The SOC That Saw Nothing

CISA red team assessment AA26-237A, published August 25, 2026, tested two critical infrastructure organizations. Both fully compromised at domain level. Both had sensitive business systems and cloud resources accessed. One Security Operations Center detected nothing across the entire attack. The other isolated compromised hosts within minutes.

Organization A is in the Government Services and Facilities Sector. Organization B is Water and Wastewater Systems. Both critical infrastructure. Both had SOCs. Only one worked.

The Timeline of What Organization A Missed

Initial access → no detection.

Privilege escalation → no detection.

Lateral movement → no detection.

Domain admin acquisition → no detection.

Sensitive business system access → no detection.

Cloud resource compromise → no detection.

The red team walked through the full kill chain and the SOC saw none of it. That's not a missed alert. That's operational blindness.

The Vulnerabilities Weren't Novel

Machine Account Quota left at default (ms-DS-MachineAccountQuota = 10). Active Directory allows unprivileged users to create machine accounts for Kerberos abuse and RBCD attacks. Known vulnerability. Neither organization had changed it.

AD Certificate Services templates misconfigured. ESC1 and ESC8 privilege escalation paths present. Well-documented vulnerability class. Neither organization had hardened their templates.

Cleartext credentials on network-accessible systems. Service and database passwords stored in scripts, config files, Group Policy Preferences. The red team harvested them.

Hybrid cloud environment with on-premises AD synced to Azure AD (Entra ID). Domain compromise led directly to cloud lateral movement via synced accounts.

These are baseline configuration failures. Not zero-days. Not novel tradecraft. Competent penetration testing in 2026 finds these in most environments.

Organization B's SOC Did What a SOC Is Supposed To Do

Organization B had the same vulnerable configurations. Machine Account Quota at default. AD CS templates misconfigured. Cleartext credentials on the network.

The red team still reached domain-level compromise.

But Organization B's SOC isolated the compromised hosts within minutes of initial activity.

Not hours. Minutes. Rapid detection, rapid containment, incident stopped before the attacker could complete objectives.

That's what detection looks like when it works.

Water Treatment and Public Health

Organization B is water and wastewater infrastructure. Domain compromise in that environment means potential access to operational systems—SCADA, ICS controls, water treatment processes.

A compromised water treatment facility where the SOC detects nothing is a public health incident waiting for an attacker to decide it's worth the effort.

Organization B's SOC saw the intrusion and contained it. Organization A's wouldn't have.

What CISA Is Telling the Rest of You

AA26-237A is a message to every critical infrastructure organization: you might be Organization A and not know it until someone compromises you for real.

Your SOC might be staffed 24/7, might be logging events, might be running a SIEM—and still miss domain compromise happening in real time.

CISA's recommendations: audit Machine Account Quota, harden AD CS templates, eliminate cleartext credentials, validate SOC detection.

Those aren't new mitigations. They're what should have been configured before the assessment.

The Accountability Question

Organization A is a government services facility. Taxpayer-funded. The SOC saw nothing while attackers took full control of the domain, accessed sensitive business systems, and pivoted to cloud resources.

That's not a technical gap. That's a failure to do the job the SOC exists to do.

The difference between Organization A and Organization B isn't budget or sector or tooling. It's whether the SOC can actually see an attack when it's happening.

If your SOC can't detect domain compromise, every incident response plan you've written is based on an assumption that doesn't hold.

And when the breach is real, you won't find out until the attacker decides to tell you.