@jehna Most likely: do you "build" security infrastructure/tools (SOC, endpoint detection, etc.) vs "break" into the security systems (pentesting, malware/red team tool developer, maybe risk assessment)
@jehna That's what I've heard it used as. But someone can be a breaker in a blue team (testing rules and security controls being built) and a builder in a red team (creating C2 infrastructure, building red team tools, purple teaming/assisting the blue team/client on how to fix issues found)
@jehna breaker roles usually just do technical testing like application security assessments, code review, various forms of penetration testing. Builders deploy and/or code stuff. That’s how I think about it anyway