A Tale of Two SOCs: Insights From Two Red Team Assessments
ID: 6cf18e3c-479f-57bb-87a3-f684b3fa4ebf
STIX ID: report--6cf18e3c-479f-57bb-87a3-f684b3fa4ebf
Feed Name: CISA Cybersecurity Advisories
This CISA advisory summarizes two red team assessments in which attackers leveraged phishing, Active Directory misconfigurations (MAQ, ADCS), credential theft/DCSync, Kerberos ticket abuse, and excessive cloud application permissions to achieve domain compromise and cloud/SBS access; Organization B detected and limited impacts through tuned detection and rapid response while Organization A failed to detect or contain the activity. The advisory maps the red team’s techniques to MITRE ATT&CK, documents defensive gaps, and provides prioritized mitigations for AD, cloud, endpoint management, and IT/OT segmentation.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
