Dennis Chow (Detection Engineering Director, back for round two) and Michael LaSalvia (red team lead) join Dispatch to talk about their new book, *Evasion Engineering: Building Custom Red Team Tools for the Modern Defenses*, and what happens when a blue teamer and a red teamer decide to write the playbook together instead of against each other.
In this episode we get into:
- Why off-the-shelf adversary emulation repos are dying, and why building your own evasive tooling, not just running someone else's, makes you a fundamentally better detection engineer
- The trusted advisor model: bringing blue teamers inside red team ops so trust replaces the us vs. them dynamic
- The unmodified Kali header in a packet that blew a six month long campaign
Shared fate as an operating model, borrowed from cloud providers, to stop punishing one side for the other's success
- Go (open-source programming language aka Golang supported by Google) and cross platform payloads: why Windows only red team frameworks have difficulty in keeping up with cloud and identity based attack paths
- Their favorite chapters to write: low and slow exfiltration, and the hybrid packer that finally got past an EDR that wouldn't quit
Follow Dennis & Michael's work on:
- *Evasion Engineering: Building Custom Red Team Tools for the Modern Defenses* — available for pre-order on Packt and Amazon https://www.amazon.com/Evasion-Engineering-Building-Custom-Defenses-ebook/dp/B0GKDC57S8
- VM setup for adversary emulation & testing: https://github.com/Orange-Cyberdefense/GOAD
Detection Dispatch (Alex's Version) is an independent detection engineering & threat hunting podcast. Rebuilt. Community-first. Featuring a lineup of the real and active projects pushing the limits of detection engineering, threat hunting, and everything in between.