Red Team vs Blue Team Operations — Cybersecurity Mind Map
29. Red Team vs Blue Team Operations
Red Team and Blue Team are the offensive and defensive sides of organisational security. This mind map covers both disciplines plus the Purple Team approach that bridges them.
Topics Covered
- Red Team: adversary simulation, full engagement
- C2 frameworks: Cobalt Strike, Havoc, Sliver
- OPSEC: redirectors, domain fronting
- Blue Team: SOC tiers, SIEM, EDR, SOAR
- Detection engineering and Sigma rules
- Incident response PICERL process
- Purple Team: ATT&CK coverage testing
- Atomic Red Team exercises
- Career paths: OSCP/CRTO vs CySA+/GCIH
