Scope and authorize
We agree the starting position — standard user, unauthenticated device or both — and what is off limits.
An assumed-breach test: we start where a phished employee or a stolen laptop would, and work out how far that gets — usually measured by how quickly it becomes domain-wide control.
The question is not whether someone can get inside. It is what happens next. Most internal networks are built for people to work in, and the same convenience that makes work possible makes lateral movement easy.
We start from a standard user on a standard device, and we document the path — every step, every credential, every misconfiguration that made the next step possible — so you can break the chain wherever it is cheapest.
Typically one to two weeks, depending on the size of the estate.
We agree the starting position — standard user, unauthenticated device or both — and what is off limits.
On-site or through a connected device, we begin with exactly the access a new employee would have.
We enumerate the domain, collect what is reachable and escalate along real, evidenced paths rather than theoretical ones.
We record which actions your tooling detected and which it did not — useful whether or not detection was in scope.
The report shows the full attack path with the cheapest place to break it, followed by a readout and a retest.
Real examples of what this engagement uncovers — anonymized, and never every time. What matters is that you find out before somebody else does.
A path from a standard user account to full domain control
Service accounts with weak passwords and far more rights than the service needs
Local administrator passwords shared across hundreds of machines
Certificate templates that let any user request a certificate as anyone else
File shares holding credentials, exports and backups readable by everyone
Missing something on this list? Bring it to the call — we scope around what you have.
See everything you expose to the internet the way an attacker sees it.
Read moreProve your sensitive environments are truly isolated.
Read moreKeep Wi-Fi and wireless from becoming the way in, at every site you operate.
Read moreNot sure where to start? One of our testers reviews your internet-facing footprint and sends you a short summary of what an attacker would see — free. Nothing you don’t own is ever touched, and there’s no sales sequence.
Free. No obligation.