Recent CISA Pen Test Results

BULLETIN #QCC-2026-08

A Tale of Two SOCs

Why Identical Attacks Produced Opposite Outcomes — Lessons from CISA Advisory AA26-237A

Published August 26, 2026  |  Prepared by David L. Biser, Queen City Cyber Consulting

Overview

CISA Advisory AA26-237A describes red team assessments run in parallel against two critical infrastructure organizations: a government services entity (“Org A”) and a water/wastewater operator (“Org B”). Both suffered domain-level compromise and cloud exposure — but their outcomes diverged sharply. Org B detected and isolated the phishing entry point within 2 to 20 minutes. Org A detected nothing, undone by tool sprawl, operational friction, and alert fatigue.

The takeaway for every organization we work with: advanced tooling is not a substitute for identity hygiene, tight egress controls, and an empowered incident response process.

Key Findings

Attack PhaseSecurity GapOperational Impact
Initial AccessDefault admin credentials on exposed web apps; no internal mail filteringDirect phishing foothold on internal workstations
Privilege EscalationMisconfigured AD Certificate Services (ESC1) and default MachineAccountQuotaUnprivileged users forged Domain Admin credentials
Credential StorageCleartext service/database credentials hardcoded in SCCM and configsEnabled DCSync attacks and full krbtgt extraction
Cloud & IdentityOver-permissioned Entra ID service principals; non-expiring AWS keysAdversaries read internal security comms undetected
SOC OperationsHigh false-positive noise, siloed telemetry, undefined asset ownershipGenuine alerts on critical systems were dismissed

Recommended Actions

Queen City Cyber Consulting recommends a phased, risk-prioritized remediation approach:

Phase 1 — Identity & Configuration Hardening  (0–30 Days)

▸  Set ms-DS-MachineAccountQuota to 0 to stop unprivileged machine account creation.

▸  Audit AD CS certificate templates and revoke ESC1-vulnerable ENROLLEE_SUPPLIES_SUBJECT flags.

▸  Revoke non-expiring AWS and Entra ID static keys; move to short-lived tokens and managed identities.

Phase 2 — Architectural Defense & Credential Hygiene  (30–90 Days)

▸  Deploy automated secrets scanning across config repositories and SCCM endpoints.

▸  Enforce zero-trust egress controls on OT, DMZ, and administrative bastions.

▸  Right-size Entra ID application permissions; eliminate tenant-wide mail/directory read access.

Phase 3 — SOC Enablement & Operational Resiliency  (90+ Days)

▸  Tune SIEM/XDR to suppress benign telemetry and reduce analyst alert fatigue.

▸  Set explicit host-isolation SLAs (under 15 minutes) with pre-authorized containment authority for L1/L2 analysts.

Bottom Line

Security resilience is a function of execution, not tool procurement. The organizations that fare best are the ones that pair strong identity hygiene with SOC teams empowered to act fast on what their tools already tell them.

Queen City Cyber Consulting

Need a baseline Active Directory / AD CS posture assessment, or help operationalizing these controls? Reach out — davedoescybersec@gmail.com | (240) 609-9764.

Leave a Reply

Discover more from Dave Does Cyber Security

Subscribe now to keep reading and get access to the full archive.

Continue reading