How GitLab's Red Team automates C2 testing
Blog post from GitLab
GitLab's Red Team uses open-source command and control (C2) tools to simulate real-world threats and evaluate security measures. The team customizes these tools to bypass detections, applying professional development practices for continuous testing within the Mythic framework. They leverage GitLab CI/CD pipelines to automate testing after code changes, enabling rapid validation of updates to Mythic and its compatible agents. The public project they share includes a suite of pytest tests for integration with Mythic, supporting the iterative development of secure operations. The article also highlights the importance of continuous testing, demonstrated when a bug in Poseidon's upload function was quickly identified and resolved, showcasing collaboration with the community of C2 developers who open source their tools. GitLab encourages feedback and contributions to further enhance the security testing framework.
| Trend | Post Mentions | Total Month Mentions | Posts | Companies | MoM |
|---|---|---|---|---|---|
| Agent sandbox | 1 | 1 | 1 | 1 | - |
Use this post, company, and trend context to find content marketing opportunities, perform competitive analysis, or address product feature gaps via the Plushcap MCP server or the Plushcap API.