Red Team Methodology & Standards
Reference material. Use these standards to structure your capstone engagement (Week 26) and any future red team work.
Methodology Frameworks
- 📄 PTES (Penetration Testing Execution Standard) — Structured methodology: pre-engagement, intelligence gathering, threat modeling, exploitation, reporting
- 📄 CREST — Simulated Targeted Attack & Response — Industry standard for red team engagement reporting
- 📄 OWASP Testing Guide — Report structure: findings, severity, reproduction steps, remediation
Continuous Purple Teaming
- 📄 MITRE ATT&CK — Purple Team Exercises — Map findings to ATT&CK for continuous purple teaming
- 🔧 Atomic Red Team + CI/CD — Embed adversary emulation into CI/CD pipelines
- 🔧 Tines + Caldera Integration — Automated detection validation against emulated techniques
- 📄 Detection Coverage — MITRE ATT&CK — Map detection coverage gaps; measure security posture continuously