mimile
Back to feed

CISA red team breaches government and water networks; water utility detects attack

AI digest

This digest was compiled by AI from multiple sources — links to the originals are below.

CISA red team breaches government and water networks; water utility detects attack

CISA red teamers gained initial access to both a government organization and a water utility during a simulated attack, but only the water utility detected and quarantined the compromise. The government organization failed to respond to endpoint alerts, allowing the red team to move laterally to sensitive business systems and cloud resources.

Key Facts

  • CISA red teamers gained initial access to both a government organization and a water utility, but only the water utility detected and quarantined the compromise.
  • At the water utility, three users clicked a malicious link, and the security operations center quarantined affected workstations in 2, 10, and 20 minutes.
  • At the government organization, red teamers used an internal email address for phishing, gained elevated privileges, and moved laterally to sensitive business systems and cloud resources undetected.
  • CISA faulted the government organization's security operations center for not responding to low- and medium-severity endpoint detection and response alerts, with thousands of false positives obscuring red team activity.

Red Team Exercise

CISA published a rare public report on its red-team activities on Tuesday, detailing tests against two unnamed organizations—one in the government sector and one in the water sector. The agency conducted the tests through a voluntary, by-request process. In the government organization, red teamers used an internal email address to send phishing emails, gained elevated privileges, and moved laterally to sensitive business systems and cloud resources undetected. The water utility detected the initial compromise after a spearphishing campaign convinced three users to click a malicious link.

Defensive Response

The government organization's security operations center received low- and medium-severity endpoint detection and response alerts but did not respond to them. CISA attributed the failure to thousands of false positives, including some with higher severity, that obscured alerts triggered by red team activity, as well as organizational silos. The water utility's security operations center triaged alerts and quarantined affected workstations in 2, 10, and 20 minutes respectively. After the water utility detected the compromise, the red team moved to an 'assume breach' model, with trusted agents providing access to a host replicating the level of access the red team would have had if defenders had not detected the activity.

1 source

CISA red team breaches government and water networks; water utility detects attack