Simulated Digital Cyber Attack
We plugged a device into their network with nothing. No credentials, no map, no inside knowledge. Over five days we watched the traffic, captured dozens of passwords, and cracked them. By Friday, we had Domain Admin. Not a single alert fired all week. This is what an attacker does when no one's looking.
The one where we went from no credentials to domain admin
We plugged a device into their network with nothing. No credentials, no map, no inside knowledge. Over five days we…
The one where a JavaScript file handed us the keys
During an OSINT engagement, we found a forgotten login page still pulling a JavaScript file. Inside: admin credentials in plain…
The one where “don’t get caught” was the only rule
Two VMs. One rule: don't get caught. We exploited a single overlooked UDP port, tunnelled in via WireGuard, and pulled…
The one where a Slack message became a supply chain backdoor
A GitHub Personal Access Token posted in Slack. Left exposed since July 2024. That's all it took to compromise an…