100 Days of Red Team
Subscribe
Sign in
Home
Red Team Training
GitHub
YouTube
Uday Mittal's Substack
About
When phishing awareness starts learning from real attacks
Learn how organizations can use LLMs trained on real phishing emails to improve awareness programs.
Jan 13
•
Uday Mittal
3
Most Popular
View all
Using Havoc C2 to bypass UAC
Feb 16, 2025
•
Uday Mittal
1
2
Using PassGAN for effective password cracking
Apr 1, 2025
•
Uday Mittal
Creating a simple beacon object file for Havoc C2
Feb 23, 2025
•
Uday Mittal
2
2
1
Install Havoc C2 on Ubuntu 22.04 (2025)
Jan 19, 2025
•
Uday Mittal
Recent posts
View all
Weaponizing Organization Data - The Rise of target-specific LLMs
Taking a page from DarkBERT’s book to predict the future of Red Teaming. Moving towards LLMs specifically trained for target organizations.
Jan 2
•
Uday Mittal
2
1
5 AI Trends That Redefined Red Teaming in 2025
Learn about the 5 biggest AI trends in red teaming for 2025.
Dec 31, 2025
•
Uday Mittal
Heuristics vs AI Detection: What Actually Changed for Red Teams
Learn how AI-based security differs from traditional signature-based and heuristics-based detection, changing how alerts, risk, and evasion work in…
Dec 30, 2025
•
Uday Mittal
Operationalizing Prompt Injection and AI Jailbreaks
Learn how red teams can abuse AI vulnerabilities like prompt injection and jailbreak in real-world enterprise environments.
Dec 29, 2025
•
Uday Mittal
1
1
Leveraging WebSockets for Command and Control (C2) Communications
A proof of concept to explore how WebSockets can be leveraged for C2 communications and should they be?
Sep 19, 2025
•
Uday Mittal
WebSockets handshake for red team professionals
A simple guide to understanding the WebSocket handshake and how red teams can leverage it.
Sep 17, 2025
•
Uday Mittal
1
Using Velociraptor as C2
Velociraptor repurposed as C2: explore its powers, risks, and real-world misuse in red team operations.
Aug 29, 2025
•
Uday Mittal
2
1
Misusing SaaS app integrations for persistence
Learn how attackers abuse SaaS integrations for hidden persistence and re-entry into enterprise environments.
Aug 28, 2025
•
Uday Mittal
1
See all
Fundamentals
View all
The role of deception in red team ops
Learn how red teams leverage deception for their tradecraft.
Mar 21, 2025
•
Uday Mittal
1
Evaluating security architecture from red team's perspective
Learn how to assess security architecture from a red team's perspective.
Mar 20, 2025
•
Uday Mittal
What is purple teaming?
Let's understand what purple teaming is and how it is tied to red team operations.
Mar 18, 2025
•
Uday Mittal
Applying Outside-In thinking to red team operations
Learn how to use Outside-In thinking strategy for red team operations.
Mar 17, 2025
•
Uday Mittal
Applying 4 Ways of Seeing to red team operations
Learn how the 4 Ways of Seeing technique can be used for red team operations to understand security threats from multiple perspectives.
Mar 16, 2025
•
Uday Mittal
What most red team professionals won't tell you
Read this before you aspire to become a red team professional.
Mar 10, 2025
•
Uday Mittal
1
What is red teaming?
Let's understand what it truly means to red team something.
Mar 8, 2025
•
Uday Mittal
The Red Team Pyramid of Pain
A model showing how progressively advanced red team tradecraft makes it harder for defenders to detect and respond.
Mar 7, 2025
•
Uday Mittal
1
Communicating results of a red team engagement
How to write a report for a red team engagement and considerations to keep in mind while creating the report.
Mar 6, 2025
•
Uday Mittal
Direct and indirect syscalls for red team operations
Learn what are direct and indirect syscalls and their differences for red team tradecraft.
Feb 24, 2025
•
Uday Mittal
Role of threat intelligence in a red team engagement
Learn how red teams leverage threat intelligence for an impactful assessment.
Feb 7, 2025
•
Uday Mittal
1
How to ensure that the red team is setup for success?
Learn about six best practices for the success of a red team.
Feb 3, 2025
•
Uday Mittal
This site requires JavaScript to run correctly. Please
turn on JavaScript
or unblock scripts