全维红队演练
原名:conducting-full-scope-red-team-engagement
规划和执行全面的MITRE ATT&CK对齐红队行动,涵盖威胁建模、侦察、初始访问和后续利用,评估组织对APT风格行为的检测、预防和响应能力。
- 分类
- 开发提效
- 版本
- v1.0
- 作者
- 弈韬(@ra1nzzz)
- 下载
- 1
- 收藏
- 0
- 发布
- 2026-08-18
- 更新
- 2026-09-05
- TRACE 评分
- 3.4 / 5
内容概览
A full-scope red team engagement simulates real-world adversary behavior across all phases of the cyber kill chain — from initial reconnaissance through data exfiltration — to evaluate an organization's detection, prevention, and response capabilities. Unlike penetration testing, red team operations prioritize stealth, persistence, and objective-based scenarios that mimic advanced persistent threats (APTs). - When conducting security assessments that involve conducting full scope red team engagement - When following incident response procedures for related security events - When performing scheduled security testing or auditing activities - When validating security controls through hands-on testing - Written authorization (Rules of Engagement document) signed by executive leadership - Defined scope including in-scope/out-of-scope systems, escalation contacts, and emergency stop procedure…