Gary Lobermier on Scaling Red Team Automation with AI to Run Hundreds of Real Attacks Daily episode artwork

EPISODE · May 1, 2026 · 31 MIN

Gary Lobermier on Scaling Red Team Automation with AI to Run Hundreds of Real Attacks Daily

from Ahead of the Breach · host Sprocket Security

Most security teams test their detections once a year. Gary Lobermier, Lead Adversarial Security Engineer at Northwestern Mutual, built something different: a custom automation platform that executes hundreds of MITRE ATT&CK techniques daily across Windows, macOS, Linux, and AWS, giving his team real-time signal on whether their defenses actually hold. In this episode, Gary breaks down why off-the-shelf purple team tools fall short at enterprise scale, the procedure-level gap nobody talks about in the MITRE ATT&CK framework, and what EDR vendors don't advertise about their own coverage limits. He also shares how his non-traditional path (from network admin to red teamer) shaped the way he thinks about adversary emulation and detection engineering. If you're building or scaling an offensive security program and want to know what continuous validation actually looks like in practice, this one's worth your time.

Episode metadata supplied by the publisher feed · Published May 1, 2026

Embed this episode

NOW PLAYING

Gary Lobermier on Scaling Red Team Automation with AI to Run Hundreds of Real Attacks Daily

0:00 31:06

No transcript for this episode yet

We transcribe on demand. Request one and we'll notify you when it's ready — usually under 10 minutes.

No similar episodes found.

No similar podcasts found.

Frequently Asked Questions

How long is this episode of Ahead of the Breach?

This episode is 31 minutes long.

When was this Ahead of the Breach episode published?

This episode was published on May 1, 2026.

Can I download this Ahead of the Breach episode?

Yes. Use the download control on the episode player to save the publisher-provided media file.
URL copied to clipboard!