Switch to any value % from this page to resize cheat sheet text: % www.emerson.emory.edu/services/latex/latex_169.html \footnotesize % Small font. \begin{multicols*}{3} \begin{tabularx}{5.377cm}{X} \SetRowColor{DarkBackground} \mymulticolumn{1}{x{5.377cm}}{\bf\textcolor{white}{Nº1 Objective when Red Teaming:}} \tn \SetRowColor{white} \mymulticolumn{1}{x{5.377cm}}{{\bf{Meet the client's expectations.}}% Row Count 1 (+ 1) } \tn \hhline{>{\arrayrulecolor{DarkBackground}}-} \end{tabularx} \par\addvspace{1.3em} \begin{tabularx}{5.377cm}{X} \SetRowColor{DarkBackground} \mymulticolumn{1}{x{5.377cm}}{\bf\textcolor{white}{{\bf{Main Sources}}}} \tn \SetRowColor{white} \mymulticolumn{1}{x{5.377cm}}{{\bf{\{\{link="https://tryhackme.com/room/redteamengagements"\}\}TryHackMe\{\{/link\}\}}} \newline % Row Count 2 (+ 2) {\bf{\{\{link="https://redteam.guide/"\}\}RedTeam.Guide\{\{/link\}\}}}% Row Count 4 (+ 2) } \tn \hhline{>{\arrayrulecolor{DarkBackground}}-} \end{tabularx} \par\addvspace{1.3em} \begin{tabularx}{5.377cm}{X} \SetRowColor{DarkBackground} \mymulticolumn{1}{x{5.377cm}}{\bf\textcolor{white}{Red Team Checklists}} \tn \SetRowColor{white} \mymulticolumn{1}{x{5.377cm}}{\{\{link="https://redteam.guide/docs/checklists/red-team-checklist/"\}\}Source2\{\{/link\}\}% Row Count 2 (+ 2) } \tn \hhline{>{\arrayrulecolor{DarkBackground}}-} \end{tabularx} \par\addvspace{1.3em} \begin{tabularx}{5.377cm}{x{1.64241 cm} x{3.33459 cm} } \SetRowColor{DarkBackground} \mymulticolumn{2}{x{5.377cm}}{\bf\textcolor{white}{Campaign Planning}} \tn % Row 0 \SetRowColor{LightBackground} {\bf{Engagement Plan}} & CONOPS, Resource and Personnel Requirements, Timelines \tn % Row Count 3 (+ 3) % Row 1 \SetRowColor{white} {\bf{Operations Plan}} & Goes deeper into each Engagement Plan topic. \tn % Row Count 5 (+ 2) % Row 2 \SetRowColor{LightBackground} {\bf{MissionsPlan}} & Execution time, Commands to run, Time Objectives, Responsible Operator, etc. \tn % Row Count 8 (+ 3) % Row 3 \SetRowColor{white} {\bf{Remediation Plan}} & What to do after the engagement is done: reports, remendiation consultation, etc... \tn % Row Count 12 (+ 4) \hhline{>{\arrayrulecolor{DarkBackground}}--} \end{tabularx} \par\addvspace{1.3em} \begin{tabularx}{5.377cm}{X} \SetRowColor{DarkBackground} \mymulticolumn{1}{x{5.377cm}}{\bf\textcolor{white}{Remediation Plan}} \tn \SetRowColor{white} \mymulticolumn{1}{x{5.377cm}}{{\bf{Optional plan}} that contains a summary of the engagement details and a report of findings, \newline % Row Count 2 (+ 2) States how the client can fix vulnerabilities. May be included in the final report.% Row Count 4 (+ 2) } \tn \hhline{>{\arrayrulecolor{DarkBackground}}-} \end{tabularx} \par\addvspace{1.3em} \begin{tabularx}{5.377cm}{X} \SetRowColor{DarkBackground} \mymulticolumn{1}{x{5.377cm}}{\bf\textcolor{white}{Mission Plan includes:}} \tn \SetRowColor{white} \mymulticolumn{1}{x{5.377cm}}{{\bf{Optional Command Playbooks}} which include the exact commands, and tools to run including when, why and how we use them. Usefull for bigger teams. \newline % Row Count 3 (+ 3) {\bf{Execution Times}} that state when to start each engagement stage. Timestamps and may also include commands and tools. \newline % Row Count 6 (+ 3) {\bf{Roles and Responsabilities}} of each red team cell% Row Count 8 (+ 2) } \tn \hhline{>{\arrayrulecolor{DarkBackground}}-} \end{tabularx} \par\addvspace{1.3em} \begin{tabularx}{5.377cm}{X} \SetRowColor{DarkBackground} \mymulticolumn{1}{x{5.377cm}}{\bf\textcolor{white}{Operations Plan includes:}} \tn \SetRowColor{white} \mymulticolumn{1}{x{5.377cm}}{{\bf{Information on employee requirements}}. \newline % Row Count 1 (+ 1) {\bf{Stopping conditions}}: How and Why \newline % Row Count 2 (+ 1) {\bf{Optional RoE}} \newline % Row Count 3 (+ 1) {\bf{Technical Requirements}} Necessary knowledge% Row Count 4 (+ 1) } \tn \hhline{>{\arrayrulecolor{DarkBackground}}-} \end{tabularx} \par\addvspace{1.3em} \begin{tabularx}{5.377cm}{X} \SetRowColor{DarkBackground} \mymulticolumn{1}{x{5.377cm}}{\bf\textcolor{white}{Engagement Plan includes:}} \tn \SetRowColor{white} \mymulticolumn{1}{x{5.377cm}}{CONOPS \& Resource Plan {\emph{(Timelines and required information to assure Red Team success)}} \newline % Row Count 2 (+ 2) e.g.: Personnel, hardware, software, cloud requirements, etc..% Row Count 4 (+ 2) } \tn \hhline{>{\arrayrulecolor{DarkBackground}}-} \end{tabularx} \par\addvspace{1.3em} \begin{tabularx}{5.377cm}{X} \SetRowColor{DarkBackground} \mymulticolumn{1}{x{5.377cm}}{\bf\textcolor{white}{Standart RoE Structure (acc. to TryHackMe)}} \tn \SetRowColor{white} \mymulticolumn{1}{x{5.377cm}}{1. {\bf{Executive Summary}} (Contents and Authorization ) \newline % Row Count 2 (+ 2) 2. {\bf{Purpose}} (of the RoE) \newline % Row Count 3 (+ 1) 3. {\bf{References}} -\textgreater{} ISO's, etc... \newline % Row Count 4 (+ 1) 4. {\bf{Scope}} -\textgreater{} Restrictions and Guidelines \newline % Row Count 5 (+ 1) 5. {\bf{Definitions}} -\textgreater{} Terminology \newline % Row Count 6 (+ 1) 6. {\bf{Rules of Engagement and Support Agreement}} \newline % Row Count 7 (+ 1) 7. {\bf{Provisions}} -\textgreater{} Adicional Info and Exceptions \newline % Row Count 9 (+ 2) 8. {\bf{Requirements, Restrictions, and Authority}} -\textgreater{} Red Cell's Expectations \newline % Row Count 11 (+ 2) 9. {\bf{Ground Rules}} -\textgreater{} Red Cell's limitations \newline % Row Count 12 (+ 1) 10. {\bf{Resolution of Issues/Points of Contact}} \newline % Row Count 13 (+ 1) 11. {\bf{Authorizatio}}n - Signatures \newline % Row Count 14 (+ 1) 12. {\bf{Approval}} \newline % Row Count 15 (+ 1) 13. {\bf{Appendix}} \newline % Row Count 16 (+ 1) \{\{link="https://tryhackme.com/room/redteamengagements"\}\}Source\{\{/link\}\}% Row Count 18 (+ 2) } \tn \hhline{>{\arrayrulecolor{DarkBackground}}-} \end{tabularx} \par\addvspace{1.3em} \begin{tabularx}{5.377cm}{X} \SetRowColor{DarkBackground} \mymulticolumn{1}{x{5.377cm}}{\bf\textcolor{white}{CONOPS {\emph{Critical Components}}}} \tn \SetRowColor{white} \mymulticolumn{1}{x{5.377cm}}{{\bf{Client Name;}} \newline % Row Count 1 (+ 1) {\bf{Service Provider;}} \newline % Row Count 2 (+ 1) {\bf{Timeframe;}} \newline % Row Count 3 (+ 1) {\bf{General Objectives/Phases;}} \newline % Row Count 4 (+ 1) {\bf{Other Training Objectives (Exfiltration);}} \newline % Row Count 5 (+ 1) {\bf{High-Level Tools/Techniques planned to be used;}} \newline % Row Count 7 (+ 2) {\bf{Threat group to emulate (if any).}}% Row Count 8 (+ 1) } \tn \hhline{>{\arrayrulecolor{DarkBackground}}-} \end{tabularx} \par\addvspace{1.3em} \begin{tabularx}{5.377cm}{X} \SetRowColor{DarkBackground} \mymulticolumn{1}{x{5.377cm}}{\bf\textcolor{white}{RoE}} \tn \SetRowColor{white} \mymulticolumn{1}{x{5.377cm}}{Rules of Engagement% Row Count 1 (+ 1) } \tn \hhline{>{\arrayrulecolor{DarkBackground}}-} \end{tabularx} \par\addvspace{1.3em} \begin{tabularx}{5.377cm}{X} \SetRowColor{DarkBackground} \mymulticolumn{1}{x{5.377cm}}{\bf\textcolor{white}{Vulnerability}} \tn \SetRowColor{white} \mymulticolumn{1}{x{5.377cm}}{A {\emph{weakness}} in an asset or group of assets. \newline % Row Count 1 (+ 1) Can be exploited and harmed by one or more threats% Row Count 2 (+ 1) } \tn \hhline{>{\arrayrulecolor{DarkBackground}}-} \end{tabularx} \par\addvspace{1.3em} \begin{tabularx}{5.377cm}{X} \SetRowColor{DarkBackground} \mymulticolumn{1}{x{5.377cm}}{\bf\textcolor{white}{Threat}} \tn \SetRowColor{white} \mymulticolumn{1}{x{5.377cm}}{{\emph{Possible unwanted event.}} \newline % Row Count 1 (+ 1) When a threat turns into an actual event it may cause an unwanted incident.% Row Count 3 (+ 2) } \tn \hhline{>{\arrayrulecolor{DarkBackground}}-} \end{tabularx} \par\addvspace{1.3em} \begin{tabularx}{5.377cm}{X} \SetRowColor{DarkBackground} \mymulticolumn{1}{x{5.377cm}}{\bf\textcolor{white}{PII}} \tn \SetRowColor{white} \mymulticolumn{1}{x{5.377cm}}{Personal Identification Information% Row Count 1 (+ 1) } \tn \hhline{>{\arrayrulecolor{DarkBackground}}-} \end{tabularx} \par\addvspace{1.3em} \begin{tabularx}{5.377cm}{X} \SetRowColor{DarkBackground} \mymulticolumn{1}{x{5.377cm}}{\bf\textcolor{white}{TTS}} \tn \SetRowColor{white} \mymulticolumn{1}{x{5.377cm}}{Tactics, Techniques and Procedures% Row Count 1 (+ 1) } \tn \hhline{>{\arrayrulecolor{DarkBackground}}-} \end{tabularx} \par\addvspace{1.3em} \begin{tabularx}{5.377cm}{X} \SetRowColor{DarkBackground} \mymulticolumn{1}{x{5.377cm}}{\bf\textcolor{white}{CONOPS}} \tn \SetRowColor{white} \mymulticolumn{1}{x{5.377cm}}{{\emph{Concept of Operations}} \newline % Row Count 1 (+ 1) How to target the client and meet his expectations.% Row Count 3 (+ 2) } \tn \hhline{>{\arrayrulecolor{DarkBackground}}-} \end{tabularx} \par\addvspace{1.3em} \begin{tabularx}{5.377cm}{X} \SetRowColor{DarkBackground} \mymulticolumn{1}{x{5.377cm}}{\bf\textcolor{white}{White Card}} \tn \SetRowColor{white} \mymulticolumn{1}{x{5.377cm}}{A simulated event in an operational test. \newline % Row Count 1 (+ 1) Used when a system is too fragile or operationally critical for the adversarial team to pursue an exploitation, or when the adversarial team is unable to penetrate the system, but there is still a desire to evaluate the ability of the system to react to a penetration. \newline % Row Count 7 (+ 6) Should be used only when necessary.% Row Count 8 (+ 1) } \tn \hhline{>{\arrayrulecolor{DarkBackground}}-} \end{tabularx} \par\addvspace{1.3em} % That's all folks \end{multicols*} \end{document}