A cyber exercise from home

During a pandemic, running a cyber exercise is a huge challenge. Personal contact has to be replaced by chat and video calls. On top of that the team restructured and we introduced a SIEM. All of this would have been fairly straightforward without the pandemic. If you need to resolve something you'd normally walk up to the person and sort it out, or give them a call. These days you send a message and wait for a reply — which costs you attention, and therefore time.

Despite all of the above, we succeeded and finished third out of 22 teams. How?

The team is well-drilled — for the fourth time in the last five years we ended up on the podium (in 2020 LS didn't run). We have clearly divided competencies, knowledge, and skills. When you don't know something, there's always someone who can help. We successfully spun up the SIEM with detections in place (very useful for Windows and application logs). We patched up leaky internet-facing services. Chain of command wasn't particularly robust but it didn't slow us down in reporting and responding to attacker activity. We're good at working with MISP and the majority of what we reported was accepted positively.

Thinking about what helped the FPC team with detection — as always: a solid baseline and the use of JA3, JA3S, Alexa, and Cisco Umbrella lists. This year the RT made things harder by "hiding" in the cloud (Azure). Thanks to JA3S we were then able to better separate the wheat from the chaff and cut off attacker access. We also managed to detect attacks on industrial and mobile devices.

Photos from this year's exercise

Other Related Posts:

Locked Shields 2019

Another year, new challenges

As every year, I took part in the Locked Shields cyber exercise. This year the team responsible for Red Team detection doubled in size — whether that doubled our chances of eliminating the Red Team (attackers) was hard to judge in advance.

We spent the preparation...

12th Apr 2019