Listen to this Post
A Warning Every Security Leader Should Take Personally
A modern security operations center can have endpoint detection, identity protection, cloud monitoring, threat intelligence, automated alerts, and an impressive security budget—and still lose a battle against a relatively conventional attacker.
That is the uncomfortable lesson behind the latest CISA red-team advisory, “A Tale of Two SOCs.” The assessment demonstrates that cybersecurity is not ultimately measured by how many security products an organization owns. It is measured by whether defenders can recognize suspicious behavior, understand its significance, escalate it quickly, and take decisive action before an attacker turns a foothold into a catastrophe.
CISA compared two organizations from different critical infrastructure sectors: one in the Government Services and Facilities Sector and another in the Water and Wastewater Systems Sector. The red team used broadly similar techniques against both environments, yet the outcomes were dramatically different.
One organization allowed the intrusion to expand deep into its environment. The other detected and contained the initial compromise within minutes and continued disrupting the simulated attackers even after CISA was given additional access.
The difference was not simply technology.
It was operational readiness.
The Real Security Gap Is Often Between the Alert and the Decision
CISA’s assessment exposes an uncomfortable truth about modern cybersecurity: an alert is worthless if nobody knows what it means, who should receive it, or who has the authority to act.
Security teams frequently measure themselves by the number of alerts processed, detection rules deployed, endpoints protected, or vulnerabilities remediated. Those metrics matter, but they can hide a much more important question.
What happens when the attacker actually appears?
If analysts see suspicious activity but dismiss it because they lack context, the organization can remain technically monitored while being operationally blind.
That is precisely the type of failure CISA observed.
Two Organizations, Nearly the Same Attack
The red-team operators began their engagements with phishing, using it as an initial entry point into the target environments.
From there, they exploited familiar weaknesses in Active Directory and identity infrastructure. Among the weaknesses were the default Machine Account Quota configuration and improperly secured Active Directory Certificate Services (AD CS) templates.
Neither technique depends on an exotic zero-day.
Instead, they demonstrate how ordinary identity and configuration weaknesses can become extremely dangerous when combined with insufficient detection and response.
The Attack Chain Begins With One Compromised Endpoint
Phishing remains effective because attackers do not necessarily need to defeat every security layer simultaneously.
They only need one successful entry point.
Once an endpoint is compromised, an attacker can begin searching for credentials, privileged accounts, trust relationships, administrative systems, misconfigured services, and paths toward higher privileges.
In CISA’s assessment, the compromised endpoint became the beginning of a much larger attack chain.
The lesson is important: initial compromise should not automatically become enterprise compromise.
The security architecture should be designed around breaking that chain as early as possible.
Active Directory Became the Battleground
Active Directory remains one of the most important control planes in many enterprise environments.
It determines who can authenticate, what users and machines can access, which systems trust one another, and which identities possess administrative authority.
That also makes Active Directory an attractive target.
A weakness that appears minor when viewed in isolation can become extremely serious when combined with another identity weakness, exposed credentials, or inadequate monitoring.
CISA’s red-team activity demonstrated exactly this problem.
Machine Account Quota Can Become an Unnecessary Attack Path
One of the weaknesses involved the Machine Account Quota (MAQ) setting.
In Active Directory, this setting controls whether ordinary users can add computer accounts to the domain and how many they can create by default.
When unnecessarily permissive configurations exist, attackers who have already obtained a suitable domain identity may be able to abuse the behavior as part of a privilege-escalation chain.
The larger lesson is not simply “change one setting.”
Organizations need to understand why the setting exists, whether legitimate users require it, and whether the current configuration creates unnecessary attack paths.
A defensive review should therefore examine MAQ alongside delegated permissions, computer-account ownership, certificate enrollment permissions, and other identity relationships.
AD CS Misconfiguration Can Turn Identity Infrastructure Into an Attack Surface
The second major weakness involved Active Directory Certificate Services.
AD CS is a legitimate and powerful enterprise technology used to manage certificates and identity-related authentication. But poorly configured certificate templates can introduce serious privilege-escalation opportunities.
CISA specifically highlighted vulnerable certificate templates associated with the ESC1 attack pattern.
The problem is particularly dangerous because certificate-based authentication can become deeply integrated into enterprise identity systems.
If an attacker can obtain a certificate that effectively represents a more privileged identity, the organization may face a compromise that is considerably harder to understand than a conventional stolen-password scenario.
Organization A: Technology Without Effective Coordination
The first organization, referred to by CISA as Organization A, represents the nightmare scenario for a security operations center.
The red team progressed through the environment without encountering meaningful defensive resistance.
The attackers obtained elevated domain privileges, reached sensitive business systems, and eventually accessed cloud resources.
The organization had security technology.
What it lacked was effective operational coordination.
The Attackers Reached the Defenders Themselves
One of the most striking aspects of the assessment was that the red team eventually accessed the email of SOC personnel.
That should have been an enormous warning sign.
Instead, the attackers were able to continue their operation.
The red team also deployed keyloggers on defenders’ workstations, demonstrating how an organization can reach a particularly dangerous point where the people responsible for protecting the network themselves become targets.
At that stage, the problem is no longer simply an endpoint compromise.
It becomes a compromise of the organization’s defensive ecosystem.
Too Many Alerts Can Become Another Security Vulnerability
CISA attributed much of Organization A’s failure to operational dysfunction.
Multiple SOCs and EDR platforms were operating, but communication between teams was insufficient.
Large volumes of routine-business alerts also created noise that made genuine malicious activity harder to identify.
This is a familiar problem across security operations.
When analysts are buried under thousands of alerts, the most dangerous signal may look like just another notification.
That means alert volume is not the same thing as security visibility.
In fact, excessive noise can actively weaken security if it causes analysts to become desensitized to unusual behavior.
The Most Dangerous Alert May Be the One Nobody Owns
CISA described an especially revealing example involving suspicious activity associated with an SCCM server.
Defenders dismissed the alert because they could not determine who owned the system.
That decision illustrates a fundamental operational weakness.
Security teams must know what critical assets are, who owns them, why they exist, what normal activity looks like, and who has the authority to isolate them during an incident.
Without that context, analysts can hesitate.
And during an intrusion, hesitation is often enough.
Organization B: The Same Threat, A Completely Different Outcome
Organization B tells a much more encouraging story.
When the red team delivered the initial phishing payload, the SOC detected the activity and isolated affected workstations within approximately two to 20 minutes.
That response disrupted the attackers before they could establish meaningful command-and-control operations and expand their access.
The difference between the two organizations was not that Organization B had magically eliminated every vulnerability.
It had something more important.
It reacted.
Containment Worked Before the Attack Could Become an Enterprise Crisis
The rapid isolation of compromised systems prevented the initial intrusion from becoming a straightforward lateral-movement operation.
This is one of the most important concepts in modern incident response.
Perfect prevention is unrealistic.
Perfect detection is also unrealistic.
But an organization that can quickly isolate a compromised machine can dramatically reduce the attacker’s available options.
Every minute matters.
A compromised workstation that remains connected for hours is fundamentally different from one isolated within minutes.
CISA Changed the Scenario to Assume Breach
Because Organization B successfully disrupted the phishing-based intrusion, CISA moved to an assume-breach scenario.
This meant the red team received trusted-agent access intended to simulate an attacker who had already achieved a successful foothold.
This was an important test because it prevented the organization from relying solely on its successful phishing detection.
The question became much harder:
Could the defenders still contain an attacker who was already inside?
Privileged Access Was Still Possible
Even with the stronger defensive posture, the red team was able to exploit the same Machine Account Quota weakness.
The operators also recovered cleartext credentials from a Microsoft System Center Configuration Manager file.
They subsequently performed DCSync activity, allowing them to obtain sensitive domain credentials.
This demonstrates an important distinction between vulnerability management and incident response.
Organization B still had weaknesses.
It simply had a SOC capable of detecting and disrupting suspicious activity before those weaknesses automatically translated into total operational control.
The krbtgt Account Raised the Stakes
Among the credentials obtained was the highly sensitive krbtgt account.
This account is central to Kerberos authentication within Active Directory.
If attackers obtain the necessary credentials associated with it, they can potentially abuse Kerberos mechanisms to create forged authentication tickets, commonly referred to as Golden Tickets.
That can provide an attacker with a powerful persistence mechanism.
The presence of this account in the red-team results therefore highlights just how far the simulated attackers were able to progress after being granted assume-breach access.
Yet Organization B still demonstrated that detection and containment could limit the damage.
The OT Environment Added Another Layer of Risk
Organization B’s defenders also isolated a compromised bastion host located in an operational technology demilitarized zone.
That response is particularly important for critical infrastructure.
IT and OT environments cannot always be treated as interchangeable.
A compromised corporate workstation is serious.
A compromised system that provides a bridge toward operational technology can become considerably more dangerous because the consequences may extend beyond data theft into service disruption and physical operations.
The ability to recognize that distinction is a core part of critical infrastructure defense.
Cloud Identity Became Part of the Defense
Organization B also blocked a suspicious Azure sign-in after Microsoft alerting identified the activity.
This illustrates another major shift in modern security operations.
The enterprise perimeter is no longer simply a firewall around an office network.
Identity, cloud applications, endpoints, remote access, SaaS platforms, workload identities, and on-premises infrastructure are increasingly connected.
An attacker moving between these environments can cross boundaries that were never designed to exist in older network models.
Security operations therefore need visibility across all of them.
The Central Lesson: Security Products Do Not Respond by Themselves
The most powerful message in CISA’s assessment may be the simplest.
Buying another security product does not automatically improve security.
A company can deploy EDR, SIEM, identity protection, cloud monitoring, network detection, vulnerability scanners, and threat intelligence feeds and still fail if the people operating those systems cannot work together.
Technology produces signals.
Humans provide interpretation.
Processes provide escalation.
Authority enables action.
Without all four, the security stack can become an expensive collection of disconnected alarms.
Security Teams Need Clear Escalation Paths
An analyst should never have to wonder what happens after discovering suspicious privileged activity.
The organization should already have an answer.
Who owns the system?
Who can authorize isolation?
Who can disable an account?
Who contacts infrastructure teams?
Who handles the cloud environment?
Who makes the business-impact decision?
Who communicates with leadership?
Who coordinates with incident response?
If these questions are answered only during a live attack, the organization is already losing valuable time.
Identity Hygiene Must Become a Security Priority
CISA’s recommendations also emphasize identity configuration.
Organizations should review and restrict unnecessary Machine Account Quota permissions, remediate vulnerable certificate templates, expire old service and cloud credentials, and strengthen controls around workload identities.
These are not glamorous security projects.
They do not generate impressive product announcements.
But they can remove some of the most valuable stepping stones available to attackers.
Conditional Access Is Part of the New Defensive Perimeter
Cloud identities deserve the same attention as traditional domain accounts.
Conditional Access policies can help organizations place additional requirements around authentication based on factors such as user, device, location, application, risk, and other contextual signals.
The objective is not simply to require authentication.
It is to make unauthorized authentication significantly harder and suspicious access easier to identify.
As organizations move more workloads into cloud platforms, identity controls become increasingly important to the overall security architecture.
Service Accounts Deserve Special Attention
Long-lived service credentials are another persistent risk.
Organizations often create service accounts for applications, automation, integrations, and infrastructure and then leave them unchanged for years.
That creates an attractive target.
A credential that works indefinitely provides an attacker with persistence that can survive password changes elsewhere.
Security teams should therefore inventory service accounts, identify ownership, eliminate unnecessary privileges, rotate credentials, and monitor their usage.
Security Operations Should Measure Time, Not Just Alerts
A mature SOC should track more than how many alerts it receives.
It should measure how quickly suspicious activity is detected, investigated, escalated, contained, and resolved.
Metrics such as mean time to detect (MTTD) and mean time to respond (MTTR) can reveal whether a security program actually performs under pressure.
A SOC that closes 99% of alerts but takes hours to contain a confirmed domain compromise has a very different risk profile from a SOC that immediately isolates infected systems.
Speed matters.
Asset Ownership Is a Security Control
CISA’s SCCM example also highlights the importance of asset inventory.
Every critical system should have a known owner.
That owner should understand the system’s purpose, business importance, dependencies, normal behavior, and emergency procedures.
When analysts cannot identify who owns a suspicious server, investigation slows down.
Asset inventory is therefore not merely an IT administration task.
It is part of the organization’s incident-response infrastructure.
Detection Engineering Must Focus on Attack Chains
Individual alerts can be misleading.
A suspicious PowerShell process may be legitimate.
A new computer account may be legitimate.
An unusual authentication event may have an innocent explanation.
But when multiple events appear in sequence, the picture changes.
Security teams should build detections around behavioral chains such as initial access followed by credential access, privilege escalation, lateral movement, and unusual authentication.
Attackers operate in sequences.
Defenders should learn to detect sequences too.
Deep Analysis
Mapping the Attack Path
A useful defensive approach is to visualize the red-team operation as a sequence:
Phishing → Endpoint Compromise → Identity Discovery → Privilege Escalation → Credential Access → Lateral Movement → Domain Compromise → Cloud/OT Access
Each stage represents an opportunity to interrupt the attack.
The objective should not be to build one perfect detection.
The objective should be to create multiple independent opportunities to stop the adversary.
Reviewing Machine Account Quota
Security teams can inspect the current Machine Account Quota configuration with PowerShell:
Get-ADDomain | Select-Object -ExpandProperty ms-DS-MachineAccountQuota
A defensive review should determine whether ordinary users genuinely need the ability to create computer accounts.
If the organization has no legitimate requirement, administrators should evaluate whether reducing the setting is appropriate for their environment.
The exact change should be tested against operational dependencies before deployment.
Auditing Active Directory Certificate Services
Certificate templates should be reviewed for excessive enrollment permissions and dangerous subject or SAN configuration options.
For organizations using Microsoft AD CS, defenders should specifically investigate certificate templates that may permit lower-privileged users to request certificates usable for authentication as more privileged identities.
A useful defensive workflow is:
Enumerate certificate templates
↓
Review enrollment permissions
↓
Review authentication-related EKUs
↓
Check subject/SAN configuration
↓
Remove unnecessary enrollment rights
↓
Monitor certificate issuance
The goal is to reduce opportunities for certificate-based privilege escalation.
Investigating DCSync Indicators
DCSync-related activity should receive high-priority monitoring because legitimate directory replication behavior is generally restricted to specific privileged identities.
Defenders can investigate relevant directory replication permissions and security events using PowerShell and their SIEM.
For example:
Get-ADObject -Filter -SearchBase "CN=Configuration,DC=example,DC=local"
Organizations should replace the example domain with their own environment and use their existing auditing policies and SIEM correlation rules to investigate suspicious replication behavior.
The important point is not simply to search for one event.
It is to correlate the identity performing the activity, the source system, timing, privileges, and surrounding authentication behavior.
Monitoring Suspicious Authentication
For hybrid environments, authentication telemetry should be correlated across on-premises Active Directory and cloud identity systems.
A suspicious sign-in should be evaluated alongside:
User identity
Device identity
Source IP
Authentication method
Location
Risk indicators
Application accessed
Privilege level
Recent password or credential changes
Endpoint security alerts
This context can turn an ambiguous sign-in into a high-confidence incident.
Testing Containment Procedures
Organizations should periodically test whether analysts can actually isolate compromised endpoints.
A tabletop exercise is useful, but technical exercises are even better.
A security team should know:
Example defensive workflow concept
Get-MpComputerStatus
Get-WinEvent -LogName Security -MaxEvents 50
These commands can help establish endpoint protection status and inspect recent Windows security events during an investigation.
The larger question, however, is whether the SOC can move from detection to containment without waiting for multiple layers of approval.
Building a High-Confidence Escalation Model
A mature SOC can establish clear escalation criteria.
For example, suspicious activity involving privileged credentials, domain controllers, certificate authorities, security infrastructure, or OT-connected systems should receive substantially higher priority than an isolated low-confidence endpoint alert.
The precise thresholds should reflect the
The principle is universal:
The more dangerous the potential blast radius, the faster the escalation should occur.
Reduce Alert Noise Before the Next Incident
Security teams should continuously review false positives.
A detection that fires thousands of times without producing meaningful investigations eventually becomes background noise.
That does not mean disabling detections simply because they are inconvenient.
Instead, analysts should tune rules, add contextual enrichment, suppress genuinely benign patterns, and increase severity when multiple suspicious behaviors occur together.
The objective is a SOC where important alerts stand out.
Protect the Protectors
The compromise of SOC personnel’s email and workstations in Organization A should receive special attention.
Security teams are high-value targets because defenders often possess privileged access, sensitive communications, investigation data, and knowledge of security architecture.
SOC accounts should therefore receive strong identity protections.
Privileged administrative work should be separated from normal productivity environments where possible.
Security administrators should use hardened workstations, phishing-resistant authentication, strong privilege controls, and additional monitoring.
The people watching the network must not become the easiest route around it.
What Undercode Say:
Security Is an Operational Discipline
CISA’s assessment is ultimately a story about people and processes as much as technology.
Money Cannot Buy Instant Readiness
A larger cybersecurity budget does not automatically create a better SOC.
More Tools Can Create More Noise
Every additional security platform can produce additional alerts, workflows, and integration requirements.
Visibility Without Action Is Not Defense
Knowing that something suspicious happened is only the beginning.
Context Is the Missing Ingredient
Analysts need to know what the affected system does and why the activity matters.
Asset Ownership Matters
An alert becomes harder to investigate when nobody knows who owns the affected system.
Identity Remains the Prize
Attackers increasingly target identities because identities provide access to everything else.
Active Directory Is Still Critical
Despite the growth of cloud computing, traditional identity infrastructure remains central to many enterprises.
Configuration Weaknesses Can Become Attack Paths
Attackers do not always need sophisticated malware when identity infrastructure is poorly configured.
Phishing Is Still Dangerous
One successful phishing event can create the foothold required for a much larger operation.
Speed Changes the Outcome
Organization B demonstrates how quickly containment can alter an attacker’s options.
Minutes Can Matter More Than Millions
A rapid response can sometimes prevent a compromise from becoming an enterprise-wide incident.
Assume Breach Is Not Just a Slogan
Organizations should test what happens after an attacker is already inside.
Prevention Will Eventually Fail
No defensive control is perfect.
Containment Must Therefore Be Exceptional
The ability to isolate systems quickly is one of the most valuable capabilities a SOC can possess.
Privileged Accounts Need Extra Attention
Credentials associated with domain administration and identity infrastructure should receive enhanced protection and monitoring.
krbtgt Deserves Special Protection
Compromise of the Kerberos trust anchor can create serious persistence risks.
Cloud Identity Is Part of the Attack Surface
Azure and other cloud platforms cannot be treated as separate from the enterprise identity strategy.
OT Requires Additional Caution
An attack that approaches operational technology can carry consequences beyond traditional data loss.
SOCs Need Authority
Analysts cannot respond effectively if every containment action requires excessive approval.
Escalation Paths Must Be Predefined
The incident is the worst possible time to design the response process.
False Positives Have a Cost
Every unnecessary alert consumes attention that could have been spent investigating real malicious activity.
Detection Engineering Should Follow the Attacker
Security teams should think in terms of attack paths rather than isolated indicators.
Correlation Beats Isolation
One suspicious event may be harmless, but several connected events can reveal an intrusion.
Security Teams Need Continuous Testing
An incident-response plan that has never been tested is largely theoretical.
Red Teams Provide Valuable Reality Checks
CISA’s exercise demonstrates what happens when defensive assumptions meet realistic adversary behavior.
Vulnerability Management Is Only One Layer
Fixing weaknesses matters, but organizations also need detection and response capabilities.
Identity Governance Is Cybersecurity
Permissions, service accounts, certificates, and authentication policies are security controls.
Security Architecture Must Include Humans
Technology works through people, and people need clear procedures.
Leadership Should Measure Response Capability
Executives should ask not only what tools the SOC owns, but how quickly it can stop an attacker.
Critical Infrastructure Has Less Room for Error
Government, water, energy, transportation, and other essential sectors face consequences that can extend beyond stolen data.
The Strongest SOC Is Not the One With the Most Dashboards
It is the one that recognizes danger and acts decisively.
Organization B Shows the Better Model
Its defenses were not perfect, but its response prevented weaknesses from becoming unrestricted attacker freedom.
Organization A Shows the Dangerous Alternative
A fragmented SOC can allow an attacker to move freely despite sophisticated security products.
Security Culture Matters
Teams need the confidence to escalate suspicious activity instead of assuming someone else will handle it.
Every Alert Should Have a Destination
If nobody knows who investigates an alert, the alert is already losing value.
Every Critical Asset Should Have an Owner
Ownership creates accountability and accelerates incident response.
Every Privileged Identity Should Have a Story
Security teams should know why it exists, what it can access, and how it is being used.
The Final Lesson Is Simple
CISA’s “A Tale of Two SOCs” is not really about choosing between two organizations.
It is a warning to every organization that believes technology alone is enough.
The strongest security program is the one that combines hardened infrastructure, secure identities, useful telemetry, skilled analysts, clear escalation procedures, rapid containment, and continuous testing.
Because when the attacker finally gets inside, the organization that responds fastest is often the organization that survives the attack with the least damage.
✅ CISA Compared Two Different Defensive Outcomes
The advisory described parallel red-team assessments in which similar attacker tradecraft produced significantly different results.
Organization A allowed the simulated intrusion to progress substantially, while Organization B detected and contained the initial phishing activity rapidly.
✅ Machine Account Quota Was Part of the Attack Path
CISA identified the default Machine Account Quota configuration as one of the weaknesses leveraged during the assessment.
The case demonstrates why seemingly ordinary Active Directory settings deserve security review.
✅ AD CS Misconfiguration Can Create Privilege-Escalation Risk
CISA highlighted vulnerable Active Directory Certificate Services templates, including an ESC1-related configuration issue.
Poorly configured certificate enrollment can create opportunities for attackers to obtain authentication material associated with more privileged identities.
✅ Organization B Demonstrated Effective Containment
The second organization detected the phishing payload and isolated affected systems within roughly two to 20 minutes.
Even after the assessment moved into an assume-breach scenario, defenders continued detecting and disrupting suspicious activity.
✅ CISA’s Main Lesson Goes Beyond Technology
The assessment indicates that Organization A’s primary weakness was operational rather than simply technological.
Poor coordination, excessive alert noise, unclear escalation procedures, and limited authority prevented available security controls from producing an effective response.
Prediction
(+1) More Organizations Will Treat SOC Response Speed as a Core Security Metric
CISA’s findings are likely to push security leaders toward measuring the practical performance of their SOCs rather than focusing exclusively on security-tool deployments.
Organizations will increasingly evaluate how quickly they can identify, escalate, isolate, and investigate a compromised endpoint.
(+1) Identity Configuration Will Receive Greater Attention
Machine Account Quota, AD CS templates, service accounts, privileged identities, and cloud workload identities are likely to receive greater scrutiny as defenders recognize that attackers can exploit legitimate identity mechanisms without relying on traditional malware.
(+1) Assume-Breach Exercises Will Become More Important
Organizations are likely to conduct more exercises in which defenders are deliberately told that an attacker has already obtained access.
That approach provides a much more realistic test of detection, containment, privilege monitoring, and incident-response capabilities.
(+1) Critical Infrastructure Will Prioritize Cross-Domain Monitoring
As IT, cloud, identity, and OT environments become increasingly interconnected, security teams will place greater emphasis on monitoring activity across those boundaries.
The next generation of SOCs will need to understand not just what happens on an endpoint, but how an identity event can affect an entire operational environment.
(+1) The Best Security Programs Will Focus on Breaking Attack Chains
The future of effective defense will not depend on finding one magical detection rule.
It will depend on creating multiple opportunities to stop an attacker—from phishing detection and endpoint isolation to identity controls, privilege monitoring, cloud authentication protection, and OT segmentation.
The most important question after reading CISA’s report is therefore not “How much did we spend on cybersecurity?”
It is:
“If an attacker gets inside our network today, how quickly can we stop them?”
That is the difference between owning security technology and actually being secure.
🕵️📝Let’s dive deep and fact‑check.
🎓 Live Courses & Certifications:
Join Undercode Academy for Verified Certifications
🚀 Request a Custom Project:
Secure, high-velocity infrastructure and disruptive technological engineering. Contact our engineering team for high-tier development and proprietary systems:
[email protected]
💎 Smart Architecture | 🛡️ Secure by Design | ⭐ Trusted by Thousands
References:
Reported By: cyberpress.org
Extra Source Hub (Possible Sources for article):
https://www.instagram.com
Wikipedia
OpenAi & Undercode AI
Image Source:
Unsplash
Undercode AI DI v2
🔐JOIN OUR CYBER WORLD [ CVE News • HackMonitor • UndercodeNews ]
📢 Follow UndercodeNews & Stay Tuned:
𝕏 formerly Twitter 🐦 | @ Threads | 🔗 Linkedin | 🦋BlueSky | 🐘Mastodon | 📺Youtube




