Two anonymized excerpts from completed pentest engagements: industry and rough size are named; names, locations, and identifying details deliberately are not.
Anonymized: no client is identifiable by name or detail. Both cases were cleared with the respective client before publication.
A mid-sized manufacturing company with two plant locations commissioned a covert physical penetration test to realistically assess the effectiveness of perimeter security, access control, and its security guard service.
After several days of reconnaissance at both sites (observing access roads, barrier systems, and the guards’ patrol rhythm), two distinct attack paths emerged:
Site A: A structural weakness, a gap between the barrier and an adjacent wall wide enough to pass through, allowed repeated, unnoticed access to the company grounds without passing through the actual access control point.
Site B: After observing the patrol rhythm, the window in which the reception area (which also served as the guards’ post) was unattended was used. Access to the grounds was gained by crawling underneath the barrier; here too, the gap to the ground was wide enough to pass through unobstructed. From there, entry into the building was made through a previously identified window left in tilt position, its opening wide enough to force open quickly. It led into a room adjoining reception; the window was reset to its tilted position afterward to avoid leaving traces.
At the unattended reception desk, an unsecured key box was found, from which the cleaning service’s key was taken. This key also opened a number of interior doors. In addition, the guard service’s live camera feed was viewable at the same desk with no further access restriction, allowing real-time tracking of when the guards would return from their patrol and substantially widening the window for an unnoticed exit. The building was then left through the main entrance, opened with the stolen key and locked again afterward to restore the original state.
Documented as a further escalation path not pursued within the agreed scope: quickly duplicating the key before returning it would have enabled persistent, undetected physical access to the areas it unlocked.
Several independent physical weaknesses (a structural perimeter gap, an inadequately secured tilt window, an unsecured key box at a reception desk left unattended at times, and no access restriction on the camera feed) combined into full, undetected physical access, including a key that opened several interior doors. The company’s own security infrastructure, its camera surveillance, could also be turned against its own guard service to anticipate their movements.
Recommendations included structurally closing the perimeter gaps (barrier and tilt window), sound key management in place of the open key box, consistently keeping windows closed when rooms are unattended, and a mandatory screen-lock policy for unattended workstations. Actual implementation was coordinated with the client; specifics remain confidential under the engagement.
A larger healthcare-sector company commissioned an internal infrastructure pentest under an assumed-breach scenario: the starting point was an ordinary domain user account with no elevated privileges, the kind an attacker would typically obtain after a successful phishing campaign. The client actively ran SIEM/SOC monitoring throughout the test.
The environment’s Active Directory Certificate Services (AD CS) were found to contain a misconfiguration class known as “ESC8”: the internal certificate authority’s web enrollment service accepted certificate requests over HTTP without sufficient protection against NTLM relay attacks. By deliberately coercing NTLM authentication from a highly privileged account and relaying that authentication to the vulnerable enrollment endpoint, a client authentication certificate was issued in the name of that privileged account. This certificate then enabled full authentication as the compromised account – in this case, up to full Domain Admin privileges.
A single unprivileged standard user account was enough, via this path, to gain complete control over the entire Active Directory domain, a classic case of full domain compromise starting from minimal initial privileges. Despite active SIEM/SOC operations, the entire attack path went completely undetected and unalerted, a clear indicator of a detection gap around certificate-based AD CS attack techniques, which differ from the more classic, more heavily monitored privilege-escalation paths.
Recommendations included hardening the AD CS enrollment services against known ESC vulnerability classes (including securing/disabling HTTP enrollment and enforcing channel binding/Extended Protection for Authentication), a systematic review of all certificate templates for risky configurations, and, given the missed detection, targeted expansion of SIEM detection logic to cover AD CS/certificate-abuse indicators. Specific measures implemented by the client remain confidential under the engagement.
These cases are real excerpts – not templates. Every engagement is different. Reach out, no pressure.
Book a free consultation