The U.S. Cybersecurity and Infrastructure Safety Company (CISA) has revealed the outcomes of two purple crew assessments it carried out concurrently towards two vital infrastructure organizations, utilizing what it described as comparable tradecraft whereas recording sharply completely different defensive outcomes.
Each organizations had been totally compromised on the area degree, and in each, the purple crew additionally reached delicate enterprise techniques (SBSs) and cloud sources.
The advisory, tracked as AA26-237A and titled “A Story of Two SOCs,” was launched on August 25, 2026. CISA recognized the primary goal solely as a Authorities Providers and Amenities Sector group, known as Group A, and the second as a Water and Wastewater Methods Sector entity, known as Group B.
“CISA carried out two simultaneous purple crew assessments utilizing comparable tradecraft however noticed completely different defensive responses,” the company mentioned within the advisory.
Towards Group A, the purple crew gained preliminary entry after figuring out an online utility with default credentials for a number of built-in accounts, which allowed it to ship phishing emails from an inside deal with and land on 4 workstations.
It then escalated privileges by abusing a default Machine Account Quota alongside a misconfigured Energetic Listing Certificates Providers (AD CS) template, the identical class of certificate-template abuse behind a recently disclosed domain-takeover exploit referred to as Certighost.
The crew went on to entry three delicate enterprise techniques utilizing credentials saved in cleartext, together with decrypted database configuration information and static Amazon Net Providers (AWS) entry keys set by no means to run out.
Within the cloud, it stole a Primary Refresh Token and abused Entra ID functions carrying elevated permissions to learn the safety crew’s e mail and test whether or not defenders had been conscious of the exercise.
Group A didn’t detect any of it. CISA mentioned 1000’s of false-positive alerts from regular enterprise operations, many rated at increased severity, obscured the alerts the purple crew generated, and that the group ran a number of safety operations facilities (SOCs) and endpoint instruments with no shared visibility between them.
Analysts additionally lacked escalation procedures and had restricted authority to behave, and an actual alert tied to purple crew exercise on a System Heart Configuration Supervisor (SCCM) server was dismissed as a false constructive after defenders couldn’t establish the system’s proprietor.
CISA flagged the next weaknesses as the principle enablers of the compromise –
- Machine Account Quota left on the default, letting any area person add machine accounts.
- AD CS certificates templates had been misconfigured, permitting certificates requests for any person (ESC1).
- Cleartext credentials for service and database accounts saved on reachable techniques.
- Static cloud entry keys set by no means to run out, with no token revocation in place.
- Over-permissioned functions in Entra ID capable of learn mail throughout all customers.
Group B, operating the identical type of assault towards it, instructed a distinct story. Its SOC detected the preliminary phishing payloads as every executed and remoted the affected workstations inside 2 to twenty minutes, chopping off command-and-control (C2) communications earlier than the intrusion may unfold.
As a result of that foothold was severed, CISA’s trusted brokers on the group executed a purple crew payload on a chosen non-privileged host to duplicate the entry the crew would in any other case have obtained, shifting the engagement to an assume-breach mannequin.
From there, the crew discovered the identical underlying issues, together with cleartext credentials for a website service account in an SCCM configuration file that carried rights over a website controller, which it used to run a DCSync assault and retrieve the krbtgt secret.
The crew additionally reached a bastion host in Group B’s operational expertise (OT) demilitarized zone, however the host blocked outbound web entry, so no C2 channel was established, and the crew didn’t enter the OT techniques themselves.
CISA attributed the hole between the 2 outcomes to the people and processes working the instruments, slightly than the instruments themselves.
“Detection instruments are solely as efficient because the folks, processes, and procedures supporting them,” the company mentioned.
