Red Team Discoveries Support Organizations in Assessing Risk

Red team tests were conducted at the behest of two critical infrastructure organizations, and the lessons learned were published by the Cybersecurity and Infrastructure Security Agency (CISA).
The Red Team Assessments
In order to determine an organization’s ability to detect, probe, and respond to threats, CISA leveraged adversarial tradecraft to replicate malicious activity.
For the first organization, the red team was undetected by the security operations center (SOC) when they gained initial access to several workstations, heightened privileges over the domain, and shifted laterally to other systems.
For the second organization, when the red team gained initial access, the SOC identified and quarantined it. The red team adjusted to assumed breach model activity, and some following activity was also caught and contained by the SOC.
Lessons Learned
- Without tuning, detection tools miss threats.
- Siloes and bureaucratic complexity inhibit effective response.
- Cloud environments hold risk that is often underestimated.
Key Actions
- Fine tune tools to enact and sustain a baseline, thus reducing false alert noise.
- Overcome siloes to empower security workers.
- Establish policies for conditional access and monitor for unused or excessive permissions.
- Implement and consistently review procedures for detection and remediation in the event of cloud compromise.
Looking for a reprint of this article?
From high-res PDFs to custom plaques, order your copy today!






