
My Red Team Internship at Cloudflare: The Story So Far
My Red Team Internship at Cloudflare: The Story So Far
In June 2026, shortly after graduating in Cyber Security, I started a Red Team Security Internship at Cloudflare. I'm writing this near the end of it, with a few months of context behind me and a few weeks still to go.
The short version of what I do: I attack production infrastructure the way a real adversary would, and then I work with the blue team to detect and fix what I found. The attacking is the fun half. The second half is the one that actually makes the company safer, and it's the half I've learned the most from.
How I Started
Simple to say, considerably less simple to actually do. My first weeks were mostly orientation: understanding how the environment is put together, where the interesting edges are, and how a red team engagement is actually run at a company operating at this level, rather than in a lab or a CTF.
Operating at a Different Scale
I'd done plenty of penetration testing on university labs, CTF infrastructure, and small self-built environments before this. None of it quite prepares you for working against infrastructure that sits in the path of a meaningful share of the world's internet traffic. Every assumption I'd built up about how big a system can get needed adjusting. The scale changes how you think about everything: how you scope an engagement, how careful you have to be about impact, and how much more there is to actually explore.
Working Alongside People Who've Done This for a Long Time
The most valuable part of the internship hasn't been the tooling or the targets, it's been the people. I'm working alongside red teamers and blue teamers with years of experience running real engagements against real infrastructure, and the gap between knowing the theory and having done this hundreds of times is obvious within the first conversation. Watching how experienced operators scope an engagement, communicate risk, and decide what's worth chasing versus what's a rabbit hole has taught me more in a few months than any single course did.
Building My Own C2
Part of the internship has involved building my own command-and-control framework rather than relying entirely on off-the-shelf tooling. Writing a C2 from scratch forces you to actually understand what every existing framework is doing under the hood: how implants check in, how operators queue and route tasks, how you keep operational traffic from standing out against everything else on the wire. It's one thing to run someone else's tool. It's a completely different level of understanding to have written the thing yourself. You start thinking about every design choice differently: why encode this way, why check in at this interval, what happens if the detection side is watching for exactly this pattern.
That last part is the bit I didn't expect to enjoy so much. Building offensive tooling inside an organisation that also has a very capable blue team means you're never just building for yourself. You're building something that's going to be looked at, caught, and picked apart, and that feedback loop makes you a better engineer on both sides.
Closing the Loop With the Blue Team
The part of this job I didn't anticipate enjoying is what happens after the engagement. Finding a way in is satisfying, but on its own it's just a finding sitting in a document. The value shows up when you sit down with the detection side and work through it: did anything fire? If not, why not? What would this have looked like in the logs, and what signal would have separated it from ordinary noise?
That conversation changes how you attack. Once you've watched a detection engineer explain why one technique was invisible and a nearly identical one lit up immediately, you stop thinking of offense and defense as separate disciplines. You start seeing every action you take as something that either leaves a detectable trace or doesn't, and asking why. Working both sides of that loop, over and over, has taught me far more about monitoring and incident response than studying either one on its own would have.
The First Physical Pentest
One of the things I was most nervous about before starting was the idea of going on an actual physical security assessment. Pentesting a network you can reach from a laptop is one thing. Walking into a building and trying to get into places you're not supposed to be is a completely different kind of exposure. The first time, I was genuinely worried I'd get it badly wrong: look suspicious, get stopped, blow the assessment before it had really started.
In practice it was less dramatic and more nuanced than I expected. Physical security has its own logic. It isn't about exploiting software, it's about understanding human behaviour, building layouts, social dynamics, and what reads as out of place. You spend less time looking for a technical win and more time observing how people actually move through a space: when they hold doors open for someone behind them, which areas have meaningful access control, and which ones rely on nobody stopping to think about it.
What surprised me most is that the hardest part usually isn't the lock or the badge reader. It's holding a story together. Walking with purpose, looking like you belong, and not panicking when somebody asks what you're doing. It's social engineering in physical space, and it needs a very different headspace from sitting at a terminal.
What Comes Next
I've got a few weeks left, and the goal now is to pull everything together into the final deliverable. This experience has shown me how much depth there is to security work that you simply can't get from labs or competitions. It isn't about knowing every tool or technique. It's about developing judgment, learning from people who've done this at scale, and understanding that real-world security is always messier and more human than the textbook version.
It has also pointed me somewhere specific. I came into this thinking of myself as an offensive person. I'm leaving it much more interested in the detection and response side, because that's where the offensive knowledge actually gets cashed in. Knowing how an attacker moves is most useful when you're the one deciding what to alert on.
If you're early in a cybersecurity career and you get the chance to do a red team internship, take it. Even if it feels intimidating. Especially if it feels intimidating.