Red Teaming

An end-to-end red-team curriculum — tradecraft, initial access, evasion, credential access, lateral movement, and C2, mapped to MITRE ATT&CK. Follow it top to bottom — foundational first (16 tutorials).

Red TeamingRed Teaming Fundamentals: Mindset, Methodology, and Engagement TypesDiscover how red team engagements differ from pen testing, how the adversarial mindset works, and how MITRE ATT&CK connects offensive TTPs to…Jun 19, 2026 · 10 min readRead →Red TeamingThe Attack Lifecycle: Reconnaissance to ExfiltrationFollow a full red team operation through every MITRE ATT&CK Enterprise tactic - from passive OSINT and phishing to credential dumping, lateral…Jun 19, 2026 · 11 min readRead →Red TeamingOPSEC Principles for Red Teamers: Staying UndetectedLearn the OPSEC principles that separate realistic adversary simulations from noisy penetration tests - covering C2 infrastructure, process injection, network blending, and…Jun 19, 2026 · 12 min readRead →Red TeamingPassive OSINT: Mapping the Target Without Touching ItDiscover how authorized red teamers build a complete external attack surface map using only public, third-party data sources - certificate transparency logs,…Jun 19, 2026 · 12 min readRead →Red TeamingActive OSINT: DNS, Certificate Transparency, and Subdomain EnumerationMaster subdomain enumeration from zero-noise CT log mining to active DNS brute-force. Covers AXFR attacks, crt.sh, subfinder, puredns, and Sysmon-based detection for…Jun 19, 2026 · 12 min readRead →Red TeamingOSINT for People and Credentials: LinkedIn, Breach Data, and Email HarvestingDiscover how adversaries harvest employee identities, email addresses, and breached credentials from public sources - and how defenders can run the same…Jun 19, 2026 · 12 min readRead →Red TeamingBuilding a Red Team Lab: Infrastructure, VMs, and C2 SetupDesign and deploy a self-contained red team lab with tiered network segmentation, Sliver C2, redirector chains, and a full blue team monitoring…Jun 20, 2026 · 11 min readRead →Red TeamingPhishing Campaign Design: Pretexting, Lures, and Target ProfilingBuild effective authorized phishing simulations by mastering OSINT target profiling, pretext construction, and lure delivery selection - with full MITRE ATT&CK coverage…Jun 20, 2026 · 13 min readRead →Red TeamingPayload Delivery via Email: Attachments, Links, and Bypassing FiltersTrace the full email delivery kill chain a red team assembles - ISO containers, LNK stomping, HTML smuggling, and AiTM - then…Jun 21, 2026 · 13 min readRead →Red TeamingMalicious Office Macros: VBA Basics to Shellcode ExecutionLearn how malicious Office macros go from 'Enable Content' to a Meterpreter session - covering the three-API shellcode runner, AMSI bypass, VBA…Jun 21, 2026 · 12 min readRead →Red TeamingLNK File Weaponization for Initial AccessTear apart the MS-SHLLINK binary format, build a weaponized LNK disguised as a PDF invoice, deliver it inside an ISO, and catch…Jun 22, 2026 · 12 min readRead →Red TeamingHTA Files and mshta.exe Abuse for Payload DeliveryLearn how attackers weaponize mshta.exe and HTA files for fileless payload delivery, including inline monikers and WMI parent-chain breaking, then engineer layered…Jun 30, 2026 · 16 min readRead →