Lateral Movement and Persistence: The Decisive Red Team Phase
1. Introduction Lateral movement and persistence Red Team operations mark the difference between a contained incident and a total breach: this is the phase where the adversary abandons the initial foothold, moves across the network with stolen credentials, and secures a second entry even if discovered. In any professional engagement, lateral movement and persistence Red Team planning decide whether the exercise becomes a real demonstration of risk or a simple intrusion drill. This article covers that decisive phase with a hands-on approach: movement techniques with psexec, WMI, and Pass-the-Hash, persistence mechanisms that survive reboots, pivot tunnels with chisel and SSH, …
Active Directory Security: Attacks and Defense from Scratch
1. Introduction Active Directory security has become the central challenge of corporate cybersecurity, and it is not a coincidence: Active Directory concentrates the credentials, policies, and access control of the entire organization. When an adversary or a Red Team compromises a domain, they gain de facto control of the company. That is why this article approaches Active Directory security from scratch with a hands-on focus: mapping the terrain with BloodHound, stealing credentials through Kerberoasting and AS-REP Roasting, escalating with Pass-the-Hash and DCSync, and rolling out the controls that make Active Directory security defensible and auditable. When you finish, you will …
Physical Security: Access Card Cloning with Proxmark in Red Team Operations
1. Introduction and Objectives In this article, we will explore how easy it can be to clone certain types of cards that are widely used, not only in access controls of private organizations (hotels, etc.) but also in public institutions. To achieve this, we will make use of Proxmark3, which can be acquired from its official website: In this article, we will not demonstrate how to set up the environment to be able to use Proxmark3, as there are several tutorials available on the Internet that provide clear instructions for that: Therefore, to carry out this practice, we should have …

