
11/20/2023 · Chris Moberly
What this post added
This post details the evolution of GitLab's Red Team from opportunistic, visible operations to stealth-based exercises. It outlines the development of a maturity model, the implementation of Purple Teaming for collaborative testing with the Blue Team, and the subsequent shift to stealth operations. Key technical contributions include the creation of public Red Team issue templates, handbook pages on remote operations and stealth methodologies, and the development of infrastructure for "Attacker VMs" on corporate laptops and dedicated AWS accounts for Command and Control (C2) frameworks. The post also mentions research into C2 frameworks, agents, redirectors, and automation for deploying these environments.