[Speakers]
Adversary Village at
DEF CON 34

Michael Ortiz

Red Team Engineer

Michael Ortiz is a Red Team Engineer and SME on the U.S. Department of State's Red Cell, running adversary emulation across State enterprise and partner networks. His focus spans offensive tradecraft, evasion engineering against modern EDR's, and the cybersecurity engineering behind durable red team infrastructure. He's the founder of devZero Security, an SDVOSB offering offensive security and security engineering services to federal and commercial clients, and the developer of redStack, an open source AWS and Terraform project that stands up a full red team operations stack on demand. A Marine Corps veteran, Mike holds OSEP, OSCP, CRTO, and CRTL, among other certifications.

redStack: Boot-To-Breach Red Team Platform

10:00-11:55 PDT | Sunday, Aug 9th 2026 | Adversary Village Workshop Stage, Las Vegas Convention Center
Hands-on Workshop

Co-presented with: Michael Kim

Abstract

A two-hour hands-on workshop/tactic where attendees stand up a red team operator stack (https://github.com/BaddKharma/redStack) and execute a multi-C2 kill chain against a live cyber range. Each attendee gets their own range instance delivered over an OpenVPN tunnel, so no public DNS or exposed infrastructure is required.


Agenda:
10 min, theory and setup verification. Attendees arrive prepped per the prereq packet (AWS CLI, Terraform, AWS account, OpenVPN client). I frame the session with the multi-C2 segmentation tradecraft pattern that the rest of the time builds on.


40 min, staging and provisioning, narrated live. Attendees stand up their operator stack while I talk through each component, the design choices behind it, and the operator decisions that show up at deploy time.


10 min break.


45 min, attack path on a live cyber range. Each attendee runs against their own individually instanced range over OpenVPN. We work through the chain together: Mythic for initial access, Sliver for lateral movement, Havoc for domain dominance. I stay at the table answering questions while attendees execute.
15 min, Q&A, and teardown. I remain available after the slot for one-on-ones with anyone who wants more time on a specific piece.


A prerequisites packet will be published in advance and will cover AWS account setup, CLI and Terraform install, OpenVPN client, and any local tooling. Total AWS footprint stays within default account quotas at 8 instances and 16 vCPU, so no quota increase request is required.

Agency.


Join Adversary Village Discord Server.

Join Adversary Village official Discord server to connect with our amazing community of adversary simulation experts and offensive security researchers!