A Tale of Two SOCs: Insights From Two Red Team Assessments

A Tale of Two SOCs: Insights From Two Red Team Assessments
CISA’s dual red team assessments showed that both organizations could be fully compromised in AD, cloud, and sensitive business systems, but only Organization B detected and contained the activity quickly. The advisory highlights misconfigured ADCS and MAQ settings, excessive permissions, exposed credentials, and weak cloud token and application controls as the main causes of successful compromise. #CISA #BloodHound #AzureHound #ROADrecon #ADCS #EntraID #SCCM #SeamlessSSO

Keypoints

  • CISA ran simultaneous red team assessments at Organization A and Organization B using similar tradecraft.
  • Both organizations were fully compromised at the domain level and the red team accessed sensitive business systems and cloud resources.
  • Organization A failed to detect or contain the activity, while Organization B quickly isolated systems and forced an assume-breach model.
  • Attackers abused default credentials, phishing, AD discovery, misconfigured ADCS templates, and weak Machine Account Quota settings to escalate access.
  • Cleartext credentials, long-lived AWS IAM credentials, and excessive application permissions enabled movement into cloud and business systems.
  • Organization B’s faster alert triage, quarantine actions, and custom detections significantly limited attacker reach.
  • CISA recommends stronger baselines, reduced alert noise, tighter cloud token and application controls, AD hardening, and OT segmentation.

MITRE Techniques

  • [T1589.001 ] Gather Victim Identity Information: Credentials – The red team found a web application with default credentials that enabled internal email access. (‘identified a web application with default credentials’)
  • [T1589.002 ] Gather Victim Identity Information: Email Addresses – The red team collected employee email addresses from public websites for spearphishing. (‘gathered email addresses from public websites’)
  • [T1588.002 ] Obtain Capabilities: Tool – The red team used public tools for cloud reconnaissance. (‘including AzureHound and ROADrecon’)
  • [T1566 ] Phishing – The red team used phishing emails to gain access to workstations. (‘sent phishing emails from an internal email address’ / ‘spearphishing emails’)
  • [T1204 ] User Execution – Users clicked a malicious link or payload, enabling compromise. (‘users clicking on a malicious link’)
  • [T1136.002 ] Create Account: Domain Account – The red team created machine accounts by abusing Machine Account Quota. (‘create machine accounts on a workstation’)
  • [T1552 ] Unsecured Credentials – The red team found cleartext credentials on workstations and in cloud-related files. (‘located cleartext credentials on an administrative user’s workstation’)
  • [T1552.001 ] Unsecured Credentials: Credentials In Files – The red team decrypted files and found passwords or IAM credentials stored in files. (‘connections.json and product-preferences.xml’ / ‘credentials in configuration files’)
  • [T1003 ] OS Credential Dumping – The red team obtained cleartext credentials for MSOL and Entra accounts. (‘obtain cleartext credentials for cloud accounts’)
  • [T1003.006 ] OS Credential Dumping: DCSync – The red team used DCSync to retrieve domain account credentials. (‘used DCSync to obtain AD account credentials’)
  • [T1649 ] Steal or Forge Authentication Certificates – The red team abused misconfigured ADCS to request certificates for accounts. (‘request a certificate for the newly created machine account’)
  • [T1087.002 ] Account Discovery: Domain Account – The red team scraped AD users. (‘query and scrape AD information, including AD users’)
  • [T1018 ] Remote System Discovery – The red team enumerated computers in AD. (‘query and scrape AD information, including computers’)
  • [T1069.002 ] Permission Groups Discovery: Domain Groups – The red team enumerated groups in AD. (‘query and scrape AD information, including groups’)
  • [T1615 ] Group Policy Discovery – The red team enumerated GPOs. (‘query and scrape AD information, including GPOs’)
  • [T1033 ] System Owner/User Discovery – The red team queried SCCM to map users to devices. (‘enumerate user-device relationships’)
  • [T1526 ] Cloud Service Discovery – The red team enumerated Entra applications, permissions, and owners. (‘gather information about applications, their permissions, and their owners’)
  • [T1550.001 ] Use Alternate Authentication Material: Application Access Token – The red team used an application access token to access emails. (‘retrieve and review target emails via the Microsoft Graph API’)
  • [T1114 ] Email Collection – The red team reviewed and retrieved organizational emails. (‘review security operations center (SOC) staff emails’)
  • [T1113 ] Screen Capture – The red team captured screenshots from SOC workstations. (‘captured screenshots’)
  • [T1056.001 ] Input Capture: Keylogging – The red team used keyloggers on SOC workstations. (‘used keyloggers’)
  • [T1213.005 ] Data from Information Repositories: Messaging Applications – The red team retrieved Teams messages. (‘retrieved Microsoft Teams messages’)
  • [T1090.001 ] Proxy: Internal Proxy – The red team proxied tools through compromised workstations. (‘proxying tools through compromised workstations’)
  • [T1021.004 ] Remote Services: SSH – The red team accessed a bastion host using SSH credentials. (‘log in over Secure Shell (SSH)’)
  • [T1558 ] Steal or Forge Kerberos Tickets – The red team requested and used Kerberos tickets for impersonation and SSO abuse. (‘request a Kerberos service ticket’ / ‘asktgs module’)

Indicators of Compromise

  • [Tools] Cloud discovery and AD enumeration – BloodHound, AzureHound, ROADrecon, ADConnectDump, Rubeus
  • [File names] Credential and configuration artifacts – connections.json, product-preferences.xml, ics-[redacted]-org, and other config files
  • [Cloud application permissions] Highly privileged Microsoft Graph scopes – Mail.Read, Mail.ReadWrite, Chat.Read.All, Files.Read.All, Application.ReadWrite.All, AppRoleAssignment.ReadWrite.All
  • [Account names/prefixes] Identity artifacts used in compromise – MSOL_[prefix] accounts, Sync_[redacted], AZURESSO account names
  • [URLs/domains] Cloud access and API targets – portal[.]azure[.]com, Microsoft Graph API
  • [Credential material] Stolen or reused secrets – cleartext passwords, AES256 password hashes, primary refresh tokens (PRTs), access tokens, refresh tokens, client secrets, Kerberos TGTs and service tickets
  • [Infrastructure references] Access paths used during operations – bastion host, SCCM server, domain controller, OT DMZ host


Read more: https://www.cisa.gov/news-events/cybersecurity-advisories/aa26-237a