RedTeaming-Tactics-and-Techniques: Personal Red Team Notes Published as a GitBook
Red Teaming Tactics and Techniques
At a glance
- What is it?
- RedTeaming-Tactics-and-Techniques is a personal red teaming notes repository by @spotheplanet, published as a public GitBook at ired.team. It covers code execution, code injection, defense evasion, lateral movement, and persistence techniques studied in lab environments, with references to the original researchers who discovered each technique.
- Who is it for?
- RedTeaming-Tactics-and-Techniques suits security practitioners who want a practitioner's perspective on offensive techniques, complete with lab experiment notes and original source attribution. It is not a polished training course or an authoritative reference: the README explicitly warns that the notes may contain mistakes, are not exhaustive, and should be supplemented with additional resources.
- Can I use it commercially?
- Not without permission. GitHub finds no licence file in the repository, and without a licence all rights are reserved by default: you may read the code but not reuse it. Check the README, or ask the authors, before using it.
- Is it still maintained?
- Yes. The repository last received commits 110 days ago.
- What is it written in?
- Mainly PowerShell, according to GitHub's language statistics.
Answers come from the project's GitHub data, last synced on September 29, 2026, and from our analysis. They are not legal advice.
Editorial analysis
What This Repository Is and Who It Is For
RedTeaming-Tactics-and-Techniques is the GitHub backing for a publicly accessible personal notes site at ired.team. The author, @spotheplanet (Mantvydas Baranauskas), describes it as notes about all things focusing on, but not limited to, red teaming and offensive security.
The repository is not a tool to install or run. It holds GitBook-formatted Markdown notes that are published to the ired.team website. The audience is security practitioners who want to understand how specific offensive techniques work at a technical level, with an emphasis on Windows internals, C++, Windows APIs, and the artifacts that techniques leave on endpoints.
The README states the project goal directly: read other researchers' work, execute common and uncommon attacking techniques in a lab environment, and take notes for future reference. This is learning-by-doing documentation. The author does not claim to have discovered the techniques documented, and the README says that sources are referenced as best as possible.
Repository Structure and How to Navigate It
The top-level directory contains these entries: .gitbook/, .gitignore, .vscode/, README.md, SUMMARY.md, lab/, miscellaneous-reversing-forensics/, offensive-security-experiments/, and offensive-security/.
GitBook uses SUMMARY.md as the table of contents that generates the sidebar navigation at ired.team. The three content directories correspond to broad topic groups:
- offensive-security/ holds the main red teaming technique notes - offensive-security-experiments/ holds more experimental or lesser-known technique notes - miscellaneous-reversing-forensics/ covers reverse engineering and forensics topics - lab/ contains notes related to lab setup and tooling
Readers who clone the repository work with raw Markdown files. The .gitbook/ directory holds GitBook configuration. The site at ired.team is the rendered version, with full search and navigation. The GitHub repository is the source; GitBook builds and hosts the rendered site.
The README is formatted as a GitBook document with hint blocks ({% hint style="warning" %} and {% hint style="danger" %}) that render as callout boxes on ired.team but appear as raw template syntax in GitHub's Markdown viewer.
Topics Covered: From Code Execution to Defense Evasion
The README describes the scope as: gaining code execution, code injection, defense evasion, lateral movement, persistence, and more. The notes specifically name understanding Windows APIs and Windows internals as learning objectives, and the primary language of the repository is PowerShell, reflecting that many documented techniques involve PowerShell scripts or require a Windows environment.
The author describes writing code to understand tools and techniques used by attackers and malware authors, and studying what artifacts the techniques and tools leave behind on the endpoint. This dual focus, execution plus artifact analysis, makes the notes useful for both offensive security practitioners understanding what they can do and defensive practitioners understanding what to detect.
The techniques documented are drawn from existing security research. The README is direct: "Most of these techniques are discovered by other security researchers and I do not claim their ownership. I try to reference the sources I use the best I can."
The work is conducted in controlled lab environments. The README provides no guidance on setting up those environments, but the lab/ directory suggests some notes on that subject are included.
Limitations and the Explicit Warnings From the Author
The README contains three explicit cautions that should inform any professional use of this material.
First: "Do not take everything or anything in these notes for granted." The notes reflect one practitioner's experiments and may contain errors. Second: "Do not expect the notes to be exhaustive or covering the techniques or the artifacts they produce in full." Each technique has more depth than a personal note can capture. Third: "Expect mistakes in the notes. Always consult additional resources."
These are not boilerplate disclaimers. They reflect the genuine nature of a learning notebook that grows with the author's experiments. Any red team operator who relies solely on these notes for operational technique selection, without verifying the technique against current environment conditions, accepts the risk the author describes.
The repository also carries a direct warning against cloning ired.team and presenting it as original work, which is described as illegal and strictly forbidden. This applies to any scraping, forking, or republishing of the content under a different name.
Finally, this repository contains no tooling. There are no scripts to run, no compiled binaries, and no install instructions. It is documentation only.
How This Compares to Structured Red Team Training Resources
The closest comparable resource in structure is the PayloadsAllTheThings repository, which is also a community-maintained collection of offensive security technique references. The difference is in authorship and curation: PayloadsAllTheThings accepts community pull requests and covers a wide range of vulnerability classes in a more encyclopaedic format. RedTeaming-Tactics-and-Techniques is a single practitioner's notes, with a tighter focus on Windows internals and code-level technique analysis.
Formal training platforms such as Offensive Security's courses or SANS SEC560 are structured courses with verified lab environments, instructor support, and certification outcomes. They have explicit learning paths and are vetted for accuracy before publication. RedTeaming-Tactics-and-Techniques has none of those properties: it is a living notebook that improves when the author learns something new and may go months without an update in a given area.
For practitioners who want a peer's perspective on a specific Windows technique, with code examples and artifact notes, the ired.team site is a well-known reference in the offensive security community. For a formal qualification or a comprehensive reference, it is a complement, not a substitute.
Maintenance State and Access
The last push was on 2026-06-13, indicating activity earlier this year. The repository has no GitHub Releases and no formal changelog. Updates happen as the author adds or revises notes.
The repository has no licence file listed in the GitHub metadata. The README warning against cloning and presenting the content as original work establishes that all-rights-reserved is the intended stance, but no formal open-source licence governs the repository's use.
The published site at ired.team is the primary access point. The GitHub repository is the source of truth for the raw Markdown. Both are publicly accessible without login. The README also notes that the site can be found at https://github.com/mantvydasb/RedTeam-Tactics-and-Techniques (a slightly different repository name from the one described here; both appear to exist).
The author maintains a Patreon and accepts PayPal support for those who find the notes useful, as noted in the README.
Editorial conclusion
RedTeaming-Tactics-and-Techniques suits security practitioners who want a practitioner's perspective on offensive techniques, complete with lab experiment notes and original source attribution. It is not a polished training course or an authoritative reference: the README explicitly warns that the notes may contain mistakes, are not exhaustive, and should be supplemented with additional resources. Developers and defenders who want structured, vetted courseware should look elsewhere. The repository is a personal notebook that happens to be publicly accessible at ired.team, and it should be read as such.
Frequently asked questions
Is RedTeaming-Tactics-and-Techniques a tool or a documentation resource?
It is documentation only. The repository contains Markdown notes that power the ired.team GitBook site. There are no scripts, binaries, or install steps. The primary language is PowerShell because many documented techniques involve PowerShell, but the repository itself is not a runnable toolkit.
Can I use the ired.team notes for professional red team operations?
The README explicitly warns that the notes may contain mistakes, are not exhaustive, and should always be supplemented with additional resources. The author describes them as personal learning notes from controlled lab experiments. Professional use should treat them as a starting reference, not a definitive operational guide.
What licence applies to the RedTeaming-Tactics-and-Techniques content?
The repository carries no open-source licence file. The README explicitly prohibits cloning the site and presenting it as original work. Any intended reuse should contact the author directly.
Official sources
Add this badge to your README
If you maintain this project, the badge below links readers to this analysis and shows its maintenance status from the daily GitHub snapshot. Paste the markdown into your README; add ?metric=license or ?metric=stars to the image URL for a different field.
[](https://hysenlabs.com/projects/mantvydasb-redteaming-tactics-and-techniques)