You’ve just completed a Red Team Operation. It was a complex undertaking that required research, tool and technique development, and, of course, lots of patience. Now comes the hard work of conveying your results to the organization. You want to have the best results when talking to the teams involved, leadership, and other stakeholders. Everything hinges on your ability to convey your results.
Red Teams face this challenge at the end of each exercise, and there is minimal industry guidance on how to successfully execute this critical step. Many teams deliver reports, but I strongly believe that nothing conveys Red Team results better than getting the right people in the room for a readout. If you can communicate well and simplify the complexities of a Red Team Operation into a quality presentation, you can maximize your impact.
“Most important of all, the red team needs to communicate its findings in a clear, constructive, and collegial manner.” — p. 225
Bryce G. Hoffman (2017)
Red Teaming: How Your Business Can Conquer the Competition by Challenging Everything
In this brief, I’m going to use a Mock presentation about a fictitious Red Team Operation I’ve codenamed Mockingbird (I swear I only intended the team slide to be Hacker Movie themed, but it slowly took over). I will share the storytelling and presentation skills I’ve learned for how to deliver a great Red Team readout. I’ve intentionally used slides with no theme and distilled the content to emphasize the small details that enhance communication and the flow of delivering the readout to your audience. Real Red Team readouts are, of course, more detailed and much longer (30-70 slides on average if technical content is included).
Delivering a Red TEam readout
An overarching theme of my presentations is simplicity. Each slide adds cognitive load for the audience, and I try to keep that to a minimum. Slides should support your story and don’t need to contain every finite detail. You should carry the story through your dialogue. Delivering presentations this way allows you to adapt to the audience and drive the conversation dynamically. Detailed thoughts and insights for each slide are shared below.
Slides 1 (Title)
When your participants come into the meeting room or join the video call, you should have this slide already on the screen. It should have very little information: the type of Operation (Red Team), the codename, and the Red Team lead’s name. The lead should start the conversation. When presenting this slide, it provides an opportunity to set up the audience to understand what they’re about to experience. If the audience does not interact with security often, you can even start by drawing parallels to cybersecurity incidents they may be aware of in the news and describe how your team simulates similar attacks. Whatever is required to level set your audience should be done on this slide.
Slide Goal: Welcome the audience and provide context for what you will be presenting.
slide 2 (team)
I never like to miss an opportunity to give credit to my team. Many Red Teams perform long stints of focused work and may not have the opportunity to be as visible as other members of the security organization. Putting pictures and full names gives the audience a chance to see the individuals who took part in the exercise. The audience should see Red Team members as peers and not scary hackers who work behind the scenes. It is also relevant to highlight specific skills individuals brought to the exercise so that attendees know who to reach out to on certain topics.
Slide Goal: Give credit to those involved in the Red Team Operation
Slide 3 (Mission statement)
Now that the audience has context for the presentation and knows who was involved, it’s a good time to remind them about why your team exists. A clear mission statement can give audience members a better understanding of what value you provide to the organization. The audience should clearly understand what you do and how it directly impacts their ability to succeed. One tip to note here is that I’ve bolded a few words that I wanted to emphasize. Even though the slide is very simple, bolding key words can further help the audience reduce its cognitive load and reinforce the important information.
Slide Goal: Inform or remind the audience of your team’s mission (reason to exist)
Slide 4 (Disclaimer)
Individuals in the audience may have been caught up in the Red Team Operation and be uncertain about how to feel about that. It’s an important time to remind everyone that there is “no blame” (notice I bolded this, and you may even consider capitalizing it too). Secondarily, I remind everyone of the shared mission to make the organization more secure. Individuals targeted by the exercise may feel bad or defensive about looking bad, but uniting under a shared goal can reassure everyone that we are all here to make things better.
Slide Goal: Ensure the presentation places no blame, and you’re all there to secure your organization
Slide 5 (Operation Summary)
When starting what will be a complex technical readout, it’s important to give a summary that includes dates of the exercise and overall outcomes (I recommend no more than 1-2 sentences). Audience members can anchor to this summary later in the presentation when attempting to consume a large amount of information. Also, if the readout is shared, it’s a good place for audience members to reference if they have to convey a summary of the findings.
Slide Goal: Provide a summary of the operation including dates and high-level outcomes
Slide 6 (Operation objectives)
Being objective-driven is where Red Teaming differentiates itself from Penetration Testing. Many audiences will draw comparisons to other types of testing when being delivered a Red Team readout. This slide provides a good opportunity to reinforce that Red Teams operate by objectives, not to discover vulnerabilities. On this slide, I lay out the Operation objectives in a table and whether we (the Red Team) were successful in reaching that objective. I use colors to simplify the outcomes in a simple green (success) or red (failure) layout.
Slide Goal: State the Operation objectives and the outcome.
Slide 7 (section slides)
This slide signals that one part of the readout (setting the context) is over and that the readout is moving to the next part. Applying section slides for context switches is an effective way to manage the flow of information. I recommend staying on this slide for a moment to let the audience reset their minds and prepare to go deeper into the readout.
Slide Goal: Indicate you’re moving into a new or specific part of the readout
SLide 8 (Attack Map)
Attack maps, in my experience, have proven to be an extremely effective way of sharing the complexities of a Red Team Operation. However, they can do the opposite if they’re too cluttered and complicated. I recommend streamlining information (representing a cluster of servers as one icon) and minimizing illustrated steps to only those that moved the operation closer to the Red Team’s objectives. I’ve also found it useful to add logos and icons from widely known services (e.g., GitHub or Apache) to help minimize the cognitive load. Using what the audience is already familiar with can help them absorb complex attack maps with less friction. I try to leave screenshots and deeper technical details in the Technical Appendix, which I will discuss later.
Slide Goal: Convey high-level visual context for demonstrated attack paths
Slide 9 (vulnerabilities)
Although the goal of Red Teaming is not to discover vulnerabilities, they’re discovered and leveraged during Red Team Operations. In many cases, those vulnerabilities are still exposed, making the attack chain still feasible. I like to transition into this section (you may consider putting a section slide here) of the slide deck by pointing out the vulnerabilities that need to be remediated to eliminate these exposures. If they’re already filed, I often report the status while delivering this slide.
Slide Goal: List all vulnerabilities discovered during the exercise
slide 10 (security recommendations)
Security Recommendations are findings that cannot be patched like a vulnerability. They tend to be more systemic in nature. I categorize them as recommendations because you’re not guaranteed to get immediate action on these items. I typically indicate during the delivery of this slide that the recommendations are based on our perception of the environment. Individuals and teams that own the environment frequently provide more context that can lead to the modification of the recommendation.
Slide Goal: List all Security Recommendations for a general audience
Slide 11 (detection recommendations)
Detection Recommendations consist of actions that were taken by the Red Team, where it’s recommended to either create or update a detection. A much more comprehensive readout and meeting will likely occur directly with the Blue Team to create work tracking with specifics. It is, however, important to broadly state for your audience where you think detections can be improved. During this slide, you can reinforce with audiences who mostly deal in vulnerabilities that detections are a defense-in-depth measure. Explaining how your recommendations will benefit the organization’s ability to defend against more advanced threats fits well in this part of the readout.
Slide Goal: List all Detection Recommendations for a general audience
Slide 12 (Ending Slide)
It’s always a good idea to thank the audience and the individuals who will be involved in improving the organization’s security posture. You can either choose to take questions during your readout or after saying thanks. Reinforcing that you want a shared outcome, clarifying any misunderstandings, and declaring follow-up items with ownership is best done at this part of the presentation. You can also determine if you and audience members want to review the deeper technical details.
Slide Goal: Close out the presentation on a positive note and answer questions
technical appendix
The technical appendix should contain screenshots, supporting evidence, and additional details about how the Red Team Operation was carried out. You can even reference them in the Attack Map if you feel it’s necessary. During a Red Team readout, you may be asked deeper technical questions, and depending on the audience, it may be worth the time to review the appendix. In my experience, technical teams use the high-level readout and technical appendix to get a deeper understanding of specifically what needs to be addressed from a security perspective. For a general audience, it’s unlikely you will need the technical details, but it’s always good to have them ready to reference (especially if your results are challenged).
a final word on readouts
A Red Team readout can be created in an infinite number of ways. You should always tailor your readout to what works with your audience. What I shared in this brief are the patterns that have repeatedly led to more successful readout delivery and, overall, more impactful results. You should always be ready to tell the story of your Red Team Operations even without slides. Slides, in my opinion, simply support the visuals for the message you’re trying to convey. If you use storytelling techniques, simplify your slides, and facilitate a good conversation with your audience, you will certainly maximize the impact of your Red Team readouts.