THREAT OPS › Threat News › A Tale of Two SOCs: Insights From Two Red Team Assessments
A Tale of Two SOCs: Insights From Two Red Team Assessments
<h2><strong>Advisory at a Glance</strong></h2> <table> <tbody> <tr> <th>Title</th> <td>A Tale of Two SOCs: Insights From Two Red Team Assessments</td> </tr> <tr> <th>Original Publication </th> <td><strong>August 25, 2026</strong></td> </tr> <tr> <th>Executive Summary</th> <td> <p>The Cybersecurity and Infrastructure Security Agency (CISA) conducted simultaneous red team assessments at two org
MITRE ATT&CK techniques
- Screen CaptureT1113
- System Owner/User DiscoveryT1033
- KeyloggingT1056.001
- OS Credential DumpingT1003
- Permission Groups DiscoveryT1069
- Email CollectionT1114
- Group Policy DiscoveryT1615
- Domain AccountT1087.002
- Domain GroupsT1069.002
- SSHT1021.004
- Cloud AccountsT1586.003
- Steal or Forge Kerberos TicketsT1558
- Unsecured CredentialsT1552
- Use Alternate Authentication MaterialT1550
- Gather Victim Identity InformationT1589
- Remote ServicesT1021
- Email AddressesT1589.002
- Account DiscoveryT1087
- ProxyT1090
- Domain AccountT1136.002
- Steal or Forge Authentication CertificatesT1649
- Web ServiceT1102
- Credentials In FilesT1552.001
- User ExecutionT1204
- Cloud AccountsT1585.003
- PowerShellT1059.001
- ToolT1588.002
- PhishingT1566
- Input CaptureT1056
- CredentialsT1589.001
- ImpersonationT1684.001
- Obtain CapabilitiesT1588
- Conditional Access PoliciesT1556.009
- Data from Information RepositoriesT1213
- Create AccountT1136
- Cloud Service DiscoveryT1526
- Remote System DiscoveryT1018
- Remote Desktop ProtocolT1021.001
- Malicious LinkT1204.001
- Application Access TokenT1550.001
- Cloud AccountsT1078.004
- DCSyncT1003.006
- Internal ProxyT1090.001
- Messaging ApplicationsT1213.005
- Malicious LinkAML.T0011.003
- Obtain CapabilitiesAML.T0016
- Data from Information RepositoriesAML.T0036
- Unsecured CredentialsAML.T0055
- ImpersonationAML.T0073
- Cloud Service DiscoveryAML.T0075
- Gather Victim Identity InformationAML.T0087
- OS Credential DumpingAML.T0090
- Use Alternate Authentication MaterialAML.T0091
- Application Access TokenAML.T0091.000
Indicators of compromise
- contact@cisa.dhs.govemail
- specterops.iodomain
Original source: https://www.cisa.gov/news-events/cybersecurity-advisories/aa26-237a