~ / methodology / red-team-operations

Red Team Operations

Full-scope adversary emulation — tradecraft, infrastructure, and evasion.

Full-scope, goal-based operations that emulate a real threat actor while staying safe and in scope. Each area below is its own deep dive.

Initial Access & Phishing

  • Pretext design and payload delivery
  • Malicious document / loader tradecraft
  • Landing pages and credential capture

Redirectors & C2 Infrastructure

  • Redirector chains and domain fronting
  • C2 profile hardening and traffic shaping
  • OPSEC for infrastructure separation

AV Bypass

  • Understanding signature vs heuristic detection
  • Payload obfuscation and packing
  • Testing against representative engines

EDR Bypass

  • Telemetry sources: hooks, ETW, kernel callbacks
  • Unhooking, indirect syscalls, and BYOVD concepts
  • Behavioural evasion vs static evasion

Lateral Movement & Persistence

  • Living-off-the-land techniques
  • Credential material and ticket abuse
  • Persistence with clean removal

Exfiltration & Impact

  • Staged, throttled exfiltration
  • Objective demonstration without real harm
  • Reporting mapped to detection gaps