CISA Red Team Breaches Critical Infrastructure, Exposes SOC and Cloud Security Gaps
Key Takeaways CISA red team operations successfully breached two critical infrastructure organizations, exposing significant security vulnerabilities. The same attack techniques yielded vastly...
Key Takeaways
- CISA red team operations successfully breached two critical infrastructure organizations, exposing significant security vulnerabilities.
- The same attack techniques yielded vastly different outcomes, highlighting the critical role of human analysts and robust security processes over mere technological investment.
- One organization (Organization A) suffered a complete compromise without detection, including keylogger deployment and access to SOC staff emails.
- The other (Organization B) rapidly detected and contained initial intrusions, demonstrating effective layered defenses and human response.
- Key vulnerabilities exploited included Active Directory misconfigurations (e.g., Machine Account Quota, AD Certificate Services templates) and inadequate incident response procedures.
CISA Red Team Uncovers Major Security Gaps in Critical Infrastructure
The Cybersecurity and Infrastructure Security Agency (CISA) has issued a stark warning to critical infrastructure operators, revealing that even well-funded security systems can fail without skilled analysts and robust operational procedures. A new CISA advisory details parallel red team engagements against two distinct critical infrastructure entities, showcasing how identical attack methodologies led to dramatically divergent security outcomes.
Table Of Content
CISA’s report, titled “A Tale of Two SOCs,” outlines two red team exercises. One targeted an organization within the Government Services and Facilities Sector (Organization A), while the other focused on a Water and Wastewater Systems Sector entity (Organization B). In both simulated attacks, CISA’s operators initiated their breach with phishing campaigns, subsequently exploiting common Active Directory misconfigurations, such as default Machine Account Quotas and improperly configured Active Directory Certificate Services templates, to escalate privileges and move laterally within the networks.
Breach Successes and Failures
At Organization A, the red team achieved a comprehensive compromise. They successfully gained elevated domain privileges, infiltrated sensitive business systems, and accessed cloud resources, all without triggering any alerts. The attackers even managed to read SOC staff emails and deploy keyloggers on the defenders’ own machines, demonstrating a complete breakdown in detection and response capabilities.
Organization B, however, presented a different scenario. Its Security Operations Center (SOC) demonstrated remarkable agility, isolating compromised workstations within a rapid timeframe of 2 to 20 minutes following the execution of the initial phishing payload. This swift action effectively severed command-and-control communications, preventing the intrusion from spreading further into the network.
Due to Organization B’s effective initial containment, CISA shifted its approach to an “assume breach” model. Under this scenario, trusted internal agents granted the red team access equivalent to what they would have achieved had the initial phishing attempt gone undetected. From this advanced starting point, the red team once again escalated privileges by exploiting the same Machine Account Quota vulnerability. They further harvested cleartext credentials from a System Center Configuration Manager file and executed DCSync attacks to obtain domain controller credentials, including the highly sensitive krbtgt account, which can be used to forge Golden Tickets.
Despite this deep level of assumed compromise, Organization B’s defenders continued to exhibit resilience. They successfully isolated a compromised bastion host located in the operational technology demilitarized zone and blocked a suspicious Azure sign-in attempt that was flagged by Microsoft’s automated alerting systems. This demonstrated that even after a significant breach, layered detection mechanisms and active human intervention continued to provide critical defensive capabilities.
Operational Dysfunction vs. Empowered Response
CISA attributed Organization A’s profound security blind spots not to a lack of security tools, but to significant operational dysfunction. The organization operated multiple SOCs and utilized various Endpoint Detection and Response (EDR) platforms without adequate cross-team communication. Furthermore, thousands of false-positive alerts generated by routine business activities effectively buried genuine indicators of compromise.
Analysts at Organization A also lacked standardized operating procedures for escalating suspicious activity and possessed limited authority to act. Consequently, legitimate alerts, including one directly tied to red team activity on an SCCM server, were erroneously dismissed as false positives because defenders could not readily identify the system owner.
The advisory’s central takeaway underscores that the effectiveness of detection tooling is intrinsically linked to the human expertise and robust processes supporting it. CISA is strongly urging critical infrastructure operators to address common Active Directory weaknesses, such as unrestricted Machine Account Quotas and ESC1-vulnerable certificate templates. Additionally, they recommend enforcing credential expiration policies for service and cloud accounts and adopting Conditional Access for workload identities to mitigate risks associated with application permissions.
Crucially, organizations must establish documented escalation procedures, foster cross-team visibility, and empower their analysts. Organization B’s success was ultimately attributed to its rapid triage and decisive isolation capabilities, rather than reliance on any single security product.
What You Should Do
- Address Active Directory Misconfigurations: Immediately review and remediate common Active Directory weaknesses, including unrestricted Machine Account Quotas and vulnerable Active Directory Certificate Services (AD CS) templates (e.g., ESC1).
- Implement Strong Credential Management: Enforce credential expiration for all service accounts and cloud accounts. Implement multi-factor authentication (MFA) across all critical systems.
- Adopt Conditional Access: Utilize Conditional Access policies for workload identities to enhance security around application permissions and access.
- Develop and Enforce Incident Response Procedures: Establish clear, documented standard operating procedures (SOPs) for detecting, escalating, and responding to suspicious activity. Ensure these procedures are regularly tested and updated.
- Empower Your SOC Analysts: Provide analysts with the necessary training, tools, and authority to investigate and act decisively on security alerts. Foster a culture of proactive threat hunting and rapid response.
- Improve Cross-Team Communication: Break down silos between security teams and other IT departments to ensure a unified view of the security landscape and efficient incident resolution.
- Reduce Alert Fatigue: Optimize security tools to minimize false positives and ensure that genuine indicators of compromise are not overlooked. Prioritize alerts based on severity and potential impact.
Disclaimer: HackersRadar reports on cybersecurity threats and incidents for informational and awareness purposes only. We do not engage in hacking activities, data exfiltration, or the hosting or distribution of stolen or leaked information. All content is based on publicly available sources.



No Comment! Be the first one.