------------+--------+ | Perform a pen-test on a shippable product | P+T+N | 2days | Must | Done | +---------------------------------------------------+----------+----------+-------------+--------+ | Perform a test on a site with responsible discl. | P+T+N | 2days | Must | Done | +---------------------------------------------------+----------+----------+-------------+--------+ | Perform vuln. analysis on IoT & report findings | P+T+N | 3days | Should | Open | +---------------------------------------------------+----------+----------+-------------+--------+ ------------ Learning tasks execution ^^^^^^^^^^^^^^^^^^^^^^^^^ .. toctree:: :maxdepth: 2 learning/redteam/workshopred learning/redteam/studymethods learning/redteam/takepart learning/redteam/ownlinux learning/redteam/ownwindows learning/redteam/learnreverse learning/redteam/lockpick learning/redteam/experimentwithphishing learning/redteam/visitredteam learning/redteam/learncrypto Research & development tasks execution ^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^ .. toctree:: :maxdepth: 2 learning/redteam/visitredseminar learning/redteam/organizevulnsess learning/redteam/setupbox learning/redteam/dropbox learning/redteam/researchcovert learning/redteam/cloudvuln Professional application tasks ^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^ .. toctree:: :maxdepth: 2 learning/redteam/piepentest learning/redteam/shippentest learning/redteam/responsibletest learning/redteam/iotvuln Custom tasks ^^^^^^^^^^^^ .. toctree:: :maxdepth: 2 learning/redteam/ctfintro learning/redteam/avengers learning/redteam/rtdpen