← CYBERNETICSINTERN.COMCYBERNETIC INTERN
DetectionPostmortem

Two minutes, ten minutes, twenty minutes

CISA red-teamed two organisations at once with the same tradecraft. One never noticed. The other isolated three hosts in minutes off a medium alert.

Researched and drafted with AI assistance, then reviewed and edited by Shreyas Lipare before publication. Every source below was checked against the original.

CISA ran two red team assessments at the same time, against two different organisations, using similar tradecraft [1].

One of them never noticed. The other triaged the alerts and manually isolated three workstations in ten minutes, two minutes and twenty minutes [1].

The organisation that moved in two minutes was a water utility. The one that missed it entirely was a government services organisation. That ordering is the first thing worth sitting with, because it removes the explanation everybody reaches for first.

What happened

CISA published AA26-237A on August 25, 2026, describing two concurrent red team assessments: one at a Government Services and Facilities Sector organisation, called Organization A, and one at a Water and Wastewater Systems Sector organisation, called Organization B [1].

In both environments the red team achieved full domain compromise and reached sensitive business systems and cloud resources [1]. Nobody comes out of this advisory clean.

What differed was whether anyone saw it.

Organization A was phished after the team found a web application with default credentials on built-in accounts, which let them send mail from an internal address [1]. From four workstations they enumerated Active Directory, escalated over the domain, reached three sensitive business systems, and compromised the Microsoft cloud tenant. No defensive intervention at any point [1].

Organization B was phished too, and three users clicked [1]. Each payload generated a medium-severity alert saying that an executable file had loaded an unexpected DLL file. Staff triaged it and isolated all three workstations, terminating the red team’s command and control [1].

Because the foothold was gone, the assessment continued under an assume breach model, with the organisation’s own staff placing the team back on an internal host at equivalent access [1]. The team then escalated, reached sensitive systems, cloud resources and a bastion host in the OT demilitarised zone, where defenders detected them and isolated that system too [1].

So Organization B did not win. It was compromised as thoroughly as the other one. It just kept noticing.

Why this matters

Both organisations had endpoint detection, and both produced alerts. This is the finding that should unsettle people. Organization A’s SOC received medium and low severity EDR alerts corresponding to red team activity and did not respond to them [1]. The tooling worked. The alerts fired. Nothing happened next.

The noise was ranked above the signal. CISA states that thousands of false positives corresponding to normal business operations, many at higher severity, obscured the alerts triggered by red team activity [1]. That is worse than volume alone. The queue was actively sorted so that routine business noise sat above a live intrusion, which means more analysts working that queue would still have started at the wrong end.

The organisational failure is described in unusual detail. Organization A ran multiple SOCs and multiple EDR products. Staff did not communicate with other SOCs or have visibility into their detection tools, and SOC staff and system owners did not talk to each other [1]. In one exchange the red team recovered, defenders tried and failed to work out who owned an SCCM system and what it did, and eventually closed the alert as a false positive [1].

CISA’s read is that the SOC lacked standard operating procedures for escalating alerts and had limited personnel authority [1]. That is the red team’s belief rather than an audited finding, and the advisory says so.

The red team read the SOC’s email to see if the SOC knew. After compromising the cloud tenant they impersonated an application to retrieve messages, moved laterally to SOC workstations, took screenshots, ran keyloggers and pulled Teams messages [1]. They were watching the defenders decide not to act.

Technical breakdown

The route through Organization A is worth reading as a chain, because most of it is configuration rather than exploitation. There is not a single CVE in it.

ATTACK CHAIN
  1. ReconnaissanceA web application is found with default credentials on built-in accounts, allowing mail to be sent from an internal address
    BREAK THE CHAIN HERE
    Change default credentials on every application, including the built-in accounts nobody uses. Alert on mail submitted by application service accounts, which almost never legitimately send to staff.
  2. Initial accessPhishing from that internal address lands on workstations, and the payload generates a medium-severity endpoint alert
    BREAK THE CHAIN HERE
    This is where the second organisation stopped it. The alert was stock EDR output about an executable loading an unexpected DLL. Isolation in single-digit minutes needs an analyst with authority to act, not a better rule.
  3. DiscoveryA modified directory collector, tuned to avoid static endpoint signatures, enumerates users, groups, computers, group policy objects and access control lists
  4. Privilege escalationThe default machine account quota permits unprivileged users to add machine accounts, and a misconfigured certificate template issues certificates on behalf of other accounts
    BREAK THE CHAIN HERE
    Set the machine account quota to zero and delegate machine joins explicitly. Audit certificate templates for the enrollment misconfigurations that let low-privileged users request certificates for others, and alert on certificate requests naming a subject other than the requester.
  5. Credential accessCleartext credentials are recovered from files on administrator workstations, from developer tool configuration, and from cloud keys that were never set to expire or rotate
  6. Lateral movementTooling is proxied through compromised workstations to reach the sensitive business systems
  7. Cloud compromiseAn Entra ID application holding Application permissions is targeted, because those permissions operate outside the conditional access policies that govern users
    BREAK THE CHAIN HERE
    Apply Conditional Access for workload identities to service principals you own, and review applications holding high-privilege Graph permissions. Microsoft notes this needs Workload Identities Premium licensing and does not cover managed identities or multitenant apps.
  8. Defence evasionSOC mailboxes, chat messages and workstations are monitored to confirm defenders have not reacted
  9. ImpactFull domain compromise, access to sensitive business systems, and control of cloud resources

The cloud step deserves its own paragraph

The red team went after applications rather than users. Entra ID applications granted Application permissions can act without user consent, and they sit outside traditional conditional access, which governs people [1]. Compromise the application and you inherit its permissions.

Microsoft publishes the control for this. Conditional Access for workload identities extends policy to service principals owned by the organisation, and can block them from outside known IP ranges or on detected risk [2]. CISA’s observation is blunt: the red team has never observed an organisation using it [1].

I went to check why that might be, and Microsoft’s own documentation supplies part of the answer. The capability requires Workload Identities Premium licensing, applies only to single-tenant service principals registered in your own tenant, and does not cover managed identities or multitenant applications [2]. A policy assigned to a group containing a service principal is not enforced; the principal has to be assigned directly [2].

None of that makes the recommendation wrong. It does mean “just turn it on” is a procurement conversation and a per-principal exercise, which is a reasonable guess at why nobody has.

What defenders should do Monday morning

Immediate, within 24 hours. Answer one question honestly: if a medium-severity EDR alert fired right now on a user workstation, how long until a human read it, and does that human have the authority to isolate the host without asking permission? Organization B’s entire advantage was measured in minutes, and both halves of that question have to be yes for the minutes to exist.

Near term, this week. Check your machine account quota and set it to zero unless something genuinely depends on it. Audit certificate templates for the enrollment misconfiguration that lets a low-privileged account request certificates on behalf of others, which is the escalation path in this advisory and is common enough that CISA treats it as expected. Then look at your alert queue’s ordering rather than its size: if routine business noise outranks endpoint alerts on user workstations, fix the ranking before you hire. The fifth check in the detection audit is this exact question, and it takes an afternoon on twenty recent alerts.

Structural, this quarter. Two things, both organisational. Write down who may isolate a host, and make sure that person is on shift rather than reachable by escalation. Then find the systems nobody can identify. Organization A’s SOC closed a real alert as a false positive because nobody could establish what the system was for [1], and every estate has a list of hosts that would produce the same conversation. On the cloud side, inventory applications holding high privilege Graph permissions and decide whether Conditional Access for workload identities is worth the licence.

Checklist

  • Time measured from alert to human eyes on a medium-severity endpoint alert
  • Named role with standing authority to isolate a host, on shift, without escalation
  • Alert queue ordering reviewed so business noise does not outrank endpoint alerts
  • Machine account quota set to zero unless a documented need exists
  • Certificate templates audited for enrollment misconfigurations
  • Alerting on certificate requests naming a subject other than the requester
  • Workstations swept for cleartext credentials in files and developer tool configuration
  • Cloud access keys given expiry and rotation
  • Entra ID applications with high-privilege Graph permissions inventoried
  • Conditional Access for workload identities evaluated, including its licensing
  • Unidentifiable systems catalogued so an alert on one does not stall

The thing that was missing was permission

The comfortable reading of this advisory is that Organization A needed better tooling. It did not. It had more tooling than Organization B, across multiple SOCs and multiple EDR products, and that turned out to be part of the problem rather than the answer to it.

What Organization B had was a person who read a medium-severity alert and pulled a workstation off the network inside two minutes, without convening anything.

Our industry has spent a decade buying detection and almost nothing on the authority to act on what it detects. The budget line for a new sensor is easy to defend. The budget line for an analyst who can unilaterally disconnect a director’s laptop at eleven at night does not exist, because it is not a product, and because the first time it is used badly somebody senior is annoyed.

CISA’s version of this is drier: detection tools are only as effective as the people, processes and procedures supporting them [1]. Read against the two timelines in this advisory, that sentence has teeth. One organisation’s tools found the intrusion and told nobody who could act. The other’s found it and somebody pulled the plug.

FREQUENTLY ASKED

Did Organization B actually stop the red team?
No, and the advisory is clear about it. Detection twice forced the team to restart rather than defeated them. After defenders removed the initial foothold, the organisation's own staff deliberately placed the red team back on an internal host to continue the assessment, and from there the team reached sensitive systems, cloud resources and a bastion host in the OT DMZ, where defenders detected and isolated them again. Both organisations were fully compromised. Only one of them saw it happening.
What alert did Organization B actually act on?
A medium-severity EDR alert reading that an executable file loaded an unexpected DLL file. That is not an exotic detection or a custom rule. It is stock endpoint tooling doing an ordinary job, and the entire difference between the two organisations was that somebody read it and had the authority to pull the plug.
We have more alerts than Organization A did. Is this just a resourcing problem?
Partly, but the advisory points somewhere more specific. Organization A's true positives were medium and low severity while thousands of false positives sat above them at higher severity. That is a tuning and severity problem rather than a headcount problem: the ranking actively pushed the real events downward. More analysts triaging a badly ordered queue would still have started at the wrong end.
Why did the cloud half of the attack work?
The red team targeted Entra ID applications holding Application permissions, which operate outside the conditional access policies that govern user access. Microsoft publishes a control for exactly this, Conditional Access for workload identities, and CISA notes the red team has never observed an organisation using it. Worth knowing before you plan it: Microsoft's documentation states it needs Workload Identities Premium licensing and does not cover managed identities or multitenant apps.
Is any of this specific to government or water utilities?
No. The failures named are default machine account quota, misconfigured certificate templates, cleartext credentials in files on workstations, cloud keys that never rotate, and a SOC without escalation authority. Every one of those is available in any Active Directory estate with a Microsoft cloud tenant, which is most of them.

REFERENCES

  1. [1]A Tale of Two SOCs: Insights From Two Red Team Assessments (AA26-237A)Cybersecurity and Infrastructure Security Agency (CISA) · Published August 25, 2026 · Accessed August 28, 2026PRIMARY
  2. [2]Microsoft Entra Conditional Access for workload identitiesMicrosoft · Accessed August 28, 2026PRIMARY

BEFORE YOU GO

Was this useful?

Tell me what you'd change, what was unclear, or what you'd want covered next. Replies shape what gets written.

SEND FEEDBACK ↗

The newsletter

Follow along

Notes between posts, and whatever I'm breaking in the lab.

LINKEDIN ↗