Podcast · YouTube
🚨 HACKING like the RED TEAM 🚨🚨 With Sandra Bardón 🚨
We already saw what an ethical hacker is and how a pentest is done. What was missing was putting it all together and simulating what the bad guys do in the real world, so to talk about red team I kick off the season with Sandra Bardón, one of our own on the offensive side of things.
Sandra is one of the born-curious, the kind who ask why until they wear their mother out. She studied telecoms, drifted towards security through cryptography and passed through PKI, electronic signatures, the Joint Cyberdefence Command and forensic analysis before going over to the dark side. She spent three years in Estonia, at NATO’s cyberdefence centre in Tallinn, where she was part of the red team (around eighty people against more than twenty blue teams) in the Alliance’s biggest exercise. She explains well the difference between a pentest and a red team: the preparation time, the persistence, the pivoting and, above all, the stealth and imagination for when the blue team detects you. And she recalls moments over beers with Rafi, the creator of Cobalt Strike.
Her advice is the kind worth keeping: humility, motivation, teamwork, English and the drive to never stop learning. In Spain, she laments, we don’t value what we have, and there’s a reason so many good people end up leaving for elsewhere.