Particle.news
Download on the App Store

CISA Red Team Finds Identical Attacks Produced Divergent SOC Outcomes

The agency’s August 25 advisory shows detection failures, weak escalation rules, token controls are the decisive factors in whether identical identity and cloud flaws cause full compromise.

Overview

  • CISA published advisory AA26-237A on August 25, 2026, after running two simultaneous red-team assessments that achieved full domain control and cloud access in both tested organizations.
  • One target, a government-sector organization, missed the intrusion because thousands of noisy alerts and siloed SOCs hid real signals and analysts lacked clear escalation authority.
  • The water-sector organization detected phishing payloads and quarantined infected hosts within minutes, which limited the red team’s ability to establish persistent command‑and‑control links.
  • CISA traced the compromises to shared technical weaknesses: default Machine Account Quota, misconfigured AD CS templates (ESC1), cleartext or static cloud credentials, over‑permissioned Entra ID apps, no Conditional Access for workload identities, and no token‑revocation processes.
  • The advisory urges concrete fixes—harden AD CS templates, set unused machine quotas to zero, remove stored cleartext keys, treat SCCM as a Tier 0 asset, enable Conditional Access for service identities, and improve alert tuning and cross‑SOC escalation—which, if adopted, could materially reduce risk to other critical‑infrastructure operators.