A Tale of Two SOCs: Insights From Two Red Team Assessments
Two separate red team assessments at a Government Services and Facilities Sector organization (Organization A) and a Water and Wastewater Systems Sector organization (Organization B) revealed significant vulnerabilities and a lack of effective response. Organization A’s red team gained persistent access to the network by exploiting default credentials, misconfigured Active Directory Certificate Services (ADCS) templates, and leveraging Application permissions within Microsoft Entra ID. They were able to compromise SOC personnel by accessing emails and capturing screenshots. Organization B detected the initial compromise and moved to a ‘assume breach’ model, but still encountered defensive measures and ultimately gained access to SBSs and cloud resources, including accessing virtual desktops and leveraging long-lived AWS credentials. The assessments highlight the need for organizations to strengthen their defenses against credential abuse, improve Active Directory security, implement Conditional Access for workload identities, and enhance their incident response capabilities.
Summary written automatically in our own words from the original article, which belongs to its publisher and remains the reference. It may contain errors. Sources & data