Share E-Book
Scan to open this page

Scan with your phone to open this page

Author: 奇安信安服团队

No description

AI Reading Assistant

Whole-book reading guide from stratified index samples; jump to passages in the text

AI guide
【One-Line Pitch】 A concise field guide to how professional red teams actually break into enterprise networks during supervised attack-defense exercises—and what that reveals about where defenses fail. Best for security practitioners, blue-team defenders, and managers who want to understand attacker thinking rather than memorize tools. 【Book Arc】 - **Opening (~0%–14%)**: Defines what a red team is and how it differs from hackers and penetration testers, then frames the rise of national attack-defense exercises since 2016 and the escalating sophistication of both sides. - **Early (~14%–29%)**: Introduces the "three axes" of red-team work—intelligence gathering, establishing a foothold, and lateral movement—explaining how each stage builds on the previous one. - **Middle (~29%–57%)**: Lays out common attack tactics: weak credentials, social engineering, bypass/indirect attacks through subsidiaries and supply chains, and stealthy multi-point persistence. - **Late (~57%–86%)**: Walks through five classic case studies framed as the "Thirty-Six Stratagems," showing how real engagements combine phishing, traffic diversion, subsidiary pivoting, and opportunistic exploitation. - **Ending (~86%–100%)**: Summarizes the defensive weaknesses red teams repeatedly find across industries—messy asset inventories, unpatched middleware, exposed boundary devices, and poorly maintained internal management systems—plus an appendix on the authors' own track record. 【Key Takeaways】 - **Red teaming is not hacking or pentesting** (Early): The goal is to exhaustively find *all* weaknesses to improve defense, not to grab one win or merely verify a vulnerability—so expect breadth over a single clever trick. - **Reconnaissance is the real foundation** (Early): Organizational charts, IT assets, leaked credentials, and supplier relationships determine whether the attack goes through phishing, a direct exploit, or the supply chain. - **Weak and reused passwords remain the dominant entry point** (Middle): The text claims credential-based access accounts for the vast majority of successful intrusions, driven by default passwords, reused credentials, and leaked password databases. - **People are the softest target** (Middle): Social engineering—especially phishing and spear-phishing—works because employees trust internal mail and reuse passwords, and a single compromised PC becomes a pivot into the core network. - **Subsidiaries and supply chains are the "back door"** (Middle/Late): Poorly isolated networks between parent companies, subsidiaries, and sub-subsidiaries let attackers enter through the weakest link and roam to the real target. - **Stealth beats brute force** (Middle): Red teams avoid mass scanners, craft targeted exploits to bypass WAF/IPS, and maintain multiple redundant footholds so defenders cannot fully evict them. - **Defenders fail on fundamentals, not exotic threats** (Ending): Unpatched middleware (e.g., Weblogic deserialization), exposed VPN/email systems, and unmaintained bastion/virtualization platforms are recurring, predictable gaps. - **The book is a mindset primer, not a tool manual** (Throughout): It emphasizes strategy, sequencing, and attacker logic over step-by-step commands—useful for defenders reasoning about their own exposure. 【Reading Tips】 - Read the three-stage framework (intelligence → foothold → lateral movement) first; it is the spine that the later case studies hang on. - Treat the case studies as illustrations of *decision-making*—notice why the team chose phishing versus pivoting versus waiting—rather than as literal playbooks. - Skim the appendix on the authors' credentials if you only want the technical content; it is promotional. - Blue-team readers should jump to the final chapter on defensive weaknesses and map each item against their own environment. - Keep in mind the book is written from the attacker's viewpoint for a Chinese enterprise context; translate the principles, not the specific tool names. 【Coverage Limits】 This guide is based on stratified excerpts covering the preface, table of contents, and the main chapters through the appendix; some case-study detail and any material beyond the excerpted chunks may not be fully represented.
Excerpt 1
书名: 奇安信:红队视角下的防御体系突破 (奇安信安服团队)(Z-Library) 作者: 奇安信安服团队 实战攻防演习之 红队视角下的防御体系突破 1 实战攻防演习之 红队视角下的防御体系突破 前 言 网络实战攻防演习,是新形势下关键信息系统网络 安全保护工作的重要组成部分。演习通常是以实际运 行的信息系统为保...
View in text
Excerpt 2
红队三十六计——经典攻击实例..........14 一、浑水摸鱼——社工钓鱼突破系统..................14 6 实战攻防演习之 红队视角下的防御体系突破 二、声东击西——混淆流量躲避侦察..................17 三、李代桃僵——旁路攻击搞定目标....................
View in text
Excerpt 3
怎样执行,在另外一台计 算机也同样执行。但人却会犯各种各样的错误,同一 名员工在不同情况下的同一件事情上可能会犯不同的 错误,不同的员工在同一情况的同一件事情上也可能 会犯不同错误。很多情况下,当红队专家发现搞系统 8 实战攻防演习之 红队视角下的防御体系突破 困难时,通常会把思路转到“搞人”(社工、钓鱼等)。...
View in text
Page 18
仅站在一个据点 上去开展渗透工作,而是会采取不同的Webshell、后 门,利用不同的协议来建立不同特征的据点。因为大 部分应急响应过程并不能溯源攻击源头,也未必能分 析完整攻击路径,缺乏联动防御。蓝队在防护设备告 警时,大部分仅仅只处理告警设备中对应告警IP的服 务器,而忽略了对攻击链的梳理,导致尽管处理了告...
View in text
Excerpt 5
伤的事情,然而小P测试发现:蓝队 虽然对OA系统进行了迁移并修复了漏洞,但是居然没 有删除全部Webshell后门脚本。部分后门脚本仍然混 杂在OA程序中,并被重新部署在新的服务器。攻击队 依然可以连接之前植入的Webshell,顺利提权,拿到 21 实战攻防演习之 红队视角下的防御体系突破 了服务器权限。 拿到...
View in text
Excerpt 6
ginx、IIS都有使用。Weblogic应用比 较广泛,因存在反序列化漏洞,所以常常会被作为打 点和内网渗透的突破点。所有行业基本上都有对外开 放的邮件系统,可以针对邮件系统漏洞,譬如跨站漏 洞、CoreMail漏洞、XXE漏洞来针对性开展攻击,也 可以通过钓鱼邮件和鱼叉邮件攻击来开展社工工作, 均是比较好的突...
View in text
Tags
AI categories
CybersecurityTechnology
Publisher: iBooker it-ebooks
Publish Year: 2019
Language: Chinese
File Format: PDF
File Size: 527.5 KB
Text Preview (First 20 pages)
Registered users can read the full content for free

Register as a Gaohf Library member to read the complete e-book online for free and enjoy a better reading experience.

Generating text preview…