Lab 1.3 : Red Team Planning
Objectives
- Ensure connectivity to the lab environment
- Read and understand the Scope and Rules of Engagement
- Introduction to VECTR
- Understand VECTR Core Concepts
- Configure VECTR for use
- Create a VECTR Campaign for an Adversary Emulation Plan
- Explore VECTR’s Reporting and Timeline Capabilities
This lab will focus on the Planning Phase of a Red Team Adversary Emulation Engagement by reviewing Scope and Rules of Engagement.
Walkthrough
The Scope and Rules of Engagement establish the objective, scope, responsibility, relationship, and guidelines between the customer, Draconem Development, and the Red Team (SEC565 Students) and any stakeholders (SEC565 Instructor) required for Red Team Adversary Emulation Engagement execution.
Lab Objective
The objective of this Red Team Engagement is to emulate the HAFNIUM adversary and attempt to gain full access to the Draconem Development databases in the target network. Draconem Development is concerned with losing their intellectual property and research data. The engagement should focus on testing the effectiveness of controls that Draconem has implemented and its exposure to similar adversary attacks. The Red Team should test the people, process, and technology to obtain a holistic view of the target's security posture.
Scope
This will be a limited knowledge test for the Red Team and a zero knowledge test for Draconem Blue Team. The scope of this engagement is the Draconem Development corporate network (draconem.io | draconem.corp) to include a child development domain (dev.draconem.io | dev.draconem.corp) and the Thunderbird Group (thunderbird.group | thunderbird.corp) domain. The following is allowed but should not be limited as long as Rules of Engagement are met:
- Client-Side Attacks
- Server-Side Attacks
- Privilege Escalation Attacks
- Web Application Attacks
- Lateral Movement within the specified networks
- Credential Attacks
Rules of Engagement
- Do not execute denial-of-service attacks
- Do not execute performance-hogging attacks
- Do not change passwords for enterprise users
- Do not modify sensitive information in the environment
- Do not stop services or harden systems
- Do not attack the lab vpn environment
Warning
Breaking these rules may result in the student being asked to leave the class.
Points of Contact
The SEC565 Instructor will be the Red Team's point of contact. Please notify the instructor of any concerns with the SEC565 Target network. Likewise, the SEC565 Instructor will notify the Red Team if scheduled maintenance, reboots, or outages are experienced.
Communication Plan
Debrief schedule: At the end of each section. (During an engagement this would be scheduled on a normal cadence)
Out of scope areas/assets
The "Attacker Network" is out of scope: 10.254.252.1/24
VECTR Preparation
The Slingshot Linux VM has been configured to have VECTR installed and running in a Docker container. You can reach the VECTR web application at https://sravectr.internal:8081/. If the web application is not running then follow the below steps to start the local instance of VECTR by typing the following in a terminal on your Slingshot Linux VM:
cd /opt/vectr/
sudo systemctl restart docker
./vectr-bootstrap.sh
Note
We are forcing a restart of the docker service because time may get out of sync on a vm that has been paused. It's always DNS, when it isn't, it's time sync.
Navigate to the local VECTR instance using Firefox:
https://sravectr.internal:8081
When navigating to the website you may get a certificate warning. Accept the invalid digital certificate by clicking Advanced... and then Accept the Risk and Continue:

Introduction to VECTR
VECTR is a platform designed to facilitate Red and Blue Teams through comprehensive Purple Team styled Adversary Emulations. Its purpose is to document attacks, gauge the effectiveness of defensive tools, strengthen security, and improve detection capabilities through current and historical performance tracking.
VECTR works to serve as a system of record for the process of red teaming. It is designed to use existing data and knowledge, including community open source data, standard red teaming tradecraft, emerging purple teaming knowledge, and assist organizations in continually adapting their Red Team engagements to match realistic adversaries.
The software design is meant to allow users to both capture the results of manual audit type tests from third parties, easily record the results of novel testing like Red Team engagements, and expand beyond what VECTR includes by default. It's a repository for your organizational information security test cases, testing history, and associated Blue Team analytics to detect those activities. It can also serve as a facilitator for guiding security operation teams to better outcomes.
VECTR is authored and open-sourced by Security Risk Advisors
- Documentation: https://docs.vectr.io/
- Source: https://github.com/SecurityRiskAdvisors/VECTR
Understanding VECTR Core Concepts
In VECTR, a Database is a Target Environment. Databases represent major organizational units or groupings of different assessment types within VECTR. Before beginning a test, this is where information is gathered about the environment and where boundaries are being drawn.
This includes workstations, servers, networks, and any other targets being tested. It also includes information about defense tools, logging, and alerting capabilities.
The tests that are run will be stored in an Assessment Group (also referred to as an Assessment) in VECTR, and each Database is meant to hold multiple Assessment Groups.
Most organizations will only require 1 database, but organizations with many independent subsidiaries, or different technologies and security configurations may find it helpful to operate multiple databases. Consulting companies may want to create a database per client.
Example Database names:
- Global
- NA
- EMEA
- M&A Environment
- CorpHQ
An Assessment Group is the scope of a security testing event. This includes a list of Campaigns and tests that are to be run in an environment. Multiple Assessment Groups may be run at once. In VECTR, it’s helpful to organize these by the name of the activity and when it’s being run.
Example Assessment Group names:
- 2022 Q2 Purple Team
- SOC - Continuous Purple Team
- HAFNIUM Emulation Apr 2022
A Campaign is a group of tests to be run within an Assessment Group. This is a loose organizational data structure, similar in concept to a file folder in general computing or a test suite in software quality assurance. Tests can be grouped into Campaigns by adversary, malware, test type, kill chain phases, and any other structure that makes sense for the testing organization.
Example Campaign names:
- HAFNIUM Adversary Emulation
- Emotet Malware Emulation
- Multiple Variations of Port Scans
- Multiple Variations of Downloaded Phishing Payloads
- MITRE ATT&CK Discovery
A Test Case is an individual test to be run within a Campaign. A Test Case includes a set of commands or instructions and any necessary accompanying data designed to help an operator perform a specific, repeatable security testing activity. Once a Test Case is performed, VECTR allows the capture of additional information like when the test was performed and if it was detected by defense tools.
In the context of the MITRE ATT&CK Framework, a Test Case represents a specific, repeatable instance of an attack technique. Different Test Case variants can map to the same MITRE ATT&CK technique ID. In VECTR, it is helpful to name the activity for either the exact activity being performed or the threat that’s being emulated.
Example Test Case names:
- APT1 - Account Discovery using Net
- Wannacry Lateral Movement using DoublePulsar
- Noisy NMAP port scan of 1000 ports
- Compress Sensitive PCI data on Endpoint with Zip

Reference: https://docs.vectr.io/user/important-concepts/
Understand VECTR Workflow
The key steps to successfully using VECTR in its most common use scenario are as follows:
- Define a Database for the environment being tested
- Plan the Assessment scope
- Begin testing the target environment and record activities within the appropriate Assessment
- Generate reports based on VECTR test data
- Use VECTR to inform remediation efforts by Blue Team
Planning the Assessment scope can be done manually within VECTR by operators and can also be heavily informed by external resources like Threat Intelligence. For the purposes of this lab, the scope of the testing events is the emulation of the HAFNIUM adversary against Draconem Development.
An Adversary Emulation campaign is a common activity for organizations in targeted industries; therefore, it may be desirable to reproduce it on a regular basis. Any activities that may be repeated or reused in VECTR should be stored in the Administration section as templates.
In this lab, you will create two HAFNIUM campaign templates; one manually and one via importing threat intelligence. You will use the campaign templates to create an assessment to record all the Red Team activities performed. Blue Team will be able to provide data to populate the records during the analysis and response. Once everything is documented, you will view reports and identify any historical trends that may be interesting to the target organization.
Walkthrough
1. Navigate to the local VECTR instance using Firefox:
https://sravectr.internal:8081
Accept the invalid digital certificate by clicking Advanced... and then Accept the Risk and Continue:

2. Log in to VECTR with the following, default credentials:
- Username:
admin - Password:
11_ThisIsTheFirstPassword_11

3. You will be taken to the Choose Your Organization prompt:

4. Create a new organization. Click the + sign. Fill out the Name, Description, Abbreviation, and URL. You can also add members of the organization but it is not mandatory. Click Save when done:
- Name:
Draconem Red Team - Description:
RT for Draconem Development - Abbreviation:
RT - URL:
http://www.draconem.io

Now set the organization by clicking the new organization you just created.
5. Click through and read the "Welcome to VECTR!" pop up then create a new database by clicking the database icon then Select Session Database prompt:

Select the + icon to bring up the Create Session Database modal.

Type the new name in the Database Name field, click Submit, and then click Done:

Create a VECTR Campaign for an Adversary Emulation Plan
In this section, you will use the Adversary Emulation Plan created for HAFNIUM in the Consuming Threat Intelligence lab to create a Campaign Template in VECTR. Campaign templates are valuable for Reporting, Exercise Replay, Retesting TTPs, and reoccurring control validation testing.
6. Click CREATE NEW at the top right of the Assessment Group; this is the name of the complete effort. In this case we will add the Adversary Emulation campaign that is performed during the course. Later, you can add other assessments for further testing:

7. Fill out the following fields and click Save:
- Name:
HAFNIUM - Description:
HAFNIUM Adversary Emulation for Draconem Development - Kill Chain:
Unified Kill Chain

8. Click on the three vertical dot icon under the Actions column -> Configure Campaigns. On the Manage Campaigns click New Campaign on the top right:

9. Fill out the following fields and click Save:
- Name:
HAFNIUM - Description:
HAFNIUM Manual Test Case Creation

10. Navigate back to the Assessments page by using the left navigation pane. You should now see your HAFNIUM assessment, click on it and you will see it in the campaign dashboard view shown below.
Note
This page will be mostly blank since you have not populated any test cases.

11. Next we will show you how to populate a test case. Click on HAFNIUM in the Campaign Dashboard. Scroll down to the Test Cases group and click on the Campaign Actions -> New Test Case:

The Test Case window is where the core documentation of test cases occurs. Every Red Team action should be documented here along with the Blue Team Analysis and Response.
Let's create one together. Fill out the following fields on the Red Team Details:
Note
You will have to scroll down in this modal to get all to the input fields.
- Name:
Data Exfiltration via mega.io | mega.nz - Description:
HAFNIUM has exfiltrated data to file sharing sites, including MEGA. - Technique:
Exfiltration Over Web Service - T1567 - Phase:
Exfiltration - Operator Guidance:
Attempt to exfiltrate sample data via mega.io | mega.nz (non-sensitive data only)
Feel free to fill out other portions like the Status, Attack Start, Attack Stop, Source IPs, Attacker Tools, Target Assets, Detection Time, etc.
Click Save

12. Optional Continue to populate and add all the Test Cases from the Adversary Emulation Plan you created in prior labs. Once completed, you should have a campaign that matches the TTPs associated with HAFNIUM.
Explore VECTR’s Reporting and Timeline capabilities
Now, we will look at how Reporting works when leveraging VECTR. We will use data that has been populated by the SRA team and comes default in VECTR.
13. We will use a different, pre-populated database. Click the Database icon on the top right and Select Session Database:

Then click the check next to DEMO_PURPLE_CE and click Done:
You will see a number of assessments and, if you would like to explore, a number of campaigns under each assessment.

14. Click Reporting from the menu on the left:

Give it a few seconds to load as it is rendering a number of visualizations based on multiple campaigns and assessments. Here, you will see several drop down menus that restrict the data rendered in the graphs. You may select by Assessments and/or Campaigns:

Click Report Type and select Heat Map to see the MITRE ATT&CK Heat Map.

If not already filtered, click on the gray box under No Test Coverage to filter those out:

This is a more concise view of the assessment group and the various campaigns completed. As you can see, the mapping is to MITRE ATT&CK with the Tactics on the top row and the various Techniques in the middle rows. The numbers next to each Technique represent the different Procedures that were tested.

Click on a Technique with a number next to it to expand the details:

15. Let's take a look at another view. Click Report Type and select Historical Trending:

This view is for trends around total risk, toolset, and detection/prevention layers for all assessments in a database. The top panel has the Risk Trend Analysis over time. This is a great view to show how Red and Purple Teaming has improved the overall security stance. The bottom panel is the Toolset and Detection/Prevention Layer trends. This may be used to identify the toolset or defensive layer that requires the most investment in tuning. Select Kill Chain in the Clicked Chart dropdown above the graph then scroll down to see the coverage of testing against the selected Kill Chain:

16. When you are complete with this lab, change the database back to SEC565.
Conclusion
In this lab, the scope and rules of engagement have been defined and we explored VECTR from Security Risk Advisors. VECTR’s primary purpose is to coordinate and document Red and Blue team activities during Adversary Emulations. Depending on the organization and scope, this may be performed in the style of a Purple Team engagement or a blind Red Team Adversary Emulation where the Blue Team input is delayed until the Analysis and Response phase. VECTR can also be used to track historical Red Team engagements. The VECTR Test Cases created can be used to inform testing events that can be run to test a target or confirm remediation results.
This lab involved the creation of a Red Team-focused Adversary Emulation Plan, and if you continue to create a complete active Assessment in VECTR, running actual tests against a network and filling in all the start/stop times for your Test Cases, you can use VECTR to generate timeline reports. If you then work together with the Blue Team response, you will be able to use the full array of VECTR reporting like the provided sample data.
The value in VECTR’s tracking lies in the creation of a clear long-term test case library, the ability to compare security testing events to the MITRE ATT&CK framework, and reporting artifacts that can be generated by performing repeated tests against a network or target.
This lab introduced the free VECTR tool for creating, tracking, and reporting Adversary Emulations. For more details on using VECTR for Red Team or Purple Team tracking, see how-to videos on the VECTR page