
NEW2CTI | Red Teams with Receipts
Source: YouTube · SANS Digital Forensics and Incident Response · published Apr 2, 2026 · 26:15
[BLUF] The presentation outlines how to operationalize Cyber Threat Intelligence (CTI) through rigorous, evidence-based red teaming and adversary simulation to validate defenses against real-world threats 0:33.
Key Takeaways:
• The speaker acknowledges that previous CTI tracks focused on foundational concepts, setting the stage for this advanced discussion on practical application 0:10.
• The core topic is "red teams with receipts," emphasizing the need for concrete evidence and operationalizing CTI for authentic adversary simulation 0:28.
• The presenter covers the transition from theoretical CTI to actionable red teaming, noting the absence of co-presenter Raheel due to unforeseen circumstances 0:36.
[Closing statement] By integrating real-world adversary tactics with structured intelligence, organizations can better validate their security posture. This approach ensures that red teaming efforts yield actionable, verified insights rather than abstract data.
Sources:
Generate CPE Credits
Generate a professional CPE document from this video's transcript.
Estimated credit: 0.5 CPE hours
Estimate uses the video runtime (1 hour ≈ 1 CPE, rounded to the nearest 0.5, minimum 0.5, maximum 2.0). The final amount can be lower after review, never higher.
Topic: Penetration Testing. Commonly maps to: Security Assessment and Testing, Security Operations. Exact CISSP domains are assigned during generation.
Free account. One generation at a time, with a daily limit.
CPEBuddy is independent and not affiliated with or endorsed by ISC2, ISACA, or any certification body. Exports are formatted for common CPE submissions; acceptance is at your certification body's discretion.
Transcript Preview
First 800 characters of the transcript
Good afternoon everyone. End of the day, last talk. So I was sitting through a few of the um new to CTI tracks and I'm like wait a minute. Everything that's been talked about is like building on what I'm about to talk about. So I was like kudos to the board for that cuz I didn't know that was going to happen. So um I'll go ahead and get started. So my talk is on red team red teams with receipts operationalizing CTI for real adversary simulation. Unfortunately my uh co-presenter Ralphel who is the offense security lead at my company was unable to attend. So I'll pick up his slack to the best of my ability from the red team perspective. A little about myself. Um, I work for Granger. Joined there in 2022. Um, I'm a gym goer at least five to six. I know I need to do my rest days, but five to s…