Code Defence Cyber security

CISA Red Team report details domain and cloud tenant compromises across critical infrastructure targets

Federal cybersecurity authorities have published findings from simultaneous red team assessments conducted against critical infrastructure sectors. The advisory highlights how common Active Directory misconfigurations, unexpiring cloud access keys, and default application credentials led to total domain and cloud tenant takeovers.

Tracked under advisory AA26-237A, the assessment evaluated defensive responses across government and water sector entities. The red team achieved initial access by exploiting public web applications running default administrative credentials. Attackers escalated local domain rights by abusing default Machine Account Quotas alongside misconfigured Active Directory Certificate Services AD CS templates via the Certighost technique. In cloud environments, the team extracted cleartext database configuration files and static AWS access keys configured never to expire, leveraging Primary Refresh Tokens and over-permissioned Entra ID applications to monitor defender email communications undetected.

Failing to remediate legacy Active Directory settings and static cloud keys exposes enterprise environments to total compromise. When defensive security operation centers lack unified cross-platform visibility, false-positive alert volume obscures legitimate intrusion telemetry, granting adversaries unmonitored lateral access to sensitive business systems.

– Reduce the default Active Directory Machine Account Quota ms-DS-MachineAccountQuota parameter to zero across all domain controllers.

– Audit Active Directory Certificate Services templates to eliminate vulnerable ESC1 configurations permitting arbitrary user SAN requests.

– Eliminate static, unexpiring cloud access keys in favor of short-lived temporary credentials managed via IAM Identity Center.

– Enforce strict least-privilege permissions for all Entra ID applications and service principals integrated into cloud tenants.

Enterprise identity architecture security demands continuous Active Directory template auditing and strict non-human identity lifecycle governance to eliminate persistent domain takeover vectors. #CodeDefence #ActiveDirectory #ADCS #Certighost #CloudSecurity #EntraID #CISA #RedTeam #IdentitySecurity
/

Scroll to Top