Skip to content
Red Team Handbook

Red Team Handbook

Practical field guides for authorized security assessments. These articles focus on identity infrastructure, endpoint controls, command and control systems, and the operational decisions that keep an engagement safe and useful.

Browse by assessment area

AreaGuides
Identity and Active DirectoryDirectory discovery, the new Kerberos section, certificate services, trusts, domain-level control paths, and lateral movement paths
Windows controlsApplication control and AppLocker, credential protection, endpoint telemetry, privilege boundaries, service and task review, persistence locations, driver security, and SQL Server
Cobalt Strike and infrastructureBeacon operations, command and control design, and infrastructure assessment
Assessment operationsInitial access validation, lateral access validation, network path and pivot boundaries, malware sample triage, artifact handling, legal and privacy checks, operational security, scenario design, and reporting and cleanup

Example identities and hosts are relabeled, and public test addresses are reserved documentation ranges. Commands that change systems are marked as change-plan examples and belong in an owner-approved change window. Ticket impersonation, credential extraction, defense evasion, and privileged access demonstrations are outside the public walkthroughs; use configuration evidence, telemetry, and benign validation to document risk.