Networks. From one workstation to the keys to the kingdom.
Most breaches don't end where they start. We show how far a single foothold travels through your internal network, Active Directory and cloud tenants — and which controls actually stop it. Assumed breach is the starting point, domain dominance is the objective.
What one foothold proves.
- Segmentation is a design, not a fact. Every “isolated” zone is verified with packets, not diagrams.
- Credentials outlive hosts. Reused passwords and cached secrets connect machines that were never meant to talk.
- Tier-0 is closer than it looks. In most estates we measure, the shortest path to Domain Admin is under five steps.
- Cloud trusts on-prem. Hybrid identity turns one AD compromise into a tenant-wide problem — or proves that it can't be done.
| Step | ATT&CK |
|---|---|
| Valid account through the VPN | T1078T1133 |
| Internal discovery, credential reuse | T1087T1552 |
| Kerberoasting, delegation abuse | T1558 |
| Lateral movement over remote services | T1021 |
| Domain Admin, DC sync | T1003 |
| Cloud pivot via hybrid identity | T1098 |
What we test.
The blocks below are a menu; the operation is a chain. We combine them until the objective is reached — or your defense holds.
Active Directory
Kerberos attacks, unconstrained and resource-based delegation, ACL chains, ADCS abuse and tiering gaps — the shortest paths to Domain Admin.
Lateral movement
Pass-the-hash and pass-the-ticket, remote execution paths, and a reality-check of your network segmentation against its design documents.
Privilege escalation
Local-admin password reuse, service accounts, gMSA misuse and credential exposure in build systems and file shares.
Cloud identity & IAM
AWS and Azure escalation chains, role and policy trust abuse, hybrid pivots between on-prem AD and Entra ID.
Segmentation & boundaries
VLAN, DMZ and firewall rule verification: where the design says "isolated" and the packets say otherwise.
Detection & response
Your SOC under live attack conditions: response times, alert routing, playbook gaps — measured, not assumed.
Building a broader program? Compare all eight services in the full catalog.
How it runs.
Scope & assumed-breach setup
We agree objectives and ROE, then start either black-box or from an emulated foothold — a compromised workstation under our control.
Internal mapping
AD structure, trust relationships, credential exposure and segmentation — mapped with OPSEC controls, every action ATT&CK-tagged.
Escalation & objectives
Chained escalation toward the agreed targets: Domain Admin, crown-jewel systems, cloud tenants. Evidence captured at every step.
Debrief & hardening
Tiering fixes, segmentation corrections, detection rules and a retest to confirm the same path is closed.
What you get.
- Attack-path graph — every route to tier-0, chained and evidenced.
- Detection gap matrix — telemetry generated vs alerts your SOC actually raised.
- Tiering & hardening plan — prioritized, owner-assigned, retest-backed.
- Cloud guardrails — IAM fixes that survive real administrators.
Typical engagement: 2–6 weeks depending on estate size.
| Case | Lesson |
|---|---|
| RT-0142 | Regional bank: from a job posting to Domain Admin in six days — one reused password across 60+ hosts |
| RT-0098 | Energy: a clean IT/OT boundary — until the vendor laptop bridged it |
Get a consultation.
Tell us your estate — AD, hybrid or cloud — and your main worry. We reply within two business days with a proposed scope.
Faster: Telegram @infosecslab or [email protected].