National Cyber Warfare Foundation (NCWF)

ired.team notes for studying red teaming tradecraft in a lab


0 user ratings
2026-10-08 01:26:52
milo
Red Team (CNA)
"ired.team

ired.team notes is a long-running open knowledge base of offensive security experiments documented by @spotheplanet, aimed at professionals learning adversary tradecraft in controlled lab environments.








Toolmantvydasb/RedTeaming-Tactics-and-Techniques — public red teaming notes and experiments published as the ired.team GitBook
Categoryoffensive security knowledge base / lab notes repository (PowerShell-heavy examples)
Primary UseStudying how common offensive techniques work — code execution, injection, defense evasion, lateral movement, persistence — in controlled labs, plus the artifacts they leave on endpoints
Safe UseExplicitly a personal learning project executed in a controlled environment; intended for authorized pentesters, red teamers, defenders and students conducting experiments on systems they own
Telemetry NoteThe README states one explicit goal is recording what artifacts techniques and tools leave behind on the endpoint — the notes double as a defensive artifact-hunting reference

mantvydasb/RedTeaming-Tactics-and-Techniques, better known in the community as the ired.team notes, is not a tool in the conventional sense — it is a public, continuously maintained knowledge base of red teaming experiments, published as a GitBook at ired.team and mirrored on GitHub. With roughly 4693 stars and a codebase dominated by PowerShell, it has become one of the most referenced community resources for offensive security education. The author, who goes by @spotheplanet on Twitter, frames the entire project from the start as personal notes from experiments conducted in a controlled environment — a framing that matters, because it defines both the intended audience and the intended setting for everything that follows.


The README is candid about the project's epistemology, and this is what makes it interesting as an object of analysis rather than just a link dump. The author describes their learning method explicitly: reading other researchers' work, executing common and uncommon attacking techniques in a lab, then writing code and taking notes to internalize the mechanics. The stated philosophy is learning by doing, following, tinkering, exploring and repeating. That produces a document style that sits between a textbook and a lab journal — techniques are not merely described, they are worked through, with the author's own experimentation shaping the narrative.


Thematically, the notes cover the classic kill-chain middle: gaining code execution, code injection, defense evasion, lateral movement, and persistence. Notably absent from the README is any emphasis on initial access via mass scanning or phishing infrastructure; the focus is on what happens after a foothold exists, which is the part of tradecraft that most rewards deep understanding of Windows internals, the Windows API, and C++. The author lists these as explicit learning goals: understanding how malware is written, writing code to understand attacker tooling, and getting deeper into native Windows programming.


That defensive-adjacent framing is not incidental. One of the enumerated goals in the README is to see what artifacts the techniques and tools leave behind on the endpoint. This is the single most valuable sentence in the document for defenders: it means the corpus is not purely offensive documentation but also a compendium of observable side effects — registry changes, process behaviors, file system traces — that map naturally onto detection engineering. A blue team reader can treat the notes as a structured tour of what their telemetry should be catching, and a purple team can use the same pages to align offensive execution with defensive coverage.


The repository's PowerShell language classification is consistent with the content: a substantial portion of Windows-oriented tradecraft is naturally expressed in PowerShell, and the repo carries example code alongside prose. The topic tags — offensive-security, redteam, redteam-infrastructure, pentesting, oscp, redteaming — signal the audience clearly. The inclusion of oscp is a useful signal for readers preparing for that certification, since the notes are frequently cited in preparation communities as supplementary hands-on material, although the README itself makes no exam-specific claims.


Intellectual honesty is handled unusually well for a community resource of this scale. The author states plainly that the techniques were discovered by other researchers and that no ownership is claimed, with an explicit commitment to referencing sources and fixing attribution gaps on request. Even more useful is the warning block: do not take anything for granted, do not expect exhaustiveness, expect mistakes, always consult additional resources. For a professional reader, this is the correct posture — treat the notes as a hypothesis generator and a map, not as authoritative documentation, and verify behavior against primary sources and your own lab observations.


There is also a licensing caveat worth flagging for anyone considering operational use of the material. The README carries a strong warning that the ired.team GitBook was created by @spotheplanet and that cloning it and presenting it as one's own is described as illegal and strictly forbidden. Notably, the repository metadata shows no formal license field, which means downstream users have no explicit open-source grant for the text. Teams that want to mirror or excerpt the content internally should respect the author's terms and link to the source rather than republishing, and the support channels listed — a Patreon and PayPal — make the sustainability model explicit.


Where this fits in an authorized workflow is straightforward. For an operator on an engagement with a signed scope, the notes serve as a technique lookup and refresher, particularly around Windows internals questions that arise mid-engagement. For a detection engineer, they serve as a source of technique-to-artifact mappings to feed rule development and threat hunting hypotheses. For a student building a home lab, the stated methodology — reproduce, observe, note — is arguably more valuable than any single page of content, because it models how practitioners actually build durable knowledge rather than collecting screenshots.


Nothing in the README markets capabilities, promises effectiveness, or encourages use against third-party systems; the controlled-environment framing is established in the first paragraph and reinforced throughout. The project's honest disclaimers, attribution discipline, and explicit interest in endpoint artifacts make it a rare example of an offensive-security resource that reads as genuinely educational rather than as a weaponization shortcut. For defenders and authorized professionals alike, ired.team remains a reference worth knowing deeply — and reading critically, exactly as its author advises.



Official project repository for mantvydasb/RedTeaming-Tactics-and-Techniques.

Download Tool

Educational analysis for authorized security professionals. Use only in controlled, authorized environments.






Source: OffensiveSec
Source Link: https://www.offsecblog.com/2026/10/iredteam-notes-for-studying-red-teaming.html


Comments
new comment
Nobody has commented yet. Will you be the first?
 
Forum
Red Team (CNA)



Copyright 2012 through 2026 - National Cyber Warfare Foundation - All rights reserved worldwide.