Get a quote

Services  /  Network assessment

External and internal, under one contract.

We map your perimeter, break in the way a real attacker would, then chain Active Directory weaknesses to full domain control, proving the whole edge-to-Domain-Admin path. Aggressive on access, careful with your estate.

Capability, not destructionA white cell, alwaysSigma rules includedFree retest

The point

See the whole path, edge to Domain Admin.

Most breaches don't stop at the perimeter. We show you every step a real intruder would take from your internet edge to total domain control, and exactly where to break the chain.

Coverage

Two modules. Pick one, pick both.

Scope the external perimeter, the internal Active Directory estate, or run them together for the full attack path.

Module 01 External perimeter

Asset enumeration

CT logs, DNS, shadow IT, and forgotten subdomains, the real attack surface.

Service discovery

Full TCP / top-1000 UDP, TLS posture, manual triage on every vector.

Auth-surface testing

VPN, OWA, O365, Citrix, low-and-slow spray plus MFA-bypass detection.

Edge exploitation

Documented appliance and public-app exploit paths only.

Cloud exposure

Open buckets, IAM trust misconfigurations, and public databases.

Module 02 Internal Active Directory

Host discovery

Passive broadcast capture, mDNS, LLMNR, and NetBIOS.

AD enumeration

Full BloodHound, DACL / GPO / ACL paths, Tier-0/1/2 boundary mapping.

AD CS abuse

ESC1 through ESC11 certificate-template sweep.

Credential access

Kerberoasting, AS-REP roast, shadow credentials, LAPS retrieval.

Lateral movement

Pass-the-hash / -ticket, WinRM / DCOM / SMB with operator tooling.

Tier-0 pursuit

DCSync and golden / silver / diamond tickets, proven, never executed.

Detection-gap

Sigma rules authored for every TTP that landed without an alert.

Rules of engagement

Aggressive on access.
Careful with your estate.

We prove impact without putting production at risk. You always know what is running.

No LSASS dumps by default

We prove access without dumping credentials unless you ask us to.

krbtgt stays on-host

No golden-ticket material ever leaves your environment.

Capability, not destruction

We demonstrate impact, we never break your estate to prove it.

A white cell, not a secret

Your named contacts always know exactly what is running, and when.

How far could an intruder get in your network?

Get a quote

Proof · Financial services

One foothold. The whole domain.

From a single assumed-breach laptop, we built custom payloads that slipped past CrowdStrike EDR without an alert, then chained Active Directory weaknesses to full domain control. Nothing broken, nothing taken.

80% endpoints reachable
0alerts raised
1foothold to domain
Read the field record
AGRKEDR bypassed

“Assumed breach to Domain Admin. No malware, no data taken. Just proof.”

  • Custom loaders, EDR-evasion tested
  • Active Directory abuse, lateral movement
  • Reproducible proof-of-concept for every step

What you get

Six artefacts you can act on.

Boardroom deck

The risk story for leadership, in plain language.

Technical report

Every path and finding, with evidence and remediation.

BloodHound bundle

The graph data behind every attack path we walked.

Sigma pack

Detection rules for each TTP that landed without an alert.

Tier-0 remediation

A prioritised plan to close the domain-compromise paths.

Retest letter

Written verification that the fixes hold.

Questions, answered

The usual questions.

Will you take down our network?

No. We are careful by default, capability, not destruction, and a white cell that always knows what is running.

External, internal, or both?

Either. Most clients scope both so we can show the full edge-to-Domain-Admin path in one engagement.

Do you need domain credentials?

For the internal module we usually start from an assumed-breach position. We agree the exact starting point with you.

How long does it take?

Typically one to two weeks per module, with a fixed timeline agreed before we start.

Network assessment

Brief us on the network.

External, internal, or both. A senior operator replies within one business day.

Everything under NDA1-business-day replyFree retest included