---
title: 'Locked Shields 2021'
url: 'https://www.ondrejsramek.cz/en/blog/locked-shields-2021'
markdown: 'https://www.ondrejsramek.cz/en/blog/locked-shields-2021.md'
lang: en
date: '2021-04-16'
description: 'A cyber exercise from home During a pandemic, running a cyber exercise is a huge challenge. Personal contact has to be replaced by chat and video calls. On top of that the team restructured and we introduced a SIEM. All of this would have been fairly straightforward without the pandemic. If you nee…'
taxonomy:
  tag:
    - 'Locked Shields'
    - CCDCoE
    - 'Red Team'
    - 'Blue Team'
  category:
    - 'Cyber Security'
  '':
    - ''
  archives_year:
    - '2021'
---

# A cyber exercise from home

During a pandemic, running a cyber exercise is a **huge** challenge. Personal contact has to be replaced by chat and video calls. On top of that the team restructured and we introduced a **SIEM**. All of this would have been fairly straightforward without the pandemic. If you need to resolve something you'd normally walk up to the person and sort it out, or give them a call. These days you send a message and wait for a reply — which costs you **attention**, and therefore **time**.

Despite all of the above, we succeeded and finished [third](https://ccdcoe.org/news/2021/sweden-scored-highest-at-the-cyber-defence-exercise-locked-shields-2021/) out of 22 teams. How?

The team is **well-drilled** — for the fourth time in the last five years we ended up on the podium (in 2020 LS didn't run). We have clearly divided **competencies**, **knowledge**, and **skills**. When you don't know something, there's always someone who can help. We successfully spun up the SIEM with detections in place (very useful for Windows and application logs). We patched up leaky internet-facing services. **Chain of command** wasn't particularly robust but it didn't slow us down in reporting and responding to attacker activity. We're good at working with MISP and the majority of what we reported was accepted positively.

Thinking about what helped the FPC team with detection — as always: a solid baseline and the use of **JA3**, **JA3S**, **Alexa**, and **Cisco Umbrella** lists. This year the RT made things harder by "hiding" in the cloud (Azure). Thanks to JA3S we were then able to better separate the wheat from the chaff and cut off attacker access. We also managed to detect attacks on industrial and mobile devices.

[Photos](https://www.flickr.com/photos/133800821@N02/albums/72157718924187114/with/51118969971/) from this year's exercise

 [ Previous Post](https://www.ondrejsramek.cz/en/blog/1password-enterprise) [Next Post ](https://www.ondrejsramek.cz/en/blog/security-settings-prevented-wacom-software) 

#### Other Related Posts:

 [  Locked Shields  ](https://www.ondrejsramek.cz/en/blog/tag:Locked%20Shields#blog_list) [  Red Team  ](https://www.ondrejsramek.cz/en/blog/tag:Red%20Team#blog_list) [  Blue Team  ](https://www.ondrejsramek.cz/en/blog/tag:Blue%20Team#blog_list) 

###  Locked Shields 2019 

[Locked Shields 2019](https://www.ondrejsramek.cz/en/blog/locked-shields-2019)

# Another year, new challenges

As every year, I took part in the **Locked Shields** cyber exercise. This year the team responsible for Red Team detection doubled in size — whether that doubled our chances of eliminating the Red Team (attackers) was hard to judge in advance.

We spent the preparation...

 12th Apr 2019 

 [  botnet  ](https://www.ondrejsramek.cz/en/blog/tag:botnet#blog_list) [  Blue03  ](https://www.ondrejsramek.cz/en/blog/tag:Blue03#blog_list) [  dyi  ](https://www.ondrejsramek.cz/en/blog/tag:dyi#blog_list) [  Locked Shields  ](https://www.ondrejsramek.cz/en/blog/tag:Locked%20Shields#blog_list) [  openssl  ](https://www.ondrejsramek.cz/en/blog/tag:openssl#blog_list) [  python  ](https://www.ondrejsramek.cz/en/blog/tag:python#blog_list) [  Red Team  ](https://www.ondrejsramek.cz/en/blog/tag:Red%20Team#blog_list) [  sinkhole  ](https://www.ondrejsramek.cz/en/blog/tag:sinkhole#blog_list) 

###  Sinkholing 

[Sinkholing](https://www.ondrejsramek.cz/en/blog/sinkholing)

# What is sinkholing?

*Sinkholing is the redirection of traffic away from its original destination and into a controlled location*...

 21st Apr 2016 - ondra 

- [Intro](https://www.ondrejsramek.cz/en)
- [Projects](https://www.ondrejsramek.cz/en/projects)
- [Portfolio](https://www.ondrejsramek.cz/en/portfolio)
- [Pricing](https://www.ondrejsramek.cz/en/pricing)
- [Blog](https://www.ondrejsramek.cz/en/blog)
- English 

    - [Čeština](https://www.ondrejsramek.cz/cs/blog/locked-shields-2021)

---

## Navigation

- Parent: [Blog](https://www.ondrejsramek.cz/en/blog.md)
- Previous: [Security Settings Prevented](https://www.ondrejsramek.cz/en/blog/security-settings-prevented-wacom-software.md)
- Next: [1Password Enterprise](https://www.ondrejsramek.cz/en/blog/1password-enterprise.md)
