VORANT. Threat Intelligence Sign in Get the full feed

CISA Red Team Report Details AD, Cloud, OT Gaps

routine vulnerability government-nationalinfrastructure

CISA compares two red team assessments showing how ADCS misconfigurations, excessive cloud permissions, and alert fatigue let attackers reach SBSs and OT bastion hosts undetected in one org while another detected and contained intrusions.

CISA's advisory recounts two concurrent red team engagements—one against a Government Services and Facilities Sector organization (Organization A) and one against a Water and Wastewater Systems Sector organization (Organization B)—using similar tradecraft to test detection and response maturity. In Organization A, phishing against a vulnerable web app with default credentials led to workstation compromise, AD enumeration via a modified BloodHound collector, exploitation of a default Machine Account Quota (MAQ) and an ESC1-misconfigured ADCS template to escalate to domain admin, and ultimately undetected lateral movement into sensitive business systems and Microsoft Entra ID via abused Application permissions and stolen primary refresh tokens. The SOC never meaningfully responded due to alert fatigue, tool silos, and unclear escalation authority, allowing the red team to read SOC staff's own email and monitor their awareness of the compromise.

Organization B's defenders, by contrast, detected and isolated three phished workstations within minutes, forcing the red team into an assume-breach model. From that foothold, the team abused a permissive MAQ, cleartext SCCM credentials, and a service account's AllExtendedRights over a domain controller to conduct a resource-based constrained delegation attack, obtain DCSync privileges, and compromise the krbtgt account. They reached an OT bastion host via stolen FTP/SSH credentials but were blocked from establishing C2 by egress controls and were detected and quarantined. They also abused Entra ID Connect (ADConnectDump), Seamless SSO account impersonation, and an over-permissioned mail application to read all tenant emails, though Microsoft's automated alerting and Organization B's custom Entra risky-user detections eventually flagged the activity.

CISA draws lessons applicable broadly: untuned detection tooling and alert overload defeat even capable SOCs; organizational silos and unclear incident-response authority block escalation; both orgs underestimated cloud risk, using excessive Entra ID application permissions, long-lived unrotated AWS IAM credentials, and lacking Conditional Access for workload identities or mature token-revocation processes. The advisory recommends hardening ADCS templates, restricting MAQ, applying least privilege to service and cloud application permissions, enabling MFA universally including for sync/service accounts, tuning EDR/SIEM to reduce false positives, and establishing clear SOC escalation authority and cross-team communication.

Detection guidance

1 detection artefacts for this report are available to subscribers.

Source reporting: https://www.cisa.gov/news-events/cybersecurity-advisories/aa26-237a

This is the public brief

Subscribers see the full picture: extracted IOCs, ready-to-deploy detections (Sigma, Splunk, KQL, Elastic, YARA, Suricata), the entity graph, TAXII 2.1 feed and real-time alerts matched to your sectors.

Start free