A red-team report says every test artefact was removed. What do you require before accepting that?
answer
- ask for the inventory, not the assurance
- one entry per artefact, per host
- walk the list yourself
- what you cannot find is a visibility gap
- captured credentials must be rotated
basics
~20 sAn itemised inventory of everything planted — files, persistence, accounts, credentials, exclusions — each with host, identifier and evidence of removal; then your own hunt for every item. What you cannot find is a visibility gap.
solid answer
~50 sAsk for the artefact inventory rather than the assurance. Each entry should name the host, the object (file path and hash, scheduled task or service name, account, group membership, firewall or anti-malware exclusion, DNS record or certificate), the time it was planted, the time and method of removal, and what evidences that removal. Then verify independently: hunt for every item on the list in your own telemetry. That is a rare gift — a known-good answer key for a hunt — and anything you cannot find is a finding about your visibility rather than about their honesty. Two things cleanup cannot fix: credentials the operators captured must be rotated, because knowledge cannot be deleted, and any artefact left behind is now unowned persistence indistinguishable from a real intruder's, which some analyst will find months later and correctly treat as an intrusion.
go deeper
Know that an engagement plants real objects — files, scheduled tasks, accounts — and that removing them is an obligation with evidence attached, not a promise in a report's final paragraph.
Be able to enumerate the artefact categories, including the easily forgotten ones: added accounts and role assignments, anti-malware and firewall exclusions, tokens and certificates, and cloud or SaaS persistence.
Show that you verify independently — walk the inventory in your own telemetry, treat what you cannot see as a visibility finding, and reconcile the list against your case notes so unexplained activity goes back into investigation.
Own the terms before the engagement starts: the inventory format, the cleanup and evidencing obligation, credential-rotation responsibility, report handling and destruction dates, and who signs off that the estate is back to where it started.
## Why "we cleaned up" is not an acceptable answer An adversary-emulation engagement leaves a trail of deliberately intrusion-shaped objects across production. Every one of them is, from the moment the engagement ends, an artefact nobody owns. The failure mode is concrete and common: eleven months later an analyst finds a scheduled task with an odd name on a file server, cannot attribute it, escalates correctly, and the organisation spends a night and a retainer callout discovering that it was left behind by a test. The cost of that night is the real argument for cleanup discipline, and it lands on the defenders rather than on the operators. ## The inventory, and what belongs on it Cleanup is verifiable only against a list. Require one entry per artefact with the host, the object identifier, when it was planted, when and how it was removed, and the evidence of removal. The categories to check the list covers: - **Dropped files** — payloads, staging directories, output such as dumps and archives, with paths and hashes. - **Persistence** — scheduled tasks, services, run keys, startup items, WMI event subscriptions on Windows; cron entries, systemd units, shell profile edits, authorized_keys entries on Linux; and their cloud and SaaS equivalents such as an added function trigger, an OAuth application consented into a tenant, or an application password on an identity provider. - **Identities** — accounts created, group memberships and role assignments added, API keys and tokens issued, certificates enrolled. - **Control changes** — anti-malware or endpoint exclusions, firewall rules, logging or audit settings that were altered to allow a step to run. These are the most dangerous leftovers, because they silently weaken the estate rather than sitting in it. - **Infrastructure and decoys** — command-and-control domains and certificates, planted decoy data and beacon files. ## Verify rather than accept The defender's job is not to read the list and file it. It is to go and look for every entry, in your own telemetry and on the hosts. This is one of the few moments a security team gets an answer key: you know exactly what was placed, where and when. - If you **find** an artefact that the report says was removed, you have a cleanup failure — remove it under change control and record it. - If you **cannot find** an artefact that the report says is still there, or cannot see the historical trace of one that was planted and removed, that is a **visibility finding** — a host not shipping telemetry, a log source silently stopped, retention shorter than you believed, or a data source that never carried the field you needed. This is frequently the most valuable output of the whole engagement, and it costs nothing extra to obtain. - Reconcile the inventory against your case notes. Activity in your cases that the inventory does not explain is unattributed, and it goes back into investigation. ## Two things cleanup cannot undo 1. **Captured credentials.** If operators obtained a password, a hash, a ticket or a token, deleting their copy does not restore the secret. The client rotates: the affected accounts, the service accounts, the keys — and, where domain-level credential material was reached, the associated recovery actions the client's own eradication process defines. A certificate of destruction covers the operators' copy and nothing else. 2. **Knowledge of the estate.** The engagement report itself is now sensitive: it is a map of what worked. It gets handled accordingly, with a stated destruction date for the operators' working data. ## Some things must not be cleaned up Cleanup is not a licence to erase evidence. Logs the exercise generated stay — they are the record the client's own response is reconstructed from. Removal actions themselves should be performed in a way that is logged and attributable, at a known time, ideally coordinated with the SOC so that the removal does not look like an intruder covering tracks and start a second incident. "The red team deleted its own scheduled tasks quietly at 03:00" is a genuinely alarming sentence for whoever sees it first. ## Close the loop The engagement is not finished when the report is delivered. It is finished when the inventory has been walked, each item confirmed present or absent by the defending team, the credential rotations are done, the exclusions are back, and every gap the walk exposed is written down as a finding with an owner. Accepting the assurance instead skips all of it, and the estate carries persistence that only the defenders will pay for.
- Which category of leftover artefact worries you most, and why?Control changes — an endpoint or anti-malware exclusion, a firewall rule, an altered audit setting. Files and tasks are visible objects somebody will eventually find; a leftover exclusion is an invisible hole that makes the next real intrusion easier and quieter, and nothing in the estate alerts on its continued existence.
- The exercise ended weeks ago and you find an account matching the operators' naming convention. How do you treat it?As unattributed persistence until proven otherwise. Investigate it as you would any unexpected privileged account: when it was created, by what, what it has authenticated to since. A naming convention is copyable, and an account that outlived the engagement may have been used by someone else. Disable, preserve, then reconcile against the inventory and the deconfliction contact.
- How should the removal of planted artefacts itself be coordinated?At a known time, through logged and attributable actions, with the trusted agent aware. Uncoordinated quiet deletion of tasks, accounts and files at 03:00 is behaviourally identical to an intruder destroying evidence, and it will start a second incident — which is an expensive way to end an engagement that had already finished.
saying these in an interview costs you the question
- Accepts a written assurance instead of an itemised inventory
- Never hunts for the listed artefacts in their own estate
- Thinks destroying the operators' copy makes a captured credential safe again
- Forgets endpoint and firewall exclusions added to allow a step
- Treats artefacts they cannot find as proof of clean removal
- Lets operators delete their persistence quietly and uncoordinated