Cyber Pre-Positioning in Critical Infrastructure: Detection and Response
Understand how states establish durable access before a crisis, distinguish pre-positioning from espionage, and turn weak signals into proportionate defensive action.
Define pre-positioning by the option it creates
Cyber pre-positioning is the deliberate creation or preservation of access, knowledge, infrastructure, credentials, or capability that can support a later operation. It is preparation rather than the future effect itself. The actor may map dependencies, learn recovery procedures, obtain administrator access, compromise edge devices, or place infrastructure near a target while avoiding visible disruption. The value lies in shortening future decision and execution time.
Do not equate persistence with destructive intent. Intelligence collection also rewards stealth, durable access, and broad knowledge. Frame at least two hypotheses: collection, preparation for disruption, or a blended mission. Compare what each predicts about target selection, data sought, privilege, movement toward control systems, attention to recovery paths, and coordination with political or military events. The correct analytic product exposes uncertainty while specifying what would change the judgment.
The 2024 multi-agency CISA joint advisory on Volt Typhoon is a central public case. Agencies reported extensive reconnaissance, valid accounts, living-off-the-land behavior, and access maintained in some victim environments for years. They assessed the activity as pre-positioning for possible disruption during a future crisis. That is an official assessment grounded in combined evidence, not a universal rule that the same technique always has the same purpose.
Recognize a campaign built for long dwell time
Pre-positioning campaigns often prioritize access quality over visible volume. Analysts may see extensive environmental discovery, repeated authentication with valid accounts, use of built-in administration utilities, careful command execution, configuration collection, and attention to remote management or identity infrastructure. Compromised routers or other intermediary devices can obscure origin and separate operator infrastructure from victim-facing activity.
Living off the land is a behavior category, not an actor identity. The joint CISA living-off-the-land guidance stresses that legitimate binaries can make malicious activity difficult to distinguish from normal administration. Detection therefore depends on command context, parent process, account role, source and destination, timing, frequency, peer-group deviation, and whether the action matches an approved change. Logging defaults may omit exactly the evidence needed.
Build an evidence table with event time, source, collection method, identity, asset role, command or protocol, expected behavior, deviation, linked events, confidence, and retention. Preserve raw evidence before enrichment. A single anomalous command is weak; a sequence showing external access, credential use, domain discovery, collection of network configuration, and movement toward mission systems can support a stronger campaign hypothesis.
Hunt from mission hypotheses, not public indicators alone
Begin with the future option an adversary might seek. For a water utility, hypotheses could include access to remote administration, knowledge of treatment processes, compromise of engineering workstations, or ability to disrupt identity and communications during restoration. Translate each into observable behaviors and required telemetry. This connects the hunt to cyber key terrain instead of searching every endpoint equally.
Use public indicators to pivot and scope, but assume infrastructure and hashes expire. Durable analytics examine rare remote-management paths, service accounts used outside expected hosts, changes in privileged group membership, unexpected archive creation, network-device configuration access, unusual authentication geography, and long gaps followed by renewed activity. Baseline known administration and maintenance windows so anomaly logic does not simply rediscover normal operations.
Record negative findings with coverage. “No evidence found” is meaningful only when the relevant systems, identities, data sources, time period, query logic, and retention were adequate. Where visibility is missing, create a gap and compensating action. Strategic warning improves when hunting, architecture, intelligence, and mission owners share the same hypotheses and can state what remains unseen.
Contain access without losing the campaign picture
Treat suspected strategic access as an incident with potential national-security, safety, regulatory, and partner implications. Establish an incident commander, legal and executive contacts, mission owners, and secure communications. Confirm which systems can be isolated safely, especially where IT supports operational technology. Preserve volatile and durable evidence, protect time synchronization, and document every defensive change.
Avoid an uncoordinated account reset that leaves alternate persistence untouched. Scope identities, tokens, trust relationships, edge devices, remote access, cloud control planes, backup administration, and management networks. Rotate secrets in an order that prevents the actor from reusing stronger privileges. Rebuild or replace devices when integrity cannot be established. Validate logging and detection after changes rather than assuming that eradication created visibility.
Use the incident response lifecycle as the operational spine: preparation, detection and analysis, containment, eradication, recovery, and lessons learned. For strategic access, add an intelligence track that assesses actor knowledge, collected information, alternate footholds, and likely adaptation. Defensive urgency and analytic patience are not opposites; a coordinated plan can protect the mission while retaining the evidence needed to remove the whole access architecture.
Learn from Volt Typhoon without copying the case mechanically
Volt Typhoon illustrates a strategic pattern, not a detection signature. Public agencies described critical-infrastructure targeting, long-lived access, extensive reconnaissance, native-tool use, valid accounts, and strong operational security. The US government also disrupted the KV Botnet, which officials said used compromised small-office and home-office routers to conceal malicious traffic. The DOJ KV Botnet disruption shows that campaign infrastructure can include unwilling third parties.
Apply the case through questions. Which local systems offer durable administration? Which identities appear ordinary but cross mission boundaries? Where can configuration, topology, or continuity documents be collected? Which routers or appliances lack strong telemetry? What access would matter during a geopolitical crisis? Which recovery dependencies could an intruder already understand? These questions generalize better than copying a list of commands.
Maintain source labels. Distinguish agency observation, government assessment, vendor overlap, confirmed local evidence, and analytic inference. Do not claim that an organization is compromised merely because it uses technology mentioned in an advisory. Convert external reporting into local hypotheses, validate them against local data, and record the result with a time-bound confidence statement.
Build a repeatable pre-positioning watchboard
A useful watchboard combines adversary, access, mission, and decision information. Track priority services, cyber key terrain, relevant actor missions, observed footholds, identity anomalies, edge exposure, telemetry gaps, crisis indicators, investigative owners, containment readiness, and the next review time. Each entry should identify its source, confidence, expiry, and decision threshold.
Use three status questions. First, is access plausible or confirmed? Second, what future options could that access enable given the actual mission architecture? Third, what action is justified now: hunt, collect, harden, isolate, notify, exercise, or monitor? Separate actions that are low-regret from those that may expose collection, disrupt service, or escalate a wider confrontation.
Rehearse the transition from routine competition to crisis. Decide who can authorize containment, how partners will exchange evidence, which services receive priority, and how manual operations will be sustained. Good pre-positioning defence does not wait for proof of destructive intent. It uses uncertainty to prioritize visibility, remove unnecessary access, protect recovery, and create decision time without overstating what the evidence proves.
Frequently asked questions
What is cyber pre-positioning?
Cyber pre-positioning is the establishment and maintenance of access, knowledge, infrastructure, or capability that could support a later operation. Its immediate activity may resemble espionage, so analysts must assess target choice, persistence, reconnaissance, access paths, operational context, and plausible future effects together.
How is pre-positioning different from espionage?
Espionage primarily seeks information. Pre-positioning preserves an option to disrupt, manipulate, or support another operation later. One intrusion can serve both purposes, and public evidence may not resolve intent. Use competing hypotheses and identify observations that would distinguish them.
Why do state actors use living-off-the-land techniques?
Built-in administrative tools and valid accounts can blend with legitimate activity, reduce distinctive malware artifacts, and support long dwell time. Their use is not proof of state activity or destructive intent; defenders must combine behavior, context, identity, network, and mission evidence.
Should defenders immediately remove suspected strategic access?
Containment should be prompt but coordinated. Removing one foothold without understanding identity, persistence, dependencies, and alternate access can destroy evidence or cause the actor to accelerate. Incident command should balance safety, mission continuity, intelligence value, legal duties, and eradication confidence.