Home / Work / Aegis Bank

Red Team · Aegis Bank · 2025

Caught a supply-chain breach in 47 seconds.

A poisoned vendor update sailed past signature-based tooling. Behavior-based detection flagged it, isolated it, and rolled it back before a single customer account was touched.

Analyst workstation flagging anomalous outbound traffic in real time
DETECTION ENGINEERING — OUTBOUND ANOMALY, T+47S

The challenge

Trusted software, untrusted payload.

Aegis Bank’s patch pipeline implicitly trusted a long-standing vendor. When that vendor’s update server was compromised, a signed — and therefore “safe” — package carried a backdoor into the bank’s server estate. Legacy allow-list tooling waved it through.

Our red team had spent the prior quarter mapping exactly this scenario: what happens when the trusted channel itself turns hostile?

Approach

Behavior doesn’t lie. Signatures do.

Detect

Anomaly-first monitoring

We had baselined normal outbound traffic per host role. The backdoor’s first beacon — small, encrypted, to a new ASN — breached the baseline in under a minute.

Isolate

Automated quarantine

A pre-authorized playbook cut the affected hosts from the network while preserving memory for forensics — no waiting for a change ticket mid-incident.

Recover

Verified rollback

Hosts were rebuilt from known-good images, the vendor channel was pinned and re-verified, and the whole path was re-attacked to confirm closure.

0Financial loss
0.0MAccounts safe
0Records exposed
Quarantined hardware awaiting forensic imaging after containment
POST-INCIDENT — QUARANTINE & FORENSIC IMAGING

Outcome

A non-event, by design.

“Ironvale found a supply-chain intrusion our previous vendor missed for weeks — and contained it in under a minute. They’re the difference between a headline and a non-event.”

— Dana Reyes, CISO, Aegis Bank

StackCobalt StrikeSuricata

Could your supply chain survive this?

More work: Zero-trust at Orbital · Verdant hospitals

Test Your Detection