The US Cybersecurity and Infrastructure Security Agency (CISA) has published the results of two red team assessments that used similar attack techniques against two critical infrastructure organizations. Both organizations were eventually compromised at the domain level, but their security teams responded very differently.
In the case of “Organization A,” attackers gained access via a web application that still used default credentials. The intruders used the access to send phishing emails from an internal account and compromise four workstations.
The red team then gained higher privileges by abusing a default Active Directory setting and a misconfigured certificate template. The team used a modified BloodHound collector, customized to avoid static endpoint detection and response (EDR) signatures, to query and scrape Active Directory (AD) information. It also found cleartext credentials, permanent AWS access keys and overly powerful Entra ID applications. This allowed the team to get access to sensitive business systems and cloud resources.
Organization A failed to detect the activity. CISA said a large number of false-positive alerts, separate security tools and poor communication between security teams made it difficult to spot the real attack. One genuine alert was dismissed as a false positive because analysts couldn’t determine who owned the affected system.
“Organizational silos further hindered detection and response. The organization had multiple SOCs and multiple EDR solutions. Staff did not communicate with staff from other SOCs or have visibility on their detection tools. SOC staff and system owners also did not communicate with each other,” the advisory explains. “This led to SOC staff not actioning alerts from red team activity. For example, red team members noted chat exchanges regarding an SCCM in which defenders tried and failed to identify the system owner, its function, and its typical use. The SOC team eventually flagged the alert as a false positive.”
The CISA red team gained initial access to Organization B’s environment through a spearphishing campaign. The organization’s security team detected the phishing activity as the malicious files were opened and isolated the affected computers within two to 20 minutes. The attackers were prevented from establishing a working command-and-control connection and the attack was contained.
CISA then continued the assessment using an assume-breach approach and found that Organization B still had serious weaknesses, including exposed service-account credentials and excessive privileges. The red team was able to use the flaws to reach a domain controller and obtain sensitive authentication details.
The assessment also showed that Organization B had stronger network protections. A host in its operational technology environment could not connect to the internet, preventing the red team from establishing command-and-control. The team did not gain access to the organization's operational technology systems.