Red Team

2023 September 11

Introduction

This case study outlines a comprehensive Penetration Testing Red Team engagement focusing on Active Directory (AD) for a client lacking modern security protocols, utilizing weak passwords, and lacking a Security Operations Center (SOC) team. The primary goal is to identify vulnerabilities and weaknesses within the client’s Active Directory infrastructure and provide actionable recommendations to enhance their security posture.

The Assessment Purpose

  1. Assessing potential risks, exposing existing failures and deficiencies in the organization’s security systems that support different services, and exposing deficiencies in the Implementation of the organization’s technologies and operational processes that might expose the organization to damage or leak of information.
  2. Providing the necessary solutions to reduce or eliminate the possibility of threat actors abusing these exposures.
  3. Obtain an up-to-date picture that reflects the true state of information security in the organization in a way that will allow it to carry out the following activities:
  • Identify failures related to policy, organization, management, and technology operations in the computing systems.
  • Performing risk assessment and defining their severity.
  • Implement recommendations to improve the existing situation.

Scope

The scope of this engagement includes an in-depth assessment of the client’s AD environment, with a specific focus on the following areas:

  1. Identification of outdated protocols and services.
  2. Evaluation of password strength and security practices.
  3. Assessment of the absence of a SOC team and its impact on security.

Methodology

To achieve the objectives, the Red Team employs a structured approach that adheres to the industry’s best practices, including but not limited to:

Reconnaissance: Gathering information about the target organization and its AD infrastructure using both open-source intelligence and passive techniques.

Active Scanning: Conducting network scans and service enumeration to identify potential vulnerabilities and accessible services.
Exploitation: Attempting to exploit known weaknesses and misconfigurations in outdated protocols and services.

Password Cracking: Employing password cracking tools to assess the strength of users’ passwords.

Social Engineering: Conducting targeted phishing campaigns to assess employee awareness and susceptibility.

Lateral Movement: Attempting to gain unauthorized access to other systems and resources within the AD environment.

Post-Exploitation: Identifying weaknesses in the absence of a SOC team by performing actions that may go unnoticed for extended periods.

 

Found Vulnerabilities

Old Protocols:

The Red Team discovered that the organization’s AD environment was still supporting outdated and insecure protocols such as SMBv1 and NTLMv1. These protocols are highly susceptible to exploitation, enabling attackers to perform man-in-the-middle attacks, conduct credential harvesting, and gain unauthorized access to critical systems.

 

Weak Passwords:

Through password cracking techniques and password spraying attacks, the Red Team successfully identified several user accounts with weak passwords, including default passwords and easily guessable patterns. These weak passwords posed a significant risk to the organization’s security posture.

 

Lack of Network Monitoring and Alerts on Cyber Attacks:

During the assessment, a wide variety of different cyber-attacks were executed, including network attacks and endpoint attacks. It should be noted that we did not receive any indication that some of these attacks were detected or blocked by any entity within the organization, including security products and others.

Additionally, after the assessment was concluded, a test was conducted with Michael and Shlomo, who confirmed that they did not receive any alerts from any of the existing defense systems in the organization.

 

Conclusion

The Active Directory Penetration Test conducted by the Red Team provided valuable insights into the organization’s security weaknesses, especially concerning old protocols, weak passwords, and the absence of a SOC team. Implementing the recommended measures will enhance the organization’s security posture, mitigate potential risks, and improve overall resilience against future cyber threats. Regular security assessments and ongoing training for staff are also crucial to maintaining a robust security posture in an ever-evolving threat landscape.