#tag

Attack Paths

12 matching posts.

All tags
PentestSep 10, 202616 min read

The Service Was Observed. The Application Was Still Unknown.

Passive internet data can reveal a live service without proving its current owner, hostname, virtual host, application, or business purpose. A defensible external pentest turns that observation into a bounded application model before testing for vulnerabilities.

#pentest#external-pentest#methodology#attack-paths#web-security
PentestAug 30, 202618 min read

The Red Team Reached Domain Admin. The Exercise Still Failed.

Domain Admin is a capability, not a business objective. This field methodology turns an authorized red team operation into a testable chain of objective, runtime authority, technical action, defender signal, response decision, evidence, and verified recovery.

#red-team#pentest#attack-paths#detection#resilience
PentestAug 23, 202616 min read

The Model Proposed the Action. The Broker Decided Whether It Could Exist.

A practical architecture for AI-assisted pentest execution: resolve scope outside the model, classify side effects, issue short-lived capabilities, deny high-impact authority, and preserve a decision record that can be independently verified.

#ai-security#pentest#methodology#access-control#attack-paths
PentestJul 9, 202618 min read

The Model Is Not the Target. The Pipeline Is.

A field methodology for using MITRE ATLAS without turning an AI assessment into matrix theatre: map the production system, follow authority into tools and data, test reachable attack paths, and label the evidence only after impact is proven.

#methodology#pentest#attack-paths#cloud-security#ai-security
PentestJun 18, 202631 min read

Active Directory Hardening Is a Sequence, Not a Score

A scanner score cannot tell you whether a helpdesk account can still reach Domain Admin. This is the order I use to turn AD hardening signals into broken attack paths, tested controls, and recoverable identity infrastructure.

#active-directory#identity-security#attack-paths#methodology
Cloud SecurityApr 16, 20268 min read

The Pipeline Has No Secret. It Still Has a Cloud Identity.

Replacing static deployment keys with OIDC removes a credential from the repository. It does not decide which workflow deserves the resulting cloud role — that decision lives in the trust policy, and one wildcard can turn an organisation into a deployment API.

#cloud-security#identity-security#access-control#attack-paths
PentestMar 12, 202621 min read

AD CS ESC4: The Template Nobody Owned

How an ordinary AD CS permission becomes Domain Admin — and why ESC4 is the cause every ESC1 write-up skips.

#active-directory#identity-security#privilege-escalation#attack-paths
Web SecurityJan 29, 20269 min read

The Request Stayed Server-Side. The Credential Did Not.

SSRF severity is not the URL an application can fetch. It is the trust the outbound request inherits — network position, redirect behavior, DNS resolution, and access to metadata or control-plane identities. Test the route as a chain, not a blacklist.

#web-security#cloud-security#access-control#attack-paths
PentestDec 12, 20257 min read

Affiliates Do Not Find Novel Paths. They Find Yours.

Part three of testing the ransomware playbook: privilege escalation inside the domain uses a small, stable set of paths — the same ones already written up on this site — and the affiliate picks by reliability, not by cleverness.

#ransomware#active-directory#privilege-escalation#attack-paths
Cloud SecurityAug 14, 20259 min read

Cloud IAM Privilege Escalation: Every Permission Is Individually Fine. The Chain Is Not.

CSPM and least-privilege tools grade each IAM policy on its own, and on its own nearly every policy passes. Cloud privilege escalation is a path across roles, accounts, and trust — and a scanner that cannot see the path cannot flag the risk.

#cloud-security#identity-security#privilege-escalation#attack-paths
PentestJun 19, 20257 min read

BloodHound Path Triage: The Shortest Path Is Usually the One That Expires First

BloodHound draws every edge the same width, but a DACL lasts for years and a session lasts for minutes. Shortest-path queries are biased toward exactly the edges least likely to still be there when you walk them.

#active-directory#attack-paths#privilege-escalation#methodology
PentestApr 24, 20258 min read

Delegation Triage: You Were Taught the Rare One

Unconstrained delegation gets the diagrams. Resource-based constrained delegation is what you actually find — because it is not a checkbox anyone audits, it is a side effect of who can write to a computer object.

#active-directory#identity-security#privilege-escalation#attack-paths