CISA conducted simultaneous red team assessments at two critical infrastructure organizations using similar tradecraft. The red team achieved full domain compromise at both organizations by exploiting ADCS misconfigurations, excessive Machine Account Quota settings, cleartext credentials, and overly permissive Entra ID application permissions. Organization A failed to detect the activity due to untuned EDR alerts and organizational silos, while Organization B rapidly triaged and isolated compromised systems. Both organizations lacked Conditional Access policies for workload identities and mature processes for revoking compromised cloud tokens.
ADCS Misconfiguration
1 post
A Tale of Two SOCs: Insights From Two Red Team Assessments (2026-08-25)