A Tale of Two SOCs: Insights From Two Red Team Assessments
ID: f474b14e-67c4-5c14-8220-f535cf1fb3d1
STIX ID: report--f474b14e-67c4-5c14-8220-f535cf1fb3d1
Feed Name: CISA Advisories
CISA’s advisory describes two concurrent red team assessments: in Organization A defenders missed alerts leading to full domain compromise and access to SBSs and cloud resources, while Organization B detected and contained initial compromises but the red team still exploited AD/cloud misconfigurations (MAQ, ADCS, service-account permissions, cleartext credentials, excessive application permissions) to escalate privileges and access cloud and OT assets; the document maps observed TTPs to MITRE ATT&CK and recommends mitigations including tuning detections, eliminating silos, securing AD/certificates, enforcing Conditional Access for workload identities, token revocation processes, credential hygiene, and IT/OT segmentation.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
