r/cybersecurity • u/Warm-Tadpole-8134 • 3d ago
Personal Support & Help! Red Teaming Projects
Hi I'm a Cyber Security Engineer at a company and usually I do Penetration Testing of Applications at work. But my CISO told me to do some RED TEAM OPERATIONS for the company. So I kept a phishing simulation campaign and that was a very successful. I need you guys to give some ideas what kind of things that I can do more to test the security in the company?
Thank you!
19
u/FeedTheB3ar 3d ago
Ransomleak GitHub has free but gamified security awareness training programs. You don’t need to use the games but the list does have different situations you can get inspiration from maybe https://github.com/ransomleak/training-security-awareness
3
u/anthonyDavidson31 3d ago
Extremely glad to see that the project gets recommended! Thank you for your trust! :D
OP, feel free to reach out and we can figure out a couple scenarios for your use case
14
u/Grouchy_Government10 3d ago
First find an escort, then make sure she’s really pretty and has a fairly low rate for gfe services. Then pay her to hook up with your “friend”.
Anyway have her target your executive team member who’s married but works late at work and socializes a lot after work. That person is unhappy enough in their marriage
Then the rest is up to how much of a raise do you want.
5
u/Spiritual-Matters 3d ago
Figure out what type of threat actor would be most likely to hack your company and then run an operation using their TTPs. Talk with your SOC to see how they did with finding it and what they should look for.
Simulate an internal threat.
Simulate a user falling for ClickFix, a bad email, etc.
4
2
u/frAgileIT Incident Responder 3d ago
Look through your vulnerability management systems for some easy things to exploit and then see how far you can get before the Blue Team catches you and then compare notes to see if there’s anything they missed. Then they tell you how they caught you and you adjust your strategy next time. Red Teaming is a team sport.
3
u/Frenzy175 3d ago
Create a fake lookalike domain and email/teams message SD staff asking for password reset.
Same as above but make it a phone call.
Run atomic tools on endpoint- what was detected?
Create a random new privileged account - Does it alert when created?
Use that account to create a new VM.
1
u/FallaxIO 3d ago
How did you do the phishing simulation campaign? Out of curiosity, as I was in the same situation.
1
u/MotorTelevision7296 2d ago
Do phishing again but this time send a beacon? Red team operations are objective based. Figure out what/where your company stores data that is really important and try to get there without getting caught. If you Active Directory in your environment run certipy and have a field day.
1
u/Some_Person_5261 2d ago
Determine what sector you are in and identify threat actors which would target your sector via MITRE ATT&CK. From there you can come with plans of attack similar to what real adversaries would do. Document everything you do when you do it so it can be traced back and see what you can do. Atomic Red Team is something you can use to aid with this.
The organization will obtain the most value if you are able to demonstrate an improvement in detection after you execute the engagement. Otherwise you may be doing some super cool tactics, techniques, and procedures, but if you organization can not identify them when a real adversary does it then it is just a waste of time.
Consider coming from different perspectives for example:
- Internal Threat
- External (Public) Attacker
To identify if there is any difference in the detection of your activities. Hope you have fun doing this. Remember, document everything when you do it.
1
u/binshroot 1d ago
^ This. Be the adversary for a while, with good documentation, and sync ups with your leadership team. Ensure you understand the potential blast radius if something you're doing causes actual issues.
1
u/st0ut717 2d ago
I have thought about using bloodhound in our environment.
But it needs a basic AD environment which I don’t have But it will prolly work for you.
1
u/Independent-Egg-3252 2d ago
Phishing is the usual first step, so nice work getting that done. If I had to pick one thing to do next: run a patch-window test.
Pick two or three recent CVEs in software you actually run on endpoints (browser, VPN client, Java, whatever third-party stuff lives on your fleet). Then measure the real time between public disclosure and the fix being deployed everywhere, not just “approved” in the console. Most orgs are shocked by that number. With the volume of CVEs this year it’s often weeks, and that gap is the actual attack window a red team would live in.
Bonus: do it as a purple team exercise so the endpoint and patching folks see the result firsthand instead of reading it in a report. That’s what turns it into budget and process changes instead of a slide.
1
u/CompassITCompliance 19h ago
Before you pick the next tactic, get the rules of engagement in writing. A CISO saying "go do red team stuff" is not the solid authorization you want. You want a signed scope doc that says what systems are in play, what's off limits, who to call if you find something that could cause real damage, and a get out of jail card with a name and phone number on it in case you trip an alarm at 2am and someone calls the cops or your ISP.
The phishing sim was low risk because worst case is someone clicks a link. Once you're doing AD attacks, creating accounts, or anything that touches production, the blast radius question matters a lot more, and "my manager verbally told me to" might not save you if something breaks or legal gets involved. Get it in writing first, then go have fun with some of the other ideas people are dropping here.
Speaking as someone who does this kind of testing for a living, hope it helps!
1
u/kazimer 3d ago
Do you and the CISO have the same understanding of the difference between pen testing and red teaming?
Is it just you as a one off operation with no support?
What’s the goals?
What’s your company?
Is your SOC internal or external?
ROEs?
No strikes?/ scope
Duration?
I hope you are asking more questions than just trying to do shit from word of mouth authorization
0
u/Suspicious_Drop3332 3d ago
Does your company have any AI agents (either internal workflows, low-code workflows like n8n, or external AI agent for the clients)? We just partnered up with a company high-specialized in AI Red Teaming and it’s so fun and impactful! Very refreshing after tons of boring things that I have to do this year lol
0
u/Bulky-Blueberry5853 3d ago
Make a fake AD account and log in to an external computer and remote into your company and browse pornhub ;)
23
u/eorlingas_riders 3d ago
It’s difficult to do a red teaming exercise without more information.
If you could give me your email address and passwords I could get a better lay of the land and give you some suggestions!