The Challenge
The department delivers essential public services and holds large volumes of citizen data, which makes it a standing target for state-aligned actors and financially motivated ransomware crews. Leadership needed hard evidence, not assurances, that its defenses could withstand a determined adversary who was willing to spend weeks inside the environment.
The estate was typical of long-standing government: a sprawling Active Directory forest, legacy applications that could not simply be retired, an expanding public-facing footprint, and a broad supply chain of vendors with varying levels of maturity. The department also carried obligations under its own information security policy and wanted an engagement that spoke to those frameworks in operational terms rather than as a paperwork exercise.
Our Approach
StrikeCyber scoped an objective-based red team with defined goals and rules of engagement agreed with a small group of stakeholders, so the wider security team could respond as they would to a genuine intrusion.
- External reconnaissance and attack surface mapping across the department's public footprint, including systems operated on its behalf by vendors.
- Initial access attempts through the routes a real adversary would use, including phishing and exposed services.
- Active Directory attack path analysis, privilege escalation and lateral movement toward the systems supporting public service delivery.
Every technique was mapped to MITRE ATT&CK so the department could translate findings directly into detection engineering work rather than a list of remediations without context.
What We Found
- Multiple paths to domain admin. Several distinct chains led from an ordinary user account to full domain control, most relying on accumulated permission grants and unconstrained delegation rather than any single missing patch.
- Vendor-operated exposure. A system operated by a third party on the department's behalf ran outdated software and was reachable from the internet, providing a route into the internal environment.
- Legacy applications as pivot points. Applications retained for business continuity held credentials and trust relationships that were useful well beyond their own function.
- Detection weighted toward the perimeter. Activity at the boundary was well monitored; movement inside the environment generated far less attention.
The Outcome
The department closed the domain admin paths, which required addressing the underlying permission accumulation rather than the individual chains, and established a recurring review so the problem does not rebuild. The vendor system was brought into the department's own patching and monitoring scope, and vendor security expectations were rewritten into contract terms.
Detection engineering was redirected toward internal lateral movement and credential access, the areas the exercise showed were weakest, and validated against a follow-up purple team. Leadership received a narrative it could take to its own oversight bodies showing what was found, what was fixed and what was verified.
Why It Matters
Government departments delivering essential services are targeted by adversaries with time, funding and patience. Compliance frameworks establish a baseline, and CISA guidance sets clear expectations for public sector resilience, but neither answers whether a determined attacker gets in and how far they reach. Only an adversary who behaves like one can answer that. To test your department's resilience, get in touch.
