Water sector passes, government sector fails attempts to spot and halt simulated CISA attack
CISA red teamers compromised both a government and a water organization; water defenders detected and contained the simulated attack, government defenders did not.
CISA's red team gained initial access, elevated domain privileges, and lateral movement into sensitive business systems and cloud resources at an unnamed government organization, whose SOC ignored low- and medium-severity EDR alerts buried under thousands of false positives. A water organization's SOC quarantined phishing-compromised workstations within 2, 10, and 20 minutes, and later detected and isolated intrusions reaching the OT DMZ bastion host. Both organizations underestimated cloud risk, lacked Microsoft Conditional Access for workload identities, and had no process to revoke compromised access and refresh tokens. This is one of CISA's rare public red-team reports since 2023.
- Water organization's SOC quarantined compromised workstations within 2, 10 and 20 minutes
- Government organization ignored EDR alerts buried under thousands of false positives
- Red team reached sensitive business systems, cloud resources and an OT DMZ bastion host
- Both lacked Conditional Access for workload identities and token revocation processes
- Rare public CISA red-team report, series first published in 2023
Full article758 words · extracted from cyberscoop.com · click to collapse
Get our latest cybersecurity news first on Google.
Agency red-teamers got initial access to both organizations they tested, but one quickly isolated and shut down the attempts from going further.
Listen to this article
0:00
Learn more.
When the Cybersecurity and Infrastructure Security Agency tested defenses for two targets — one in the government sector and the other in the water sector — red teamers were able to get into both of their systems, but the water organization discovered the simulated attack and acted to defend itself, whereas the government organization did neither.
CISA published the breakdown Tuesday in a rare public report on its red-team activities, at a time when attacks on the water sector have a higher profile after revelations of targeting of water facilities across the United States over the past month and numerous government warnings.
The agency didn’t name the organizations it tested through a process that is voluntary and by-request.
“In one organization (Organization A), the team gained initial access to multiple workstations, gained elevated privileges over the domain, and moved laterally to [sensitive business systems] and cloud resources undetected,” CISA’s analysis reads. “In the second organization (Organization B), network defenders quickly detected the initial compromise and quarantined the affected systems.”
For “Organization A,” the government organization, CISA used an internal email address to send phishing emails to gain access to the workstations, probed further to gain elevated privileges, then moved around and compromised targeted sensitive business systems. The red teamers observed that the organization “did not respond effectively to red team activity” by accessing personnel emails at its security operations center, where they saw them receive low- and medium-severity endpoint detection and response alerts, but didn’t respond to them.
False positives by the thousands, including some with higher severity, “obscured the alerts triggered by red team activity,” CISA said. The agency also faulted “organizational silos.”
Meanwhile, at “Organization B,” the water organization, CISA got access via a spearphishing campaign, convincing three users to click on a malicious link to gain access to workstations. This time, the security operations center triaged the alerts and quarantined the work stations in 2, 10 and 20 minutes, respectively.
The red teamers tried another approach with the help of the organization’s IT contacts who were aware of the activity, but were foiled in their follow-ups.
“Because Organization B detected the initial compromise, the red team moved to an ‘assume breach’ model, where Organization B trusted agents (TAs) provided access to a host that replicated the level of access the red team would have had if defenders had not detected their activity,” CISA wrote. “From there, the red team escalated privileges and moved laterally to [sensitive business systems], cloud resources, and a bastion host in the OT [operational technology] demilitarized zone (DMZ), where defenders again detected activity and isolated the system.”
Still, CISA said both organizations had flaws in their defenses: They underestimated cloud risks; they lacked Conditional Access — a Microsoft security tool — for workload identities; and they didn’t have processes in place to revoke compromised access/refresh tokens.
CISA first published an advisory on its red team activity in 2023, but such advisories have been few and far between since. The agency said last year that it had not “laid off” its red team, after stories revealed the exit of contractors that included red-team members.
Latest Podcasts
Government
FBI officials say AI is bolstering adversaries, emphasizing need to focus on cyber basics, patching
Feds accuse China of ‘systematic’ distillation of U.S. AI models
CIA’s Michael Ellis says cyber intelligence is changing how the agency operates
The G7 tells industry to hurry up and prep for post-quantum encryption
Technology
Threats
Chinese espionage groups swarm to exploit triple-link chain of zero-days
Microsoft discloses two actively exploited zero-days among 974 vulnerabilities
Russian national extradited to US for alleged involvement in bank-account takeover scheme
Attackers exploit zero-days in consistently besieged SonicWall product
Policy
Whistleblower says USPS deploying new, ‘untested’ IT systems governing mail-in ballots
‘Watershed 250’ test program in Texas looks to private sector for water cybersecurity help
Former sexual abuse victims say Grok used their images, videos to train deepfake capabilities
Cyber threats nudge Trump to sign executive order on foreign equipment in U.S. energy infrastructure
Text extracted automatically; images, tables and formatting may be missing. Original: https://cyberscoop.com/cisa-red-team-report-government-water-cybersecurity/