- Home
- Business & Economics
- Industries
- The Effective Red Team (Adversary Emulation Inside the Enterprise)
The Effective Red Team (Adversary Emulation Inside the Enterprise)
List Price:
$69.99
| Expected release date is Feb 16th 2027 |
- Availability: Confirm prior to ordering
- Branding: minimum 50 pieces (add’l costs below)
- Check Freight Rates (branded products only)
Branding Options (v), Availability & Lead Times
- 1-Color Imprint: $2.00 ea.
- Promo-Page Insert: $2.50 ea. (full-color printed, single-sided page)
- Belly-Band Wrap: $2.50 ea. (full-color printed)
- Set-Up Charge: $45 per decoration
- Availability: Product availability changes daily, so please confirm your quantity is available prior to placing an order.
- Branded Products: allow 10 business days from proof approval for production. Branding options may be limited or unavailable based on product design or cover artwork.
- Unbranded Products: allow 3-5 business days for shipping. All Unbranded items receive FREE ground shipping in the US. Inquire for international shipping.
- RETURNS/CANCELLATIONS: All orders, branded or unbranded, are NON-CANCELLABLE and NON-RETURNABLE once a purchase order has been received.
Product Details
Author:
Trevin Edgeworth, Noah Potti, Jordan Potti
Format:
Paperback
Pages:
504
Publisher:
No Starch Press (February 16, 2027)
Imprint:
No Starch Press
Release Date:
February 16, 2027
Language:
English
Audience:
General/trade
ISBN-13:
9781718505100
ISBN-10:
1718505108
Weight:
13oz
Dimensions:
7" x 9.25"
File:
RandomHouse-PRH_Book_Company_PRH_PRT_Onix_full_active_D20261004T130911_158010584-20261004.xml
Folder:
RandomHouse
List Price:
$69.99
Country of Origin:
United States
Pub Discount:
65
Case Pack:
24
As low as:
$53.89
Publisher Identifier:
P-RH
Discount Code:
A
QuickShip:
Yes
Overview
Build a red team that turns successful attacks into better security.
Your red team got domain admin. Great. Now what changed?
The hardest part of red teaming starts after the breach: building a program that survives contact with the rest of the organization and turns offensive work into better security.
The Effective Red Team moves from strategy to tactics in the order you'll meet the problems. You'll assess your organization's real risks and culture, define a mission and scope stakeholders will back, build partnerships with defenders and leadership, hire and develop operators, choose metrics that don't lie, and communicate uncomfortable findings so they get fixed.
Then you'll run operations. You'll design an engagement, build quiet, reusable attacker infrastructure, follow a complete case study emulating the ShinyHunters threat actor, and turn the results into reports, outbriefs, and detection rules engineers will act on. Part IV covers the tactical methodologies themselves: initial access, persistence, expanding access, and acting on objectives in cloud-heavy enterprise environments.
Seven appendixes give you the working documents: rules of engagement, a process document, a finding template, a development matrix, and a sample operation report.
Trevin Edgeworth, Noah Potti, and Jordan Potti built and led the red teams at American Express, Capital One, and Symantec, and wrote this from that experience. It is for practitioners building or running internal red teams, and assumes working knowledge of Active Directory, cloud infrastructure, and networking.
Finding a way in is half the job. The real win is making sure the same attack never works twice.
Your red team got domain admin. Great. Now what changed?
The hardest part of red teaming starts after the breach: building a program that survives contact with the rest of the organization and turns offensive work into better security.
The Effective Red Team moves from strategy to tactics in the order you'll meet the problems. You'll assess your organization's real risks and culture, define a mission and scope stakeholders will back, build partnerships with defenders and leadership, hire and develop operators, choose metrics that don't lie, and communicate uncomfortable findings so they get fixed.
Then you'll run operations. You'll design an engagement, build quiet, reusable attacker infrastructure, follow a complete case study emulating the ShinyHunters threat actor, and turn the results into reports, outbriefs, and detection rules engineers will act on. Part IV covers the tactical methodologies themselves: initial access, persistence, expanding access, and acting on objectives in cloud-heavy enterprise environments.
Seven appendixes give you the working documents: rules of engagement, a process document, a finding template, a development matrix, and a sample operation report.
Trevin Edgeworth, Noah Potti, and Jordan Potti built and led the red teams at American Express, Capital One, and Symantec, and wrote this from that experience. It is for practitioners building or running internal red teams, and assumes working knowledge of Active Directory, cloud infrastructure, and networking.
Finding a way in is half the job. The real win is making sure the same attack never works twice.









