CISA Red Team Fully Compromises Two Critical Infrastructure Orgs via ADCS ESC1 and AzureHound Cloud Enumeration (AA26-237A) — Threadlinqs Intelligence
As of 2026-08-26, CISA Red Team Fully Compromises Two Critical Infrastructure Orgs via ADCS ESC1 and AzureHound Cloud Enumeration (AA26-237A) is a high-severity vulnerability threat attributed to CISA Red Team, tracked by Threadlinqs Intelligence with 9 detection rules (Splunk SPL, Microsoft KQL, Sigma) and 10 indicators of compromise.
Threat ID: TL-2026-2161 · Severity: HIGH · Status: ACTIVE · Category: VULNERABILITY
Attribution: CISA Red Team · UNKNOWN
CISA advisory AA26-237A, "A Tale of Two SOCs," documents two simultaneous authorized red team assessments — one against a Government Services and Facilities Sector organization, one against a Water
On 2026-08-25, CISA published AA26-237A, comparing two concurrent red team assessments run with the same tradecraft against critical infrastructure organizations to illustrate how detection maturity — not tooling — determines outcome.
Against Organization A (Government Services and Facilities Sector), the red team found a web application still using default credentials for built-in accounts, used that foothold to send phishing emails from a trusted internal address, and landed payloads on four workstations. From there it abused the domain's default Machine Account Quota (MAQ) to add unauthorized machine accounts, then exploited an ESC1-class misconfiguration in Active Directory Certificate Services — templates with `CT_FLAG_ENROLLEE_SUPPLIES_SUBJECT` enabled and client-authentication EKUs — to request certificates impersonating privileged accounts. The team recovered cleartext database and service credentials from configuration files (including a `connections.json`-style file) and long-lived, non-expiring static AWS IAM access keys, then pivoted to the cloud by harvesting a Primary Refresh Token and abusing over-permissioned Entra ID applications, ultimately reading mail across the tenant. The SOC never detected any of it: staff were buried under thousands of false-positive alerts (many scored higher-severity than the actual intrusion), multiple siloed SOCs ran different EDR stacks with no shared visibility, and there were no written escalation procedures. The red team confirmed the miss by reading the defenders' own SOC email.
Against Organization B (Water and Wastewater Systems Sector), the same phishing payload was detected on execution and the affected workstations were isolated within 2-20 minutes, cutting off C2 before the intrusion could spread — so the engagement shifted to an assume-breach model from a designated non-privileged host. From there the team found a domain service account's password stored in cleartext inside an XML file on an SCCM distribution point; that account held rights sufficient to perform a DCSync attack and obtain the `krbtgt` hash. The team forged a Golden Ticket and used the resulting Kerberos tickets — via Seamless SSO — to authenticate to Azure without any user's cleartext password, running AzureHound, ROADrecon, and ADConnectDump for cloud enumeration and abusing Microsoft Graph API scopes (Mail.Read, Mail.ReadWrite, Chat.Read.All, Files.Read.All, Application.ReadWrite.All, AppRoleAssignment.ReadWrite.All) — at one point re-enabling a disabled, MFA-exempt legacy AD-sync (MSOL_) account, DCSyncing its credentials, and adding a client secret to gain full mailbox access across the organization. The team also reached an OT-network bastion host reached via FTP credentials on a jump server, but outbound access was blocked and no C2 channel was established there. This time Organization B's custom Entra ID risky-user detections — "Unfamiliar sign-in properties" and "Suspicious API traffic" — flagged the AzureHound HTTP user agent and accounts exceeding Graph API request thresholds, and the SOC triaged, coordinated with engineering, and reimaged affected hosts.
Neither organization had Conditional Access enabled for workload identities, letting applications with broad Graph permissions bypass normal Conditional Access rules in both cases. CISA's core recommendation is architectural and procedural: disable `CT_FLAG_ENROLLEE_SUPPLIES_SUBJECT` and restrict enrollment on ADCS templates, zero out Machine Account Quota where unneeded, eliminate cleartext credentials and rotate long-lived cloud keys, enforce Conditional Access for workload identities, treat SCCM as a Tier 0 asset, and — the advisory's central point — tune alerting to cut false-positive volume and give SOC staff clear escalation authority, since Organization B's success came from process maturity rather than superior tools.
Weaknesses (CWE)
CWE-798, CWE-522, CWE-269, CWE-613
Target sectors: government facilities, water and wastewater systems, critical infrastructure
Target regions: united states of america
Timeline
- CISA publishes AA26-237A, "A Tale of Two SOCs," comparing two concurrent red team assessments against critical infrastructure organizations.
- Red team gains initial access to Organization A (Government Services and Facilities) via a web application using default credentials, then sends phishing emails from a trusted internal address, landing payloads on four workstations.
- Red team abuses Organization A's default Machine Account Quota to add unauthorized machine accounts and exploits an ESC1-vulnerable ADCS certificate template to request certificates impersonating privileged accounts.
- Red team recovers cleartext credentials and non-expiring static AWS IAM keys, harvests a Primary Refresh Token, and abuses over-permissioned Entra ID applications to read tenant mail; Organization A's SOC never detects the intrusion amid thousands of higher-severity false positives.
- The same phishing payload against Organization B (Water and Wastewater Systems) is detected on execution; the SOC isolates affected workstations within 2-20 minutes, forcing the red team into an assume-breach model.
- From an assume-breach foothold, the red team finds a domain service account's password stored in cleartext inside an XML file on an SCCM distribution point and performs a DCSync attack to obtain the krbtgt hash.
- Red team forges a Golden Ticket and uses Kerberos-based Seamless SSO to authenticate to Azure, running AzureHound, ROADrecon, and ADConnectDump for cloud enumeration and abusing Microsoft Graph API scopes to access mailboxes tenant-wide.
- Organization B's Entra ID risky-user detections flag the AzureHound user agent and anomalous Microsoft Graph API request volume; the SOC triages, coordinates with engineering, and reimages affected hosts before the OT-adjacent bastion host can be leveraged further.
- SecurityAffairs, The Hacker News, and other outlets report on AA26-237A's findings as a case study in SOC detection maturity across critical infrastructure sectors.
Detections & IOCs
As of 2026-09-06, this threat has 9 detection rule(s) across Splunk SPL, Microsoft KQL and Sigma, and 10 indicator(s) of compromise. Detection query text and full IOC values are available to authenticated users and programmatically via the Threadlinqs MCP server (Purple tier). View plans.
VULNERABILITY, HIGH, threat intelligence, cybersecurity, T1589.001, T1589.002, T1566, T1078, T1204.001, T1136.002, T1649, T1003, T1003.006, T1552.001