A Tale of Two SOCs: Insights From Two Red Team Assessments
CISA conducted two simultaneous red team assessments at two organizations and observed different defensive outcomes. In both environments, the red team achieved full domain compromise and accessed sensitive business systems (SBSs) and cloud resources. Organization A faile…
Intelligence analysis by Llama
Two organizations were subjected to a red team assessment by CISA, resulting in different defensive outcomes. Organization A failed to detect the activity, while Organization B quickly identified and isolated the affected systems, forcing the red team into an assume breach model.
Imagine two teams trying to break into a house. One team gets in easily and the other team gets caught quickly. The team that got caught had better security measures in place, which helped them detect and stop the break-in.
Analysis
Red Team Assessments and Defensive Outcomes
The Cybersecurity and Infrastructure Security Agency (CISA) conducted two simultaneous red team assessments at two organizations and observed different defensive outcomes. In both environments, the red team achieved full domain compromise and accessed sensitive business systems (SBSs) and cloud resources. Organization A failed to detect or contain the activity, but Organization B rapidly identified initial compromise attempts, isolated affected systems, and forced the red team into an assume breach model.
Lessons Learned
Untuned detection tools lead to missed threats. Without well-defined baselines and alert filtering, false positives and routine alerts overwhelm network defenders. Organizational silos and bureaucratic hurdles prevent effective incident response. Detection tools are only as effective as the people, processes, and procedures supporting them; fragmented communication, unclear responsibilities, and limited defender authority hinder effective incident response.
Cloud Environments and Unestimated Risks
Cloud environments are often an underestimated risk. Organizations often lack security controls for cloud environments and processes for responding to a cloud compromise. To mitigate this, organizations should establish and regularly review comprehensive procedures for detecting, remediating, and revoking access/refresh tokens in the event of a cloud compromise.
Key Actions
Establish and continuously maintain a baseline and reduce alert noise by fine tuning. Break down silos and empower network defenders. Implement Conditional Access policies for workload identities and monitor for excessive or unused permissions. Establish and regularly review comprehensive procedures for detecting, remediating, and revoking access/refresh tokens in the event of a cloud compromise.
Key points
- Untuned detection tools lead to missed threats.
- Organizational silos and bureaucratic hurdles prevent effective incident response.
- Cloud environments are often an underestimated risk.
- Establish and regularly review comprehensive procedures for detecting, remediating, and revoking access/refresh tokens in the event of a cloud compromise.
If organizations implement the recommendations in this advisory, they can reduce the likelihood and impact of malicious cyber incidents. This can lead to improved detection, response, and protections in IT, cloud, and operational technology (OT) environments.
If organizations fail to implement the recommendations in this advisory, they may experience increased risk of malicious cyber incidents, which can lead to significant financial and reputational losses.



