What does it take to think like an adversary well enough to break into a nuclear facility’s steam loop, ground an entire fleet of trains, or hijack a swarm of drones all without touching a single real network?
“So, I can just stop all the trains?”
Those are questions that Aaron Rosenmund has been answering for eight years as U.S. Air Force 1st Lieutenant and the OPFOR (Red Team) Work Group Lead for Cyber Shield, the Department of Defense’s largest unclassified cyber defense exercise. And it’s the same mindset and detailed expert thinking he brings to his work at OnDefend.
In a recent episode of the Cyber Shield: Defense, Offense, and Strategy podcast, Aaron sat down with host Capt. LaPortia Jackson to talk about what it takes to run the offense at this scale, and why that experience makes him – and OnDefend – better at defending organizations in real life.
Eight Years Leading the Opposition
As OPFOR work group lead, Aaron is running the teams that play the opposing force and set up the MSELs (the “injects”) that Blue Teams have to detect and respond to all week. He’s held the role for eight years, and in that time the team has grown from about 60 people to around 150. That kind of growth doesn’t happen by accident. It happens because the training is realistic enough, and hard enough, that people keep coming back for more. That, coupled with strong leadership and the commitment to creating a culture that emphasizes relationship building and the balancing both fun and excellence, creates an environment people want to be a part of.
A Cyber Range Built from Scratch
Before OPFOR can attack anything, the team has to build something to attack. As Aaron explains it, a cyber range works the same way a live-fire range or a bombing range does – it’s a place to safely practice something when you can’t practice on the real thing. Because you obviously can’t create a cyber attack within a company’s real environment, the team builds a virtualized copy of what an enterprise network would look like, using “the smallest viable version” of the components that make up a realistic environment. Those virtual machines get copied over and over, so the exercise ends up running 40 identical environments at once.
A Day in the Life of a Red Teamer
Once the exercise starts, the pace is relentless.
Every single day we condense an entire exercise into one day, and OPFOR does it three separate times, against three different simulated threat actors. Each day builds toward one attack chain, and by 4:30 in the afternoon, the Red Team sits down with the Blue Teams for a “hot wash” where discussions go over: here’s what we did, here’s where we came from, what did you catch, and how can we help you do better next time.
One detail Aaron points out: unlike defensive tools, which typically come from vendors like Cisco or Microsoft with documentation and support behind them, Red Team tooling often doesn’t have that safety net. This year, in fact, virtually everything OPFOR used or built was custom – a byproduct, Aaron notes, of how fast AI now lets teams and attackers develop their own tooling instead of relying on known, easily identifiable tools.
Planning for an Adversary That Keeps Changing
Red Team planning starts broad (what’s the general target, what’s the effect OPFOR wants to have) and gets specific with TTPs (tactics, techniques, and procedures) closer to execution. Some of those details, down to what goes in the command line, don’t get finalized until the team is on-site. Aaron and his team, many of whom coordinate year-round in a 1,000-person Discord community, are constantly weighing new techniques against what he calls the “good idea cutoff line”: the point where an idea has to either get built now or get shelved for a future exercise.
Real-World Stakes: Trains, Nuclear Plants, and Drones
Each year, OPFOR builds its scenario around one of the critical infrastructure sectors identified under Presidential Policy Directive 21 (PPD-21) – sectors like agriculture, finance, and, this year, power. Past years have tackled nuclear energy and water combined, and rail.
The railway example is a favorite of Aaron’s.
Freight train brakes are controlled by an RF signal rather than a physical wire, and interrupting that signal at all causes the brakes to engage automatically – meaning an attacker doesn’t need precision, just the ability to send erroneous signals, to stop an entire train. For last year’s agriculture-focused exercise, the team virtualized the same drone firmware used in Ukraine, fed it physics data through a fake flight controller, and then compromised the drones as they “flew” inside the simulated environment. And in the nuclear-and-water scenario, the team traced a real vulnerability: some nuclear facilities pull wastewater into their steam loop, meaning an attack on a wastewater treatment facility could realistically affect a nuclear plant’s operation.
Why Every Defender Should Spend Time on Offense
Aaron is direct about why this matters for defenders, not just attackers.
Blue Teams often walk away from Cyber Shield realizing they missed far more than they caught (sometimes up to 50 individual actions behind a single inject) and that their confidence in certain tools or controls was higher than it should have been. Cyber Shield is intentionally designed to expose that gap: antivirus stays on across the entire exercise, and OPFOR works to give Blue Teams as much visibility as possible, while still finding ways past it.
Becoming genuinely excellent at cybersecurity can take about as long as becoming a doctor. And spending time on the Red Team, even briefly, is one of the fastest ways to become a sharper Blue Teamer.
From Cyber Shield to OnDefend
That’s exactly the philosophy Aaron brings back to OnDefend every year. As Managing Director of Tradecraft & Programs, his job is to make sure the offensive techniques behind our client engagements are just as custom, just as current, and just as realistic as the ones he builds for Cyber Shield – not recycled playbooks, but attack chains built around how a specific adversary would actually target a specific environment. The same instinct that led him to ask, “Could a wastewater attack really affect a nuclear plant?” is the instinct he applies when he’s mapping out how a real attacker would move through one of our clients’ networks.