Skip to content

Lab 5.4: Red Team Closure

Objectives

  • Add Test Cases to VECTR
  • Explore VECTR’s Reporting and Timeline Capabilities

This lab will build off of Lab 1.3: Red Team Planning. We will use VECTR to document the test cases from the campaign. Ideally you would document before, during, and after executing the test case. For lab purposes we will enter a subset of the tests that we conducted and adjust dates as needed to demonstrate the actions of the Red Team.

VECTR Preparation

The Slingshot Linux VM has been configured to have VECTR installed and running in a Docker container. You can reach the VECTR web application at https://sravectr.internal:8081/. If the web application is not running, then follow the below steps to start the local instance of VECTR by typing the following in a terminal on your Slingshot Linux VM:

cd /opt/vectr/
sudo systemctl restart docker
./vectr-bootstrap.sh

Note

We are forcing a restart of the docker service because time may get out of sync on a VM that has been paused. It's always DNS, and when it isn't, it's time sync.

Walkthrough

1. Navigate to the local VECTR instance using Firefox:

https://sravectr.internal:8081

Accept the invalid digital certificate by clicking Advanced... and then Accept the Risk and Continue:

2. Log in to VECTR with the following, default credentials:

  • Username: admin
  • Password: 11_ThisIsTheFirstPassword_11

3. If you completed Lab 1.3: Red Team Planning then you may skip to step 12. Otherwise, you will be taken to the Choose Your Organization prompt:

4. Create a new organization. Click the + sign. Fill out the Name, Description, Abbreviation, and URL. You can also add members of the organization but it is not mandatory. Click Save when done:

  • Name: Draconem Red Team
  • Description: RT for Draconem Development
  • Abbreviation: RT
  • URL: http://www.draconem.io

Now set the organization by clicking the new organization you just created.

5. Create a new database by clicking the database icon, then Select Session Database prompt:

Select the + icon to bring up the Create Session Database modal.

Type the new name in the Database Name field, click Submit, and then click Done:

Create a VECTR Campaign for an Adversary Emulation Plan

In this section, you will use the Adversary Emulation Plan created for HAFNIUM in the Consuming Threat Intelligence lab to create a Campaign Template in VECTR. Campaign templates are valuable for Reporting, Exercise Replay, Retesting TTPs, and reoccurring control validation testing.

6. Click CREATE NEW at the top right of the Assessment Group; this is the name of the complete effort. In this case we will add the Adversary Emulation campaign that is performed during the course. Later, you can add other assessments for further testing:

7. Fill out the following fields and click Save:

  • Name: HAFNIUM
  • Description: HAFNIUM Adversary Emulation for Draconem Development
  • Kill Chain: Unified Kill Chain

8. Click on the three vertical dot icon under the Actions column -> Configure Campaigns. On the Manage Campaigns click New Campaign on the top right:

9. Fill out the following fields and click Save:

  • Name: HAFNIUM
  • Description: HAFNIUM Manual Test Case Creation

10. Navigate back to the Assessments page by using the left navigation pane. You should now see your HAFNIUM assessment; click on it and you will see it in the campaign dashboard view shown below.

Note

This page will be mostly blank since you have not populated any test cases.

11. Next we will show you how to populate a test case. Click on HAFNIUM in the Campaign Dashboard. Scroll down to the Test Cases group and click on the Campaign Actions -> New Test Case:

The Test Case window is where the core documentation of test cases occurs. Every Red Team action should be documented here along with the Blue Team Analysis and Response.

Let's create one together. Fill out the following fields on the Red Team Details:

Note

You will have to scroll down in this modal to get all to the input fields.

  • Name: Data Exfiltration via mega.io | mega.nz
  • Description: HAFNIUM has exfiltrated data to file sharing sites, including MEGA.
  • Technique: Exfiltration Over Web Service - T1567
  • Phase: Exfiltration
  • Operator Guidance: Attempt to exfiltrate sample data via mega.io | mega.nz (non-sensitive data only)

Feel free to fill out other portions like the Status, Attack Start, Attack Stop, Source IPs, Attacker Tools, Target Assets, Detection Time, etc.

Click Save.

12. Let's create another test case for our information gathering during Reconnaissance. We completed this test case during Lab 1.4: Reconnaissance and Password Attacks.

Red Team Details

  • Name: Gather Email addresses from draconem.io
  • Description: Scrape target website to collect email addresses.
  • Technique: Gather Victim Identity Information - T1589
  • Phase: Reconnaissance
  • Operator Guidance: sudo cewl http://www.draconem.io/ -v -d 1 -m 9 -w words.txt -e --email_file emails.txt

Blue Team Details

  • Outcome: Check the box labeled Detected
  • What was the alert severity?: Check the box labeled Info
  • Outcome Notes: Logged but not acted on.

Click on Save.

13. Now let's set the start time of that test. Do your best to backdate the test. Click on the test case to bring up the edit modal. Under Status: NotPerformed click the triangle play icon, then click the square stop icon. Now under Attack Start, select the gear icon.

14. When the new modal appears, click on the green New button and provide the date and time you completed Lab 1.4: Reconnaissance and Password Attacks and set the following values:

  • Team: Red
  • Date: Date of Lab 1.4
  • Time: Time of Lab 1.4
  • Description: Start test

15. Let's create another test case for our PowerShell execution on the mail server during Lab 3.2.

Red Team Details

  • Name: PowerShell Execution on mail.draconem.io
  • Description: Use PowerShell to export mailboxes
  • Technique: PowerShell - T1059.001
  • Phase: Execution
  • Operator Guidance:
powershell -c "Add-PSSnapIn Microsoft.Exchange.Management.Powershell.SnapIn; Get-Recipient | Format-Table -Auto Alias" 

function Export-Email {
    param (
        $User
    )
    Add-PSSnapIn Microsoft.Exchange.Management.Powershell.SnapIn;
    $OutFile = "\\127.0.0.1\c$\ProgramData\" + $User + ".pst";
    New-MailboxExportRequest -Mailbox $User -FilePath $OutFile;
};

Blue Team Details

  • Outcome: Check the box labeled NotDetected
  • Was the event source logged?: Check the box labeled Yes

Click on Save.

16. Now let's set the start time of that test. Do your best to backdate the test. Click on the test case to bring up the edit modal. Under Status: NotPerformed click the triangle play icon, then click the square stop icon. Now under Attack Start, select the gear icon.

17. When the new modal appears, click on the green New button and provide the date and time you completed Lab 3.2: Reconnaissance and Password Attacks and set the following values:

  • Team: Red
  • Date: Date of Lab 3.2
  • Time: Time of Lab 3.2
  • Description: Start test

18. By now you should understand how keeping an accurate account of your actions in real time is the best way to rebuild a timeline for reporting. Although we have only added a few test cases, let's look at the Escalation Path. This would be an impactful graphic when fulling filled in.

19. With each action documented, VECTR can be used to synchronize the red and blue team. In a real engagement you would communicate with the blue team on each test case and update the blue team actions based off what they detected and when. VECTR is capable of creating reports to show how effective the blue team was at detecting the actions of the red team. With historical tracking the organization should get a picture of how the blue team is improving their detections over time. Click on the Reporting tab in the left navigation pane to view the different reports.

20. When you are complete with this lab, stop the VECTR containers by using a terminal.

cd /opt/vectr/
docker-compose down

Conclusion

In this lab, we picked up where we left off on in Lab 1.3: Red Team Planning with VECTR. Although we waited until Red Team Closure to complete the test plans, we learned quickly that keeping track of actions in real time is far more convenient. Also. keeping track in real time ensures that we do not forget to document any of our actions and to use the VECTR application as a guide when communicating with the blue team.

This concludes the in-class labs for SEC565: Red Team Operations and Adversary Emulation. Now the final challenge is the Immersive Red Team Capture the Flag.