One security operations center stopped CISA’s simulated intrusion within minutes. Another received alerts but largely allowed the attack to continue.
The Cybersecurity and Infrastructure Security Agency disclosed results from red-team assessments of two US critical-infrastructure organizations on Aug. 25. CISA ultimately achieved full domain compromise and reached sensitive business systems and cloud resources at both, but the stronger defender stopped the initial intrusion before testing continued under an assume-breach scenario.
The exercises show how controlled security testing can expose weaknesses beyond the first point of compromise, a concern also examined in recent cybersecurity evaluation environments. CISA’s Aug. 25 advisory describes one organization that struggled to act on endpoint alerts and another that contained the first compromise quickly but still exposed Active Directory and cloud-identity weaknesses once testing resumed.
Why one SOC stopped CISA
CISA assessed an unnamed Government Services and Facilities Sector organization, Organization A, and a Water and Wastewater Systems Sector organization, Organization B.
At Organization A, the red team found a web application using default credentials, sent phishing emails from an internal address, and compromised four workstations. Endpoint detection tools generated alerts, but defenders did not respond effectively. CISA attributed the breakdown partly to alert noise and organizational silos between SOC teams and system owners.
At Organization B, three employees clicked malicious links, and each payload execution triggered a medium-severity EDR alert. SOC staff isolated the affected workstations after about 10, two, and 20 minutes, cutting off CISA’s initial access.
CISA then switched to an assume-breach exercise. Organization B’s IT staff executed a red-team payload on a designated internal host so testing could continue from an attacker’s position inside the network.
At Organization A, CISA exploited the default Machine Account Quota alongside a misconfigured Active Directory Certificate Services template and recovered cleartext database credentials and long-lived AWS IAM credentials.
At Organization B, CISA recovered cleartext credentials for a service account whose excessive AllExtendedRights permission enabled DCSync and ultimately domain compromise. The team also recovered Microsoft identity synchronization credentials and found an application with broad email permissions across the tenant. Similar risks involving cloud application permissions are growing as enterprise workloads gain access to sensitive systems and data.
CISA did not identify a zero-day vulnerability. The weaknesses involved configuration, credentials, and permissions that security teams can audit directly.
What eWeek Found: Fast SOC Response Did Not Close Identity and Cloud Gaps
Organization B provides the strongest comparison. Its SOC isolated all three initially compromised endpoints within 20 minutes or less, forcing the red team off its original attack path. Once testing resumed under assume-breach conditions, identity and cloud configuration still provided routes to privileged systems.
Effective EDR reduced the initial foothold without demonstrating that Active Directory privileges, service accounts, or cloud application permissions were equally hardened. Those controls carry more weight as enterprises introduce AI agents and other non-human identities that can rely on service accounts, API keys, OAuth tokens, or delegated permissions.
CISA found that neither organization used Conditional Access for workload identities. Microsoft says Conditional Access for workload identities can apply location- or risk-based restrictions to organizational service principals.
Organization B showed that rapid containment can stop an initial intrusion without eliminating attack paths available after an adversary obtains a trusted identity or internal foothold. Endpoint response, Active Directory privilege, and cloud identity therefore need to be tested across the same attack chain.
Read more: Critical-infrastructure operators are also weighing how far automated defenses should go, as the UK’s planned AI-powered Cyber Shield puts detection, response authority, and oversight under scrutiny.


