Contact us: info@tenendo.com

Assumed Breach and Privilege Escalation Case

OSCP · OSEP · CRTO certified operators In-house tooling & payloads PCI QSA & ISO 27001 LA
The Challenge
The assumed breach scenario tested infrastructure security by simulating insider threats. Major weaknesses included 2FA absence, weak endpoint security, and poor segmentation.
The Solution
The assumed breach scenario tested infrastructure security by simulating insider threats. Major weaknesses included 2FA absence, weak endpoint security, and poor segmentation.

How we did it

  • Exploited open VPN access and AnyDesk admin controls.
  • Used DCSync & Shadow Credentials for privilege escalation.
  • Performed lateral movement through SMB pivots.

Conclusion

The engagement revealed weak security configurations, which allowed for undetected privilege escalation. Network segmentation and MFA were prioritised for mitigation.