Ep. 76 - A Tale of Two SOCs: Invisible in One Network, Caught in 10 Minutes in the Other

CISA's own red team ran two critical-infrastructure assessments at once — and got opposite results. Host Tova Dvorin and SafeBreach offensive security engineer Adrian Culley break down advisory AA26-237A: how an ESC1 certificate template flaw and a default machine account quota chained into full domain compromise, why one SOC isolated three infected workstations in 10 minutes while the other never noticed, and the cloud identity gaps both organizations shared.

Timestamps:

00:00 What Can We Learn From CISA’s Tale of Two SOCs?

02:45 How Did Active Directory Misconfigurations Lead to Domain Compromise?
Default machine-account settings and a weak certificate template let the attackers escalate from a basic user account to domain-wide access.

06:10 How Did Cloud Identity Become the Weak Link?

09:14 What Did Organization B Get Right?

10:12 Where Did Organization B Still Fall Short?

14:35 What Are the Biggest Lessons From Both Assessments?

16:20 What Should Security Leaders Do First?

18:17 Why Does Continuous Validation Matter?

Read our full coverage and see how SafeBreach maps 26 existing simulations to this:
https://www.safebreach.com/blog/safebreach-coverage-for-cisa-advisory-aa26-237a-two-socs/

#cybersecurity #infosec #CISO #CISA #ActiveDirectory #CriticalInfrastructure #RedTeam #BAS