By Gregory Hale
It wasn’t that long ago when a large critical infrastructure organization with multiple geographically separated sites requested a red team assessment (RTA) from the feds.

In the exercise, the team gained persistent access to the organization’s network, moved laterally across the organization’s multiple geographically separated sites, and eventually gained access to systems adjacent to the organization’s sensitive business systems (SBSs). Multifactor authentication (MFA) prompts prevented the team from achieving access to one SBS, and the team was unable to complete its viable plan to compromise a second SBSs within the assessment period.

Despite having a mature cyber posture, the organization did not detect the red team’s activity throughout the assessment, including when the team attempted to trigger a security response.

As a result of that exercise, the Cybersecurity and Infrastructure Security Agency (CISA) released a Cybersecurity Advisory (CSA) detailing the red team’s tactics, techniques, and procedures (TTPs) and key findings to provide network defenders of critical infrastructure organizations proactive steps to reduce the threat of similar activity from malicious cyber actors.

Importance of Logs
This CSA highlights the importance of collecting and monitoring logs for unusual activity as well as continuous testing and exercises to ensure your organization’s environment is not vulnerable to compromise, regardless of the maturity of its cyber posture.

Schneider Bold

As a result of its findings, CISA encourages critical infrastructure organizations to apply the recommendations.

Actions to harden your local environment:

  • Establish a security baseline of normal network activity; tune network and host-based appliances to detect anomalous behavior.
  • Conduct regular assessments to ensure appropriate procedures are created and can be followed by security staff and end users.
  • Enforce phishing-resistant MFA to the greatest extent possible.

“Upon reading the report, my initial reaction is that OT networks and systems are not mentioned,” said Jori VanAntwerp, chief executive and co-founder at SynSaber. “While the IT system discussed could adversely affect the day-to-day business operations of an organization, there isn’t any explicit mention or evidence of manipulation or interruption to process control or operation. While the simulated breach in this red team is concerning, and defenses should be bolstered, I’m not entirely sure that this would have affected the operations of a critical infrastructure environment.

“Critical infrastructure providers are more aware than ever of what needs to be done to secure their environments. The challenge now shifts to the implementation of best practices to mitigate risk, such as segmentation, visibility, detection, and monitoring. Exercises such as this provide defenders with the point of proof necessary to ensure that budget and resources are properly implemented to improve posture and overall defense of operations.

“These findings highlight some of the challenges OT is facing in terms of implementing cybersecurity best practices such as proper segmentation, network visibility, detection, access privileges, and more.”

During RTAs, a CISA red team emulates cyber threat actors to assess an organization’s cyber detection and response capabilities. During Phase I, the red team attempts to gain and maintain persistent access to an organization’s enterprise network while avoiding detection and evading defenses. During Phase II, the red team attempts to trigger a security response from the organization’s people, processes, or technology.

The “victim” for this assessment was a large organization with multiple geographically separated sites throughout the United States. For this assessment, the red team’s goal during Phase I was to gain access to certain sensitive business systems.

The organization’s network was segmented with both logical and geographical boundaries. CISA’s red team gained initial access to two organization workstations at separate sites via spearphishing emails.

Leveraging Active Directory
After gaining access and leveraging Active Directory (AD) data, the team gained persistent access to a third host via spearphishing emails. From that host, the team moved laterally to a misconfigured server, from which they compromised the domain controller (DC). They then used forged credentials to move to multiple hosts across different sites in the environment and eventually gained root access to all workstations connected to the organization’s mobile device management (MDM) server.

The team used this root access to move laterally to SBS-connected workstations. However, a multifactor authentication (MFA) prompt prevented the team from achieving access to one SBS, and Phase I ended before the team could implement a seemingly viable plan to achieve access to a second SBS.

Red Team cyber threat activity shows initial access and lateral movement.Source: CISA

The CISA red team gained initial access to two workstations at geographically separated sites (Site 1 and Site 2) via spearphishing emails. The team first conducted open-source research to identify potential targets for spearphishing. Specifically, the team looked for email addresses as well as names that could be used to derive email addresses based on the team’s identification of the email naming scheme.

The red team sent tailored spearphishing emails to seven targets using commercially available email platforms. The team used the logging and tracking features of one of the platforms to analyze the organization’s email filtering defenses and confirm the emails had reached the target’s inbox.

Building Rapport
The team built a rapport with some targeted individuals through emails, eventually leading these individuals to accept a virtual meeting invite. The meeting invite took them to a red team-controlled domain with a button, which, when clicked, downloaded a “malicious” ISO file. After the download, another button appeared, which, when clicked, executed the file.

Two of the seven targets responded to the phishing attempt, giving the red team access to a workstation at Site 1 (Workstation 1) and a workstation at Site 2. On Workstation 1, the team leveraged a modified SharpHound collector, ldapsearch, and command-line tool, dsquery, to query and scrape AD information, including AD users, computers, groups, access control lists (ACLs), organizational units (OU), and group policy objects (GPOs). SharpHound is a BloodHound collector, an open-source AD reconnaissance tool. Bloodhound has multiple collectors that assist with information querying.

“My view is that for critical infrastructure, I don’t think their security posture or the advice that they should be following has changed,” said Paul Scott, R&D solutions engineer at Cado Security. “Threat actors continue to do what works which at the moment still tends to be phishing of staff or abusing publicly known exploits in unpatched web-facing infrastructure. For critical infrastructure, their key difference between corporations is their industrial control systems which are often never patched or not able to be patched and are accessible remotely by support vendors with limited or no network segmentation or controls in place.

  • “To me,” Scott said, “the key things that I’ve seen fail in industrial settings are:
  • Little or no network segmentation between industrial control devices
  • Little or no segmentation of domains and domain trusts
  • Little or no implementation of strict firewall rules between applications
  • No logging or detections on access from 3rd party support providers
  • No ability to detect anomalies on industrial systems (e.g., programmable logic controllers)
  • Overly permissive user account access allowing lateral movement after initial compromise”

Click here for more on the Red Team advisory.

ISSSource

Pin It on Pinterest

Share This