
Introdução ao Red Team Operations
um guia básico para suas operações de Red TeamBy Joas Antonio dos SantosLength4h 43m
About this audiobook
É um livro abrangente e envolvente que mergulha nas estratégias e técnicas utilizadas pelo Red Team, uma equipe especializada em simular ataques cibernéticos para fortalecer a segurança de organizações. Nesta obra, o leitor será guiado por uma jornada que abrange desde os conceitos básicos até as metodologias avançadas de emulação de adversários.
Ao explorar a história e a evolução do Red Team, o autor apresenta as principais técnicas e procedimentos usados, como o Comando e Controle (C2), a Ameaça Persistente Avançada (APT) e a Cyber Kill Chain. Além disso, o livro explora a estruturação de um Red Team e a sua colaboração com Blue Team.
O leitor também terá acesso a um vasto conjunto de ferramentas de código aberto e comerciais usadas pelo Red Team, bem como orientações para criar um plano eficaz de emulação de adversários. Através de exemplos práticos e estudos de caso, o livro oferece insights valiosos sobre a execução de campanhas de emulação.
Audiobook details
GenreTechnology
Length4 hrs 43 mins
Narrated byListen with 1,000+ voices
FormateBook with Audio
Publish dateDec 7, 2023
LanguagePortuguese
Table of contents
1Introduction
26THREAT MODEL
21 INTRODUÇÃO AO RED TEAM
27THREAT INTELLIGENCE
3HISTÓRIA DO RED TEAM
28THREAT PROFILE
4CONCEITOS SOBRE RED TEAM
29THREAT EMULATION
5BLUE CELL
30REGRAS DE ENGAJAMENTO (ROE)
Show all chaptersShow less
6BLUE TEAM
312 ESTRUTURA DE UMA ÁREA DE RED TEAM
7COMANDO E CONTROLE (C2)
32INTRODUÇÃO
8TIPOS DE COMANDO E CONTROLE (C2)
33TAREFAS DO RED TEAM
9INTERATIVO
34NIST CYBER SECURITY FRAMEWORK
10SHORT HAUL
35NIST E RED TEAM
11LONG HAUL
36CIS CONTROLS E NIST
12APT (AMEAÇA PERSISTENTE AVANÇADA)
373 COMANDO E CONTROLE (C2)
13CYBER KILL CHAIN
38MODELOS DE C2 (COMANDO E CONTROLE)
14RED TEAM
39ARQUITETURA CENTRALIZADA
15RED TEAM OPERATOR
40ARQUITETURA PONTO A PONTO (P2P)
16RED TEAM LEADER
41ARQUITETURA ALEATÓRIA
17PURPLE TEAM
42COMANDO E CONTROLE CUSTOMIZADO (C3)
18INDICADOR DE COMPROMISSO (IOC)
43EXEMPLO DE C3 – BRUTE RATEL
19OPSEC (OPERATIONAL SECURITY)
44EXEMPLO DE C3 - WITHSECURELABS
20RED CELL
45MATRIZ DE COMANDO E CONTROLE: LISTAS DE FERRAMENTAS DE C2 E C3 (OPEN SOURCE E COMERCIAL)
21MITRE ATT&CK
464 CRIANDO UM PLANO DE ADVERSARY EMULATION
22TTPS (TÁTICAS, TÉCNICAS E PROCEDIMENTOS)
47INTRODUÇÃO
231. TÁTICAS
48PASSO A PASSO DA ELABORAÇÃO DE UM PLANO
242. TÉCNICAS
49BIBLIOTECA DE ADVERSARY EMULATION
253. PROCEDIMENTOS
50MICRO EMULAÇÃO DE AMEAÇAS