Red Team/Blue Team example exercise, attacking Company Z
In this section, we are going to go over the steps and activities involved in performing an industrial control system (ICS)-centric Red Team/Blue Team exercise. The engagement is held around a fictitious organization, aptly called Company Z. We will go over the prerequisites, preparation, implementation, and results of the exercise in the following sections.
Red Team strategy
The Red Team's strategy is simple: get to the objective of the engagement using the same tactics, techniques, and procedures (TTPs) that potential adversaries of the exercise's target would likely use as well. Time is not a factor, so we can take as much or as little time as we need. The goal is to stay under the radar as much as possible, but being detected should not be considered a failure but instead an indicator of the competence of the target's Blue Team's capabilities.
Blue Team preparation
As the saying goes, as defenders...