Security · Aug 28
CISA AA26-237A: two domain compromises, one silent SOC
CISA’s advisory shows full domain compromise is not the only metric; whether the SOC notices is the plot twist.
- Test whether your SOC can detect domain level compromise, not just initial access.
- Treat Active Directory and cloud control plane logs as core detection sources.
- Convert red team findings into owned detections, test cases, and response drills.