Red Team Handbook
Red Team Handbook
Practical field guides for authorized security assessments. These articles focus on identity infrastructure, endpoint controls, command and control systems, and the operational decisions that keep an engagement safe and useful.
Browse by assessment area
| Area | Guides |
|---|---|
| Identity and Active Directory | Directory discovery, the new Kerberos section, certificate services, trusts, domain-level control paths, and lateral movement paths |
| Windows controls | Application control and AppLocker, credential protection, endpoint telemetry, privilege boundaries, service and task review, persistence locations, driver security, and SQL Server |
| Cobalt Strike and infrastructure | Beacon operations, command and control design, and infrastructure assessment |
| Assessment operations | Initial access validation, lateral access validation, network path and pivot boundaries, malware sample triage, artifact handling, legal and privacy checks, operational security, scenario design, and reporting and cleanup |
Example identities and hosts are relabeled, and public test addresses are reserved documentation ranges. Commands that change systems are marked as change-plan examples and belong in an owner-approved change window. Ticket impersonation, credential extraction, defense evasion, and privileged access demonstrations are outside the public walkthroughs; use configuration evidence, telemetry, and benign validation to document risk.