APT-level red team operations for enterprises and organizations
CASE FILE RT-0171 Telecom

Six hours from a helpdesk call to global admin

No malware, no phishing email, no endpoint. One phone call to the right helpdesk — scripted from a conference speaker list — produced Global Admin in under six hours.

Objective
Obtain Entra ID Global Admin without touching any user’s endpoint
Path
Pure vishing. Using OSINT from a conference speaker list, we impersonated a regional IT director and talked the helpdesk through an “urgent MFA re-enrollment” for a dormant service account. The re-enrollment queue auto-elevated the account into a privileged role whose PIM activation required no second approver.
Detected
The helpdesk had no callback procedure for privileged-account changes; PIM activation alerts existed but routed to a shared mailbox

After: Mandatory callback verification for privileged changes, two-approver PIM for tier-0 roles, and a red-team vishing drill added to on-call training.

Names, sectors and infrastructure details are changed; timelines and tradecraft are not. More case files →

The pattern in one page

  • Helpdesk identity verification is your weakest authentication factor. Callback to a stored number, every time.
  • Automation that elevates silently is a standing invitation. Privileged roles need a second pair of eyes.
  • Alerts routed to a shared mailbox are alerts nobody owns.
Recognize the pattern?
We can verifyTypical effort
The same path against your estate, under signed ROE2–4 wks
Detection validation: what your SOC would have seenincluded
Retest after fixes, within three monthsfree

Could this path exist in your estate?

Tell us your crown jewels — we will tell you how close this case file is to your reality.

Request assessment