4 ms·
>yeah, but crowdstike or whatever antivirus you use can. ...No, it really can't. Not all of the time. It doesn't understand your business logic behind your arc
by HotPotato787 3y ago
>yeah, but crowdstike or whatever antivirus you use can.
...No, it really can't. Not all of the time. It doesn't understand your business logic behind your architecture, it doesn't know how to separate normal from anomalous behaviour (yes, even if you have XtremeAI or whatever the vendor peddled to you), it cannot correlate alerts and activites in patterns not explicitly programmed and it can't generate alerts with 100% precision. In short, it's not intelligent.
- slt2021 3y agothats not the job of red team, this is blue team work (Detection Engineering or Incident Response or Security Operations whatever they are called) - a SIEM tool monkey basically. again, no need for a fulltime red teamer
- surge 3y agoI don't think you know what the point of a red team is, if you did you'd understand how oxymoronic your statement is. A part time red teamer is just a pen tester. That's not what a red team does, and adequate threat emulation isn't someone who flies in for two weeks does somethings that you can only accomplish in two weeks, then fly out to the next company to do the same things. You actually need to dig deep and research a companies individual weaknesses and that takes time. Threat actors have that kind of time to sit and observe and probe, a part time noisy pen test isn't going to get you more than the basics. Also a blue team has to be right all the time, the attacker only has to get things right once. That's why you constantly test your assumptions with a red team and give blue someone to "train" with and improve with that isn't an actual threat actor. You don't want the first time you fight to be in the ring, you need to spar. A lot of pen testing consultancies brand themselves as red teams, but a lot of them are just rebranding pen testing services to the ignorant.
- slt2021 3y agoyeah nice word salad, except that it doesnt happen in real world. what you described is probably just one threat intelligence engineer that also does bunch of other stuff like IR
- surge 3y agoThis is literally what I do, but okay. Threat Intel informs the red team, and we'll model our ops or threat emulation exercises off of that information, we also have a few members that came over from threat intel. Last I checked, Threat Intel engineers don't write malware to simulate malware real threat actors that target a companies industry use. I think you're speaking from your limited experience at your own company. Again, you have to have a mature blue team before you're ready for a red team. Most orgs aren't ready for that, especially if you think Qualys covers your threat models. That's just vulnerability management and might catch some apps/hosts that missed the patch cycle. If it's word salad, maybe its because you're out of your depth when and ignorant of how these programs are supposed to work.