Include key pieces of information gathered
Interesting observations that assisted the
red team during the engagementOperators often take advantage of unique situations to support an engagement. This is often nontechnical in nature. Observations related to people, processes, and technology should be documented.
Include
●
Logic
flaws found in the environment●
Response (or lack of) from defenders
Interesting observations that maybe of concern but that are not directly related to the engagement
Engagement offer a unique view to a range of systems. Operators often find interesting paths or other observations that mayor may not have been explored. These should be documented.
A single observation should Include the following elements (a complete example is available on the companion website)
●
Observation title
●
A
narrative description●
Technical details
○
Source/destination IP addresses
○
Tools or techniques
○
Results (Including impacts)
●
Screenshots