Truths from the Test
Welcome to the Aftermath Blog Series. Instead of a standard technical blog series diving deep into specific tools and commands to pop some kind of leet exploit, I wanted to write about what happens after. Rather than focusing on the technical details for security professionals, this series is geared toward the business side of things. I want to discuss the impact of what was found, how it was resolved, and some concerns that came up along the way.
This blog series is broken into four different entries, each highlighting a different security issue designed to tell the story of an attacker starting from the outside of a network and eventually completely compromising an organization. Admittedly, this didn’t all happen back-to-back on one client, but these are all actions that we at Red Siege—and I myself—have successfully performed many times. And like a bad episode of Dragnet—“The story you are about to see is true. The names have been changed to protect the innocent.”
The Phone Call
In this first entry, Jason explains how even the most seemingly well prepared organizations can fall victim to highly skilled social engineering tactics via – a phone call.
Explore this blog!
The Condition
Valid credentials in hand, here’s how a lack of conditional access policies allowed Jason to gain network access despite multifactor authentication being in use.
Explore this blog!
The Simple Stuff
After obtaining credentials, bypassing MFA, and gaining access to a VDI environment Jason explains how and why he established Command and Control.
Explore this blog!
The Vendor Requirement
In the final entry, we find out how a vendor requirement for Active Directory Certificate Services was leveraged to escalate into Domain Admin.
Explore this blog!After the Dust Settles
Overwhelmed with what to do in The Aftermath of receiving your penetration test report? Don’t panic! Check out this blog from CEO Tim Medin Essential Steps for Management to Maximize the Value of a Penetration Test Report