Memoirs of a DoD Red Teamer, Vol 1: Welcome to the Team
This is the first post in what is probably going to be a long series and it is something different than the other more topical posts. This is the slower walk through the years I spent inside the Marine Corps Cyberspace Operations Group, what the work actually looked like, and how I ended up running the Marine Corps Red Team.
I am going to split this across several posts because the material is too dense to do justice in one. Vol 1 is the on-ramp. How I got to MCCOG, what I was doing there before the red team, and how I ended up walking onto the team.
We will be keeping a tight OPSEC posture throughout the volumes and content to come. No dates, no specific techniques, no names beyond people who already publish under their own names. Where details have been generalized, they have been generalized on purpose.
MCCOG
Before the MCCOG, I spent the first stretch of my Marine Corps career in the communications and electronics field, doing telecommunications and maintenance work. I moved into cybersecurity later in that stretch, when the Marine Corps was still figuring out how to build the workforce for it and the pipeline was less formalized than it is now. I spent the three years before the MCCOG in Okinawa, running a group-level cybersecurity program in the Pacific. I left Okinawa in 2018 and picked up at the Marine Corps Cyberspace Operations Group as a cyber threat analyst.
MCCOG is the operational hub for Marine Corps cyber. The defenders sit there. The red team sits there. The threat analysis function sits there. The leadership for most of the Marine Corps’s day-to-day cyber operations sits there. Walking in for the first time as a Staff Sergeant who had spent the last three years running a group-level cybersecurity program in the Pacific was a different kind of culture shock than I was expecting. It was a difference scale and tempo, with different kinds of conversations happening in every room.
My job for the first stretch was on the threat analysis side. I spent that year looking at Marine Corps networks through the lens of the MITRE ATT&CK framework, mapping what we knew about adversary tactics and techniques against what our networks were actually configured to detect and prevent. The work was equal parts intelligence analysis and defensive engineering, and it was the first time in my career I was being asked to think about the network from the adversary’s perspective rather than from the administrator’s. That shift in framing is the thing that pulled me toward offensive work later. Once you start asking what an adversary would do here, it is hard to go back to asking only what the policy says you should do.
The Schools and the Certs
In parallel with the day job, I was in school more or less continuously.
The Marine Corps had a relatively new cyber pipeline at the time, and I was working my way through it. The career-level school for cyber Marines and the technical courses that came after it, along with he cross-training that the command pushed people through when they had operational gaps to fill. I was also working toward a Project Management Professional certification, because the work I was doing was as much program management as it was technical, and the PMP was a useful credential to have on the paperwork side.
I was also working toward a bachelor’s degree in cybersecurity policy and management. The degree had been on my list for a while, and the years at MCCOG were when I actually committed to finishing it. I took classes on the same general cadence I worked through the certifications, which is to say in whatever windows the job and the rest of life left available. The degree program lived somewhere between academic and applied, which suited the kind of work I was doing. The policy half kept me honest about how the institution was supposed to operate. The management half gave me the vocabulary to talk about it.
The thing that made all of the certificates possible was the Marine Corps COOL program. Credentialing Opportunities On-Line. The short version is that COOL paid for certifications relevant to your military occupational specialty, and if you were willing to put in the study time, you could stack credentials at the institution’s expense. I took full advantage of it. I worked through a series of CompTIA certs. I studied for them on my own time, scheduled the exam when I felt ready, and rolled the next one in behind it. The pattern that worked for me was simple. Study until I was confident enough to take the test and then move to the next one.
Some people in the building viewed COOL as something to be tolerated. I viewed it as the institution offering me free credentials and free training, and I did not understand why anyone would say no to that. The credentials were not the point in themselves. The studying that produced the credentials was the point. Every cert I prepared for taught me something I had not known before, and the body of knowledge accumulated. By the time I rotated toward the red team, I was carrying a stack of certifications that opened doors and, more importantly, a working knowledge of the material those certifications represented.
I am going to take a small detour here to say something that I think a lot of people in this field get wrong. The certification is not the value. The studying is the value. If you cram for an exam, pass it, and forget the material, you have a piece of paper and nothing else. If you take the studying seriously, the paper is the byproduct of work that actually changed what you know. The COOL program let me do the work for free. That is the part that mattered.
The Engineering Cell Lead
The other thing that happened during that stretch at MCCOG was that I reconnected with an old friend. Robert Woodcock. One of the best men you will ever meet.
He and I went back. We had met years earlier in an airport and instantly became great friends. We were both heading to the Marine Corps cybersecurity school and decided to live together as roommates during the schooling, before I left for Okinawa and he went on to MCCOG. By the time I arrived several years later, he had been on the red team for a while and had grown into the engineering cell lead. The reunion was the kind that does not require any catching up. You pick up where you left off and you keep going.
He was the second-ranking Marine on the team. The engineering cell handled the things that did not get into the trade-press writeups but determined whether the team could actually execute. The backbone of what the team did rested on the cell he was running.
We were close, which meant I gave him no peace about his job. I told him, more than once and with varying degrees of seriousness, that I was going to take it from him. He took the joke well, mostly because I think he assumed it was a joke. I am not sure I was entirely joking.
The thing about being in the same building as a red team you are interested in is that the team sees your work. The chief of the red team was leaving. The federal civilian who ran the broader team had heard my name enough through the normal flow of cross-team work that he had formed an opinion about me. He kept telling the leadership of the Defensive Cyber Operations section that we all fell under that he wanted me. I did not know any of this at the time. I learned it later. What I knew at the time was that I got told there was an opportunity to come over to the team if I could prove I belonged there.
The Course
The way you proved you belonged was the Marine Corps Red Team Operations Course.
The course was the team’s internal pipeline. The team ran it. The team graded it. The team decided whether you were going to be allowed to walk through the door at the end of it. Two weeks, front to back. A mix of academics and practical work, with the practical portion designed to put you under realistic operational load and see how you held up. Long days, hard problems, no shortage of opportunities to make mistakes, and people watching to see how you responded to making them.
The curriculum walked through the phases of a red team operation in the order they actually happen. Open-source intelligence work first, because reconnaissance is where every operation starts and where a surprising amount of the final report ends up being sourced from. Phishing came next, because getting an initial foothold is the operation’s first real inflection point, and doing it well takes more craft than people who have not tried it tend to appreciate. Then command and control, moving from foothold to persistence to lateral movement, the mechanics of actually operating inside a network without getting caught. Then the network takeover work itself, the escalation, the domain compromise, the objectives that make the operation matter. Then reporting, which is a discipline of its own and should be taken as seriously as any of the technical phases, because a report that does not communicate the finding does not fix anything and the whole operation was for nothing.
Each of those phases had a classroom component and a lab component. You would spend part of a day learning the material and part of the day doing it against a target environment set up for the course. The instructors would rotate through, watching, occasionally intervening when the situation warranted, mostly letting you figure things out, take notes on the times you did not, and remind you when you hit a wall in the network you think might be a defect that “that is the intended result.”
The last two days of the course were the exam. Day one was an eight-hour window in which you had to run a full engagement against the lab network, from outside in. You started from nothing. No credentials, no foothold, no map. You did your own reconnaissance, you built your own phishing pretext, you got your own initial access, and you worked your way through to domain compromise on the clock. Eight hours is not a long time to do that end to end. The instructors set it up that way deliberately. Real operations take weeks or months. The exam compresses the arc into a day because you cannot run a two-week test as a two-week exam, but you can learn a lot about somebody by watching them do the whole thing under time pressure with nobody helping.
Day two was the report. You had the day to write it. What you had done, how you had done it, what you had found, what the organization should do about it. If day one told the instructors how you operated, day two told them how you communicated. Both mattered. A red teamer who cannot write is a red teamer whose work does not land.
I will not get into more of the curriculum than that. The short version of how it went for me is that I did well. I was carrying the work I had done on the threat analysis side, the program management instincts from running the unit-level cybersecurity program in Okinawa, the technical knowledge from the COOL grind, and the operational mindset I had been building in the months leading up to the course. The course was hard. I was prepared for hard.
By the end of it, the team made the offer. I accepted
The Seat
My friend rotated up to red team chief as the previous chief left. I took the seat he had just vacated and became the engineering cell lead. The transition happened cleanly, and the building barely flinched.
What I walked into was a job with more surface area than I had appreciated from the outside. I was responsible for the team’s infrastructure, the tooling we used to execute operations, the phishing program for the entire Marine Corps, and the internal capability development that made everything else possible. A lot of what the team did externally rested on whether my cell was producing internally, and a lot of what my cell was supposed to be producing was, when I got there, behind where it needed to be. Some of the tooling was out of date. Some of the infrastructure had drifted. The phishing program needed work. This was not due to Woody in the seat before me because, as I knew as, there was always a list of things that needed done, and the list was long.
That list, and what it took to actually work through it, is where Vol 2 picks up.
This was a stretch of my career working inside the Department of Defense, and the descriptions in this post have been generalized to keep the focus on the experience and the lessons rather than the tradecraft. No personnel beyond those who already publish under their own names are identifiable. No units, dates, locations, techniques, or outcomes are presented in a way that would identify specific systems or people. Where details have been generalized, they have been generalized on purpose.


