If you missed the first two parts of this series, the short version is that this was MWX, the Marine Air Ground Task Force Warfighting Exercise. My team had spent the first stretch of the op in a hotel room, building and rebuilding a phishing capability against a new web proxy, and we had finally gotten in. To move into the actual wargame, we had to cede that access, pack our gear, and move on-site to a part of the base the exercise was being run from.
That is where this part starts.
Resetting On Site
The move on-site changed everything about how the op felt.
In the hotel, we had been working a target environment that, from our perspective, looked like a normal enterprise network. People doing normal things in email and chat. We knew the exercise was real because we could feel the broader exercise tempo around us, but our piece of it was quiet, methodical work.
On-site, the tempo was different. We were put in one of the side areas alongside a few other cells of the game-running team. Not the main floor, but a space behind some pull-out partition walls where they had room for us. We got our own table, big enough to fit the whole team with seats for everyone, which was an upgrade from the hotel. You could walk out past the partitions and talk to one of our points of contact in a few seconds. The one thing we never got was a whiteline, a normal internet connection, which meant any time we needed to research something we had to walk outside to a car. That was a recurring annoyance for the rest of the exercise.
But you could feel the exercise running around us. Radios going, map boards getting updated every few hours, briefings happening in the hallway. It was a reminder that what we were doing was not happening in isolation. There were Marines in the desert acting out scenarios that our access was supposed to feed into.
The other DoD red team rotated in some different personnel for the on-keyboard portion of the work, and the new operators were a minor step up from what we had been working with. They were keyboard people, which was an improvement on its own. But they were not experienced. The mental model they brought to a fresh box was something like “run mimikatz and magic happens,” and when the magic did not happen, the next move was not always obvious to them. I had a few conversations with the civilian lead who came out with this rotation about where things stood. In the end we gave them two callbacks to work on while one of my team provided oversight, making sure they did not do anything that would get us burned or cripple the network. The rest of my team operated toward the objectives. Much of the arrangement was still shoulder-surfing to learn, which was fine in principle but frustrating given how short the timeframe had gotten. We were on the right network now and the exercise was ending in just a few days.
I want to be clear about why I bring this up. It is not to run down junior operators. Every one of us was that person at some point, and the only way out of it is reps on real networks. The problem was the decision to send an entirely junior crew into a tasking with a timeline this short. Red teams at an exercise like this are there to support the training of the exercise force, not the training of the operators. There was no room in the schedule to teach, and the people we were supposed to be teaching could not yet carry a callback on their own. So my team was doing the job of one cell and then some, operating toward the objectives while also carrying the other cell’s weight and watching their hands. The babysitting from the first phase did not stop. It just shifted shape.
Working Our Way Up
I am not going to describe the specifics of how we built access inside the exercise network. The short, generalized version is that we worked through enumeration, identified accounts that gave us the leverage we wanted, and took those accounts over. From there, we moved into a position from which we could deliver effects against the targets the exercise was actually about.
What I will say is that getting to that position took most of the energy of the on-site phase. The exercise network was a different beast than the enterprise environment had been. Fewer users, different segmentation, and traffic that did not look like an enterprise network. We were learning the network and operating on it at the same time, which is the situation most red teams find themselves in most of the time, but at a pace that did not allow for a lot of rework.
Once we had what we needed, the work shifted from building access to using access.
Intel Is the Name of the Game
I have had a conversation with many commanders over the years, and it goes roughly like this.
The commander wants to understand what their cyber capability can do for them. The default mental model is destructive. Take the network down or deny comms. There is value in those effects in the right context, and I am not going to argue that they should never be on the table. But the destructive option burns the access. Once you have produced the effect, you cannot use the network anymore, because the network is gone.
The other option is to leave the network up and use it.
Use it to read the traffic, watch the plans get drafted before they get executed, and track where units are headed and what they are talking about doing when they get there. The network is how the enemy force coordinates with itself. If you own that channel and you sit quietly inside it, you are watching their decision-making happen in real time and feeding what you see back to your own side.
When I have offered that choice to a commander, with the two options laid out plainly, I have never met one who did not go for option two with a giddy “you can do that?” The look on their faces when they realize the network can be a sensor instead of just a target is the look you want to see if you are trying to change how people think about cyber.
That principle drove the next phase of this op.
We took over a chat server that the exercise force was using for internal coordination. Once that takeover was clean, we were positioned to do interesting things with it. The first thing we did was push out a request through the account of a senior officer running the exercise force, asking everyone to submit a position report. POSREPs. Standard request from that role. Nothing about the message looked off to the people receiving it.
The POSREPs came back and our eyes widened.


