Internal Network Penetration Test
Challenge
A mid-sized financial firm needed to validate their internal network segmentation and Active Directory security before a regulatory review.
Key Findings
Kerberoastable service accounts with weak passwords, unauthenticated SMB shares exposing sensitive data, and a clear lateral movement path to the domain controller.
Result
Full domain compromise scenario identified and remediated before audit. Segmentation gaps patched within 30 days, closing all critical attack paths.