Operation Dark Horizon

30 Apr 2025 - joe

Operation Dark Horizon: A Cybersecurity Tabletop Exercise for MSSPs

Exercise Overview

Title: Operation Dark Horizon
Duration: 4 hours (recommended)
Target Audience: SOC analysts, incident responders, security engineers, management team
Difficulty: Moderate to Advanced
Objective: Test the organization’s incident response capabilities during a sophisticated multi-stage attack targeting both the MSSP and its clients simultaneously.

Learning Objectives

  1. Evaluate team coordination during complex incident response
  2. Test technical response capabilities across different attack vectors
  3. Assess communication protocols both internally and with clients
  4. Practice decision-making under pressure with limited information
  5. Identify gaps in current incident response plans

Exercise Structure

Preparation Phase (2 weeks prior)

  1. Facilitator Selection: Appoint 1-2 individuals to lead the exercise
  2. Participant Selection: Identify key stakeholders from various teams
  3. Resource Preparation: Ready the necessary documentation, communication channels, and simulated environments
  4. Pre-Exercise Briefing: Conduct a short session explaining exercise rules and expectations

Exercise Roles

  1. Exercise Facilitator: Controls exercise flow, introduces injects, evaluates responses
  2. Players: SOC analysts, incident responders, security engineers, management
  3. Observers: Document actions, decisions, and potential improvement areas
  4. Client Representatives: (Optional) Can participate to add realism to client communications

Exercise Materials

Required Documents

  1. Incident response plan
  2. Communication templates
  3. Client contact information
  4. Escalation procedures
  5. Technical documentation of systems
  6. Exercise evaluation forms

Technical Setup (Optional)

  1. Isolated test environment for simulated forensic analysis
  2. Communication channels (separate from production)
  3. Timer display
  4. Digital collaboration tools

Scenario Background

MegaGuard Security Solutions is a well-established MSSP providing security monitoring and incident response services to over 50 clients across various industries. Among their key clients are:

MegaGuard uses a SOC platform that aggregates logs and alerts from client environments, with a centralized dashboard for monitoring and response.

Exercise Narrative

A sophisticated threat actor has identified MegaGuard as a prime target for a supply chain attack. Their objective is to compromise MegaGuard’s infrastructure to gain access to high-value clients. The attack will unfold in multiple stages over the course of the exercise.

Exercise Timeline and Injects

Phase 1: Initial Compromise (0:00-1:00)

Setting the Scene (0:00-0:10)

Inject 1 (0:10): Suspicious Login Alert

Expected Actions:

Inject 2 (0:30): Discovery of Suspicious Activity

Expected Actions:

Inject 3 (0:45): Malicious Tool Detection

Expected Actions:

Phase 2: Escalation (1:00-2:00)

Inject 4 (1:00): Client Alert - NexBank

Expected Actions:

Inject 5 (1:20): Malware Detection

Expected Actions:

Inject 6 (1:40): Detection Evasion

Expected Actions:

Phase 3: Crisis Management (2:00-3:00)

Inject 7 (2:00): Critical Infrastructure Alert

Expected Actions:

Inject 8 (2:20): Executive Involvement

Expected Actions:

Inject 9 (2:40): Ransom Demand

Expected Actions:

Phase 4: Resolution and Recovery (3:00-4:00)

Inject 10 (3:00): Attacker TTPs Identified

Expected Actions:

Inject 11 (3:20): Containment Decision Point

Expected Actions:

Inject 12 (3:40): Recovery Planning

Expected Actions:

Conclusion (3:50-4:00)

Exercise Evaluation

Evaluation Metrics

  1. Detection Effectiveness
    • Time to detect initial compromise
    • Ability to identify related security events
    • Thoroughness of investigation
  2. Response Efficiency
    • Time from detection to initial response
    • Appropriateness of response actions
    • Resource allocation and utilization
  3. Communication Effectiveness
    • Internal communication clarity and timeliness
    • Client communication appropriateness
    • Management updates and escalations
  4. Decision Quality
    • Risk assessment accuracy
    • Decision-making under pressure
    • Balance between security and business continuity

Post-Exercise Activities

  1. Hot Wash (Immediately following exercise)
    • Quick round-table discussion of initial impressions
    • Identification of major strengths and challenges
    • Collection of immediate feedback
  2. Formal Debrief (1-2 days after exercise)
    • Structured review of exercise timeline and decisions
    • Analysis of major decision points
    • Documentation of lessons learned
  3. Improvement Planning (1-2 weeks after exercise)
    • Development of specific action items
    • Assignment of responsibilities for improvements
    • Timeline for implementing changes
  4. Follow-up Exercise (3-6 months later)
    • Targeted scenario to test improvements
    • Focus on previously identified weaknesses
    • Validate effectiveness of changes

Facilitator Guidelines

Pre-Exercise Preparation

  1. Scenario Customization
    • Adjust technical details to match your organization’s environment
    • Modify client names and industries as appropriate
    • Ensure technical injects are realistic for your tools and processes
  2. Information Control
    • Determine what information is available to participants at each stage
    • Prepare answers for likely questions from participants
    • Create physical or digital information cards for injects
  3. Environment Setup
    • Arrange the exercise space to facilitate team communications
    • Test any technical systems or simulations
    • Prepare backup plans for technical failures

During Exercise Facilitation

  1. Maintaining Realism
    • Introduce complications that might occur in real incidents
    • Provide realistic time pressures
    • Limit information as would happen in real scenarios
  2. Adaptability
    • Be prepared to adjust scenario pacing based on participant progress
    • Have additional injects ready if teams resolve issues quickly
    • Be willing to provide hints if teams get completely stuck
  3. Observation
    • Take notes on key decisions and actions
    • Identify teaching moments for the debrief
    • Document specific areas for improvement

Post-Exercise Activities

  1. Facilitating Discussion
    • Use open-ended questions to promote reflection
    • Focus on process improvements rather than assigning blame
    • Highlight both strengths and areas for improvement
  2. Documentation
    • Compile observations and participant feedback
    • Prepare a comprehensive after-action report
    • Develop specific, actionable recommendations

Appendix: Detailed Technical Injects

Technical Details for Inject 1

Technical Details for Inject 2

Technical Details for Inject 3

Technical Details for Inject 5

Technical Details for Inject 7

Technical Details for Inject 9

Technical Details for Inject 10