SiegeCast: Be Your Enemy
By Red Siege | September 10, 2024
Collaboration between offensive (Red Team) and defensive (Blue Team) operations is essential to fortify an organization’s defenses. During a recent SiegeCast session, Tim Medin (CEO of Red Siege), Justin Palk (Senior Security Consultant), and Mike Saunders (Principal Consultant) discussed how Blue Teams can improve their defense strategies by utilizing Red Team tactics and tools. Here’s a deep dive into the key takeaways from the session and how cybersecurity professionals can apply these insights.
You can download the slides to the SiegeCast HERE
As Tim Medin highlighted, many effective Red Teamers start their careers on the Blue side, often working as sysadmins or defenders. This experience gives them a detailed understanding of the systems they are later tasked with attacking. The knowledge of system configurations, shortcuts, and vulnerabilities that defenders rely on every day becomes an advantage for offensive operations. However, this deep insight is also why Red Team tactics can be invaluable to Blue Teams.
Rather than seeing Red Team operations as adversarial, organizations should view them as opportunities for collaboration. The goal of Red Teams is to help Blue Teams identify weaknesses and fix them before real-world attackers do. By adopting an attacker’s mindset, defenders can proactively close gaps, strengthen their environment, and reduce the risk of a breach.
MFA adds a critical layer of defense, but organizations need to ensure it is consistently applied across all systems. Tools like MFA Sweep help defenders test various authentication interfaces to verify if MFA is enforced across different platforms, such as web portals and APIs. This ensures that attackers cannot bypass MFA due to configuration gaps.
Blue Teams can enhance their defense capabilities by running offensive tools in their own environments. By hacking themselves, they gain the following benefits:
Implementing Red Team tools into your defense strategy isn’t just for external pen tests. As a Blue Teamer, you can start using these tools in your environment to identify issues and make real-time improvements. Courses like our Offense for Defense provide hands-on training to learn these tactics and apply them to your organization’s security program.
By adopting Red Team tactics, Blue Teams can significantly strengthen their defenses. The key is shifting from a reactive mindset to a proactive one—identifying weaknesses before they are exploited by attackers. As Justin Polk pointed out, “Running these tools will help you take control of your environment before anyone else can.”
For cybersecurity professionals, the message is clear: don’t wait for a breach to start thinking like an attacker. Use these offensive techniques today to build a stronger, more resilient security posture.
Resources & Tools:
Related Stories
View MoreBy Red Siege | September 3, 2026
by Justin Palk A couple of years ago, I put together a series on standing up a simple Windows AD domain in a lab environment. This article is part of […]
Learn MoreBy Red Siege | August 13, 2026
by Justin Palk A couple of years ago, I put together a series on standing up a simple Windows AD domain in a lab environment. This article is part of […]
Learn MoreBy Red Siege | July 7, 2026
by Justin Palk A couple of years ago, I put together a series on standing up a simple Windows AD domain in a lab environment. This is the start of […]
Learn More