What is considered the most important aspect of a red team engagement?
The final report, as it must accurately communicate objectives, findings, business impacts, and recommendations.
The Cobalt Strike _____ report provides an overall timeline of post-exploitation activity.
Activity
Which Cobalt Strike report summarizes information collected on each host, such as services and credentials?
The Hosts report.
The Cobalt Strike _____ report provides technical details like a C2 traffic profile, domains, and file hashes, akin to a threat intelligence report.
IOC (Indicators of Compromise)
Which Cobalt Strike report summarizes post-exploitation activity on a per-session basis?
The Sessions report.
The Cobalt Strike _____ report details activity from its built-in spear phishing capabilities, like which users clicked malicious links.
Social engineering
Which Cobalt Strike report maps the recorded activity to MITRE’s ATT&CK Matrix?
The TTP (Tactics, Techniques, and Procedures) report.
How are Cobalt Strike reports typically used when delivering them to a client?
They are typically included as appendices with the main report, not handed over directly.
What sources are used to construct the final red team report?
All logs and notes from the engagement, including Cobalt Strike reports and individual operator logs.
Which section of a red team report is aimed at business executives and provides a concise, non-technical overview of findings and risks?
The Executive Summary.
The _____ section of a red team report summarizes the testing methodology, goals, and scope of the assessment.
Goals & Scenario
Which section constitutes the bulk of a red team report’s content and outlines the sequence of events in technical detail?
The Attack Narrative.
The _____ section of a red team report describes deficiencies in the organization’s ability to prevent, detect, or respond.
Observations & Recommendations
In a red team report, what does an ‘observation’ typically describe?
A deficiency in an organization’s ability to prevent, detect, and/or respond to a specific activity.
For each ‘observation’ in a report, what should be provided to mitigate the identified deficiency?
One or more recommendations.
Which section of a red team report reiterates the significance of the key findings and provides a final statement of business risk?
The Conclusion.
What is the term for the meetings held with an organization’s personnel to review the content of the final report?
Out-briefs.
What is the name of the out-brief tailored toward management, which is performed soon after an engagement completes?
An executive brief.
What is the primary goal of conducting an executive brief with management?
To ensure they understand the business impact and to get their buy-in for implementing improvements.
Which type of out-brief involves a detailed review of activities and outcomes between the red team and other technical teams, such as a blue team?
A technical out-brief.
What is considered the best opportunity for offensive and defensive teams to learn from each other following an engagement?
The technical out-brief.
If a Cobalt Strike client is connected to multiple team servers, how does it handle data when generating a report?
It automatically aggregates and orders the data from all of them.