CISA Red Team Owned Two Critical Infrastructure Networks. One SOC Saw Nothing
- The Mess: CISA ran simultaneous red-team assessments against two critical-infrastructure organizations using similar attack techniques. In both cases, the red team ultimately reached full domain compromise, sensitive business systems and cloud resources. The difference was brutal: one SOC detected the initial intrusion and contained it quickly; the other failed to recognize the compromise and the attackers moved through the environment largely undetected.
This wasn’t a theoretical exercise.
CISA was inside the networks.
The initial access came through spearphishing. From there, the red team worked through compromised workstations, escalated privileges and moved laterally.
In Organization A, the defenders essentially lost the race.
CISA reached elevated domain privileges, sensitive systems and cloud resources without being stopped. The red team even observed security alerts reaching the SOC, but the organization failed to respond effectively. Thousands of false positives and organizational silos helped bury the useful signals.
That’s the ugly reality of security monitoring.
You can have EDR.
You can have SIEM.
You can have dashboards.
You can have a wall full of alerts.
And still miss the attacker.
Organization B had a very different outcome.
The SOC detected the initial compromise and quarantined affected workstations within 2, 10 and 20 minutes. CISA then switched to an “assume breach” scenario to continue testing what could happen after defenders had detected the intrusion.
The red team still reached sensitive business systems, cloud resources and an OT DMZ host during the controlled exercise.
But the defenders kept forcing them to operate under pressure.
That’s a massive difference.
- The Damage: The assessment shows that attackers can move from a single phishing foothold to domain compromise, cloud access and sensitive operational systems when detection and identity controls fail.
The really interesting part isn’t the phishing.
Everyone knows phishing works.
The problem is what happens afterward.
CISA identified weaknesses around Active Directory, cloud identities, Conditional Access and token revocation. Neither organization was using Conditional Access for workload identities, and neither had effective processes for revoking compromised access and refresh tokens.
That’s a nasty combination.
An attacker compromises a workstation.
Gets credentials.
Moves laterally.
Finds privileged identities.
Then moves into cloud infrastructure.
At that point, having a strong endpoint security product isn’t enough.
The attacker is abusing legitimate identities.
The computer isn’t necessarily screaming “malware.”
The attacker may simply look like another user with too many permissions.
And once they control the identity layer, the cloud becomes another playground.
This is why the difference between the two organizations matters so much.
Organization B wasn’t magically immune.
The red team still got in.
Its advantage was much simpler:
someone noticed.
Then someone acted.
That’s what stopped the simulated attack from becoming a quiet domain takeover.
- The Fix: Reduce alert noise, enforce Conditional Access for workload identities, establish rapid token/session revocation procedures, segment sensitive systems, and make SOC detection-to-isolation response measurable in minutes rather than hours.
CISA’s recommendations are not exotic.
They are mostly about doing the boring security work properly.
Tune detections.
Remove useless alerts.
Know which identities have privileged access.
Monitor cloud authentication.
Protect service principals.
Revoke compromised sessions quickly.
Separate critical systems from ordinary user networks.
And test it.
Not with a checklist.
With an actual red team.
Because a security control that exists on paper but doesn’t trigger a response is decoration.
The assessment also exposed a major cloud problem.
Organizations can have mature endpoint monitoring and still have weak cloud identity controls.
That gap is becoming more important as attackers move between on-premises Active Directory and cloud environments.
The perimeter isn’t disappearing.
It’s multiplying.
Bugstoday Opinion
This might be more useful than another CVE with a scary number.
CISA effectively ran the same experiment twice.
Two organizations. Similar attackers. Similar tradecraft. Completely different defensive outcomes.
One SOC saw the intrusion and started throwing sand into the gears.
The other watched alerts accumulate while the attacker walked toward domain compromise.
That’s the uncomfortable lesson.
Detection isn’t security. Response is security.
An alert sitting unread in a SIEM doesn’t stop an attacker.
An EDR notification nobody investigates doesn’t stop an attacker.
A perfect dashboard doesn’t stop an attacker.
A person who sees the signal, understands it and quarantines the machine in minutes?
That can.
Bugstoday verdict: the attacker doesn’t need to be invisible. Sometimes they just need your SOC to be too busy to notice.




