SiegeCast: Be Your Enemy

By Red Siege | September 10, 2024

Collaboration between offensive (Red Team) and defensive (Blue Team) operations is essential to fortify an organization’s defenses. During a recent SiegeCast session, Tim Medin (CEO of Red Siege), Justin Palk (Senior Security Consultant), and Mike Saunders (Principal Consultant) discussed how Blue Teams can improve their defense strategies by utilizing Red Team tactics and tools. Here’s a deep dive into the key takeaways from the session and how cybersecurity professionals can apply these insights.

You can download the slides to the SiegeCast HERE

 

Why Red Team Knowledge is Crucial for Blue Teams

As Tim Medin highlighted, many effective Red Teamers start their careers on the Blue side, often working as sysadmins or defenders. This experience gives them a detailed understanding of the systems they are later tasked with attacking. The knowledge of system configurations, shortcuts, and vulnerabilities that defenders rely on every day becomes an advantage for offensive operations. However, this deep insight is also why Red Team tactics can be invaluable to Blue Teams.

Rather than seeing Red Team operations as adversarial, organizations should view them as opportunities for collaboration. The goal of Red Teams is to help Blue Teams identify weaknesses and fix them before real-world attackers do. By adopting an attacker’s mindset, defenders can proactively close gaps, strengthen their environment, and reduce the risk of a breach.

Key Red Team Tactics for Blue Teams

  1. Credential Attacks – Password Spraying & Credential Stuffing One of the most common attack vectors Red Teams (and real-world attackers) use is password spraying and credential stuffing. Attackers often gain access to breach databases on the dark web and test compromised credentials across multiple services. A user who reuses the same password across accounts makes their organization vulnerable.To mitigate these attacks, Blue Teams should:
    • Audit Passwords: Use tools like Hashcat to audit internal password policies. Identify weak or common password patterns, such as passwords using seasons or favorite sports teams.
    • Enforce Multi-Factor Authentication (MFA): MFA can act as a safeguard when passwords are compromised. Ensure it’s enabled for all critical systems and accounts.
  2. Kerberoasting and Service Account Vulnerabilities Service accounts, particularly those with high privileges, are often left vulnerable. With Kerberoasting, attackers request service tickets and crack them offline without risk of lockout. Blue Teams can counteract this by:
    • Regularly rotating service account passwords.
    • Ensuring strict password policies for service accounts.
    • Auditing and removing unnecessary service accounts.
  3. Active Directory Misconfigurations Tools like Bloodhound allow attackers to map relationships and permissions within Active Directory (AD), identifying paths to elevate privileges or move laterally within the network. For Blue Teams:
    • Run Bloodhound: This tool can help you understand AD misconfigurations before attackers do. Look for excessive permissions or users in high-privilege groups.
    • PingCastle: Use PingCastle for more readable reports on AD health and vulnerabilities, particularly for executive-level summaries.
  4. Identifying Insecure File Shares Attackers often gain access to sensitive information by finding improperly secured file shares. Tools like PowerView and Snaffler help identify exposed file shares that may contain credentials, intellectual property, or sensitive data.
    • Regularly audit file shares and review permissions.
    • Set up honey files or honey shares to detect unauthorized access attempts.

 

Multi-Factor Authentication (MFA) Testing with MFA Sweep

MFA adds a critical layer of defense, but organizations need to ensure it is consistently applied across all systems. Tools like MFA Sweep help defenders test various authentication interfaces to verify if MFA is enforced across different platforms, such as web portals and APIs. This ensures that attackers cannot bypass MFA due to configuration gaps.

Becoming Your Own Attacker

Blue Teams can enhance their defense capabilities by running offensive tools in their own environments. By hacking themselves, they gain the following benefits:

  • Proactive Defense: Detect vulnerabilities before attackers do.
  • Mindset of the Attacker: Understand the methods, tools, and techniques attackers use to break into systems. This allows defenders to better anticipate where they might be targeted.
  • Incident Response Readiness: Test your ability to detect attacks and respond effectively, providing an opportunity to refine incident response processes.

 

Start Hacking Yourself: Offense for Defense

Implementing Red Team tools into your defense strategy isn’t just for external pen tests. As a Blue Teamer, you can start using these tools in your environment to identify issues and make real-time improvements. Courses like our Offense for Defense provide hands-on training to learn these tactics and apply them to your organization’s security program.

Final Thoughts

By adopting Red Team tactics, Blue Teams can significantly strengthen their defenses. The key is shifting from a reactive mindset to a proactive one—identifying weaknesses before they are exploited by attackers. As Justin Polk pointed out, “Running these tools will help you take control of your environment before anyone else can.”

For cybersecurity professionals, the message is clear: don’t wait for a breach to start thinking like an attacker. Use these offensive techniques today to build a stronger, more resilient security posture.

Resources & Tools:

  • Hashcat: Password cracking tool.
  • Bloodhound: Active Directory attack path mapping tool.
  • PingCastle: AD security audit tool.
  • PowerView: AD enumeration tool.
  • Snaffler: File share enumeration tool.
  • MFA Sweep: Tool for testing MFA enforcement.

Improving Your Simple Windows Domain for Offensive Testing: Installing MS SQL Server Express on Windows Server 2022 Server Core Edition

By Red Siege | September 3, 2026

by Justin Palk A couple of years ago, I put together a series on standing up a simple Windows AD domain in a lab environment. This article is part of […]

Learn More
Improving Your Simple Windows Domain for Offensive Testing: Installing MS SQL Server Express on Windows Server 2022 Server Core Edition

Improving Your Simple Windows Domain for Offensive Testing: Sysmon

By Red Siege | August 13, 2026

by Justin Palk A couple of years ago, I put together a series on standing up a simple Windows AD domain in a lab environment. This article is part of […]

Learn More
Improving Your Simple Windows Domain for Offensive Testing: Sysmon

Improving Your Simple Windows Domain for Offensive Testing: Elastic Defend EDR

By Red Siege | July 7, 2026

 by Justin Palk A couple of years ago, I put together a series on standing up a simple Windows AD domain in a lab environment. This is the start of […]

Learn More
Improving Your Simple Windows Domain for Offensive Testing: Elastic Defend EDR

Find Out What’s Next

Stay in the loop with our upcoming events.