ZeroHour
CyberScooppublished ()ingested @timstarks1

Water sector passes, government sector fails attempts to spot and halt simulated CISA attack

infoAdvisoryimportance 55
AI summary · glm-5.3-flash

CISA red teamers compromised both a government and a water organization; water defenders detected and contained the simulated attack, government defenders did not.

CISA's red team gained initial access, elevated domain privileges, and lateral movement into sensitive business systems and cloud resources at an unnamed government organization, whose SOC ignored low- and medium-severity EDR alerts buried under thousands of false positives. A water organization's SOC quarantined phishing-compromised workstations within 2, 10, and 20 minutes, and later detected and isolated intrusions reaching the OT DMZ bastion host. Both organizations underestimated cloud risk, lacked Microsoft Conditional Access for workload identities, and had no process to revoke compromised access and refresh tokens. This is one of CISA's rare public red-team reports since 2023.

  • Water organization's SOC quarantined compromised workstations within 2, 10 and 20 minutes
  • Government organization ignored EDR alerts buried under thousands of false positives
  • Red team reached sensitive business systems, cloud resources and an OT DMZ bastion host
  • Both lacked Conditional Access for workload identities and token revocation processes
  • Rare public CISA red-team report, series first published in 2023
VendorsMicrosoft
OrganizationsCISA
CountriesUnited States
Full article758 words · extracted from cyberscoop.com · click to collapse
Skip to main content

Get our latest cybersecurity news first on Google.

Click here!

Agency red-teamers got initial access to both organizations they tested, but one quickly isolated and shut down the attempts from going further.

Listen to this article

0:00

Learn more.

(Getty Images)

When the Cybersecurity and Infrastructure Security Agency tested defenses for two targets — one in the government sector and the other in the water sector — red teamers were able to get into both of their systems, but the water organization discovered the simulated attack and acted to defend itself, whereas the government organization did neither.

CISA published the breakdown Tuesday in a rare public report on its red-team activities, at a time when attacks on the water sector have a higher profile after revelations of targeting of water facilities across the United States over the past month and numerous government warnings.

The agency didn’t name the organizations it tested through a process that is voluntary and by-request.

“In one organization (Organization A), the team gained initial access to multiple workstations, gained elevated privileges over the domain, and moved laterally to [sensitive business systems] and cloud resources undetected,” CISA’s analysis reads. “In the second organization (Organization B), network defenders quickly detected the initial compromise and quarantined the affected systems.”

For “Organization A,” the government organization, CISA used an internal email address to send phishing emails to gain access to the workstations, probed further to gain elevated privileges, then moved around and compromised targeted sensitive business systems. The red teamers observed that the organization “did not respond effectively to red team activity” by accessing personnel emails at its security operations center, where they saw them receive low- and medium-severity endpoint detection and response alerts, but didn’t respond to them.

False positives by the thousands, including some with higher severity, “obscured the alerts triggered by red team activity,” CISA said. The agency also faulted “organizational silos.”

Meanwhile, at “Organization B,” the water organization, CISA got access via a spearphishing campaign, convincing three users to click on a malicious link to gain access to workstations. This time, the security operations center triaged the alerts and quarantined the work stations in 2, 10 and 20 minutes, respectively.

The red teamers tried another approach with the help of the organization’s IT contacts who were aware of the activity, but were foiled in their follow-ups.

“Because Organization B detected the initial compromise, the red team moved to an ‘assume breach’ model, where Organization B trusted agents (TAs) provided access to a host that replicated the level of access the red team would have had if defenders had not detected their activity,” CISA wrote. “From there, the red team escalated privileges and moved laterally to [sensitive business systems], cloud resources, and a bastion host in the OT [operational technology] demilitarized zone (DMZ), where defenders again detected activity and isolated the system.”

Still, CISA said both organizations had flaws in their defenses: They underestimated cloud risks; they lacked Conditional Access — a Microsoft security tool — for workload identities; and they didn’t have processes in place to revoke compromised access/refresh tokens.

CISA first published an advisory on its red team activity in 2023, but such advisories have been few and far between since. The agency said last year that it had not “laid off” its red team, after stories revealed the exit of contractors that included red-team members.

Latest Podcasts

Text extracted automatically; images, tables and formatting may be missing. Original: https://cyberscoop.com/cisa-red-team-report-government-water-cybersecurity/