(TL24) (INCYBER) Du premier clic à l'arrêt de production, journal de bord d'un Red Team

(TL24) (INCYBER) Du premier clic à l'arrêt de production, journal de bord d'un Red Team

🎙 Anthony and Christophe (Advance) 👥 7K 📅 April 15, 2026 ⏱ 30 min 👁 90 📄 expert opinion 🧭 2026-08-13
Available in: English (current) Français

Keywords

Red TeamPenetration TestingSocial EngineeringActive DirectoryPhysical Intrusion

Summary

This presentation by two red teamers from Advance walks through a simulated red team engagement against a fictional pharmaceutical company, My Pharma. The mission aims to achieve three flags: full compromise of the internal network, persistence and compromise of backups, and access to production lines. The speakers detail their methodology, starting with OSINT to gather employee information and email formats, then performing password spraying with IPv6 rotation to avoid detection. When that fails, they resort to spear phishing via SMS, using Evilginx to bypass MFA and gain access to a user account. From there, they escalate privileges through DLL hijacking, compromise a domain admin account, and achieve the first flag. For the second flag, they use a C2 server with domain fronting and a packer to evade EDR, demonstrating persistence on the backup server. For the final flag, they conduct a physical intrusion, using social engineering to enter the facility and deploy a custom implant (Raspberry Pi) to gain network access. The presentation emphasizes the combination of technical and social techniques in red teaming and provides practical insights from real-world experiences.

181 words

Critical Evaluation

Value of the Information & Strength of the Argument

The presentation offers valuable insights into the red teaming process, highlighting the importance of combining technical and social engineering techniques. The speakers provide concrete examples and real-world anecdotes, which strengthens the credibility of their arguments. They clearly differentiate between penetration testing and red teaming, and explain each step of the engagement, from initial reconnaissance to physical intrusion. The argumentation is solid, though some technical details are simplified for the audience, which is acceptable given the time constraints.

Scientific Rigor, Source Quality, Title Accuracy

The speakers are experienced professionals from Advance, lending credibility to the content. However, they do not cite external sources or provide references to specific tools or research, relying instead on their own expertise and experiences. The title accurately reflects the content, which follows a red team mission from initial access to production shutdown. The presentation is well-structured and informative, though it lacks formal citations.

156 words

Title / Content Match

The title accurately reflects the content, which follows a red team mission from initial access to production shutdown.

Quality & Reliability

7/10

The speakers are experienced red teamers from Advance, providing a realistic and detailed account of a red team engagement. The technical content is accurate and well-illustrated with real-world examples, though some techniques are simplified for brevity.

Key Moments

Cited Sources

Concurring Sources

  • MITRE ATT&CK — Framework for understanding adversary tactics and techniques, consistent with the methods described.

Contribution & Novelties

This presentation provides a realistic and detailed walkthrough of a red team engagement, emphasizing the combination of technical and social engineering techniques. It offers practical insights from real-world experiences, such as using SMS for phishing to bypass email security and deploying custom implants for physical intrusion. The speakers also highlight the importance of stealth and persistence in red teaming.

Pour aller plus loin :

100 words

Radar Profile

The radar profile shows high scores in information quantity and quality, with moderate technical depth and reliability. This indicates a well-rounded presentation that is informative and credible, though not extremely technical or heavily sourced.

Reliability 7/10