Going from a red team lead on numerous international red team engagements and recently a TIBER test to a detection engineer at a large financial institution, perspectives on red teaming change. Come along as we dissect the results of Storebrand's first TIBER test in a brutally honest story covering targeted (successful) social engineering against portfolio managers, the very real human toll of red team testing, (really) expensive red team tools and C2 frameworks being used against us, company wide attack alerts, token theft, defensive failures, pitfalls and huge wins. The talk will explore a reformed red teamers perspective on their previous actions, social engineering tactics, OPSEC, engagement value and what they would do differently were they performing red teaming today.
Eirik Sveen
Eirik is a Senior Detection Engineer at Storebrand CDC, performing threat research and detection engineering. Eirik har previously been the red team lead at Orange Cyberdefense Norway and a red team operator at the Danish boutique red team consultancy Banshie, where he was a part of a team performing red team operations, TIBER, assumed breach assessments and detection validation exercises.
Eirik is also an occasional host of the Norwegian security podcast 5h3llcast and have held talks at both HackCon and Sikkerhetsfestivalen.