
Blueprint Live at SANSFIRE 2022: A panel with Heather Mahalik, Katie Nickels and Jeff McJunkin
Blueprint: Build the Best in Cyber Defense
00:00
Red Team Light vs Pentest?
If your goal is to exercise blue, you may spend two or three months and many tens of thousands of dollars to find that you don't really much in the way of detective controls. So i would rather tend to iterate faster with sometimes we refer to assumed breech testing as red team light. Start with a compromised end point. Look at the post exploitation activities that happen, and what detective controls do you have in place? Do you you even have the te logging, let alone the actual alerting? Do you have the sismond? You have the windows of enforting? DoYou have, sure the elk or splunk? But looking for some of this known bad
Transcript
Play full episode