
(TL24) (INCYBER) Du premier clic à l'arrêt de production, journal de bord d'un Red Team
Keywords
Summary
181 words
Critical Evaluation
Value of the Information & Strength of the Argument
The presentation offers valuable insights into the red teaming process, highlighting the importance of combining technical and social engineering techniques. The speakers provide concrete examples and real-world anecdotes, which strengthens the credibility of their arguments. They clearly differentiate between penetration testing and red teaming, and explain each step of the engagement, from initial reconnaissance to physical intrusion. The argumentation is solid, though some technical details are simplified for the audience, which is acceptable given the time constraints.
Scientific Rigor, Source Quality, Title Accuracy
The speakers are experienced professionals from Advance, lending credibility to the content. However, they do not cite external sources or provide references to specific tools or research, relying instead on their own expertise and experiences. The title accurately reflects the content, which follows a red team mission from initial access to production shutdown. The presentation is well-structured and informative, though it lacks formal citations.
156 words
Title / Content Match
The title accurately reflects the content, which follows a red team mission from initial access to production shutdown.
Quality & Reliability
7/10
The speakers are experienced red teamers from Advance, providing a realistic and detailed account of a red team engagement. The technical content is accurate and well-illustrated with real-world examples, though some techniques are simplified for brevity.
Key Moments
Markers derived by PSI from the transcript: the creator did not define chapters.
- Introduction and presentation of the speakers and the red team concept.
- Explanation of the difference between penetration testing and red teaming.
- Introduction of the fictional company My Pharma and the three flags.
- OSINT phase: gathering employee information and email formats.
- Password spraying with IPv6 rotation and failure to find valid credentials.
- Spear phishing via SMS using Evilginx to bypass MFA and gain access.
- Privilege escalation through DLL hijacking and compromise of a domain admin account.
- Persistence and backup compromise using C2 with domain fronting and packer.
- Physical intrusion preparation: social engineering and equipment.
- Physical intrusion execution and deployment of the implant to access production lines.
Cited Sources
- INCYBER Forum Europe — The presentation was given at the INCYBER Forum Europe 2026.
- INCYBER Forum Europe LinkedIn — LinkedIn page of the INCYBER Forum Europe.
Concurring Sources
- MITRE ATT&CK — Framework for understanding adversary tactics and techniques, consistent with the methods described.
Contribution & Novelties
This presentation provides a realistic and detailed walkthrough of a red team engagement, emphasizing the combination of technical and social engineering techniques. It offers practical insights from real-world experiences, such as using SMS for phishing to bypass email security and deploying custom implants for physical intrusion. The speakers also highlight the importance of stealth and persistence in red teaming.
Pour aller plus loin :
- Red team (security) — Overview of red teaming concepts.
- Evilginx — Tool used for phishing with MFA bypass.
- DLL hijacking — MITRE ATT&CK technique for privilege escalation.
- Domain fronting — Technique used to hide C2 traffic.
100 words
Radar Profile
The radar profile shows high scores in information quantity and quality, with moderate technical depth and reliability. This indicates a well-rounded presentation that is informative and credible, though not extremely technical or heavily sourced.