Finance 
Red Teaming Challenges
A Red Team Assessment in the Banking Sector
We performed a Red Team Assessment for a bank, which aimed to recreate realistic attack scenarios in order to gain undetected access to the internal network without the company or the internal Blue Team detecting the attack.
To accomplish this, the first step was to search for information about the company using freely available sources (OSINT). As no valid passwords or vulnerable systems could be identified, the next step was to send phishing emails to selected employees. The company was well prepared, as one phishing email was recognized and reported immediately. Another phishing email was not recognized and the payload was basically executed by the employee, but the code execution was blocked. Employees on the systems were not allowed to execute new programs, therefore the attack was mitigated.
For further analysis of the internal servers, internal tests were carried out from a notebook provided by the company. This revealed several vulnerabilities that could have been used to extend rights. The company was again well prepared and the Blue Team responded very quickly to the received alerts. As the company was already well prepared , it was recommended to continuously harden the internal systems and to further strengthen the security awareness among employees.
