Truth in IT
    • Sign In
    • Register
        • Videos
        • Channels
        • Pages
        • Galleries
        • News
        • Events
        • All
Truth in IT Truth in IT
  • Data Management ▼
    • Converged Infrastructure
    • DevOps
    • Networking
    • Storage
    • Virtualization
  • Cybersecurity ▼
    • Application Security
    • Backup & Recovery
    • Data Security
    • Identity & Access Management (IAM)
    • Zero Trust
    • Compliance & GRC
    • Endpoint Security
  • Cloud ▼
    • Hybrid Cloud
    • Private Cloud
    • Public Cloud
  • Webinar Library
  • TiPs
  • DRAW

Sophos Red Team: Offensive Security Testing Explained

Sophos
09/21/2026
0 (0%)
Share
  • Comments
  • Download
  • Transcript
Report Like Favorite
  • Share/Embed
  • Email
Link
Embed

Transcript


Welcome, everybody. Thank you for being here in the Sophos Theater. My name is Anthony Boissy, and I am absolutely proud to be able to announce that at this Black Hat, at Black Hat 2026, we have announced something truly special. We have announced Sophos Fusion. Sophos Fusion, it is a unique AI-native cybersecurity defense system that is not a platform. It is not a stack. It is not a stack of platforms. You're gonna be walking around here, and you're gonna be hearing everybody talking about platforms, you're gonna be hearing them talking about stacks, and this is neither of those. This truly is a system, and this system reacts and adapts to your environment and to what you feed. It is agnostic, it is truly open, and it is positioned to be able to, and designed to help you address the latest threats that may be hitting your environment today. Now, with that said, your environment is only as good as you know. I have got a friend that will show you that your environment isn't as good as what you potentially think, and that friend is this guy, Mr. Eric Escobar. He is on our red team, and again, your environment is only as good as what you are aware, and in a lot of cases, there's so many unseen things, and he helps, and his team helps uncover that. So, with no further ado, I'm actually gonna hand some time over, and hand this mic over to Mr. Escobar. So, Eric, please, take it away. All right, hey, everybody. Whoa, my voice is magnified. It's like Bruce Almighty. So, yeah, my name's Eric Escobar. Let's see if I can get these slides to work. If not, I can just click through them this way. Or not. Now use the do. There we go. I promised I know how to use technology. Anyways, like I was saying, my name's Eric Escobar. I am a member of the Sophos Red team. I have the absolute coolest job in the entire world. If I didn't have permission to do what I do, I would basically be liable for several hundred felonies every single day. If you think about it, computer abuse and breaking into systems, all of those are felonies, and so when you consider a typical Red team engagement, we can crack up to, I mean, we've had clients that have hundreds of thousands of credentials, clients, PII, intellectual property, all of those would qualify for as a felony. So we do it for good. We do it for our clients to make sure that they know where their holes are, where their gaps are, and what would really happen in the event that there's a real-world threat or a real-world individual that's going to go and break in, whether or not they're a nation state, just a Lazarus group or some small little hacker team, no matter the scope, that's something that we attempt to emulate as a part of what we do. So a little bit about kind of the way that we approach it when we have different clients is with some of our clients, we don't just say, hey, everybody gets an off-the-shelf test. We don't look at every client the same. Everybody has different industries, they have different things that they care about, they have different things that they want to see done that they want to see have tested. So if we have, say, a company, and they are looking at new intellectual property, they have patents that are going to come to market, we ask them, what is most important to you? What is the goal? What do you want to see us compromise? What do you want to see us break into? So what we can do as a part of it is kind of go through some of the goals and see what does that client find most interesting. So we can do industrial espionage. We can go and emulate a person. We can go emulate an executive. We can use different forms of tradecraft if they're really worried about something in particular. Now, if a client doesn't know, if a client's like, hey, we're not really sure, we've never done a penetration test before, then basically what we say is, hey, you're going to let a group of individuals who are some of the best hackers on the planet that do it for good into your environment, and we can find different paths and find things that you potentially didn't know were going to be there. And what's funny about this is that this is, I joke with all my coworkers that this is the one, two times a year that we're actually standing up talking to clients in person. Most of what we do is remote. We do come on site for some of our physical engagements, and I'll walk you through what some of those different processes look like. But if you kind of look down the stack as far as what we're doing, we can look at endpoints. We now see, obviously, a lot more people are using things in the cloud, a lot of agentic systems, a lot of hybrid clouds. And that's where attackers can live, because I was talking to one of our clients today, and what we see and what we've seen attackers do is it's easy when you're on premise. Everything is a physical server, it's a virtual machine. The moment things are up into a cloud, the moment things are into a data center, you're not quite sure where that data is, and that's the perfect place for a penetration test, because the time where you don't want to figure out, hey, your data's been exposed, is when somebody's ransoming it from you, right? You want to find out, when you're just talking to me on the phone, say, hey, guess what? I found this data, this is how you're going to secure it. It's a way better conversation when you're having it with me, because you've hired me to do the penetration test, than it is if you're on the other line with some ransomware threat actor who's trying to extort some Bitcoin from you. And as a part of this, we do, again, goal-based. So what are your goals? What are the things that you care most about? Sometimes it's intellectual property. Sometimes a company's going to go public, and so they want to know shareholder value, what are the things that they hold dear? Maybe times it's just the data that they have. Maybe it's data on companies, if they're hospitals, if they're in insurance. Having that data get leaked, having that data get out there is catastrophic, and so those are all the sorts of things that we go after and look at. A little bit about our team. So we have about 75 hackers spread across the globe. There's basically, the sun never sets on our team, so if we have a large engagement, we can basically hand it off to my buddy, Zach, right there in Australia, and then I'll pick it back up, U.S. side, state side. So if you have a specific industry, a specific vertical, a specific region that you're going to be in, that is something that we can accommodate. We have a lot of in-house tools that we use. We have proprietary devices that let us do our testing remotely. This comes in really handy if you're in any type of industrial situation or health and safety might be on the line. You don't have to have us come on site. You can have one of our proprietary devices be on site with one of your, basically with one of your workers, or just you leave it alone right there, and we can do all of our testing from there, which basically keeps our costs down because we are not having to charge for a T&E. We're not having to charge to have somebody on site. Our team, all of our team are very, very senior. I think that our last hire was around six years ago, as far as the seniority of our team. We've won several competitions. If you see Michael Aguilar, he looks like a hacker working around here. He's won the biohacking competition at DEF CON three years in a row. He regularly talks to federal authorities about medical devices and things that are found there. The team has also won the DEF CON Wireless Capture the Flag three years in a row. We got a couple black badges from that, and we now basically get into DEF CON free for life. We get about 12 CVEs a year throughout our team while we're doing our normal work. So basically, our team, we're tip of the spear. We're not new at this. We've been doing this for years and years and years, and honestly, we can't believe that they pay us to do this because it's so much fun. So a little bit about some of the engagements that we have. So basically, everything is going to be across the board as far as early security maturity all the way to full-on red team exercises. Vulnerability scanning, but really our bread and butter is going to be that penetration testing where we're doing, maybe from the perspective of a wireless engagement. Well, maybe we're going to go look at an internal network as if somebody had clicked on an email, clicked some malicious thing within your network. We have full-on web application assessments, whether it's a mobile device, an API, we can do all that type of testing. Then we have our purple team engagements. Our purple team engagements, that's where we basically sit either with your team physically or we sit with your team in a chat room, and so we're throwing all these different attacks at your team, and we're not just seeing, hey, did you detect this attack, but what was the time between when we performed the attack and when your team found out about it? So it's really that lather, rinse, repeat to make sure that your team is razor sharp and they're aware of what's happening in the network, and maybe if you have a real threat actor in your network, you detect five of the six things that they're able to do, but you're missing that one. That's what that purple team test is good to do, is to say, hey, we're going to throw everything at you. We want to make sure, not only do you detect everything, but do you also get it in a timely manner? There are several clients that we've done testing for where we'll have full domain admin level access, right? We'll fully compromise this network. We'll say, did you get any alerts? And they go, no, that's crazy, though. We have great EDR, we should be able to see at least something, we should have some indication. It turns out, all of those emails, all those notifications were going to somebody that had left the company the year before, right? So those are the things you don't want to find out in the middle of an active engagement. We also do full red team exercises. Those can be fully remote, or we can also do physical testing. If you want to talk physical testing, we've done lots and lots of things where we actually just performed a bank heist where we robbed a bank, which is really fun. We can't talk a lot about it, but it's one of those things that, again, my wife is just, every time I go travel for work, she's like, do you guys realize you're doing the most fun thing, and you're getting paid to do it? And I'm like, I completely agree. It's not often that you get all the friends together and you get to go rob a bank. We also have a lot of other ancillary services as well, high-speed password cracking. If you have OT, SCADA, any type of hardware environments, that type of testing, medical device testing, hardware testing, basically, you can dream it up. If it can be compromised, that's something that we love to dig into. If you have a custom LLM, chatbot, agent, all that kind of stuff that's all the buzz, we can test that as well. So this is just a really high level. If there's something specific you want to talk about, absolutely, come see me. I'm going to skip through, really, just to our stories, because our stories, I think, highlight some of what we're able to do the best. So the reason that I like to go with stories is because it's really easy to articulate. Oftentimes, you have to get a penetration test done because it has to go with compliance for compliance. And even though you have to do it for compliance, it doesn't mean you can't get something out of it. So when we do our goal-based testing, when we're talking with a client, when we're speaking with a client, we say, what can we help you with? Do you want us to look at your firewalls more? Do you want us to go replace some type of hardware or software, what are you looking to implement? And so then, as a part of the penetration test, yes, does it cover all the things that you need to as far as compliance? Absolutely. But what it also covers in there, which is most important, is the objectives that you want. Because I might know that you need new firewalls, you might know that you need new firewalls, but your CFO, your C-suite, your board of directors, they may not be there for the buy-in, right? But when they read our reports, they see, oh my gosh, our firewall was Swiss cheese. They were able to route in some way, shape, or form to get through a network. And one of those is we were testing a K-12 school district. Not really the first thing that you think of when you think of high-stakes security, but when you imagine what a K-12 school district has for several thousand students, all that student data, all the grades, all of just the family information, all of the government information that should never go out there. What they brought us in to do is basically say, is it possible for you to compromise our school district? So what did we do is we saw that there's a staff wireless network that just used credentials. So when a staff person logs into their computer, it just uses their normal credentials, same thing to get on Wi-Fi. So we set up a rogue access point. We were able to capture and crack their credentials. Then we joined that network as a staff person. Well, if you're a staff in a K-12 school district, you're going to be able to already see tons of student data. There's no multi-factor authentication, and we're able to leverage a certificate authority to then basically escalate to a domain admin. Now, if you've ever run a Windows network, you realize that a Windows network is one of those things that if you're a domain admin, you can basically do whatever you want. We were able to access every student's record, all the protected records. We were able to change grades, edit grades, all those sorts of things. So this is pretty much what would have been the worst case if you're the school district, and this is what we were brought in to do. We were brought in to basically make this case to the powers that be that control the purse strings to the school district and say, this is what was possible. This is what we're able to do. We weren't making any hypotheticals. We could show them the student data. We could show them how we went in there. And that's what's really powerful. If you just run a vulnerability scan and say, hey, you might have some of these vulnerabilities. This might be a problem. That's not as impactful as saying, hey, I have 12,000 student records right here, and I can edit them. I could change them. I could zip them up, and if I were a ransomware threat actor, I could hold this for ransom right there. And it was all just from one tiny little rat trap that we had stuck a Raspberry Pi and some of our proprietary wireless technology in, and we were able to compromise it from there. Anyways, that's the story. If you guys want more stories, come see me. I'll be walking around the booth.

TL;DR

  • Sophos announced Sophos Fusion at Black Hat 2026, positioning it as an AI-native cybersecurity defense system — explicitly not a platform or stack — designed to adapt to each customer's environment.
  • The Sophos Red Team consists of roughly 75 senior hackers worldwide, with multiple DEF CON competition wins and approximately 12 CVEs discovered annually, offering engagements from basic penetration testing to physical bank heist simulations.
  • Purple team engagements go beyond detection to measure response time, helping organizations identify gaps where alerts are generated but never acted on — including cases where notifications were routing to departed employees.
  • A K-12 school district case study demonstrated how a rogue access point, cracked credentials, and a missing MFA policy led to full domain admin access and the ability to read and edit 12,000 student records.

Sophos Fusion and the Red Team Mission

Recorded live at Black Hat 2026, this session opens with Anthony Boissy introducing Sophos Fusion — described as an AI-native cybersecurity defense system that Sophos explicitly distinguishes from a platform or a stack. The framing is deliberate: Fusion is positioned as a reactive, adaptive system that is open and agnostic to the customer's environment. The introduction sets up the core argument that even the most sophisticated defensive tooling is only as effective as an organization's awareness of its own attack surface — which is where the Sophos Red Team enters the picture.

Red Team Capabilities and Engagement Types

Eric Escobar, a senior member of the Sophos Red Team, walks through the team's structure and service offerings. The team comprises approximately 75 hackers distributed globally, enabling around-the-clock engagement handoffs across time zones. Credentials include multiple DEF CON competition wins — including the biohacking and wireless Capture the Flag events — and roughly 12 CVEs discovered annually during normal client work. Engagements span vulnerability scanning, penetration testing across wireless, internal network, web application, and API vectors, full red team exercises (both remote and physical), and purple team exercises that measure not just detection capability but detection speed. Physical engagements have included bank heist simulations. The team also offers testing for OT/SCADA environments, medical devices, hardware, and custom LLMs or AI agents.

K-12 School District Case Study

Escobar closes with a detailed real-world engagement story involving a K-12 school district — an organization not typically associated with high-stakes security risk, but one holding thousands of sensitive student records, family data, and government information. The attack chain began with a rogue wireless access point that captured and cracked staff credentials, which were shared between workstation login and Wi-Fi authentication. From there, the team joined the network as a staff member, exploited the absence of multi-factor authentication, leveraged a certificate authority to escalate privileges to domain admin, and ultimately accessed and demonstrated the ability to edit every student record in the district. The story is used to illustrate the difference between a vulnerability scan that flags theoretical risk and a penetration test that produces tangible, boardroom-ready evidence — in this case, 12,000 editable student records accessed via a Raspberry Pi and proprietary wireless hardware.

Chapters

0:00 - Sophos Fusion Announcement
1:33 - Eric Escobar Introduction
2:56 - Goal-Based Testing Approach
5:33 - Team Credentials and Capabilities
7:13 - Engagement Types Overview
9:54 - K-12 School District Case Study

Key Quotes

1:00 "Your environment is only as good as you know."
2:10 "I have the absolute coolest job in the entire world. If I didn't have permission to do what I do, I would basically be liable for several hundred felonies every single day."
4:49 "The time where you don't want to figure out, hey, your data's been exposed, is when somebody's ransoming it from you. You want to find out when you're just talking to me on the phone."
8:34 "We'll fully compromise this network. We'll say, did you get any alerts? And they go, no. It turns out, all of those emails, all those notifications were going to somebody that had left the company the year before."
12:36 "Hey, I have 12,000 student records right here, and I can edit them. I could change them. I could zip them up, and if I were a ransomware threat actor, I could hold this for ransom right there."

FAQ

What is the difference between a penetration test and a red team exercise?

As described by Eric Escobar, penetration testing typically targets specific systems or vectors — such as wireless networks, internal networks, web applications, or APIs — and is often scoped to meet compliance requirements. A red team exercise is broader and more adversarial, emulating a real-world threat actor attempting to achieve specific goals such as stealing intellectual property or compromising executive accounts. Red team engagements can be fully remote or include physical components like on-site intrusion simulations.

What is a purple team engagement and how does it differ from a standard red team test?

In a purple team engagement, the Sophos Red Team works collaboratively with the client's security team — either in person or via a shared chat environment — launching attacks in real time while the client's defenders attempt to detect them. The key metric is not just whether an attack was detected, but how long it took to detect it. This iterative approach helps organizations sharpen their detection and response capabilities and identify specific gaps, such as attack techniques that consistently evade detection or generate alerts that are never reviewed.


Categories:
  • » Data Protection
Channels:
News:
Events:
Tags:
  • Security Operations
  • Threat Intelligence
  • Demo
  • Technical Deep Dive
  • Best Practices
  • AI & Machine Learning
  • Penetration Testing
  • Red Team Operations
  • Purple Team Exercises
  • Physical Security Testing
  • Offensive Security
  • Sophos Fusion
  • Credential Attacks
Show more Show less

Browse videos

  • Related
  • Featured
  • By date
  • Most viewed
  • Top rated
  •  

              Video's comments: Sophos Red Team: Offensive Security Testing Explained

              Industry Events (Sponsor Hosted)

              • Sep
                23

                Invisible Data: The Key to Effective Protection Strategies

                09/23/202601:00 PM ET
                • Sep
                  29

                  Embracing AI Adoption While Ensuring Robust Security Measures

                  09/29/202612:00 PM ET
                  • Oct
                    15

                    Risk in Real Time Demo Series: Virtual Patching: Protection at the Speed of Exploitation

                    10/15/202611:00 AM ET
                    More events

                    Upcoming Webinar Calendar

                    • 09/23/2026
                      01:00 PM
                      09/23/2026
                      Invisible Data: The Key to Effective Protection Strategies
                      https://www.truthinit.com/index.php/channel/2087/invisible-data-the-key-to-effective-protection-strategies/
                    • 09/29/2026
                      12:00 PM
                      09/29/2026
                      Embracing AI Adoption While Ensuring Robust Security Measures
                      https://www.truthinit.com/index.php/channel/2092/embracing-ai-adoption-while-ensuring-robust-security-measures/
                    • 09/30/2026
                      04:00 AM
                      09/30/2026
                      AI Command Center: Enhanced Visibility and Control in Your Operations
                      https://www.truthinit.com/index.php/channel/2024/ai-command-center-enhanced-visibility-and-control-in-your-operations/
                    • 10/15/2026
                      11:00 AM
                      10/15/2026
                      Risk in Real Time Demo Series: Virtual Patching: Protection at the Speed of Exploitation
                      https://www.truthinit.com/index.php/channel/1372/risk-in-real-time-demo-series-the-autonomous-era-orchestrating-a-resilient-enterprise/
                    • 11/19/2026
                      01:00 PM
                      11/19/2026
                      360View: Govern, Secure & Recover Your Microsoft 365 Environment
                      https://www.truthinit.com/index.php/channel/2076/360view-govern-secure-recover-your-microsoft-365-environment/
                    Truth in IT
                    • Sponsor
                    • About Us
                    • Terms of Service
                    • Privacy Policy
                    • Contact Us
                    • Preference Management
                    Desktop version
                    Standard version