The Red-Book
The Art of Offensive CyberSecurity


The Art of Offensive CyberSecurity
Technical notes and cheat sheets for red teamers, pentesters and security researchers, sourced from research papers, industry blogs and field experience, and kept in one place.
Where to start
Red-Teaming
The host and endpoint attack lifecycle, ordered by the ATT&CK kill chain: recon, execution, persistence, privilege escalation, evasion, credential access, lateral movement, exfiltration.
Active Directory
The deepest tree in the book: Kerberos, NTLM, AD-CS, DACLs, delegations, coerced authentication, SCCM/MECM, trusts and persistence.
Web Pentesting
Server-side and client-side vulnerabilities, plus the infrastructure underneath: web servers, CMSs, frameworks and DBMSs.
Network & Wireless
Service-by-service notes for the protocols you meet on an engagement, plus WiFi and Bluetooth.
Cloud & CI/CD
AWS and Entra ID identity abuse, Kubernetes, containers, and the pipelines that deploy them.
Smart Contracts
EVM attack surfaces, upgradeability patterns and protocol-layer weaknesses, tagged with SCWE identifiers.
AI Red-Teaming
Attacking LLMs, RAG pipelines, ML models, and the agents and training infrastructure around them.
About this book
The Red-Book by infiltr8 collects practical knowledge rooted in real-world experience. Techniques and methodologies here have been vetted and tested, but we are human, so mistakes are possible. Corrections are welcome.
Offensive security is not about malicious intent. It is about understanding the tactics an adversary would use, and applying that understanding to defend against them. Knowledge is power, and with power comes responsibility.
Contributions, feedback and suggestions are welcome. Open an issue or a pull request on GitHub.
Around 90% of the Active Directory content originates from The Hacker Recipes. Many thanks to Charlie Bromberg for that work.
Disclaimer
The information here is provided for educational and informational purposes only.
- No unlawful activity. Using anything in this book for unauthorised access or any activity that violates applicable law is strictly prohibited.
- Ethical use. Apply these techniques only where you have explicit authorisation to do so.
- Your responsibility. You alone are accountable for your actions and their consequences. infiltr8 and its contributors accept no liability for misuse.
- No guarantees. We aim for accuracy but make no warranty as to completeness or reliability, so verify independently.
- External links and tools. Mentioning a tool or service is not an endorsement, and we are not responsible for third-party content or security.
By using this site you accept these terms. If you do not agree with them, please do not use it.