Microsoft Threat Intelligence Podcast

The Art and Science of Microsoft’s Red Team

8 snips
Jun 25, 2025
Craig Nelson, leader of Microsoft’s elite Red Team and a veteran in simulating real-world attacks, shares pivotal insights on cybersecurity dynamics. He discusses how human behavior can influence security breaches and the importance of collaboration between red and blue teams. Craig explores the impact of AI on attacker tactics and stresses creative thinking in identifying vulnerabilities. He reflects on his journey from the ’90s hacker scene to navigating cloud security challenges, offering valuable advice for aspiring red teamers.
Ask episode
AI Snips
Chapters
Books
Transcript
Episode notes
INSIGHT

Threat Intel Legitimized Red Team Evolution

  • Public attribution of nation-state threat actors legitimized and transformed threat intelligence.
  • This shifted red teams to simulate realistic, geopolitically-informed attacker behaviors beyond generic threats.
INSIGHT

Microsoft Red Team Role Defined

  • The Microsoft Red Team is the 'lawful good bad guys' attacking Microsoft's infrastructure, not customers'.
  • They conduct operations across the threat spectrum, simulating real-world attacker techniques including nation-state level.
ANECDOTE

Red Team Exploit Meets Human Factor

  • The Red Team once used a complex exploit to enter a Microsoft building by simulating biometric access.
  • The operation succeeded because a security guard manually let the red team member in, optimizing for user experience over strict security.
Get the Snipd Podcast app to discover more snips from this episode
Get the app