Things I like and recommend. No affiliations, no kickbacks, nothing sponsored.

Dead entries stay on the list, struck through, with a note on what happened. A lot of this thinking came from them.

Blogs#

  • Red Team Journal (site offline, returns 404). The closest thing the field had to a journal of record on red teaming as an idea. Most of what I argue about definitions traces back here.
  • Red Team Journal-Plus (domain no longer resolves). The paid companion, gone with it.
  • Redteams.net (domain lapsed and was re-registered by someone else, deliberately not linked). Was a genuinely good red teaming blog and podcast. The domain belongs to someone else now, so treat anything on it as unrelated.
  • Adversarial Mindset (still up, last post 2022). Treats adversarial thinking as a habit you build, not a toolkit you buy.
  • Modern Adversary. Offensive tradecraft written by someone who does the work, without the vendor voice.
  • 0xmoose
  • Embrace The Red. Attacks and red team strategy, and some of the sharpest AI-attack work happening right now.

Podcasts#

  • Redteams.net (same lapsed domain as above, deliberately not linked). The Red Team Podcast. Worth digging out of an archive if you can find it.
  • Adversarial Conversations (offline, last episode 2019). Only ever two episodes, but the premise was right.
  • Darknet Diaries. The storytelling standard for this industry. Hand it to anyone who asks what you do for a living.
  • Malicious Life. The history of the field, told properly. Context you don’t get from a threat report.

Books#

  • Red Team by Micah Zenko. The case for institutional devil’s advocacy across the military, intelligence and business. The book that names what I keep arguing about.
  • Left of Bang. How to read a baseline and catch the anomaly before anything happens. Makes “trust your gut” into something teachable.
  • Ender’s Game. Thinking from the opponent’s side, long before it was a job title.
  • The Applied Critical Thinking Handbook. The Army’s own red teaming manual. Free, practical, and full of techniques that survive contact with a meeting room.
  • Red Teams and Counterterrorism Training. The academic treatment, and useful for exactly that reason.
  • Surveillance Zone by Ami Toben. What corporate surveillance and surveillance detection actually look like day to day, from someone doing it.
  • Rinsed by Geoff White. Where the money goes after the breach. The part of cybercrime most security people never follow all the way through.
  • Never Split the Difference by Chris Voss. Negotiation as applied empathy. Half of security work is convincing people, and this is the best book on that.
  • Warbreaker by Brandon Sanderson. Not security at all. Sanderson gives it away from his own site, which is its own kind of statement.

Equipment#