CyberSecurityNews

CISA Red Team Breaches Critical Infrastructure to Reveal SOC and Cloud Security Gaps


CISA’s latest advisory for red teams warns critical infrastructure operators that security systems can fail even if they have a lot of funding. This is because trained analysts are needed to respond to alerts effectively.

The agency’s “A Tale of Two SOCs” report compares two parallel red team engagements: one against a Government Services and Facilities Sector organization and another against a Water and Wastewater Systems Sector entity, using nearly identical attack tradecraft but producing starkly different outcomes.

In both cases, CISA’s operators used phishing to gain an initial foothold, then leaned on Active Directory misconfigurations such as a default Machine Account Quota and misconfigured Active Directory Certificate Services templates to escalate privileges and move laterally.

CISA Red Team Breaches Critical Infrastructure

At Organization A, the team gained elevated domain privileges and reached sensitive business systems and cloud resources entirely undetected, eventually reading SOC staff emails and deploying keyloggers on defenders’ own machines without triggering a response.

Organization B told a different story: its SOC isolated compromised workstations within 2 to 20 minutes of the initial phishing payload executing, cutting off command-and-control communications before the intrusion could spread.

Because Organization B caught the breach so quickly, CISA shifted to an “assume breach” model, with trusted agents granting the red team access equivalent to what they would have had if the phishing attempt had gone unnoticed.

From there, the team again escalated privileges through the same Machine Account Quota weakness, harvested cleartext credentials via a System Center Configuration Manager file, and used DCSync attacks to obtain domain controller credentials, including the sensitive krbtgt account used to forge Golden Tickets.

Despite this deep access, Organization B’s defenders isolated a compromised bastion host in the operational technology demilitarized zone and blocked a suspicious Azure sign-in flagged by Microsoft’s automated alerting, showing that layered detection kept working even after the network was assumed compromised.

CISA attributes Organization A’s blind spots not to a lack of tools but to operational dysfunction. The organization ran multiple SOCs and multiple EDR platforms without cross-team communication, and thousands of false-positive alerts from routine business activity buried the genuine indicators of compromise.

Analysts also lacked standard operating procedures for escalating suspicious activity and had limited authority to act, so real alerts, including one tied to red team activity on an SCCM server, were dismissed as false positives after defenders simply couldn’t identify the system owner.

The advisory’s central takeaway is that detection tooling is only as effective as the humans and processes behind it. CISA is urging critical infrastructure operators to fix common Active Directory weaknesses such as unrestricted Machine Account Quotas and ESC1-vulnerable certificate templates, enforce credential expiration for service and cloud accounts, and adopt Conditional Access for workload identities to close gaps around application permissions.

Just as importantly, organizations need documented escalation procedures, cross-team visibility, and empowered analysts, since Organization B’s success came down to fast triage and decisive isolation rather than any single security product.

Prevent incidents due to slow investigations. Power your Tier 1 with threat intelligence from 15K SOCs: Integrate TI Lookup in your SOC



Source link