Sr. Director of Research at Mitiga, working on cloud threats and incident response. Before that, Global Director of Offensive Services at AB InBev. Before that, I built the red team at EY Israel.
Red teams#
Most people hear “red team” and think penetration testing. It’s not. A red team is devil’s advocate, the tenth man, opposing force. The job is attacking the assumption, not just the network.
I’ve made that argument twice, seven years apart, in two languages: Adversarial Mindset and On Red Teams.
Background#
B.A. in Business Administration with a major in Cyber Security. M.A. in Criminology.
The criminology is the half I use most. Offensive security teaches you how a system breaks. Criminology teaches you why someone decides to break it.
Red teaming, social engineering, physical security, cloud, incident response.
Tools#
I’m not a developer. I write tools when I need something that doesn’t exist. ADFSpray, RDPassSpray, Disruption, ghosttype and a few others are on GitHub, most with a post here about what they solve.
Speaking#
BSidesLV, CODE BLUE, DeepSec, BSidesVienna, and a lot of meetups. It’s all on the talks page.
I co-organize BSidesTLV, sit on the CFP team for The Diana Initiative, and I’m a DEF CON Goon and a Trace Labs judge. I like the reviewing side as much as the speaking.
Contact#
- [email protected]
- Signal:
xFreed0m.55, for anything sensitive - GitHub and LinkedIn
