Services / Network assessment
External and internal, under one contract.
We map your perimeter, break in the way a real attacker would, then chain Active Directory weaknesses to full domain control, proving the whole edge-to-Domain-Admin path. Aggressive on access, careful with your estate.
The point
See the whole path, edge to Domain Admin.
Most breaches don't stop at the perimeter. We show you every step a real intruder would take from your internet edge to total domain control, and exactly where to break the chain.
Coverage
Two modules. Pick one, pick both.
Scope the external perimeter, the internal Active Directory estate, or run them together for the full attack path.
Module 01 External perimeter
Asset enumeration
CT logs, DNS, shadow IT, and forgotten subdomains, the real attack surface.
Service discovery
Full TCP / top-1000 UDP, TLS posture, manual triage on every vector.
Auth-surface testing
VPN, OWA, O365, Citrix, low-and-slow spray plus MFA-bypass detection.
Edge exploitation
Documented appliance and public-app exploit paths only.
Cloud exposure
Open buckets, IAM trust misconfigurations, and public databases.
Module 02 Internal Active Directory
Host discovery
Passive broadcast capture, mDNS, LLMNR, and NetBIOS.
AD enumeration
Full BloodHound, DACL / GPO / ACL paths, Tier-0/1/2 boundary mapping.
AD CS abuse
ESC1 through ESC11 certificate-template sweep.
Credential access
Kerberoasting, AS-REP roast, shadow credentials, LAPS retrieval.
Lateral movement
Pass-the-hash / -ticket, WinRM / DCOM / SMB with operator tooling.
Tier-0 pursuit
DCSync and golden / silver / diamond tickets, proven, never executed.
Detection-gap
Sigma rules authored for every TTP that landed without an alert.
Rules of engagement
Aggressive on access.
Careful with your estate.
We prove impact without putting production at risk. You always know what is running.
No LSASS dumps by default
We prove access without dumping credentials unless you ask us to.
krbtgt stays on-host
No golden-ticket material ever leaves your environment.
Capability, not destruction
We demonstrate impact, we never break your estate to prove it.
A white cell, not a secret
Your named contacts always know exactly what is running, and when.
How far could an intruder get in your network?
Get a quote →Proof · Financial services
One foothold. The whole domain.
From a single assumed-breach laptop, we built custom payloads that slipped past CrowdStrike EDR without an alert, then chained Active Directory weaknesses to full domain control. Nothing broken, nothing taken.
“Assumed breach to Domain Admin. No malware, no data taken. Just proof.”
- → Custom loaders, EDR-evasion tested
- → Active Directory abuse, lateral movement
- → Reproducible proof-of-concept for every step
What you get
Six artefacts you can act on.
Boardroom deck
The risk story for leadership, in plain language.
Technical report
Every path and finding, with evidence and remediation.
BloodHound bundle
The graph data behind every attack path we walked.
Sigma pack
Detection rules for each TTP that landed without an alert.
Tier-0 remediation
A prioritised plan to close the domain-compromise paths.
Retest letter
Written verification that the fixes hold.
Questions, answered
The usual questions.
Will you take down our network?
No. We are careful by default, capability, not destruction, and a white cell that always knows what is running.
External, internal, or both?
Either. Most clients scope both so we can show the full edge-to-Domain-Admin path in one engagement.
Do you need domain credentials?
For the internal module we usually start from an assumed-breach position. We agree the exact starting point with you.
How long does it take?
Typically one to two weeks per module, with a fixed timeline agreed before we start.
Network assessment
Brief us on the network.
External, internal, or both. A senior operator replies within one business day.