Attack Paths
12 matching posts.
The Service Was Observed. The Application Was Still Unknown.
Passive internet data can reveal a live service without proving its current owner, hostname, virtual host, application, or business purpose. A defensible external pentest turns that observation into a bounded application model before testing for vulnerabilities.
The Red Team Reached Domain Admin. The Exercise Still Failed.
Domain Admin is a capability, not a business objective. This field methodology turns an authorized red team operation into a testable chain of objective, runtime authority, technical action, defender signal, response decision, evidence, and verified recovery.
The Model Proposed the Action. The Broker Decided Whether It Could Exist.
A practical architecture for AI-assisted pentest execution: resolve scope outside the model, classify side effects, issue short-lived capabilities, deny high-impact authority, and preserve a decision record that can be independently verified.
The Model Is Not the Target. The Pipeline Is.
A field methodology for using MITRE ATLAS without turning an AI assessment into matrix theatre: map the production system, follow authority into tools and data, test reachable attack paths, and label the evidence only after impact is proven.
Active Directory Hardening Is a Sequence, Not a Score
A scanner score cannot tell you whether a helpdesk account can still reach Domain Admin. This is the order I use to turn AD hardening signals into broken attack paths, tested controls, and recoverable identity infrastructure.
The Pipeline Has No Secret. It Still Has a Cloud Identity.
Replacing static deployment keys with OIDC removes a credential from the repository. It does not decide which workflow deserves the resulting cloud role — that decision lives in the trust policy, and one wildcard can turn an organisation into a deployment API.
AD CS ESC4: The Template Nobody Owned
How an ordinary AD CS permission becomes Domain Admin — and why ESC4 is the cause every ESC1 write-up skips.
The Request Stayed Server-Side. The Credential Did Not.
SSRF severity is not the URL an application can fetch. It is the trust the outbound request inherits — network position, redirect behavior, DNS resolution, and access to metadata or control-plane identities. Test the route as a chain, not a blacklist.
Affiliates Do Not Find Novel Paths. They Find Yours.
Part three of testing the ransomware playbook: privilege escalation inside the domain uses a small, stable set of paths — the same ones already written up on this site — and the affiliate picks by reliability, not by cleverness.
Cloud IAM Privilege Escalation: Every Permission Is Individually Fine. The Chain Is Not.
CSPM and least-privilege tools grade each IAM policy on its own, and on its own nearly every policy passes. Cloud privilege escalation is a path across roles, accounts, and trust — and a scanner that cannot see the path cannot flag the risk.
BloodHound Path Triage: The Shortest Path Is Usually the One That Expires First
BloodHound draws every edge the same width, but a DACL lasts for years and a session lasts for minutes. Shortest-path queries are biased toward exactly the edges least likely to still be there when you walk them.
Delegation Triage: You Were Taught the Rare One
Unconstrained delegation gets the diagrams. Resource-based constrained delegation is what you actually find — because it is not a checkbox anyone audits, it is a side effect of who can write to a computer object.
