Network Assessment

External and internal, under one contract.

Two modules, your external perimeter and your internal Active Directory. We map how an attacker moves from the edge to domain admin, and prove it, where the real risk lives.

External + internalSafety-first, prod-awareReproducibleUnder NDA
operator@overwatch

What we cover

Two modules. Pick one, pick both.

Every step is run by hand and triaged manually, never a scanner dump. Scope one module or both under a single engagement.

public

External perimeter

Everything an internet-facing attacker can reach, mapped and pressure-tested.

  • Asset enumerationCT logs, DNS, shadow IT & forgotten subdomains, the real attack surface.
  • Service discoveryFull TCP / top-1000 UDP, TLS posture, manual triage on every vector.
  • Auth-surface testingVPN, OWA, O365, Citrix, low-and-slow spray + MFA-bypass detection.
  • Edge exploitationDocumented appliance and public-app exploit paths only.
  • Cloud exposureOpen buckets, IAM trust misconfigurations, public databases.
lan

Internal Active Directory

An assumed-breach foothold on the internal network, driven toward Tier-0.

  • Host discoveryPassive broadcast capture, mDNS, LLMNR, NetBIOS.
  • AD enumerationFull BloodHound, DACL / GPO / ACL paths, Tier-0/1/2 boundary mapping.
  • AD CS abuseESC1 through ESC11 certificate-template sweep.
  • Credential accessKerberoasting, AS-REP roast, shadow credentials, LAPS retrieval.
  • Lateral movementPass-the-hash / -ticket, WinRM / DCOM / SMB with operator tooling.
  • Tier-0 pursuitDCSync + golden / silver / diamond ticket, proven, never executed.
  • Detection-gapSigma rules authored for every TTP that landed without an alert.

How we operate

Aggressive on access. Careful with your estate.

We push for real impact without putting production at risk. The safety rails are defaults, documented in the report, not afterthoughts.

memory

No LSASS dumps by default

Opt-in only, after a detection-validation review. We document the gap before we touch it.

key

krbtgt stays on-host

DCSync is demonstrated, but the krbtgt hash is never extracted off the domain controller.

verified_user

Capability, not destruction

Golden and silver ticket capability is proven, never executed. We don't push exploits that risk DC replication.

groups

A white cell, not a secret

A white-cell of two minimum, your IT lead can be one. No engagement hidden from the people who run the estate.

What you get

Six artefacts you can act on.

Boardroom deck

A short path-to-domain-admin narrative, written for people who don't read packet captures.

Technical report

Per-TTP reproduction with timing, enough to replay and verify every step.

BloodHound bundle

Cleansed attack graph plus the custom Cypher queries we used to find the paths.

Sigma pack

Detection rules for every TTP that landed, what your stack should have caught.

Tier-0 remediation

Privileged path, fix, owner and ETA, a list your team can work straight through.

Retest letter

Operator-signed validation after your fix cycle confirms what's actually closed.

FAQ

Questions, answered.

What's the difference between the external and internal phases?
External looks at your internet-facing perimeter, the assets, services, and login portals an attacker can reach with no prior access. Internal starts from a foothold inside the network and works through your Active Directory the way an attacker would after a phish or a compromised laptop. External is the short ramp; internal is where the real risk usually lives.
Is it safe to run this against production and live domain controllers?
Yes, that's the default posture. We push for real impact without putting the estate at risk: no LSASS dumps unless you opt in after a detection review, the krbtgt hash never leaves the DC, and we don't run exploits that risk DC replication. Rules of engagement, blast radius, and out-of-scope systems are all agreed before we touch anything, and every safety rail is documented in the report.
What access do you need to start the internal phase?
We run it as an assumed breach. You give us a standard user account and a network position, a domain-joined VM, a wired drop, or VPN access, that mirrors where an attacker lands after a phish or a stolen laptop. We don't need admin rights or a head start; that's the point. If you'd rather we earn the foothold first, external can feed straight into it.
Do you actually go for Domain Admin and Tier-0?
Yes, where the paths exist. The goal is to prove how far an attacker gets, so we map and pursue routes to Tier-0 and demonstrate control, DCSync, for example, rather than stopping at "we found some issues." We prove capability without destruction: golden and silver tickets are shown to be possible, never executed against your domain.
Is a retest included after we fix the findings?
Yes, and it's not an upsell. Once your team has worked through the remediation, we re-test the findings and confirm what's actually closed, then send an operator-signed retest letter you can show your board or auditors.

Brief us on the network.

Tell us what you need. An operator replies within one business day.