{"id":5636,"date":"2021-03-14T01:12:17","date_gmt":"2021-03-14T00:12:17","guid":{"rendered":"https:\/\/nethemba.com\/?p=5636"},"modified":"2021-03-14T13:24:26","modified_gmt":"2021-03-14T12:24:26","slug":"red-teaming-odolate-profesionalne-vedenemu-utoku","status":"publish","type":"post","link":"https:\/\/nethemba.com\/sk\/red-teaming-odolate-profesionalne-vedenemu-utoku\/","title":{"rendered":"Red Teaming &#8211; odol\u00e1te profesion\u00e1lne veden\u00e9mu \u00fatoku?"},"content":{"rendered":"<h1><span style=\"font-weight: 400;\">1 \u010co je Red Teaming?<\/span><\/h1>\n<p><span style=\"font-weight: 400;\">V nasleduj\u00facom \u010dl\u00e1nku si vysvetl\u00edme, \u010do presne znamen\u00e1 \u201cRed Teaming\u201d, v \u010dom sa l\u00ed\u0161\u00ed od tradi\u010dn\u00fdch penetra\u010dn\u00fdch testov, v \u010dom je pr\u00edstup \u201cRed Teamingu\u201d unik\u00e1tny a pre\u010do najlep\u0161ie simuluje re\u00e1lny koordinovan\u00fd \u00fatok.<\/span><\/p>\n<p><span style=\"font-weight: 400;\">V Nethembe sme \u201cRed Teaming\u201d vykon\u00e1vali mnoho rokov predt\u00fdm ako sa v technickej verejnosti ujal tento term\u00edn &#8211; ide o kombin\u00e1ciu information gatheringu (OSINT), blackbox penetra\u010dn\u00fdch testov s cie\u013eom minimalizova\u0165 ich detekciu zo strany z\u00e1kazn\u00edka a soci\u00e1lneho in\u017einierstva ako vo forme sofistikovan\u00e9ho spear phishingu, tak fyzickej infiltr\u00e1cie.<\/span><\/p>\n<p><b>Red Team predstavuje profesion\u00e1lny t\u00edm hackerov<\/b><span style=\"font-weight: 400;\">, soci\u00e1lnych in\u017einierov a \u201cintelligence\u201d expertov, ktor\u00ed dok\u00e1\u017ee z\u00edskava\u0165, analyzova\u0165 a n\u00e1sledne vyu\u017e\u00edva\u0165 mno\u017estvo d\u00f4le\u017eit\u00fdch inform\u00e1ci\u00ed potrebn\u00fdch na samotn\u00fa infiltr\u00e1ciu.<\/span><\/p>\n<p><b>Blue Team predstavuje profesion\u00e1lny t\u00edm ochrancov<\/b><span style=\"font-weight: 400;\">, obvykle syst\u00e9mov\u00fdch administr\u00e1torov z\u00e1kazn\u00edka, ktor\u00fdch cie\u013eom je detegova\u0165 \u00fatoky \u201cRed Teamu\u201d a \u010do najviac ich eliminova\u0165.<\/span><\/p>\n<p><b>White Team predstavuje \u00fazku skupinu koordin\u00e1torov jednotliv\u00fdch t\u00edmov<\/b><span style=\"font-weight: 400;\"> (objedn\u00e1vate\u013e), ako jedin\u00ed s\u00fa informovan\u00ed o \u00fatoku Red Teamu.<\/span><\/p>\n<p><b>Red Teaming je sofistikovan\u00fd, koordinovan\u00fd \u00fatok<\/b><span style=\"font-weight: 400;\">, ktor\u00fd simuluje re\u00e1lny hackersk\u00fd \u00fatok, s cie\u013eom vyhn\u00fa\u0165 sa detekcii (zo strany tzv. \u201cBlue Teamu\u201d). Za norm\u00e1lnych okolnost\u00ed IT oddelenie z\u00e1kazn\u00edka teda (s v\u00fdnimkou zad\u00e1vate\u013ea) nie je o \u00fatoku informovan\u00e9. Samotn\u00fd Red Team obvykle tie\u017e nedisponuje \u017eiadnymi inform\u00e1ciami o cie\u013eovej infra\u0161trukt\u00fare, syst\u00e9moch \u010di zamestnancoch danej organiz\u00e1cie. Z tohto h\u013eadiska ide o tzv. <\/span><b>\u201cblackbox test\u201d<\/b><span style=\"font-weight: 400;\">. Jedin\u00e1 inform\u00e1cia, ktor\u00fa z\u00e1kazn\u00edk schva\u013euje, je zoznam odhalen\u00fdch potenci\u00e1lnych cie\u013eov, ktor\u00e9 Red Team n\u00e1sledne vyu\u017eije k \u00fatoku (inak by toti\u017e mohlo d\u00f4js\u0165 k neleg\u00e1lnym \u00fatokom na infra\u0161trukt\u00faru, ktor\u00fa z\u00e1kazn\u00edk nevlastn\u00ed) a zoznam zak\u00e1zan\u00fdch met\u00f3d alebo prakt\u00edk, ktor\u00e9 Red Team nem\u00f4\u017ee pou\u017ei\u0165 (napr\u00edklad DoS \u00fatoky, vydieranie\/vyhr\u00e1\u017eanie sa v pr\u00edpade soci\u00e1lneho in\u017einierstva apod).<\/span><\/p>\n<p><b>Red Teaming napriek tomu, \u017ee nejde do \u0161\u00edrky s cie\u013eom identifikova\u0165 v\u0161etky mo\u017en\u00e9 zranite\u013enosti, tak vyu\u017e\u00edva viacero vektorov \u00fatokov nad r\u00e1mec be\u017en\u00fdch penetra\u010dn\u00fdch testov (napr\u00edklad soci\u00e1lne in\u017einierstvo). <\/b><\/p>\n<p><span style=\"font-weight: 400;\">Jeho cie\u013eom je dosiahnutie \u201cvlajky\u201d (\u201cflag\u201d) ako napr\u00edklad z\u00edskanie lok\u00e1lneho dom\u00e9nov\u00e9ho administr\u00e1tora alebo kompromitovanie hrani\u010dn\u00e9ho smerova\u010da. A toto je mo\u017en\u00e9 docieli\u0165 ak\u00fdmko\u013evek sp\u00f4sobom &#8211; od technick\u00e9ho prieniku na samotn\u00e9 syst\u00e9my a\u017e po psychologick\u00fa manipul\u00e1ciu hlavn\u00e9ho admina vo firme.<\/span><\/p>\n<p><b>Cie\u013eom Red Teamingu je otestova\u0165 spolo\u010dnos\u0165 na komplexn\u00fd hybridn\u00fd \u00fatok<\/b><span style=\"font-weight: 400;\">, pri ktorom s\u00fa vyu\u017eit\u00e9 v\u0161etky mo\u017en\u00e9 dostupn\u00e9 sp\u00f4soby na dosiahnutie tohto cie\u013ea.<\/span><\/p>\n<p><b>Vz\u0165ah medzi Red Teamom a Blue Teamom je asymetrick\u00fd a to na dvoch \u00farovniach <\/b><span style=\"font-weight: 400;\">&#8211; Red Teamu sta\u010d\u00ed n\u00e1js\u0165 len jedna zranite\u013enos\u0165, aby sa dok\u00e1zal pri svojom \u00fatoku posun\u00fa\u0165 dopredu. Blue Team mus\u00ed ale ma\u0165 opraven\u00e9 (a neust\u00e1le opravova\u0165) v\u0161etky mo\u017en\u00e9 zneu\u017eite\u013en\u00e9 zranite\u013enosti. S\u00fa\u010dasne Red Teamu sta\u010d\u00ed spravi\u0165 jednu chybu, aby ho Blue Team dok\u00e1zal odhali\u0165 (a napr\u00edklad \u00faplne zablokova\u0165) a Red Team mus\u00ed za\u010da\u0165 odznova.<\/span><\/p>\n<h1><span style=\"font-weight: 400;\">2 Priebeh Red Teamingu<\/span><\/h1>\n<h2><span style=\"font-weight: 400;\">2.1 Z\u00edskavanie inform\u00e1ci\u00ed (information gathering)<\/span><\/h2>\n<p><span style=\"font-weight: 400;\">Ide o pas\u00edvnu, \u00favodn\u00fa f\u00e1zu Red Teamingu. Cie\u013eom tejto f\u00e1zy je z verejne dostupn\u00fdch zdrojov (datab\u00e1z, registrov, vyh\u013ead\u00e1va\u010dov, soci\u00e1lnych siet\u00ed) z\u00edska\u0165 \u010do najviac inform\u00e1ci\u00ed, ktor\u00e9 m\u00f4\u017eu by\u0165 vyu\u017eit\u00e9 pri \u010fal\u0161om prieniku. Ide hlavne o:<\/span><span style=\"font-weight: 400;\"><br \/>\n<\/span><\/p>\n<ul>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">IP adresn\u00e9 rozsahy, IP adresy, ktor\u00e9 bud\u00fa \u010falej predmetom akt\u00edvneho testovania (ich zoznam mus\u00ed by\u0165 explicitne schv\u00e1len\u00fd z\u00e1kazn\u00edkom)<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Zoznam zamestnancov a ich osobn\u00fdch inform\u00e1ci\u00ed (e-mailov\u00e9 adresy, telef\u00f3nne \u010d\u00edsla, osobn\u00e9 preferencie, technol\u00f3gie, ktor\u00e9 pou\u017e\u00edvaj\u00fa, miesta, kde sa vyskytuj\u00fa, pr\u00edpadne \u013eudia, ktor\u00fdm veria a s ktor\u00fdmi komunikuj\u00fa). Tieto inform\u00e1cie bud\u00fa n\u00e1sledne vyu\u017eit\u00e9 vo f\u00e1ze cielen\u00e9ho soci\u00e1lneho in\u017einierstva a enumera\u010dn\u00fdch \u00fatokoch<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Identifik\u00e1ciu partnerov z\u00e1kazn\u00edkov (pre pr\u00edpadn\u00fa impersonifik\u00e1ciu vo f\u00e1ze soci\u00e1lneho in\u017einierstva)<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Identifik\u00e1ciu fyzick\u00fdch budov, kancel\u00e1rskych priestorov, popis ich zabezpe\u010denia (pre pr\u00edpad fyzickej infiltr\u00e1cie)<\/span><\/li>\n<\/ul>\n<h2><span style=\"font-weight: 400;\">2.2 Cielen\u00fd \u00fatok na infra\u0161trukt\u00faru a zamestnancov organiz\u00e1cie<\/span><\/h2>\n<p><span style=\"font-weight: 400;\">Cielen\u00fd \u00fatok na infra\u0161trukt\u00faru aj zamestnancov organiz\u00e1cie m\u00f4\u017ee prebieha\u0165 paralelne. \u010clenovia Red Teamu s\u00fa v neust\u00e1lom kontakte, inform\u00e1cie navz\u00e1jom si zdie\u013eaj\u00fa a vyu\u017e\u00edvaj\u00fa pri samotnom \u00fatoku.<\/span><\/p>\n<h3><span style=\"font-weight: 400;\">2.2.1 <\/span><a href=\"https:\/\/nethemba.com\/sk\/sluzby\/sietova-a-systemova-bezpecnost\/externy-blackbox-penetracny-test\/\"><span style=\"font-weight: 400;\">Blackbox penetra\u010dn\u00fd test externej infra\u0161trukt\u00fary<\/span><\/a><\/h3>\n<p><span style=\"font-weight: 400;\">Blacbox penetra\u010dn\u00fd test externej infra\u0161trukt\u00fary je mo\u017en\u00e9 vykona\u0165 hne\u010f po tom ako zad\u00e1vate\u013e (White Team) schv\u00e1li zoznam odhalen\u00fdch cie\u013eov \u00fatoku (s cie\u013eom znemo\u017eni\u0165 \u00fatoky na nepovolen\u00e9 adresn\u00e9 rozsahy).<\/span><\/p>\n<p><span style=\"font-weight: 400;\">Na rozdiel od be\u017en\u00e9ho blackbox penetra\u010dn\u00e9ho testu, tento prebieha v maxim\u00e1lnom utajen\u00ed (tzv. \u201cstealth re\u017eime\u201d), bu\u010f z unik\u00e1tnych VPN alebo Tor uzlov, ktor\u00e9 s\u00fa pod\u013ea potreby menen\u00e9. \u0160tandardn\u00fdm cie\u013eom je z\u00edska\u0165 pr\u00edstup do internej siete (z\u00edskanie VPN pr\u00edstupov, kompromitovanie serverov v DMZ, cielen\u00e9 \u00fatoky na klientov &#8211; vi\u010f ni\u017e\u0161ie \u201csoci\u00e1lne in\u017einierstvo).<\/span><\/p>\n<h3><span style=\"font-weight: 400;\">2.2.2\u00a0<a href=\"https:\/\/nethemba.com\/sk\/sluzby\/it-bezpecnostne-sluzby\/socialne-inzinierstvo\/\">Soci\u00e1lne in\u017einierstvo<\/a><\/span><\/h3>\n<p><span style=\"font-weight: 400;\">Soci\u00e1lne in\u017einierstvo (vo forme spear phishingu \u010di fyzickej infiltr\u00e1cie) m\u00e1 podobne ako penetra\u010dn\u00fd test vyt\u00fd\u010den\u00fd konkr\u00e9tny cie\u013e (\u201cflag\u201d) a vyu\u017e\u00edva v\u0161etky met\u00f3dy (ktor\u00e9 nie s\u00fa explicitne zak\u00e1zan\u00e9 z\u00e1kazn\u00edkom) na jeho dosiahnutie. Tam patr\u00ed cielen\u00fd phishing (spear phishing), \u010dastokr\u00e1t so \u0161peci\u00e1lne upraven\u00fdm malv\u00e9rom, ktor\u00e9ho cie\u013eom je kompromitova\u0165 koncov\u00e9ho mailov\u00e9ho klienta alebo prehliada\u010d a z\u00edska\u0165 pr\u00edstup do internej siete. \u010castokr\u00e1t sa na to vyu\u017e\u00edvaj\u00fa d\u00f4veryhodne vyzeraj\u00face podvrhnut\u00e9 internetov\u00e9 dom\u00e9ny, falo\u0161n\u00e9 certifik\u00e1ty at\u010f.<\/span><\/p>\n<h2><span style=\"font-weight: 400;\">2.3 Eskal\u00e1cia opr\u00e1vnen\u00ed a \u010fal\u0161ia infiltr\u00e1cia<\/span><\/h2>\n<p><b><\/b><span style=\"font-weight: 400;\">V pr\u00edpade, \u017ee \u00fatok na infra\u0161trukt\u00faru alebo zamestnancov organiz\u00e1cie je \u00faspe\u0161n\u00fd a Red Team z\u00edska pr\u00edstupov\u00e9 \u00fadaje do intern\u00fdch syst\u00e9mov alebo sa mu podar\u00ed fyzicky dosta\u0165 do budovy, tak pokra\u010duje v eskal\u00e1cii opr\u00e1vnen\u00ed a \u010fal\u0161ej infiltr\u00e1cii.<\/span><\/p>\n<h3><span style=\"font-weight: 400;\">2.3.1 \u00datok v internej sieti<\/span><\/h3>\n<p><span style=\"font-weight: 400;\">Z\u00edskanie VPN pou\u017e\u00edvate\u013ea alebo ak\u00e9hoko\u013evek intern\u00e9ho pr\u00edstupu (z extern\u00fdch penetra\u010dn\u00fdch testov alebo soci\u00e1lneho in\u017einierstva) znamen\u00e1, \u017ee Red Team pokra\u010duje \u00fatokmi v internej sieti. Toto m\u00f4\u017eu by\u0165 \u00fatoky na L2\/L3 vrstve (napr\u00edklad ARP poisoning) s cie\u013eom z\u00edska\u0165 kontrolu nad komunik\u00e1ciou intern\u00fdch stan\u00edc alebo serverov (pou\u017eit\u00e9 techniky s\u00fa podobn\u00e9 <\/span><a href=\"https:\/\/nethemba.com\/sk\/sluzby\/sietova-a-systemova-bezpecnost\/penetracny-test-intranetu\/\"><span style=\"font-weight: 400;\">intern\u00e9mu penetra\u010dn\u00e9mu testu<\/span><\/a><span style=\"font-weight: 400;\">).<\/span><\/p>\n<p><span style=\"font-weight: 400;\">Ak cie\u013eov\u00e1 vlajka nie je definovan\u00e1 inak, cie\u013eom je eskal\u00e1cia opr\u00e1vnen\u00ed na dom\u00e9nov\u00e9ho administr\u00e1tora\/ root pou\u017e\u00edvate\u013ea k\u013e\u00fa\u010dov\u00fdch serverov \u010di plnej kontrole nad hlavnou sie\u0165ovou br\u00e1nou.<\/span><\/p>\n<p><span style=\"font-weight: 400;\">\u00datok v internej sieti m\u00f4\u017ee znamena\u0165 pre Red Team tie\u017e nasadenie zadn\u00fdch vr\u00e1tok (tzv. \u201cbackdoors\u201d), v pr\u00edpade, \u017ee Blue Team dan\u00e9 zneu\u017eit\u00e9 zranite\u013enosti oprav\u00ed.<\/span><\/p>\n<h3><span style=\"font-weight: 400;\">2.3.2 Pokra\u010dovanie fyzickej infiltr\u00e1cie<\/span><\/h3>\n<p><span style=\"font-weight: 400;\">Ak sa Red Team fyzicky dostane do budovy organiz\u00e1cie, tak pokra\u010duje v infiltr\u00e1cii. Ak cie\u013eov\u00e1 vlajka nie je definovan\u00e1 inak, tak obvykle je d\u00f4le\u017eit\u00e9 z\u00edska\u0165 fyzick\u00fd pr\u00edstup do serverovne \u010di fyzick\u00e9ho arch\u00edvu citliv\u00fdch dokumentov (pracov\u0148a CEO). Na tento \u00fa\u010del \u010dlenovia Red Teamu pou\u017e\u00edvaj\u00fa \u0161pecializovan\u00fd hardv\u00e9r (mini kamery, portabiln\u00e9 wifi hotspoty, klonovacie zariadenia na \u010dipov\u00e9 karty at\u010f). Disponuj\u00fa tie\u017e tzv. \u201cGet out of jail letter\u201d, teda ofici\u00e1lnym dokumentom, ktor\u00fdm sa preuk\u00e1\u017eu v pr\u00edpade, \u017ee bud\u00fa prichyten\u00ed s cie\u013eom pred\u00eds\u0165 pr\u00edpadn\u00e9mu n\u00e1siliu.<\/span><\/p>\n<h1><span style=\"font-weight: 400;\">3 V\u00fdsledn\u00e1 spr\u00e1va<\/span><\/h1>\n<p><span style=\"font-weight: 400;\">V\u00fdsledn\u00e1 spr\u00e1va okrem mana\u017e\u00e9rskeho zhrnutia obsahuje zoznam v\u0161etk\u00fdch ciest (v\u00e4\u010d\u0161ina je slep\u00fdch), ktor\u00e9 Red Team vysk\u00fa\u0161al. Dokumentuje presn\u00fd priebeh ako sa Red Team z\u00edskal k dan\u00e9mu cie\u013eu a ak\u00fdm n\u00e1strah\u00e1m po\u010das tohto procesu musel \u010deli\u0165. S\u00fa\u010das\u0165ou je zoznam zneu\u017eit\u00fdch zranite\u013enost\u00ed vr\u00e1tane toho ako uveden\u00fa zranite\u013enos\u0165 bu\u010f \u00faplne alebo aspo\u0148 \u010diasto\u010dne opravi\u0165.<\/span><\/p>\n<h1><span style=\"font-weight: 400;\">Odol\u00e1te profesion\u00e1lne veden\u00e9mu \u00fatoku?<\/span><\/h1>\n<p><span style=\"font-weight: 400;\">S na\u0161ou Red Teaming slu\u017ebou sa to m\u00f4\u017eete dozvedie\u0165 behom p\u00e1r t\u00fd\u017ed\u0148ov. Vysk\u00fa\u0161ajte ju a nechajte sa prekvapi\u0165.<\/span><\/p>\n<p><span style=\"font-weight: 400;\">V Nethembe m\u00e1me 14-ro\u010dn\u00e9 sk\u00fasenosti so v\u0161etk\u00fdmi f\u00e1zami Red Teamingu, realizovali sme ich nespo\u010detne ve\u013eakr\u00e1t pri komplexn\u00fdch, koordinovan\u00fdch \u00fatokoch. S\u00fa\u010dasne m\u00e1me ve\u013ea sk\u00fasenosti so \u0161kolen\u00edm syst\u00e9mov\u00fdch administr\u00e1torov (Blue Team) a vyvoj\u00e1rov aplik\u00e1cie (Red Team).<\/span><\/p>\n","protected":false},"excerpt":{"rendered":"<p>1 \u010co je Red Teaming? V nasleduj\u00facom \u010dl\u00e1nku si vysvetl\u00edme, \u010do presne znamen\u00e1 \u201cRed Teaming\u201d, v \u010dom sa l\u00ed\u0161\u00ed od tradi\u010dn\u00fdch penetra\u010dn\u00fdch testov, v \u010dom je pr\u00edstup \u201cRed Teamingu\u201d unik\u00e1tny a pre\u010do najlep\u0161ie simuluje re\u00e1lny koordinovan\u00fd \u00fatok. V Nethembe sme \u201cRed Teaming\u201d vykon\u00e1vali mnoho rokov predt\u00fdm ako sa v technickej verejnosti ujal tento term\u00edn &#8211; [&hellip;]<\/p>\n","protected":false},"author":2,"featured_media":5637,"comment_status":"open","ping_status":"open","sticky":false,"template":"","format":"standard","meta":{"inline_featured_image":false,"_monsterinsights_skip_tracking":false,"_monsterinsights_sitenote_active":false,"_monsterinsights_sitenote_note":"","_monsterinsights_sitenote_category":0,"footnotes":""},"categories":[2870,13],"tags":[2899,2898,2900,2896,2906,513,2901],"class_list":["post-5636","post","type-post","status-publish","format-standard","has-post-thumbnail","hentry","category-blog","category-uncategorized-sk","tag-eskalacia-privilegii","tag-fyzicka-infiltracia","tag-infiltracia","tag-red-team","tag-red-teaming-sk","tag-socialne-inzinierstvo-sk","tag-utok"],"yoast_head":"<!-- This site is optimized with the Yoast SEO plugin v27.4 - https:\/\/yoast.com\/product\/yoast-seo-wordpress\/ -->\n<title>Red Teaming - odol\u00e1te profesion\u00e1lne veden\u00e9mu \u00fatoku? - Nethemba<\/title>\n<meta name=\"robots\" content=\"index, follow, max-snippet:-1, max-image-preview:large, max-video-preview:-1\" \/>\n<link rel=\"canonical\" href=\"https:\/\/nethemba.com\/sk\/red-teaming-odolate-profesionalne-vedenemu-utoku\/\" \/>\n<meta property=\"og:locale\" content=\"sk_SK\" \/>\n<meta property=\"og:type\" content=\"article\" \/>\n<meta property=\"og:title\" content=\"Red Teaming - odol\u00e1te profesion\u00e1lne veden\u00e9mu \u00fatoku? - Nethemba\" \/>\n<meta property=\"og:description\" content=\"1 \u010co je Red Teaming? V nasleduj\u00facom \u010dl\u00e1nku si vysvetl\u00edme, \u010do presne znamen\u00e1 \u201cRed Teaming\u201d, v \u010dom sa l\u00ed\u0161\u00ed od tradi\u010dn\u00fdch penetra\u010dn\u00fdch testov, v \u010dom je pr\u00edstup \u201cRed Teamingu\u201d unik\u00e1tny a pre\u010do najlep\u0161ie simuluje re\u00e1lny koordinovan\u00fd \u00fatok. V Nethembe sme \u201cRed Teaming\u201d vykon\u00e1vali mnoho rokov predt\u00fdm ako sa v technickej verejnosti ujal tento term\u00edn &#8211; [&hellip;]\" \/>\n<meta property=\"og:url\" content=\"https:\/\/nethemba.com\/sk\/red-teaming-odolate-profesionalne-vedenemu-utoku\/\" \/>\n<meta property=\"og:site_name\" content=\"Nethemba\" \/>\n<meta property=\"article:publisher\" content=\"https:\/\/www.facebook.com\/nethemba\" \/>\n<meta property=\"article:published_time\" content=\"2021-03-14T00:12:17+00:00\" \/>\n<meta property=\"article:modified_time\" content=\"2021-03-14T12:24:26+00:00\" \/>\n<meta property=\"og:image\" content=\"https:\/\/nethemba.com\/wp-content\/uploads\/2021\/03\/Try-Red-Teaming-Nethemba.png\" \/>\n\t<meta property=\"og:image:width\" content=\"2240\" \/>\n\t<meta property=\"og:image:height\" content=\"1260\" \/>\n\t<meta property=\"og:image:type\" content=\"image\/png\" \/>\n<meta name=\"author\" content=\"Pavol Lupt\u00e1k\" \/>\n<meta name=\"twitter:card\" content=\"summary_large_image\" \/>\n<meta name=\"twitter:creator\" content=\"@nethemba\" \/>\n<meta name=\"twitter:site\" content=\"@nethemba\" \/>\n<meta name=\"twitter:label1\" content=\"Autor\" \/>\n\t<meta name=\"twitter:data1\" content=\"Pavol Lupt\u00e1k\" \/>\n\t<meta name=\"twitter:label2\" content=\"Predpokladan\u00fd \u010das \u010d\u00edtania\" \/>\n\t<meta name=\"twitter:data2\" content=\"7 min\u00fat\" \/>\n<script type=\"application\/ld+json\" class=\"yoast-schema-graph\">{\"@context\":\"https:\\\/\\\/schema.org\",\"@graph\":[{\"@type\":\"Article\",\"@id\":\"https:\\\/\\\/nethemba.com\\\/sk\\\/red-teaming-odolate-profesionalne-vedenemu-utoku\\\/#article\",\"isPartOf\":{\"@id\":\"https:\\\/\\\/nethemba.com\\\/sk\\\/red-teaming-odolate-profesionalne-vedenemu-utoku\\\/\"},\"author\":{\"name\":\"Pavol Lupt\u00e1k\",\"@id\":\"https:\\\/\\\/nethemba.com\\\/de\\\/#\\\/schema\\\/person\\\/5f4ba68c8e1a2013d30e0804245b8234\"},\"headline\":\"Red Teaming &#8211; odol\u00e1te profesion\u00e1lne veden\u00e9mu \u00fatoku?\",\"datePublished\":\"2021-03-14T00:12:17+00:00\",\"dateModified\":\"2021-03-14T12:24:26+00:00\",\"mainEntityOfPage\":{\"@id\":\"https:\\\/\\\/nethemba.com\\\/sk\\\/red-teaming-odolate-profesionalne-vedenemu-utoku\\\/\"},\"wordCount\":1482,\"commentCount\":0,\"image\":{\"@id\":\"https:\\\/\\\/nethemba.com\\\/sk\\\/red-teaming-odolate-profesionalne-vedenemu-utoku\\\/#primaryimage\"},\"thumbnailUrl\":\"https:\\\/\\\/nethemba.com\\\/wp-content\\\/uploads\\\/2021\\\/03\\\/Try-Red-Teaming-Nethemba.png\",\"keywords\":[\"eskal\u00e1cia privil\u00e9gi\u00ed\",\"fyzick\u00e1 infiltr\u00e1cia\",\"infiltr\u00e1cia\",\"red team\",\"red teaming\",\"soci\u00e1lne in\u017einierstvo\",\"\u00fatok\"],\"articleSection\":[\"Blog\",\"Uncategorized @sk\"],\"inLanguage\":\"sk-SK\",\"potentialAction\":[{\"@type\":\"CommentAction\",\"name\":\"Comment\",\"target\":[\"https:\\\/\\\/nethemba.com\\\/sk\\\/red-teaming-odolate-profesionalne-vedenemu-utoku\\\/#respond\"]}]},{\"@type\":\"WebPage\",\"@id\":\"https:\\\/\\\/nethemba.com\\\/sk\\\/red-teaming-odolate-profesionalne-vedenemu-utoku\\\/\",\"url\":\"https:\\\/\\\/nethemba.com\\\/sk\\\/red-teaming-odolate-profesionalne-vedenemu-utoku\\\/\",\"name\":\"Red Teaming - odol\u00e1te profesion\u00e1lne veden\u00e9mu \u00fatoku? - Nethemba\",\"isPartOf\":{\"@id\":\"https:\\\/\\\/nethemba.com\\\/de\\\/#website\"},\"primaryImageOfPage\":{\"@id\":\"https:\\\/\\\/nethemba.com\\\/sk\\\/red-teaming-odolate-profesionalne-vedenemu-utoku\\\/#primaryimage\"},\"image\":{\"@id\":\"https:\\\/\\\/nethemba.com\\\/sk\\\/red-teaming-odolate-profesionalne-vedenemu-utoku\\\/#primaryimage\"},\"thumbnailUrl\":\"https:\\\/\\\/nethemba.com\\\/wp-content\\\/uploads\\\/2021\\\/03\\\/Try-Red-Teaming-Nethemba.png\",\"datePublished\":\"2021-03-14T00:12:17+00:00\",\"dateModified\":\"2021-03-14T12:24:26+00:00\",\"author\":{\"@id\":\"https:\\\/\\\/nethemba.com\\\/de\\\/#\\\/schema\\\/person\\\/5f4ba68c8e1a2013d30e0804245b8234\"},\"breadcrumb\":{\"@id\":\"https:\\\/\\\/nethemba.com\\\/sk\\\/red-teaming-odolate-profesionalne-vedenemu-utoku\\\/#breadcrumb\"},\"inLanguage\":\"sk-SK\",\"potentialAction\":[{\"@type\":\"ReadAction\",\"target\":[\"https:\\\/\\\/nethemba.com\\\/sk\\\/red-teaming-odolate-profesionalne-vedenemu-utoku\\\/\"]}]},{\"@type\":\"ImageObject\",\"inLanguage\":\"sk-SK\",\"@id\":\"https:\\\/\\\/nethemba.com\\\/sk\\\/red-teaming-odolate-profesionalne-vedenemu-utoku\\\/#primaryimage\",\"url\":\"https:\\\/\\\/nethemba.com\\\/wp-content\\\/uploads\\\/2021\\\/03\\\/Try-Red-Teaming-Nethemba.png\",\"contentUrl\":\"https:\\\/\\\/nethemba.com\\\/wp-content\\\/uploads\\\/2021\\\/03\\\/Try-Red-Teaming-Nethemba.png\",\"width\":2240,\"height\":1260},{\"@type\":\"BreadcrumbList\",\"@id\":\"https:\\\/\\\/nethemba.com\\\/sk\\\/red-teaming-odolate-profesionalne-vedenemu-utoku\\\/#breadcrumb\",\"itemListElement\":[{\"@type\":\"ListItem\",\"position\":1,\"name\":\"Home\",\"item\":\"https:\\\/\\\/nethemba.com\\\/sk\\\/domov\\\/\"},{\"@type\":\"ListItem\",\"position\":2,\"name\":\"Red Teaming &#8211; odol\u00e1te profesion\u00e1lne veden\u00e9mu \u00fatoku?\"}]},{\"@type\":\"WebSite\",\"@id\":\"https:\\\/\\\/nethemba.com\\\/de\\\/#website\",\"url\":\"https:\\\/\\\/nethemba.com\\\/de\\\/\",\"name\":\"Nethemba\",\"description\":\"We care about your security\",\"potentialAction\":[{\"@type\":\"SearchAction\",\"target\":{\"@type\":\"EntryPoint\",\"urlTemplate\":\"https:\\\/\\\/nethemba.com\\\/de\\\/?s={search_term_string}\"},\"query-input\":{\"@type\":\"PropertyValueSpecification\",\"valueRequired\":true,\"valueName\":\"search_term_string\"}}],\"inLanguage\":\"sk-SK\"},{\"@type\":\"Person\",\"@id\":\"https:\\\/\\\/nethemba.com\\\/de\\\/#\\\/schema\\\/person\\\/5f4ba68c8e1a2013d30e0804245b8234\",\"name\":\"Pavol Lupt\u00e1k\",\"image\":{\"@type\":\"ImageObject\",\"inLanguage\":\"sk-SK\",\"@id\":\"https:\\\/\\\/secure.gravatar.com\\\/avatar\\\/978b23022518d076eaa243b375d2e0272af4f00dd502ce79cc357276d9bc2495?s=96&d=mm&r=g\",\"url\":\"https:\\\/\\\/secure.gravatar.com\\\/avatar\\\/978b23022518d076eaa243b375d2e0272af4f00dd502ce79cc357276d9bc2495?s=96&d=mm&r=g\",\"contentUrl\":\"https:\\\/\\\/secure.gravatar.com\\\/avatar\\\/978b23022518d076eaa243b375d2e0272af4f00dd502ce79cc357276d9bc2495?s=96&d=mm&r=g\",\"caption\":\"Pavol Lupt\u00e1k\"},\"sameAs\":[\"https:\\\/\\\/www.nethemba.com\\\/\"],\"url\":\"https:\\\/\\\/nethemba.com\\\/sk\\\/author\\\/nethemba-admin\\\/\"}]}<\/script>\n<!-- \/ Yoast SEO plugin. -->","yoast_head_json":{"title":"Red Teaming - odol\u00e1te profesion\u00e1lne veden\u00e9mu \u00fatoku? - Nethemba","robots":{"index":"index","follow":"follow","max-snippet":"max-snippet:-1","max-image-preview":"max-image-preview:large","max-video-preview":"max-video-preview:-1"},"canonical":"https:\/\/nethemba.com\/sk\/red-teaming-odolate-profesionalne-vedenemu-utoku\/","og_locale":"sk_SK","og_type":"article","og_title":"Red Teaming - odol\u00e1te profesion\u00e1lne veden\u00e9mu \u00fatoku? - Nethemba","og_description":"1 \u010co je Red Teaming? V nasleduj\u00facom \u010dl\u00e1nku si vysvetl\u00edme, \u010do presne znamen\u00e1 \u201cRed Teaming\u201d, v \u010dom sa l\u00ed\u0161\u00ed od tradi\u010dn\u00fdch penetra\u010dn\u00fdch testov, v \u010dom je pr\u00edstup \u201cRed Teamingu\u201d unik\u00e1tny a pre\u010do najlep\u0161ie simuluje re\u00e1lny koordinovan\u00fd \u00fatok. V Nethembe sme \u201cRed Teaming\u201d vykon\u00e1vali mnoho rokov predt\u00fdm ako sa v technickej verejnosti ujal tento term\u00edn &#8211; [&hellip;]","og_url":"https:\/\/nethemba.com\/sk\/red-teaming-odolate-profesionalne-vedenemu-utoku\/","og_site_name":"Nethemba","article_publisher":"https:\/\/www.facebook.com\/nethemba","article_published_time":"2021-03-14T00:12:17+00:00","article_modified_time":"2021-03-14T12:24:26+00:00","og_image":[{"width":2240,"height":1260,"url":"https:\/\/nethemba.com\/wp-content\/uploads\/2021\/03\/Try-Red-Teaming-Nethemba.png","type":"image\/png"}],"author":"Pavol Lupt\u00e1k","twitter_card":"summary_large_image","twitter_creator":"@nethemba","twitter_site":"@nethemba","twitter_misc":{"Autor":"Pavol Lupt\u00e1k","Predpokladan\u00fd \u010das \u010d\u00edtania":"7 min\u00fat"},"schema":{"@context":"https:\/\/schema.org","@graph":[{"@type":"Article","@id":"https:\/\/nethemba.com\/sk\/red-teaming-odolate-profesionalne-vedenemu-utoku\/#article","isPartOf":{"@id":"https:\/\/nethemba.com\/sk\/red-teaming-odolate-profesionalne-vedenemu-utoku\/"},"author":{"name":"Pavol Lupt\u00e1k","@id":"https:\/\/nethemba.com\/de\/#\/schema\/person\/5f4ba68c8e1a2013d30e0804245b8234"},"headline":"Red Teaming &#8211; odol\u00e1te profesion\u00e1lne veden\u00e9mu \u00fatoku?","datePublished":"2021-03-14T00:12:17+00:00","dateModified":"2021-03-14T12:24:26+00:00","mainEntityOfPage":{"@id":"https:\/\/nethemba.com\/sk\/red-teaming-odolate-profesionalne-vedenemu-utoku\/"},"wordCount":1482,"commentCount":0,"image":{"@id":"https:\/\/nethemba.com\/sk\/red-teaming-odolate-profesionalne-vedenemu-utoku\/#primaryimage"},"thumbnailUrl":"https:\/\/nethemba.com\/wp-content\/uploads\/2021\/03\/Try-Red-Teaming-Nethemba.png","keywords":["eskal\u00e1cia privil\u00e9gi\u00ed","fyzick\u00e1 infiltr\u00e1cia","infiltr\u00e1cia","red team","red teaming","soci\u00e1lne in\u017einierstvo","\u00fatok"],"articleSection":["Blog","Uncategorized @sk"],"inLanguage":"sk-SK","potentialAction":[{"@type":"CommentAction","name":"Comment","target":["https:\/\/nethemba.com\/sk\/red-teaming-odolate-profesionalne-vedenemu-utoku\/#respond"]}]},{"@type":"WebPage","@id":"https:\/\/nethemba.com\/sk\/red-teaming-odolate-profesionalne-vedenemu-utoku\/","url":"https:\/\/nethemba.com\/sk\/red-teaming-odolate-profesionalne-vedenemu-utoku\/","name":"Red Teaming - odol\u00e1te profesion\u00e1lne veden\u00e9mu \u00fatoku? - Nethemba","isPartOf":{"@id":"https:\/\/nethemba.com\/de\/#website"},"primaryImageOfPage":{"@id":"https:\/\/nethemba.com\/sk\/red-teaming-odolate-profesionalne-vedenemu-utoku\/#primaryimage"},"image":{"@id":"https:\/\/nethemba.com\/sk\/red-teaming-odolate-profesionalne-vedenemu-utoku\/#primaryimage"},"thumbnailUrl":"https:\/\/nethemba.com\/wp-content\/uploads\/2021\/03\/Try-Red-Teaming-Nethemba.png","datePublished":"2021-03-14T00:12:17+00:00","dateModified":"2021-03-14T12:24:26+00:00","author":{"@id":"https:\/\/nethemba.com\/de\/#\/schema\/person\/5f4ba68c8e1a2013d30e0804245b8234"},"breadcrumb":{"@id":"https:\/\/nethemba.com\/sk\/red-teaming-odolate-profesionalne-vedenemu-utoku\/#breadcrumb"},"inLanguage":"sk-SK","potentialAction":[{"@type":"ReadAction","target":["https:\/\/nethemba.com\/sk\/red-teaming-odolate-profesionalne-vedenemu-utoku\/"]}]},{"@type":"ImageObject","inLanguage":"sk-SK","@id":"https:\/\/nethemba.com\/sk\/red-teaming-odolate-profesionalne-vedenemu-utoku\/#primaryimage","url":"https:\/\/nethemba.com\/wp-content\/uploads\/2021\/03\/Try-Red-Teaming-Nethemba.png","contentUrl":"https:\/\/nethemba.com\/wp-content\/uploads\/2021\/03\/Try-Red-Teaming-Nethemba.png","width":2240,"height":1260},{"@type":"BreadcrumbList","@id":"https:\/\/nethemba.com\/sk\/red-teaming-odolate-profesionalne-vedenemu-utoku\/#breadcrumb","itemListElement":[{"@type":"ListItem","position":1,"name":"Home","item":"https:\/\/nethemba.com\/sk\/domov\/"},{"@type":"ListItem","position":2,"name":"Red Teaming &#8211; odol\u00e1te profesion\u00e1lne veden\u00e9mu \u00fatoku?"}]},{"@type":"WebSite","@id":"https:\/\/nethemba.com\/de\/#website","url":"https:\/\/nethemba.com\/de\/","name":"Nethemba","description":"We care about your security","potentialAction":[{"@type":"SearchAction","target":{"@type":"EntryPoint","urlTemplate":"https:\/\/nethemba.com\/de\/?s={search_term_string}"},"query-input":{"@type":"PropertyValueSpecification","valueRequired":true,"valueName":"search_term_string"}}],"inLanguage":"sk-SK"},{"@type":"Person","@id":"https:\/\/nethemba.com\/de\/#\/schema\/person\/5f4ba68c8e1a2013d30e0804245b8234","name":"Pavol Lupt\u00e1k","image":{"@type":"ImageObject","inLanguage":"sk-SK","@id":"https:\/\/secure.gravatar.com\/avatar\/978b23022518d076eaa243b375d2e0272af4f00dd502ce79cc357276d9bc2495?s=96&d=mm&r=g","url":"https:\/\/secure.gravatar.com\/avatar\/978b23022518d076eaa243b375d2e0272af4f00dd502ce79cc357276d9bc2495?s=96&d=mm&r=g","contentUrl":"https:\/\/secure.gravatar.com\/avatar\/978b23022518d076eaa243b375d2e0272af4f00dd502ce79cc357276d9bc2495?s=96&d=mm&r=g","caption":"Pavol Lupt\u00e1k"},"sameAs":["https:\/\/www.nethemba.com\/"],"url":"https:\/\/nethemba.com\/sk\/author\/nethemba-admin\/"}]}},"_links":{"self":[{"href":"https:\/\/nethemba.com\/sk\/wp-json\/wp\/v2\/posts\/5636","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/nethemba.com\/sk\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/nethemba.com\/sk\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/nethemba.com\/sk\/wp-json\/wp\/v2\/users\/2"}],"replies":[{"embeddable":true,"href":"https:\/\/nethemba.com\/sk\/wp-json\/wp\/v2\/comments?post=5636"}],"version-history":[{"count":0,"href":"https:\/\/nethemba.com\/sk\/wp-json\/wp\/v2\/posts\/5636\/revisions"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/nethemba.com\/sk\/wp-json\/wp\/v2\/media\/5637"}],"wp:attachment":[{"href":"https:\/\/nethemba.com\/sk\/wp-json\/wp\/v2\/media?parent=5636"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/nethemba.com\/sk\/wp-json\/wp\/v2\/categories?post=5636"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/nethemba.com\/sk\/wp-json\/wp\/v2\/tags?post=5636"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}