Home / Companies / GitLab / Blog / Post Details
Content Deep Dive

How GitLab's Red Team automates C2 testing

Blog post from GitLab

Post Details
Company
Date Published
Author
Josh Feehs
Word Count
2,544
Company Posts That Month
14
Language
English
Hacker News Points
-
Post removed?
No
Summary

GitLab's Red Team uses open-source command and control (C2) tools to simulate real-world threats and evaluate security measures. The team customizes these tools to bypass detections, applying professional development practices for continuous testing within the Mythic framework. They leverage GitLab CI/CD pipelines to automate testing after code changes, enabling rapid validation of updates to Mythic and its compatible agents. The public project they share includes a suite of pytest tests for integration with Mythic, supporting the iterative development of secure operations. The article also highlights the importance of continuous testing, demonstrated when a bug in Poseidon's upload function was quickly identified and resolved, showcasing collaboration with the community of C2 developers who open source their tools. GitLab encourages feedback and contributions to further enhance the security testing framework.

Trends Found in this Post
Trend Post Mentions Total Month Mentions Posts Companies MoM
Agent sandbox 1 1 1 1 -
Use This Data

Use this post, company, and trend context to find content marketing opportunities, perform competitive analysis, or address product feature gaps via the Plushcap MCP server or the Plushcap API.