Network Assessment
External and internal, under one contract.
Two modules, your external perimeter and your internal Active Directory. We map how an attacker moves from the edge to domain admin, and prove it, where the real risk lives.
What we cover
Two modules. Pick one, pick both.
Every step is run by hand and triaged manually, never a scanner dump. Scope one module or both under a single engagement.
External perimeter
Everything an internet-facing attacker can reach, mapped and pressure-tested.
- Asset enumerationCT logs, DNS, shadow IT & forgotten subdomains, the real attack surface.
- Service discoveryFull TCP / top-1000 UDP, TLS posture, manual triage on every vector.
- Auth-surface testingVPN, OWA, O365, Citrix, low-and-slow spray + MFA-bypass detection.
- Edge exploitationDocumented appliance and public-app exploit paths only.
- Cloud exposureOpen buckets, IAM trust misconfigurations, public databases.
Internal Active Directory
An assumed-breach foothold on the internal network, driven toward Tier-0.
- Host discoveryPassive broadcast capture, mDNS, LLMNR, NetBIOS.
- AD enumerationFull BloodHound, DACL / GPO / ACL paths, Tier-0/1/2 boundary mapping.
- AD CS abuseESC1 through ESC11 certificate-template sweep.
- Credential accessKerberoasting, AS-REP roast, shadow credentials, LAPS retrieval.
- Lateral movementPass-the-hash / -ticket, WinRM / DCOM / SMB with operator tooling.
- Tier-0 pursuitDCSync + golden / silver / diamond ticket, proven, never executed.
- Detection-gapSigma rules authored for every TTP that landed without an alert.
How we operate
Aggressive on access. Careful with your estate.
We push for real impact without putting production at risk. The safety rails are defaults, documented in the report, not afterthoughts.
No LSASS dumps by default
Opt-in only, after a detection-validation review. We document the gap before we touch it.
krbtgt stays on-host
DCSync is demonstrated, but the krbtgt hash is never extracted off the domain controller.
Capability, not destruction
Golden and silver ticket capability is proven, never executed. We don't push exploits that risk DC replication.
A white cell, not a secret
A white-cell of two minimum, your IT lead can be one. No engagement hidden from the people who run the estate.
What you get
Six artefacts you can act on.
Boardroom deck
A short path-to-domain-admin narrative, written for people who don't read packet captures.
Technical report
Per-TTP reproduction with timing, enough to replay and verify every step.
BloodHound bundle
Cleansed attack graph plus the custom Cypher queries we used to find the paths.
Sigma pack
Detection rules for every TTP that landed, what your stack should have caught.
Tier-0 remediation
Privileged path, fix, owner and ETA, a list your team can work straight through.
Retest letter
Operator-signed validation after your fix cycle confirms what's actually closed.
FAQ
Questions, answered.
What's the difference between the external and internal phases?
Is it safe to run this against production and live domain controllers?
What access do you need to start the internal phase?
Do you actually go for Domain Admin and Tier-0?
Is a retest included after we fix the findings?
Brief us on the network.
Tell us what you need. An operator replies within one business day.