CISA's 'A Tale of Two SOCs' Highlights Critical SOC Gaps

CISA Red Team Exercise Reveals Stark Gaps in Security Monitoring

MEDIUM
August 30, 2026
4m read
Security OperationsIncident ResponseThreat Intelligence

Related Entities

Products & Tech

Active Directory Certificate ServicesEntra ID

Full Report

Executive Summary

The U.S. Cybersecurity and Infrastructure Security Agency (CISA) has published an advisory, "A Tale of Two SOCs" (AA26-237A), detailing the results of two parallel red team exercises against critical infrastructure organizations. The report serves as a powerful case study on the difference between having security tools and having effective security operations. One organization, a water utility, demonstrated a mature defensive posture by rapidly detecting and containing the CISA red team. The other, a government services entity, was completely compromised without generating a single alert, blinded by thousands of false positives from poorly configured tools. The findings provide crucial lessons for all organizations on the importance of security operations maturity.

Incident Timeline

The advisory details two concurrent but separate red team engagements.

Organization A: Government Services and Facilities Sector

  • Initial Access: The CISA red team exploited default credentials on a web application.
  • Execution & Persistence: They used this access to send an internal phishing email, compromising four workstations. They established persistence by abusing misconfigured Active Directory Certificate Services (AD CS) templates, a technique similar to 'Certighost'.
  • Discovery & Lateral Movement: The team found cleartext credentials, including static Amazon Web Services (AWS) access keys, on file shares. This allowed them to move laterally to business-critical systems and cloud resources.
  • Defense Evasion: The red team gained access to the security team's email inbox to monitor for detection but found no signs of their activity being noticed.
  • Outcome: Total Failure of Detection. The organization's Security Operations Center (SOC) was overwhelmed with thousands of false-positive alerts from misconfigured tools, which completely masked the real, sophisticated intrusion. The red team achieved all its objectives, including domain-level compromise.

Organization B: Water and Wastewater Systems Sector

  • Initial Access: The CISA red team attempted to gain initial access using similar TTPs.
  • Detection & Response: The organization's SOC detected the initial access attempts within one hour.
  • Containment: The SOC team correctly identified the access vector, isolated the affected systems, and began remediation procedures.
  • Outcome: Successful Defense. The red team was unable to achieve its objectives. The SOC's quick and effective response neutralized the threat before any significant impact could occur.

Technical Findings

The primary technical gap at Organization A was not a lack of tools, but a failure to properly implement and manage them. The SOC was effectively non-functional due to alert fatigue. Key misconfigurations included:

  • Default Credentials: A simple but high-impact failure.
  • AD CS Misconfiguration: A common but complex vulnerability that allows for privilege escalation.
  • Credential Storage: Storing credentials and access keys in cleartext on file shares.

In contrast, Organization B demonstrated effective use of its security stack, with well-tuned alerts, clear escalation procedures, and an empowered team capable of taking decisive action.

Detection & Response

The report emphasizes that effective detection and response is a combination of people, process, and technology:

  1. Alert Tuning: Security tools must be tuned to reduce false positives, allowing analysts to focus on real threats. This is a crucial aspect of implementing D3FEND's detection techniques like D3-PA - Process Analysis.
  2. Hypothesis-Driven Hunting: Instead of passively waiting for alerts, mature SOCs actively hunt for threats based on intelligence and hypotheses about attacker behavior.
  3. Integrated Tooling: A well-integrated security stack (e.g., EDR, NDR, SIEM) provides a holistic view, making it easier to connect disparate events into a coherent attack chain.

Lessons Learned

  • Technology is Not a Panacea: Owning security tools is meaningless if they are not properly configured and monitored by a skilled team.
  • Alert Fatigue is a Threat: An overwhelming volume of low-fidelity alerts is as dangerous as no alerts at all, as it desensitizes analysts and hides real attacks.
  • Fundamentals Matter: Failures in basic cybersecurity hygiene, such as managing default credentials and securing secrets, provide easy entry points for attackers.

Mitigation Recommendations

Based on the findings, CISA recommends that organizations:

  1. Invest in People and Process: Prioritize hiring, training, and retaining skilled security analysts. Develop and drill clear incident response playbooks.
  2. ** Harden Active Directory:** Specifically audit and correct AD CS misconfigurations and other common AD vulnerabilities.
  3. Implement Secrets Management: Eliminate the storage of cleartext credentials. Use secure vaults for managing passwords, API keys, and other secrets.
  4. Conduct Adversary Emulation: Regularly test defenses with red team exercises or breach and attack simulation (BAS) tools to identify gaps in a controlled manner.

Timeline of Events

1
August 25, 2026
CISA releases advisory AA26-237A, 'A Tale of Two SOCs', detailing the red team findings.
2
August 30, 2026
This article was published

MITRE ATT&CK Mitigations

Audit

M1047enterprise

Regularly audit and tune security alerts to reduce false positives and ensure real threats are visible.

Harden Active Directory and AD CS configurations to prevent common privilege escalation techniques.

Implement secrets management solutions to avoid storing credentials in cleartext.

Conduct regular adversary emulation exercises (e.g., red teaming) to test and validate security controls and SOC responsiveness.

Timeline of Events

1
August 25, 2026

CISA releases advisory AA26-237A, 'A Tale of Two SOCs', detailing the red team findings.

Sources & References

Article Author

Jason Gomes

Jason Gomes

• Cybersecurity Practitioner

Cybersecurity professional with over 10 years of specialized experience in security operations, threat intelligence, incident response, and security automation. Expertise spans SOAR/XSOAR orchestration, threat intelligence platforms, SIEM/UEBA analytics, and building cyber fusion centers. Background includes technical enablement, solution architecture for enterprise and government clients, and implementing security automation workflows across IR, TIP, and SOC use cases.

Threat Intelligence & AnalysisSecurity Orchestration (SOAR/XSOAR)Incident Response & Digital ForensicsSecurity Operations Center (SOC)SIEM & Security AnalyticsCyber Fusion & Threat SharingSecurity Automation & IntegrationManaged Detection & Response (MDR)

Editorial Standards & Analyst Review

CyberNetSec.io uses automation to assist source monitoring, deduplication, observable extraction, and structured intelligence generation. Published analysis follows human-defined editorial standards and adds defensive context including MITRE ATT&CK, D3FEND, STIX, and Sigma where applicable. Read our editorial policy.

Tags

cisared teamsocsecurity operationsincident responsealert fatigueactive directory

📢 Share This Article

Help others stay informed about cybersecurity threats

🎯 MITRE ATT&CK Mapped

Every tactic, technique, and sub-technique used in this threat has been identified and mapped to the MITRE ATT&CK framework for consistent, actionable threat language.

🧠 Enriched & Analyzed

Observables and indicators of compromise (IOCs) have been extracted and cataloged. Risk has been assessed and correlated with known threat actors and historical campaigns.

🛡️ Actionable Guidance

Detection rules, incident response steps, and D3FEND-aligned mitigation strategies are included so your team can act on this intelligence immediately.

🔗 STIX Visualizer

Structured threat data is packaged as a STIX 2.1 bundle and can be visualized as an interactive graph — relationships between actors, malware, techniques, and indicators.

Sigma Generator

Sigma detection rules are derived from the threat techniques in this article and can be converted for deployment across any major SIEM or EDR platform.