Contents
Context
The client was a Series C healthcare SaaS provider whose customer base included regulated US healthcare organisations subject to HIPAA. They had passed previous penetration tests cleanly and wanted the next intensity up — a full-scope red team engagement designed to test detection and response, not just prevention.
The crown-jewel objective was clear: demonstrate access to a representative sample of simulated protected health information (PHI) from outside the network perimeter without being caught.
Scoping and rules of engagement
The engagement was scoped over a fortnight before any traffic flew. Rules of engagement covered:
- Permitted initial-access vectors (phishing was in scope; physical access and supply-chain attacks were not)
- Permitted lateral-movement targets (any host in the corporate environment; explicit no-go list for life-safety-critical systems on the customer side)
- Permitted final actions (read-only access to a simulated PHI dataset)
- A small clearing group of three (CISO, head of platform, deputy CTO) who knew the engagement was happening
The blue team did not know.
The engagement
Week 1 — Initial access. A targeted phishing campaign was crafted around an industry conference the client’s engineering team was attending. The lure pretexted as a calendar-coordination request from a known peer at a similar healthcare SaaS. Three users clicked; one ran the embedded macro.
Week 1–2 — Foothold and escalation. Initial access delivered a custom in-memory implant calling back to a Cloudflare-fronted C2 domain. From the engineering laptop we reached an internal jump host, then escalated through an outdated service-account configuration to obtain a Tier-1 administrator credential. Domain administrator followed within forty-eight hours.
Week 3–5 — Persistence and reconnaissance. With domain administrator established, persistence was placed on three diverse hosts (each using a different mechanism), the C2 was reconfigured to a slower beacon cadence to evade behavioural detection, and the production environment was enumerated carefully.
Week 5 — Objective execution. The simulated PHI dataset was identified, accessed read-only, and a representative sample was exfiltrated through a secondary covert channel.
Throughout — EDR evasion. The implant remained undetected by the deployed EDR for fourteen consecutive days of active operation. No alert was raised by the blue team.
Purple-team debrief
The engagement closed with a full-day debrief between our team and the blue team. Every TTP we used was walked through, the corresponding telemetry that should have fired was identified, and a roadmap of eleven specific detection-engineering improvements was handed over.
The most valuable outcome was not the report — it was a blue team that, by the end of the debrief, could articulate exactly where their detection capability needed investment.
Tags