A Tier 1 construction company puts its incident response to the test

Volkis ran a 5-month Red Team engagement emulating a ransomware group end-to-end, uncovering gaps that years of clean penetration test results had never surfaced.

The Company is a Tier 1 construction business that wished to remain anonymous in public-facing documents, but can provide a private reference upon request.

The Challenge

The Company had previously performed multiple penetration tests with other providers. Having received consistently clean results, with few vulnerabilities identified, the Company wanted to step things up and perform a long-term Red Team exercise to test the end-to-end security of their business.

The Company had three simple, but broad goals:

  • Identify issues and improvements to the Company’s security processes.
  • Identify any vulnerabilities that may have been missed during previous security assurance activities.
  • Test the response of the SOC, and the security team.

“We’re not trying to tick a box. We’re trying to find out how we can improve our posture.” — Company’s CIO

Rather than perform a Red Team with a limited scope, the Company chose to holistically target the entire business. Attackers would not limit their scope when attacking a target, and the ability to think like hackers and mimic adversaries was essential to achieving the Company’s goals.

“We don’t want people to go to the dark side, but we were happy for the boundaries to be certainly pushed,” emphasised the CIO.

Why Volkis

When asked, the CIO explained, “There was a sense of competence. ‘These guys sound like they know what they’re doing’, we said.”

Our passion, transparency, and empathy play a big role in all of our work. But they are especially important during a Red Team exercise, due to the level of trust required.

Comparing us to larger companies, the CIO said, “If you go to the KPMGs and those groups, you’re buying respectability, at least at a board level… But our experience is, often dealing with the bigger groups, you’re paying for layers of cost and management.”

This is where our size and team structure shine. Our consultants are well versed in both technical and human skills, meaning one person is accountable for the entire Red Team exercise, from organisation to execution, and communication throughout.

“[With Volkis] we would be dealing with the people who were actually going to run it… That was important to us.” — Company’s CIO

The Exercise

The Red Team exercise ran for 5 months with multiple campaigns attempted throughout; some successful, others not. The Red Team were tasked with emulating a ransomware group as the most likely and damaging adversary to the Company.

Primary objectives were to show the ability to deploy ransomware on any system, server or workstation, and to access and show the ability to delete backups. Secondary objectives were to show the ability to impact day-to-day operations, access sensitive information, and perform invoice or financial fraud by changing the details of a subcontractor.

OSINT and infrastructure setup. This was the first, and most important, campaign as it would set up the rest of the exercise for success. Open Source Intelligence (OSINT) gathering allowed the Red Team to discover the Company’s assets, staff, email addresses, physical addresses, password leaks, documents, and more. Bespoke phishing and Command and Control (C2) infrastructure was also set up for later campaigns.

Gaining internal entry. Multiple phishing campaigns were performed with the goal of gaining user credentials. This was partially successful, providing a username and password, but not a multi-factor authentication (MFA) token, preventing access to internet-facing services. These credentials were taken on-site to the Company’s office and used to access the wireless network — successfully gaining access to the internal network and its systems. An implant device was later left in a secret location for persistent remote access.

Lateral movement. By chaining a printer misconfiguration with lateral movement techniques such as “Pass-the-Cert”, the Red Team managed to gain Domain Admin privileges, and used that access to explore the Company’s assets in Microsoft 365 and its accounting applications — achieving all but one of the Red Team’s objectives.

Detection and response. The Company’s detection and response capabilities were effective — the Red Team was detected several times and kicked off the network. However, through multiple persistence techniques, and a flaw in the Company’s incident response process, the Red Team was able to maintain internal network persistence.

Purple Team Workshop. After the exercise wrapped up and a report was sent to the Company, a 2.5 hour workshop was performed with both the Volkis Red Team and the Company’s Blue Team, to discuss what had occurred from both perspectives. Though the exercise is adversarial by nature, the workshop was light-hearted, as both teams ultimately had the same goal: strengthen the Company’s security.

The Results

Were the Company’s goals achieved? Yes. The exercise helped the Company close some obscure, but large, gaps in their incident response process, along with some previously undetected vulnerabilities.

“We have already closed out the majority of issues,” explained the CIO when asked about progress just two weeks after the exercise concluded.

Read the full PDF case study

“We had a lot more exposed than we thought we had… We didn’t expect that you’d be able to traverse as well as you did across our environment.”

Company's CIO
Tier 1 Construction Company

Want to give your customers peace of mind?

Chat with us today