Module 20 Flashcards

(22 cards)

1
Q

What is considered the most important aspect of a red team engagement?

A

The final report, as it must accurately communicate objectives, findings, business impacts, and recommendations.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
2
Q

The Cobalt Strike _____ report provides an overall timeline of post-exploitation activity.

A

Activity

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
3
Q

Which Cobalt Strike report summarizes information collected on each host, such as services and credentials?

A

The Hosts report.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
4
Q

The Cobalt Strike _____ report provides technical details like a C2 traffic profile, domains, and file hashes, akin to a threat intelligence report.

A

IOC (Indicators of Compromise)

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
5
Q

Which Cobalt Strike report summarizes post-exploitation activity on a per-session basis?

A

The Sessions report.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
6
Q

The Cobalt Strike _____ report details activity from its built-in spear phishing capabilities, like which users clicked malicious links.

A

Social engineering

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
7
Q

Which Cobalt Strike report maps the recorded activity to MITRE’s ATT&CK Matrix?

A

The TTP (Tactics, Techniques, and Procedures) report.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
8
Q

How are Cobalt Strike reports typically used when delivering them to a client?

A

They are typically included as appendices with the main report, not handed over directly.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
9
Q

What sources are used to construct the final red team report?

A

All logs and notes from the engagement, including Cobalt Strike reports and individual operator logs.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
10
Q

Which section of a red team report is aimed at business executives and provides a concise, non-technical overview of findings and risks?

A

The Executive Summary.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
11
Q

The _____ section of a red team report summarizes the testing methodology, goals, and scope of the assessment.

A

Goals & Scenario

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
12
Q

Which section constitutes the bulk of a red team report’s content and outlines the sequence of events in technical detail?

A

The Attack Narrative.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
13
Q

The _____ section of a red team report describes deficiencies in the organization’s ability to prevent, detect, or respond.

A

Observations & Recommendations

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
14
Q

In a red team report, what does an ‘observation’ typically describe?

A

A deficiency in an organization’s ability to prevent, detect, and/or respond to a specific activity.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
15
Q

For each ‘observation’ in a report, what should be provided to mitigate the identified deficiency?

A

One or more recommendations.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
16
Q

Which section of a red team report reiterates the significance of the key findings and provides a final statement of business risk?

A

The Conclusion.

17
Q

What is the term for the meetings held with an organization’s personnel to review the content of the final report?

18
Q

What is the name of the out-brief tailored toward management, which is performed soon after an engagement completes?

A

An executive brief.

19
Q

What is the primary goal of conducting an executive brief with management?

A

To ensure they understand the business impact and to get their buy-in for implementing improvements.

20
Q

Which type of out-brief involves a detailed review of activities and outcomes between the red team and other technical teams, such as a blue team?

A

A technical out-brief.

21
Q

What is considered the best opportunity for offensive and defensive teams to learn from each other following an engagement?

A

The technical out-brief.

22
Q

If a Cobalt Strike client is connected to multiple team servers, how does it handle data when generating a report?

A

It automatically aggregates and orders the data from all of them.