Red Teaming gaps and musings

DerbyCon 8.0 - Evolution

Presented by: Samuel Sayen
Date: Friday October 05, 2018
Time: 12:00 - 12:25
Location: Kentucky C & D
Track: Stable

Red Teaming is currently the closest most companies get to adversary emulation. While Red Teaming can do a good job pointing out security gaps, blind spots, and human weaknesses within an organization, there are also limitations. Engagement SOW’s, timelines, and laws impose limitations which can unwittingly push a Red Team engagement far from adversary emulation. Some thoughts on the current status quo, and ways to mix it up.

Samuel Sayen

Sam has served in the State Department's Foreign Service as a security engineer who worked on threat hunting and red teaming. He is currently a proactive consultant for Mandiant.


KhanFu - Mobile schedules for INFOSEC conferences.
Mobile interface | Alternate Formats