Posts

Recon _Alias Information Gathering

From previous posts hope you readers have got some idea about redteaming and its stages now its time to jump over some technical aspects of Redteaming. If u want to murder someone or propose someone you would be knowing about the target right , In simple manners recon is all about information collection. Although various blogs about OSINT were available ,I ll try to simplify as much as important points which needs to be considered while using recon OK Cool What is OSINT : Open-source intelligence (OSINT) ​ ​ is using ​ publicly available ​ sources to collect information (i.e., intelligence) about persons or entities from a wide array of sources including the Internet. OSINT is usually performed during the Reconnaissance phase of hacking, and information collected from this phase is carried over into the Network Enumeration phase. Due to the broad amount of information available on the web, attackers must have a clear and defined search framework ​ ,as well as a wide arr...

Red Teaming types : An introduction

In general Red Teams are used in two ways ●      External independent testing i.e from external point of view third party team will test it up ●      Internal in-house team Let us first look at how external Red Teaming may function External independent pen testing teams can be engaged in different capacities depending on a clients requirements, these can include but are not limited to: ●      Physical ○      Testing physical access to buildings, this includes to staff areas, infrastructure eg. cafeterias,parking lots etc ○      Social Engineering/impersonation/phishing ○      Lockpicking yes ○      Security control evasion ●      Social Engineering ○      Phishing attacks ○      Impersonation ○      Tailgating ...