Skip to content
DnsLister Forum

Where domain hunters compare notes

AA26-237A: two red teams, full domain compromise both times, one SOC caught it in 2 minutes

CISA published AA26-237A on August 25 – two red team assessments run at the same time against two different organizations. One in government services, one in water and wastewater. The red team got full domain compromise at both. That part is not the interesting bit. The interesting bit is the detection gap. Organization A never noticed. Organization B isolated the three compromised workstations in 10 minutes, 2 minutes, and 20 minutes respectively. Same tradecraft both times: a modified BloodHound collector, the default Machine Account Quota of 10 that nobody ever changes, an ADCS certificate template with ESC1 misconfigured, and Entra ID application permission abuse using a stolen Primary Refresh Token. The mitigations CISA leads with are not tooling purchases. The first one is to establish a baseline and tune down alert noise. The second is to break down silos between the SOC and the network team. Which tracks. Organization A almost certainly had the telemetry. It just had too much of it and nobody empowered to act on any of it. Two things worth checking today regardless: your Machine Account Quota, and whether any ADCS template allows a requester to supply their own subject alternative name.

Source: r/u/FranklyToday · by /u/FranklyToday

Leave a Reply

Your email address will not be published. Required fields are marked *