Simulated internal and external attacks that demonstrate how an attacker can move laterally, escalate privileges, and take full control of the domain.
Internal and external tests that simulate lateral movement, privilege escalation, and full domain compromise. Based on PTES, NIST, and MITRE ATT&CK.
Simulates an external attacker: asset discovery, port scanning, service enumeration, exploitation of VPNs, firewalls, and initial access attempts. We identify real entry points.
Positioned as an insider or attacker who has already accessed the network. Enumeration, lateral movement, privilege escalation, compromise of servers and workstations up to Domain Admin.
Deep AD assessment: Kerberoasting, AS-REP Roast, DCSync, vulnerable ACLs, insecure GPOs, delegated trusts, and paths to full compromise.
Assessment of corporate Wi-Fi networks: WPA2/3 attacks, evil twin, PMKID cracking, deauthentication, rogue AP, and verification of segmentation between wireless and wired networks.
Security configuration analysis of servers and workstations against CIS Benchmarks, patch levels, user permissions, logs, unnecessary services, and group policies.
Audit of firewall rules (Palo Alto, Fortinet, Cisco, pfSense): analysis of zoning, implicit rules, logging, egress filtering, and segmentation.
Each node represents an asset, each edge an attack vector — one animated dot per path.
86% of internal networks have a critical escalation path
Average time to compromise: 16-24h
94% of attacks use valid credentials + lateral movement
Each engagement follows a rigorous process based on PTES, OWASP and MITRE ATT&CK — ensuring full coverage and actionable results.
Scope definition, rules of engagement, business objectives and NDA signing. Everything documented before the first scan.
Passive and active information gathering: subdomains, exposed technologies, employees, leaked credentials and digital footprint.
Identification and prioritization of critical assets, likely attack vectors and most relevant business scenarios based on MITRE ATT&CK.
Detailed mapping of ports, services, versions, users and configurations — building a precise attack surface.
Controlled exploitation of vulnerabilities to gain initial access and demonstrate real impact — without causing damage to the environment.
Lateral movement, privilege escalation, persistence and data exfiltration to measure the real extent of the compromise.
Complete documentation with evidence, CVSS classification, business impact, technical and strategic recommendations — plus a replay session with teams.