Contact us: info@tenendo.com
Assumed Breach and Privilege Escalation Case
The Challenge
The assumed breach scenario tested infrastructure security by simulating insider threats. Major weaknesses included 2FA absence, weak endpoint security, and poor segmentation.
The Solution
The assumed breach scenario tested infrastructure security by simulating insider threats. Major weaknesses included 2FA absence, weak endpoint security, and poor segmentation.
How we did it
- Exploited open VPN access and AnyDesk admin controls.
- Used DCSync & Shadow Credentials for privilege escalation.
- Performed lateral movement through SMB pivots.
Conclusion
The engagement revealed weak security configurations, which allowed for undetected privilege escalation. Network segmentation and MFA were prioritised for mitigation.