No description
AI Reading Assistant
Whole-book reading guide from stratified index samples; jump to passages in the text
AI guide
【One-Line Pitch】
A hands-on red-team playbook that walks you through a full adversary simulation—from building C2 infrastructure and evading antivirus to Active Directory exploitation and reporting—for security practitioners who already know the basics and want to operate like a real threat actor.
【Book Arc】
- **Opening (~0%–10%)**: Frames the red-team mindset versus traditional pentesting, sets up the fictional "Cyber Space Kittens" engagement, and covers legal/authorization warnings plus the assumed-breach exercise concept.
- **Early (~10%–30%)**: Builds the attack infrastructure—VPS setup, Metasploit, Cobalt Strike, PowerShell Empire, dnscat2, and other C2 frameworks—and introduces MITRE ATT&CK as the planning backbone.
- **Middle (~30%–55%)**: Moves into reconnaissance and initial access: environment probing, scan diffing, cloud scanning, subdomain discovery, then web exploitation (XSS, NoSQL injection, deserialization, SSRF, XXE) and network footholds via Responder, CrackMapExec, and credential harvesting.
- **Late (~55%–80%)**: Covers post-exploitation depth—privilege escalation on Windows and Linux, lateral movement (Pass-the-Hash, DCOM, RDP tunneling), Active Directory/Kerberos abuse, BloodHound, and social engineering (phishing, macro/DDE payloads, domain lookalikes).
- **Ending (~80%–100%)**: Closes with physical access attacks (LAN Turtle, Bash Bunny), AV/network evasion and custom malware development, automation, password cracking, and post-engagement analysis and reporting.
【Key Takeaways】
- **Red teaming differs from pentesting in goal, not just tools** (Opening): the focus shifts from finding vulnerabilities to testing detection and response, measured by metrics like time-to-detect (TTD) and time-to-mitigate (TTM).
- **Infrastructure is a first-class concern** (Early): reusable, redirectable C2 setups using domain fronting and CDNs let you survive takedowns and blend traffic with legitimate services.
- **C2 diversity matters** (Early): frameworks like Cobalt Strike, Empire, and dnscat2 each solve different problems—SMB beacons for internal pivoting, DNS tunneling for restricted egress.
- **Web exploitation remains a primary entry vector** (Middle): the book walks through XSS variants, NoSQL injection, deserialization, template injection, SSRF, and XXE with practical lab scenarios.
- **Credential access drives lateral movement** (Late): Responder, CrackMapExec, Pass-the-Hash, and SPN enumeration form the chain from a single foothold to domain-wide compromise.
- **Active Directory is the endgame** (Late): BloodHound/SharpHound mapping, DCOM abuse, and domain controller hash dumping show how attackers escalate from workstation to domain.
- **Evasion requires custom tooling** (Ending): recompiling Meterpreter, code caves, PowerShell obfuscation, and application whitelist bypasses are presented as necessary skills, not optional extras.
- **Reporting and metrics close the loop** (Ending): the book emphasizes translating red-team activity into actionable data for defenders, not just a list of exploited hosts.
【Reading Tips】
- **Deep-read the infrastructure and evasion chapters** (Early and Ending): these are the most reusable and hardest to improvise; skim the tool installation steps if you already have a lab.
- **Treat the labs as mandatory practice**: the book is explicitly exercise-driven; reading without reproducing the scenarios will not build the muscle memory it aims for.
- **Expect a steep curve on Active Directory and Kerberos**: if you lack AD fundamentals, pause and study those before the lateral movement chapters.
- **Use MITRE ATT&CK as a companion map**: keep the matrix open while reading to see how each technique fits into a broader TTP taxonomy.
- **Re-read after a gap**: the author himself notes that two or three passes with digestion time in between are typical for absorbing the material.
【Coverage Limits】
This guide is based on stratified excerpts covering the table of contents, introduction, and early-to-middle chapters; later chapters on physical attacks, evasion, and reporting are summarized from headings and brief fragments, so specific techniques and lab details in those sections are not fully represented.
Excerpt 1
文件 1.8.2.1 非宏的 Office 文件 —— DDE 1.8.2.2 隐藏的加密 payload 1.8.2.3 利用社会工程学攻破内网 Jenkins 1.8.3 本章总结 1.8.4 第6章 短传——物理访问攻击 1.9 ID 卡复制器 1.9.1 绕过入口点的物理工具 1.9.2 LAN Turt...
View in text
Excerpt 2
看看他们的防御团队是否能够发现或阻止你。 你要决定用什么类型的 TTP(战术策略,威胁情报和恶意程序)去进行你的工作呢?在这场战斗中,你前期需要做大量的信息收集工作,去观察寻找他们外部基础设施的薄弱点,社工他们公司的员工,提升你的权限,获取内部网络的信息,在整个内网中进行漫游,并且能够最终窃取有关 KITT-3n...
View in text
Excerpt 3
d-keywords=books”; 主机 header 设置为 Amazon: header “Host” “www.amazon.com”; 甚至一些自定义服务器的 header 也从 C2 服务器发回: header “x-amz-id-1” “THKUYEZKCKPGY5T42PZT”; header “...
View in text
Excerpt 4
ershell.exe,而是在 powershell 运行空间环境(.NET)中运行 powershell 命令和函数。它包含了大量的 PowerShell 攻击模块和二进制文件,使后期利用过程变得更加容易。我们尝试的是建立一个‘一体化’的后渗透利用工具,我们可以使用它来绕过所有保护措施(至少是其中一些),p0w...
View in text
Excerpt 5
代码保存到错误的仓库(将其发送到他们的公开仓库而不是公司的私有仓库),要么意外地保存敏感数据(如密码),然后试图删除它。Github 的一个优点是,它可以在每次修改或删除代码时进行记录。这意味着如果有一次将敏感数据保存到仓库中,那么即使删除了该敏感数据,那么它仍然会在数据更改中被记录。只要仓库是公开的,你就能够查...
View in text
Excerpt 6
很多 其他的平台 。这些平台可以支付从零到两万美元以上之间的奖励。 我的许多学生觉得开始寻找漏洞是件令人畏缩却步的事情。这真的需要你投入其中,每天花几个小时做这件事情,并专注于理解如何利用第六感找到漏洞。一般来说,开始的时候可以看看无报酬的漏洞赏金项目(因为专业的赏金猎人不会注意它们)或像 Yahoo 这样大型的...
View in text
Excerpt 7
过 HTLM5打开相机并拍摄受害者的照片,你可以在屏幕上显示覆盖图以捕获凭据,也可以将其重定向到恶意网站以执行恶意软件。 以下是 BeEF 从 XSS 攻击中引发大量问题的快速演示: 首先,确保你的 BeEF 服务器在攻击者计算机上运行。在我们的易受攻击的聊天支持系统的应用程序中,你可以访问 http://cha...
View in text
Excerpt 8
和感叹号,我们可以重新创建 alert(1)。 JSF*ck Payload: [][(![]+[])[+[]]+([![]]+[][[]])[+!+[]+[+[]]]+(![]+[])[!+[]+!+[]]+(!![]+[])[+[]]+(!![]+[])[!+[]+!+[]+!+[]]+(!![]+[])[+...
View in text
Tags
AI categories
CybersecurityDevOpsTechnology
Loading comments...
Reply to Comment
Edit Comment