CISA Shares Advice to Improve Networks’ Monitoring and Hardening

New guidelines have been published by the US Cybersecurity and Infrastructure Security Agency (CISA) to help network defenders improve their systems monitoring and hardening efforts.

Recommendations are based on the Red Team Assessment (RTA) CISA conducted in 2022 at the request of a large, unnamed critical infrastructure company with multiple geographically separated buildings.

“Teams gain permanent access to the organization’s network, move laterally across multiple geographically separated sites of the organization, and eventually to systems adjacent to the organization’s confidential business systems (SBS). access,” CISA wrote on Tuesday. Recommendation.

The agency also explained that despite its strong cyber defenses, the organization detected no intrusion attempts at any point during the drill.

To help companies detect similar attacks in the future, CISA now publishes the Tactics, Techniques and Procedures (TTPs) used by the Red Team during the evaluation.

“This CSA [Cybersecurity Advisory] The importance of collecting and monitoring logs for anomalous activity and ongoing testing and exercises to ensure that an organization’s environment is not vulnerable to compromise, regardless of the maturity of an organization’s cyber posture. It emphasizes the importance of “,” reads the document.

According to it, CISA used Active Directory (AD) data to gain initial access to two organizational workstations in separate sites. It then gained permanent access to a third host via spear phishing emails.

“From that host, the team moved laterally to a misconfigured server and from there compromised a domain controller (DC),” CSA said.

“We then used the forged credentials to navigate to multiple hosts across different sites in our environment, and eventually, all workstations connected to our organization’s mobile device management (MDM) servers. You have gained root access to

CISA’s red team says they used root access to move laterally to a workstation connected to SBS.

“However, multi-factor authentication (MFA) prompts prevented the team from achieving access to one SBS, and Phase I was designed to implement a viable plan for the team to achieve access to a second SBS. I finished before I did.”

Details regarding the TTPs used in this attack can be found in the original advisory.Its publication comes a few weeks after Pepsi Bottling Ventures revealed the offense One of those networks that led to the theft of employee data.

Source link

Leave a Reply

Your email address will not be published. Required fields are marked *