Advice from NECCDC Red Team

Incident Reports can help win back points, but only if they are good!

  1. Review the National CCDC Rules: “9 Scoring” (section d)
  2. If an attacker has access to your Domain Controller, then the sky is actually falling.
  3. Executives have no idea what an ssh shell is, or any other technical term. Use business terms that your grandparents would understand when creating your executive summary.
  4. Your executives will be really upset if you report “bogus incidents”. The black team service status poller is a really bad bogus incident to report.

Tips for Effective IR Reports:

This blog has some good tips for IR:

Manage credentials carefully

Monitor network traffic with tools, such as wireshark, tcpdump, or netresec Networkminer.

Verify that Windows Defender is actually running, and is configured correctly.

Miscellaneous thoughts:

Windows Red Team Tactics

Linux Red Team Tactics

Red Team Training Material

Other Material (after you finish the Red Team Material)