Red Teaming types : An introduction


In general Red Teams are used in two ways


●     External independent testing i.e from external point of view third party team will test it up

●     Internal in-house team

Let us first look at how external Red Teaming may function


External independent pen testing teams can be engaged in different capacities depending on a clients requirements, these can include but are not limited to:

●     Physical

○     Testing physical access to buildings, this includes to staff areas, infrastructure eg. cafeterias,parking lots etc
○     Social Engineering/impersonation/phishing

○     Lockpicking yes

○     Security control evasion

●     Social Engineering

○     Phishing attacks

○     Impersonation

○     Tailgating

○     Drop Attack

●     Network Infrastructure

○     Firewall bypass

○     Router testing/configuration

○     DNS footprinting

○     Proxy Servers

○     Vulnerability exploits

○     Configuration

●     Web application compromise and exploitation – physical and Cloud

●     Wireless

○     Configuration

○     Unauthorised access points

○     Default passwords

○     Encryption protocols

●     Application testing – databases, - physical and Cloud
●     Operating system build standards


○     Server

○     Desktop

○     Mobile

●     IOT





 


Comments