A small rant:
The State of Art in Red Team is whatever you want to believe
@XC3LL i agree with your sentiments completely, and feel that it’s only getting worse. the ‘assume breach’ mode that regulatory testing likes means that tests can flail around phishing for a token amount of time and almost certainly fail, then get let in and destroy the org but management still gets to say “the perimeter is flawless keep on not caring about security”
@XC3LL as an assessor, I am going to slap every customer with this screenshot when they push back against recommendations.