Know Your Adversary | The State of APM: Tradecraft Trends (Ep. 6)

Know Your Adversary | The State of APM: Tradecraft Trends (Ep. 6)

Source: YouTube · SpecterOps · published Nov 13, 2025 · 20:44

Penetration Testing
No ratings yet Log in to rate
Transcript Available
Description

[BLUF] Andrew Charles, VP of Tradecraft at Spectre Ops, discusses emerging trends in attacker tradecraft, emphasizing the shift towards sophisticated, multi-stage operations and the critical need for defenders to understand adversary methodologies to improve detection and response 0:18.

Key Takeaways:
• Charles explains his role involves overseeing tradecraft creation, refining it for training, and informing consultants to better enable clients and the security community 0:30.
• The discussion highlights how attackers are increasingly adopting complex tradecraft techniques that mimic legitimate behavior to evade detection, requiring defenders to stay ahead of these evolving tactics 0:45.
• There is a significant trend toward the automation and customization of attack tools, allowing adversaries to scale operations while maintaining a low profile across diverse environments 1:15.
• Defenders must shift from purely signature-based detection to behavior-based analysis to identify the subtle indicators of compromise associated with modern tradecraft 1:45.

Understanding these trends is essential for proactive defense strategies. By studying attacker tradecraft, organizations can better anticipate threats and strengthen their overall security posture.

Sources:

  • 0:18 Introduction of Andrew Charles and the podcast topic.
  • 0:30 Overview of Spectre Ops' role in tradecraft and training.
  • 0:45 Discussion on enabling clients and the community.
  • 1:15 Trends in attacker tool automation and customizatio

Generate CPE Credits

Generate a professional CPE document from this video's transcript.

Estimated credit: 0.5 CPE hours

Estimate uses the video runtime (1 hour ≈ 1 CPE, rounded to the nearest 0.5, minimum 0.5, maximum 2.0). The final amount can be lower after review, never higher.

Topic: Penetration Testing. Commonly maps to: Security Assessment and Testing, Security Operations. Exact CISSP domains are assigned during generation.

CISSP Domain Mapping
Learning Objectives
Self-Assessment Questions
PDF Export Ready

Free account. One generation at a time, with a daily limit.

CPEBuddy is independent and not affiliated with or endorsed by ISC2, ISACA, or any certification body. Exports are formatted for common CPE submissions; acceptance is at your certification body's discretion.

Watch on YouTube

Transcript Preview

First 800 characters of the transcript

Hi, welcome back to the Know Your Adversary podcast. I'm Justin Kohler. I'm joined by Jared Atinson. Uh today we have Andrew Charles who's talking about trends in attacker tradecraft. Uh Andrew, what uh what made you want to, you know, put that article out? like kind of give your overview of your role and like what gives you that like overview of what's going on. >> Well, my my current role at Spectre Ops as VP of Tradecraft is really to oversee all the tradecraftraft at Spectre Ops and how we one create that and distill it into trainings and um inform our consultants on what that tradecraftraft is, refine it, help enable them, our clients and our community as well. So triple C consultants, clients and community. I made that up. So uh from that one of the things we want to do as well is en…