Red Team Tactics: Let’s defend!

No ratings

Presented at Hack Sydney 2025 by

You implement all the Cybersecurity basics, you try to defend against all initial attack vectors, (think continuous patching, MFA for all accounts, yearly external pen tests for all web facing apps …) But then an attacker exploits a zero day vulnerability on a global internet facing software you use and is suddenly inside your network! This is where this talk starts, relying on my experience working on mitigating findings from Red and Purple team reports for the past 3 years specifically, I want to walk the audience through a few different common techniques that the attacker use once inside the network to move laterally and provide them with the necessary actionable security controls to help defend against them.