treasury.firstnationalbank.com

Purple team exercise against port 443. Started 2026-08-26 03:00 UTC and finished in 8.1 seconds.

0
critical
1
high
1
medium
0
low
0
info

Engagement

Engagement id
18268c52-98f6-4bab-9ea8-f3d05a2f76c9
Target
treasury.firstnationalbank.com
Port
443
Scan type
Purple team exercise
Started
2026-08-26 03:00 UTC
Completed
2026-08-26 03:00 UTC
Duration
8.05 s
Findings
2

Blue team score

67% FAIR
Overall detection coverage 4 of 6
Cryptographic action coverage 67%
Web action coverage 67%

Red team actions

ActionCategoryResultDetailDetected
Harvest now decrypt later capture
harvest_now_decrypt_later
Cryptography SUCCESS Captured 412 handshakes negotiated under a classical group. Stored transcripts remain recoverable once quantum capability lands. Yes
Protocol downgrade attempt
tls_downgrade
Cryptography SUCCESS The listener accepted a TLSv1.2 hello and dropped the hybrid group from the negotiated parameters. Yes
Certificate substitution
certificate_forgery
Cryptography SUCCESS A substitute chain built on a classical issuing key was accepted by the default client trust store. No
Response header injection
header_injection
Web BLOCKED The edge proxy normalised the response and dropped the injected header before it left the origin. Yes
Information disclosure probe
information_disclosure
Web BLOCKED Error responses were generic. No product, build or path information was returned. Yes
Authentication weakness probe
authentication_weakness
Web SUCCESS The login surface accepted unlimited attempts with no second factor and no lockout. No

Findings

HIGH Blue team missed certificate substitution 9b280f58

The red team ran certificate substitution against treasury.firstnationalbank.com and no detection fired. The action completed with no entry in the monitoring pipeline, so the same technique would run unobserved in a live intrusion.

Remediation. Add a detection rule for this technique and replay the exercise to confirm the rule fires end to end.

Categorycrypto
NIST 800-53SI-4, AU-6
CMMCSI.L2-3.14.6, AU.L2-3.3.5
CNSA 2.0CNSA 2.0 Monitoring
ATT&CKT1557
MEDIUM Blue team missed authentication weakness probe 7acb1349

The red team ran authentication weakness probe against treasury.firstnationalbank.com and no detection fired. The action completed with no entry in the monitoring pipeline, so the same technique would run unobserved in a live intrusion.

Remediation. Add a detection rule for this technique and replay the exercise to confirm the rule fires end to end.

Categoryweb
NIST 800-53SI-4, AU-6
CMMCSI.L2-3.14.6, AU.L2-3.3.5
ATT&CKT1552, T1539

MITRE ATT&CK techniques exercised

Full coverage view
TechniqueNameTacticMitigation
T1040 Network Sniffing Credential Access Establish sessions with a hybrid group so a recorded transcript cannot be unwound once quantum capability arrives.
T1190 Exploit Public Facing Application Initial Access Remove unauthenticated administrative paths from the public origin and place a policy aware proxy in front of it.
T1539 Steal Web Session Cookie Credential Access Set Secure, HttpOnly and SameSite on every session cookie and scope the cookie to the narrowest path that works.
T1552 Unsecured Credentials Credential Access Move credential material into a hardware backed store, rotate on exposure and require a second factor on every administrative login.
T1557 Adversary in the Middle Credential Access Pin the issuing authority and require hybrid key agreement so an interposed relay cannot substitute its own public key.
T1592 Gather Victim Host Information Reconnaissance Suppress server, framework and build version banners at the edge so reconnaissance yields no version specific target list.
Back to engagements Rerun this assessment