(TL20) (INCYBER) Immersion Lab : une Red Team à cœur ouvert

(TL20) (INCYBER) Immersion Lab : une Red Team à cœur ouvert

🎙 INCYBER 👥 7K 📅 April 14, 2026 ⏱ 60 min 👁 58 📄 expert opinion 🧭 2026-08-13
Available in: English (current) Français

Keywords

red teamoffensive securityphishingC2 infrastructurephysical intrusion

Summary

The video features a panel from the offensive security team at Loite France, discussing red team operations. They differentiate red teaming from vulnerability scanning and penetration testing, emphasizing scenario-based attacks to achieve specific objectives. The presentation covers the objectives of red teaming, including tactical goals like evaluating exposure and strategic goals like raising awareness among executives. Key success factors include starting from an external position, planning for ’legups’ (assists), calibrating the level of sophistication, and embracing detection as part of the exercise. The speakers then delve into the infrastructure behind red team operations, detailing the setup for phishing campaigns, C2 servers, and the importance of automation and infrastructure as code. They also touch on physical intrusion techniques and the use of implants. The talk concludes with lessons learned and a Q&A session, providing a comprehensive look at the inner workings of a red team.

144 words

Critical Evaluation

Value of the Information & Strength of the Argument

The video offers valuable insights into the practical aspects of red teaming, drawing on the speakers’ extensive experience. They provide concrete examples of phishing scenarios and infrastructure design, which enhances the credibility of their arguments. The argumentation is coherent, with a clear structure that moves from general concepts to specific details. However, the presentation is largely anecdotal, and the speakers do not provide empirical evidence or comparative analysis to support their claims, which limits the scientific rigor.

Scientific Rigor, Source Quality, Title Accuracy

The speakers demonstrate a high level of expertise, but they do not cite external sources or reference specific research. The content is based on their professional experience, which is valuable but not independently verifiable. The title accurately reflects the content, as the video provides an open look into their red team operations. The description includes links to the INCYBER Forum website and LinkedIn, which are relevant for context but not directly cited in the video. No comments were provided for analysis.

173 words

Title / Content Match

The title accurately reflects the content, as the speakers provide an in-depth look into their red team's operations, infrastructure, and methodologies.

Quality & Reliability

7/10

The video provides a detailed, expert-led overview of red team operations, with practical insights and real-world examples. However, it lacks formal citations and is based on the speakers' professional experience, which limits its verifiability.

Key Moments

Cited Sources

Concurring Sources

  • MITRE ATT&CK — The video's discussion of attack techniques aligns with the MITRE ATT&CK framework, which is widely used in red teaming.

Contribution & Novelties

The video provides a rare, candid look into the operational aspects of a red team, including infrastructure design, phishing tactics, and physical intrusion methods. It emphasizes the importance of automation and infrastructure as code, which is not commonly discussed in public forums. The speakers also highlight the strategic value of red teaming beyond technical assessments, such as raising executive awareness and challenging security investments.

Pour aller plus loin :

  • Red team (security) — Provides a general overview of red teaming concepts.
  • MITRE ATT&CK — A knowledge base of adversary tactics and techniques, relevant to red team planning.
  • DORA regulation — The EU regulation mentioned in the video, which mandates threat-led penetration testing for financial entities.

115 words

Radar Profile

The radar profile shows high scores in information quantity and technical level, reflecting the detailed and expert nature of the content. The lower score in reliability is due to the lack of formal citations and reliance on anecdotal evidence.

Reliability 6/10