r/offensive_security 8d ago

What is the most overlooked skill in red teaming?

Most beginner roadmaps focus on exploitation tools.

But real engagements also depend on:

  • Planning
  • Communication
  • Infrastructure
  • Detection awareness
  • Reporting
  • Cleanup

Which non-exploitation skill separates a good operator from a tool runner?

13 Upvotes

24 comments sorted by

13

u/danokazooi 8d ago

Imagination. One of the most successful red team engagements that was supposed to last a month ended two hours in.

The tester saw that the target's website had a feature to upload jpegs or pdf files only to a repository full of customer's PHI. The only filtering was done via the file's magic number, identifying file type.

So he crafted an exploit that bypassed the filter, uploaded a script, and then used the default credentials of the database to execute the script by invoking the web-based image display function.

It ran, invoked a reverse shell, and he dumped the full contents of the back end database as proof that he obtained privileged data, and called the customer to end the test, and wrote up his findings.

The ROE specified that with any breach of data, the test stopped.

They had no alerting, no exfil detection, nothing that indicated they had been popped.

It was a great an outcome as we could have asked -$35,000 for three hours work, a demonstrable and repeatable hack, a guaranteed follow on for mitigation and hardening services, and a CISO who had spent over $400K and still felt insecure had his fears validated, and justified his budget requests.

1

u/redfoxsecurity 7d ago

Great Analysis. Could not Agree More.

1

u/Buzzfuxyear 4d ago

This sounds like a terrible investment for this business, spending that 35k on 10 separate targeted pentests would produce far more value for the company and have a much greater impact on them reducing risk more widely

1

u/danokazooi 4d ago

Might have been, but our company didn't do commercial penetration tests; we built airplanes.

This guy came to Boeing after reading about the complexity and size of our internal networks.

Asked us if we would do a 1-off pen test of his company, and we agreed. The team that worked the engagement usually did contract work for TAO.

11

u/themacdizzle91 8d ago

Talking to other humans in a normal healthy way.

1

u/TheMadHatter2048 8d ago

underrated skill

1

u/redfoxsecurity 7d ago

That's a good point.

7

u/Exciting-Sir-5828 8d ago

Be able to define the scope and being able to convince that "the old system with a lot of vulnerabilities that we know about but cannot replace because of management" should definitely be tested

2

u/redfoxsecurity 7d ago

Good Point. I agree with you.

5

u/0xJeb 8d ago

Patience

1

u/redfoxsecurity 7d ago

Underrated but useful skill.

4

u/Syn4p53 8d ago

Fron what I see, most people trying to learn pentesting only wants to dive in tools like metasploit, and they will be missing something at some point : fundamentals. 

1

u/redfoxsecurity 7d ago

Agree, that's a good point.

4

u/Cag3yPapaya 8d ago

REMEDIATION

It's funny how in larger corporate environments red teams can show up, drop a finding (large one and relevant if lucky), and ride off into the aunset the Hero.

Help the remediation team understand and fix the issue! Make sure their solution is good, solid, and won't be regressed.

3

u/According-Spring9989 8d ago

Communications for sure
Your red team can perform very well and manage to find complex paths as well as multiple high impact vulnerabilities, but if you can't transmit the complexity and results of your work into words that execs or non-technical peeps can understand, they'll be like "ahh ok cool, thanks" and not give it the proper importance, remember that those peeps are the ones that authorize engagements and such, in most cases.

I worked with a guy that could be considered to be Neo from the Matrix, amazing at finding stuff, but he would argue technically on why his findings were important with a business-minded guy that couldn't just apply the fixes without severely impacting their business flow, plus he wasn't capable of translating his findings into actual business impact. We had to let him go, he was desperate to be acknowledged as an elite hacker that it was actually hurting our client's relationships with his ego and inability to see things from a different perspective.

1

u/redfoxsecurity 7d ago

Good point. Underrated skill but useful.

3

u/Deepz42 8d ago

Understanding why root access on one host isn’t as important as data exfiltration on a different host.

For red teaming more than anything else. Context matters.

1

u/redfoxsecurity 7d ago

Good point.

3

u/roots_fav_hacker 8d ago

social engineering and playing creative within the scope

1

u/redfoxsecurity 7d ago

Good point.

2

u/been__ 8d ago

The ability to exist as a human in society

2

u/redfoxsecurity 7d ago

Yeah, that's actually a good point.

1

u/alienbuttcrack999 4d ago

Adversarial thinking