Contact us: info@tenendo.com

This case is a very good example why manual penetration tests are valuable - the team achieved compromise without administrator access to the application, not using any known exploits or discovering injection/deserialization/other RCE flaws.
Do you want to know how your organisation will fare against an internal attack? Look no further than Tenendo's Internal Adversary Simulation.
The adversary simulation activity helped the client identify and remediate multiple issues with the on-premise infrastructure and vulnerabilities, calculate potential risks, and improve the overall security posture. Each finding also included proposed solutions for applying industry-standard defences.
The Azure penetration test helped the client identify and remediate multiple issues and misconfigurations, harden their infrastructure and calculate potential risks.
Evaluating EDR Product against Threat Actors: Uncovering Limitations and Collaboration for Enhanced Detection of Multiple Killchains.
Successful phishing attacks revealed detection gaps in support and SOC teams, allowing unauthorized access without alerts.
Weak authentication and poor segmentation enabled privilege escalation from VPN access to full domain control.
Poor network segmentation enabled an attacker to pivot from internal access to full cloud takeover.
A threat model helped prioritize vulnerabilities, leading to the identification of a phishing attack chain that bypassed MFA and allowed unauthorized transactions.