IDE Attack Prevention
You asked, and our Red Team answered

You asked, and our Red Team answered

1/29/2021 · Heather Simpson

What this post added

This post details the Red Team's approach to endpoint security and credential hunting, including the development and use of tools like gitrob and token hunter. It also describes their methodology for simulating insider threats and assumed breach scenarios, and how they use GitLab and Vectr for managing testing intelligence. The post highlights their collaborative approach with other security and application groups, and their strategies for building trust and breaking down the stigma associated with red teaming within the organization. It also touches on mimicking known TTPs from frameworks like MITRE ATT&CK and tailoring them to GitLab's environment.

Read the original post ↗