Red Teaming and Social Engineering

Red Team operations consist of a realistic scenario of a global offensive attack, often used for large-scale targets. Red Teams use every documented and innovative method to penetrate the victim’s cyberspace. These standards are in accordance with MITRE ATT&CK and simulate all fourteen documented plans for a global cyberattack in a controlled manner. This simulation seriously tests the state of all your defense mechanisms and their functional quality. Therefore, Red Team services are considered one of the most important and sensitive offensive security services.

 

  • Red teaming differs from penetration testing in several ways: the red team is not limited to a specific domain and is not restricted (for example, access level is limited to the scope of a specific web application).
  • Discovering vulnerabilities specific to access control, some of which are only relevant to the red team, such as discovering vulnerabilities from browsers and using them in an attack scenario.
  • Red team operations are not limited to technical techniques, but also include human factors (social engineering) as well as physical security (level of physical access to the site).
  • Red team operations should not be noisy, as one of the goals is to remain anonymous from defense mechanisms in order to better communicate with the hacker’s command and control center.
  • We perform authorized social engineering attacks, which typically involve preparing and delivering phishing campaigns targeting client employees. The attack target may be planned individually with each client.
  • Other scenarios may also be possible for on-premises Wi-Fi users, where a rogue AP (Evil Twin) is enabled by a piece of peripheral hardware. The first connection of employees to the wireless network allows for a MiTM (Man-in-The-Middle) scenario to inject malicious executables into traffic or hijack downloaded files for further access.
  • We are able to conduct simulated attacks at APT (Advanced Persistent Threat) quality level through CPH (Cyber-Physical-Human) techniques. Red Team operations are intended to reflect real cyberattack scenarios that may be faced by a particular organization.
  • Red team exercises are used to assess the current security posture within a targeted company, employee awareness, as well as the response time of internal security teams such as the SOC (Security Operations Center).
  • The red team always tries to apply its innovative methods in all the required stages of the attack, therefore the quality of the attack and the testing of the blue team’s strategies always depends on the level of knowledge applied in the red team’s attack.
  • The main goal of physical security testing is to enable the implementation of red team scenarios based on accessing the organization’s building, restricted access areas, documents, company devices, and internal network. Physical attacks implemented based on peripheral equipment can be very dangerous and out of sight of defense mechanisms.
  • As part of our Red Team operations, we conduct both external and internal network attacks, where the primary goal is to gain access to critical company resources, data, or a way into the internal network. However, in most cases, after gaining initial access to the network, we use social engineering or physical access to escalate the attack.

Initial Access

The attacker is always trying to gather information to use in planning future operations. Reconnaissance operations involve techniques in which attackers actively or passively gather information. These techniques are used to support the target and the information obtained from them may include details about the victim’s organization, infrastructure, or employees and personnel and is used by the attacker to assist the attacker in other stages of the infiltration cycle, such as performing Information Gathering to plan and execute the Initial Access phase.

Establish Initial Access

An attacker is trying to initial access to your network. First-time access involves techniques that use various entry vectors to gain initial access to a network. Techniques used to initial access include spear phishing and exploiting vulnerabilities in public web servers. The bases gained through first-time access can provide persistent access, such as trusted accounts and external remote services.

Persistence

The attacker is trying to maintain access. Access persistence includes techniques that the attacker uses to prevent re-establishing access to the system, changing credentials, and other interruptions that would cause access to be lost. Techniques used for persistence include any action or configuration change that would allow the attacker to maintain their position on the system, such as replacing or hijacking authorized code or adding code to Startup.

Privilege Escalation

Privilege Escalation involves techniques that an attacker uses to gain Privilege Escalation on a system or network. Attackers can often break into a network with unprivileged access and explore it, but they need higher access to pursue their goals. This need is met through common approaches, exploiting weaknesses or misconfigurations and system vulnerabilities. These techniques are often combined with access persistence techniques.

Defense Evasion

Defense Evasion refers to techniques that attackers use to Defense Evasion during their attacks. These techniques include removing and disabling security software or obfuscating and encrypting data and scripts. Attackers also exploit trusted processes to hide and remain hidden from view.

Discovery

Discovery involves techniques that an attacker might use to gain information about the internal system and network. These techniques help attackers observe and navigate the environment before deciding how to operate. The information gained allows attackers to discover what they can control, what is around their entry point, and how to exploit the target system once they have compromised it. There are native operating system tools that are often used to gather information.

Lateral Movement

Lateral movement involves techniques that attackers use to gain access to and control remote systems on a network. Pursuing the primary target often requires exploring the network to find and subsequently gain access to the target. Reaching the target often involves rotating through multiple systems and accounts to gain access. Attackers may install their own remote access tools to perform Lateral Movement or use authorized credentials with local network and operating system tools (which may be hidden).

Collection

This collection consists of techniques that attackers may use to gather information and gather information from targeted resources. Often, the next step after collecting data is to steal it. Victim resources typically include various types of drives, browsers, audio, video, and email. Common collection methods include screen captures and keyboard inputs.