3 ms·
This is literally what I do, but okay. Threat Intel informs the red team, and we'll model our ops or threat emulation exercises off of that information, we als
by surge 3y ago
This is literally what I do, but okay.
Threat Intel informs the red team, and we'll model our ops or threat emulation exercises off of that information, we also have a few members that came over from threat intel. Last I checked, Threat Intel engineers don't write malware to simulate malware real threat actors that target a companies industry use.
I think you're speaking from your limited experience at your own company. Again, you have to have a mature blue team before you're ready for a red team. Most orgs aren't ready for that, especially if you think Qualys covers your threat models. That's just vulnerability management and might catch some apps/hosts that missed the patch cycle.
If it's word salad, maybe its because you're out of your depth when and ignorant of how these programs are supposed to work.