Executive Summary
CISA conducted simultaneous red team assessments at two organizations in August 2026, revealing stark differences in defensive capabilities. Both organizations suffered full domain compromise and sensitive business system access, but Organization A failed to detect any malicious activity while Organization B rapidly identified and contained threats within 2-20 minutes. The assessments exposed critical gaps in cloud security, Active Directory configurations, and incident response processes across both critical infrastructure entities.
This incident highlights the growing sophistication of identity-based attacks and the urgent need for organizations to mature their cloud security postures as threat actors increasingly target hybrid environments and exploit authentication mechanisms like Entra ID and AWS IAM.
Why This Matters Now
With ransomware groups like Salt Typhoon and Medusa increasingly targeting cloud identities and hybrid environments, organizations must urgently address detection gaps and cloud security misconfigurations before attackers exploit these same techniques in real-world scenarios.
Attack Path Analysis
The red team compromised both organizations through phishing and web application default credentials, escalated privileges via Active Directory misconfigurations (ADCS templates, Machine Account Quota), moved laterally through SCCM servers and compromised credentials, established command and control through proxied traffic and cloud token abuse, exfiltrated data via email access and credential harvesting, and achieved full domain compromise with potential for operational disruption.
Kill Chain Progression
Initial Compromise
Description
Red team gained initial access through phishing emails and web application with default credentials, compromising multiple workstations in both organizations
MITRE ATT&CK® Techniques
Phishing
OS Credential Dumping: DCSync
Create Account: Domain Account
Unsecured Credentials: Credentials In Files
Use Alternate Authentication Material: Application Access Token
Cloud Service Discovery
Email Collection
Steal or Forge Authentication Certificates
Potential Compliance Exposure
Mapping incident impact across multiple compliance frameworks.
PCI DSS 4.0 – Strong Authentication for Access to Cardholder Data Environment
Control ID: 8.2.1
NYDFS 23 NYCRR 500 – Multi-Factor Authentication
Control ID: 500.12
CISA ZTMM 2.0 – Application Security
Control ID: M4
DORA – ICT Risk Management Framework
Control ID: Article 11
NIS2 Directive – Cybersecurity Measures
Control ID: Article 21
ISO 27001:2022 – Management of Privileged Access Rights
Control ID: A.9.2.3
Sector Implications
Industry-specific impact of the vulnerabilities, including operational, regulatory, and cloud security risks.
Government Administration
Red team assessments reveal critical vulnerabilities in SOC operations, Active Directory configurations, and cloud security controls affecting government IT infrastructure and sensitive systems.
Utilities
Water/wastewater sector faces elevated risks from IT-OT lateral movement, bastion host compromises, and inadequate segmentation between operational technology and enterprise networks.
Financial Services
Banking systems vulnerable to privilege escalation, encrypted traffic interception, and cloud application abuse requiring enhanced zero trust segmentation and anomaly detection capabilities.
Health Care / Life Sciences
Healthcare organizations at risk from east-west traffic exploitation, HIPAA compliance gaps, and inadequate egress security controls enabling potential patient data exfiltration.
Sources
- A Tale of Two SOCs: Insights From Two Red Team Assessmentshttps://www.cisa.gov/news-events/cybersecurity-advisories/aa26-237aVerified
- CISA Cross-Sector Cybersecurity Performance Goalshttps://www.cisa.gov/cross-sector-cybersecurity-performance-goalsVerified
- MITRE ATT&CK Matrix for Enterprisehttps://attack.mitre.org/matrices/enterprise/Verified
- Microsoft Entra ID Authentication Documentationhttps://docs.microsoft.com/en-us/azure/active-directory/authentication/Verified
- CISA Secure Cloud Business Applications (SCuBA) Projecthttps://www.cisa.gov/scubaVerified
Frequently Asked Questions
Cloud Native Security Fabric Mitigations and ControlsCNSF
Aviatrix Zero Trust CNSF would have significantly reduced the blast radius of this multi-stage red team operation by implementing microsegmentation and controlling east-west traffic flows. The segmented architecture would likely have constrained lateral movement between compromised systems and limited the scope of privilege escalation across both organizations.
Control: Cloud Native Security Fabric (CNSF)
Mitigation: Initial workstation compromises would likely have been contained within isolated network segments, reducing the attacker's ability to enumerate and access additional systems across the infrastructure
Control: Zero Trust Segmentation
Mitigation: Zero trust segmentation would likely have constrained the scope of privilege escalation by limiting service account access to specific network segments and reducing the reach of compromised credentials
Control: East-West Traffic Security
Mitigation: East-west traffic controls would likely have blocked or restricted unauthorized communication paths between SCCM servers, virtual desktops, and workstations, significantly limiting the attacker's lateral movement capabilities
Control: Multicloud Visibility & Control
Mitigation: Multicloud visibility controls would likely have detected and constrained unauthorized cloud application access patterns and suspicious SSO authentication flows across hybrid environments
Control: Egress Security & Policy Enforcement
Mitigation: Egress security policies would likely have detected and blocked large-scale data transfers from email systems and database servers, reducing the volume of sensitive information successfully exfiltrated
The overall organizational impact would likely have been significantly reduced, with attackers constrained to specific network segments rather than achieving full domain compromise and OT environment access
Impact at a Glance
Affected Business Functions
- IT Security Operations
- Critical Infrastructure Operations
- Sensitive Business Systems
- Cloud-based Services
Estimated downtime: N/A
Estimated loss: N/A
Red team demonstrated ability to access sensitive business systems including databases, automated processing systems, email communications of security operations center staff, Microsoft Teams messages, and cloud resources. In Organization B, access to operational technology network visibility was achieved through bastion hosts.
Recommended Actions
Key Takeaways & Next Steps
- • Implement Zero Trust Segmentation with least privilege policies to prevent lateral movement between workstations and critical systems like SCCM
- • Deploy Egress Security & Policy Enforcement to block unauthorized outbound traffic and detect data exfiltration attempts to external destinations
- • Enable Multicloud Visibility & Control with centralized policy management to detect anomalous cloud application activities and excessive permission usage
- • Establish East-West Traffic Security monitoring to identify and block lateral movement patterns between internal network segments
- • Implement Encrypted Traffic (HPE) controls for data in transit protection and deploy Threat Detection & Anomaly Response capabilities for real-time monitoring of credential abuse and privilege escalation attempts



