Skip to content
8bytes
Healthcare SaaS · Red team engagement · 8 weeks ·

Established C2, evaded EDR for 14 days, exfiltrated simulated PHI. Full detection roadmap delivered.

Eight-week full-scope red team engagement against a HIPAA-regulated SaaS platform. Initial access via targeted phishing, domain administrator within five days, persistent C2 maintained for fourteen days without detection.

Outcomes

  • Domain administrator in 5 days from initial access
  • 14-day C2 dwell time without EDR detection
  • Simulated PHI exfiltration completed without alert
  • Detection roadmap covering 11 ATT&CK techniques
  • Purple-team debrief with the blue team on engagement close
Contents

Context

The client was a Series C healthcare SaaS provider whose customer base included regulated US healthcare organisations subject to HIPAA. They had passed previous penetration tests cleanly and wanted the next intensity up — a full-scope red team engagement designed to test detection and response, not just prevention.

The crown-jewel objective was clear: demonstrate access to a representative sample of simulated protected health information (PHI) from outside the network perimeter without being caught.

Scoping and rules of engagement

The engagement was scoped over a fortnight before any traffic flew. Rules of engagement covered:

  • Permitted initial-access vectors (phishing was in scope; physical access and supply-chain attacks were not)
  • Permitted lateral-movement targets (any host in the corporate environment; explicit no-go list for life-safety-critical systems on the customer side)
  • Permitted final actions (read-only access to a simulated PHI dataset)
  • A small clearing group of three (CISO, head of platform, deputy CTO) who knew the engagement was happening

The blue team did not know.

The engagement

Week 1 — Initial access. A targeted phishing campaign was crafted around an industry conference the client’s engineering team was attending. The lure pretexted as a calendar-coordination request from a known peer at a similar healthcare SaaS. Three users clicked; one ran the embedded macro.

Week 1–2 — Foothold and escalation. Initial access delivered a custom in-memory implant calling back to a Cloudflare-fronted C2 domain. From the engineering laptop we reached an internal jump host, then escalated through an outdated service-account configuration to obtain a Tier-1 administrator credential. Domain administrator followed within forty-eight hours.

Week 3–5 — Persistence and reconnaissance. With domain administrator established, persistence was placed on three diverse hosts (each using a different mechanism), the C2 was reconfigured to a slower beacon cadence to evade behavioural detection, and the production environment was enumerated carefully.

Week 5 — Objective execution. The simulated PHI dataset was identified, accessed read-only, and a representative sample was exfiltrated through a secondary covert channel.

Throughout — EDR evasion. The implant remained undetected by the deployed EDR for fourteen consecutive days of active operation. No alert was raised by the blue team.

Purple-team debrief

The engagement closed with a full-day debrief between our team and the blue team. Every TTP we used was walked through, the corresponding telemetry that should have fired was identified, and a roadmap of eleven specific detection-engineering improvements was handed over.

The most valuable outcome was not the report — it was a blue team that, by the end of the debrief, could articulate exactly where their detection capability needed investment.

Tags

red-team healthcare edr-evasion purple-team

Client name, regulated data, and identifying details are withheld under engagement NDA. References available on request.

Start a scope

Your engagement next?

Book a call

Free 30-min scoping call. No commitment.