> Skip to content
[]
  • Published: 16 February 2027
  • ISBN: 9781718505117
  • Imprint: RH US eBook Adult
  • Format: EBook
  • Pages: 504

The Effective Red Team

Adversary Emulation Inside the Enterprise




Build a red team that turns successful attacks into better security.

Your red team got domain admin. Great. Now what changed?
The hardest part of red teaming starts after the breach: building a program that survives contact with the rest of the organization and turns offensive work into better security.

The Effective Red Team moves from strategy to tactics in the order you'll meet the problems. You'll assess your organization's real risks and culture, define a mission and scope stakeholders will back, build partnerships with defenders and leadership, hire and develop operators, choose metrics that don't lie, and communicate uncomfortable findings so they get fixed.

Then you'll run operations. You'll design an engagement, build quiet, reusable attacker infrastructure, follow a complete case study emulating the ShinyHunters threat actor, and turn the results into reports, outbriefs, and detection rules engineers will act on. Part IV covers the tactical methodologies themselves: initial access, persistence, expanding access, and acting on objectives in cloud-heavy enterprise environments.

Seven appendixes give you the working documents: rules of engagement, a process document, a finding template, a development matrix, and a sample operation report.

Trevin Edgeworth, Noah Potti, and Jordan Potti built and led the red teams at American Express, Capital One, and Symantec, and wrote this from that experience. It is for practitioners building or running internal red teams, and assumes working knowledge of Active Directory, cloud infrastructure, and networking.

Finding a way in is half the job. The real win is making sure the same attack never works twice.

  • Published: 16 February 2027
  • ISBN: 9781718505117
  • Imprint: RH US eBook Adult
  • Format: EBook
  • Pages: 504