Red Team

Assumed breach methodology

How the Strobes red team simulates an attacker who is already inside, from internal reconnaissance through post-exploitation and exfiltration, to measure how fast you detect and respond.

CRESTISO 27001SOC 2Accredited adversary simulation and red team engagements
0Adversary simulation model
0Core attack phases
0What it measures

Assumed breach is a type of adversary simulation exercise where an organization assumes that a breach has already happened, or that it is only a matter of time until it will. The goal is to evaluate how well the organization can detect and respond to a compromise.

In an assumed breach engagement, the Strobes red team starts from a foothold already inside the network and works outward, using the same tactics, techniques, and procedures (TTPs) that real threat-actor groups employ.

Assumed breach starts from the attacker's best day: a foothold already inside. It measures whether you can detect and respond before that foothold becomes a crisis.

Attack path

From a foothold inside to data out

The assumed breach path: starting from access already inside the network, measured against detection and response.

Assumed breach attack path: a start card for the assumed foothold with domain-user access already inside, flowing into phase 1 internal reconnaissance to enumerate the network, phase 2 post-exploitation covering escalate, lateral, and persist, and phase 3 exfiltration to bypass egress and move a proof-of-concept data sample out. A bar underneath reads: detection and response measured across every phase.
1

Where the red team focuses

In an assumed breach engagement, the Strobes red team focuses on:

  • Use the current user's privileges and the built-in tools available on the workstation
  • Move laterally through the network to reach password vaults, highly confidential servers, and any custom objectives set by the customer
  • Exfiltrate sensitive information, or a representative sample of it
  • Use the tactics, techniques, and procedures (TTPs) employed by real threat-actor groups
2

Internal reconnaissance

The team enumerates the internal network to build situational awareness and find the weaknesses an intruder would use to move.

  • Enumerate the network for situational awareness
  • Discover network misconfigurations such as open shares
  • Enumerate domain user privileges
  • Identify Active Directory misconfigurations
  • Perform weak-password spraying
3

Post-exploitation

Using the intelligence gathered during reconnaissance, the team:

  • Escalate privileges: raise privileges on the current workstation, or move to one held by a compromised user with higher privileges
  • Lateral movement: pivot to high-security Tier 0 and Tier 1 networks or workstations, in the cloud or on-premises, where possible
  • Persistence: employ a variety of techniques to maintain access on compromised workstations or hosts
4

Exfiltration

The team tests whether target data can leave the environment without being caught.

  • Bypass egress restrictions set on the customer infrastructure
  • Exfiltrate a proof-of-concept (PoC) sample of sensitive data to attacker-controlled infrastructure
5

Objectives

Objectives vary with the purpose of the exercise. Typical assumed breach goals include, and are not limited to:

  • Gain access to a highly sensitive server
  • Emulate a user's privileges to identify over-privileged accounts
  • Gain access to a specific user's mailbox and exfiltrate information
  • Bypass host-based controls to execute specific payload types
  • Execute sample ransomware payloads to assess detection and response
6

Requirements from customers

  • Access to a workstation inside the corporate network with common domain-user privileges
  • Set of objectives to achieve, if any
7

Deliverables

  • Assumed breach report
  • Executive summary report

Frequently asked questions

Assume you're already breached. Then find out.

Let the Strobes red team start from a foothold inside your network and show you how far an attacker gets, and how fast you would catch them.

Join 150+ security teams already reducing exposure with Strobes