Red team operations for enterprises
[email protected] @infosecslab Authorized testing only

What an operation actually looks like.

Real patterns from real engagements, anonymized and sanitized. Names, sectors and infrastructure details changed — the lessons are intact.

CASE FILE RT-0142 · Financial sector

From a job posting to Domain Admin in six days

Objective
Access the core payment-processing database of a regional bank
Path
A developer’s home-network NAS, exposed by a forgotten port forward, yielded corporate VPN credentials saved in a browser profile. MFA was enforced — but the VPN portal allowed push-fatigue spam. Push #14 was approved on a Friday evening. From the VPN, an outdated internal CI server reused the same local-admin password across 60+ hosts; the DPAPI-protected credentials of a tier-0 operator were recoverable from a misconfigured build agent.
Detected
The MFA-fatigue burst triggered no alert; the pass-the-hash across CI hosts fired a single low-severity rule nobody owned

After: number-matching + PIN enforced, local-admin passwords randomized, unowned alert rules reassigned — the same scenario retested clean three months later.

CASE FILE RT-0117 · SaaS provider

The crown jewels were one consent prompt away

Objective
Exfiltrate a sample of customer records from a multi-tenant SaaS platform
Path
No perimeter exploit was needed. A convincing “new shared inbox policy” lure sent to 40 finance staff yielded two MFA-approved AitM sessions. One account had standing consent to a third-party reporting app with Graph API scope over mailbox data — and the tenant permitted users to approve OAuth grants. Data was staged into a sanctioned-looking SharePoint folder and exfiltrated through an approved sync client.
Detected
The OAuth consent was logged but unmonitored; egress volume from the sync client blended into baseline

After: tenant-wide OAuth consent restrictions, high-volume egress alerting, and a helpdesk script for verifying “policy” emails.

CASE FILE RT-0098 · Energy / OT adjacent

A clean IT/OT boundary — until the vendor laptop

Objective
Assess whether the corporate-to-OT segmentation holds under a determined insider-style path
Path
Corporate phishing gave us a foothold in IT. The segmented OT network itself was solid. The gap: a maintenance vendor's dual-homed laptop that legitimately bridged zones during scheduled visits, with stored RDP credentials for the historian server. Our objective was reached during a simulated maintenance window — with written authorization from site management at every step.
Detected
Nothing fired: vendor traffic was implicitly trusted at the boundary

After: vendor laptops moved to a dedicated brokered jump host, and every zone crossing now requires a just-in-time access grant.

CASE FILE RT-0171 · Telecom

Six hours from a helpdesk call to global admin

Objective
Obtain Entra ID Global Admin without touching any user's endpoint
Path
Pure vishing. Using OSINT from a conference speaker list, we impersonated a regional IT director and talked the helpdesk through an “urgent MFA re-enrollment” for a dormant service account. The re-enrollment queue auto-elevated the account into a privileged role whose PIM activation required no second approver.
Detected
The helpdesk had no callback procedure for privileged-account changes; PIM activation alerts existed but routed to a shared mailbox

After: mandatory callback verification for privileged changes, two-approver PIM for tier-0 roles, and a red-team vishing drill added to on-call training.

What would our next case file say about you?

Every engagement above ended with fixes that held. Start yours before an attacker writes it for you.

Request assessment