Case Studies

Sanitized reports from real engagements. Names and identifying details removed — the lessons remain.

Red Team Financial Services

Fortune 500 Bank — Domain Compromise in Under 4 Hours

Initial access via spearphish → credential harvesting → lateral movement → domain admin in 3h 47m. Zero detection by SOC or EDR.

Objective

Full adversary simulation targeting the organization's crown jewels — the core banking platform. Rules of engagement: no physical, no social engineering of executives.

Approach

Recon identified a misconfigured dev subdomain leaking internal email formats. Custom phishing payload bypassed email gateway using a zero-day in their email filtering appliance. Harvested credentials via fake SSO portal, pivoted through unpatched internal Jenkins server.

Impact

Achieved domain admin, demonstrated access to wire transfer systems and customer PII. Exfiltrated 2TB of simulated data through DNS tunneling without triggering DLP.

3h 47m Time to Domain Admin
0 SOC Alerts Triggered
14 Critical Findings
2TB Simulated Exfil

Outcome

Client restructured SOC monitoring, deployed network segmentation for banking systems, and implemented conditional access policies. Follow-up engagement showed 92% improvement in detection coverage.

Pentest Healthcare

Hospital Network — Critical Device Exposure

External pentest revealed direct access to IoMT devices, PACS systems, and patient records through a chain of 3 misconfigurations.

Objective

External and internal penetration test of a multi-hospital network spanning 12 facilities, 40,000+ endpoints, including IoMT (Internet of Medical Things) devices.

Approach

External scan revealed VPN concentrator with default credentials. Internal access led to flat network — medical devices, workstations, and servers all on the same VLAN. PACS server running unpatched DICOM service with anonymous access.

Impact

Demonstrated ability to access patient imaging data, modify treatment records, and interact with infusion pump controllers. Regulatory exposure: HIPAA, HITECH.

12 Facilities Tested
347 Vulnerable Devices
3 Misconfig Chain
CRITICAL Risk Rating

Outcome

Client implemented network segmentation isolating IoMT devices, replaced default credentials org-wide, and deployed medical device monitoring. Passed subsequent HIPAA audit with no critical findings.

Incident Response Technology / SaaS

SaaS Platform — Supply Chain Compromise Containment

Active intrusion via compromised CI/CD pipeline. Threat actor had persistent access for 6 weeks before detection. Full containment achieved in 72 hours.

Situation

Client detected anomalous API calls from their production environment. Initial investigation by their internal team was inconclusive. BLACKLABS was engaged for emergency incident response.

Investigation

Traced intrusion to a compromised GitHub Actions workflow. Threat actor injected a backdoor into a third-party dependency used in CI/CD pipeline. Persistent access via stolen service account tokens and modified container images in ECR.

Impact

Threat actor accessed customer data for ~800 accounts, exfiltrated API keys, and planted dormant ransomware scheduled to activate the following quarter.

6 wks Dwell Time
72h To Full Containment
800 Accounts Affected
1 Ransomware Defused

Outcome

Contained the threat actor, rotated all secrets, rebuilt CI/CD from scratch with signed commits and immutable build pipelines. Implemented SLSA Level 3 compliance. Client retained BLACKLABS for ongoing threat hunting.

Architecture Review Defense / Government

Government Agency — Zero Trust Transformation

Comprehensive security architecture review and Zero Trust implementation roadmap for a classified network environment.

Objective

Assess existing network architecture against NIST 800-207 (Zero Trust Architecture) framework and deliver an actionable implementation roadmap within budget constraints.

Approach

Conducted full architecture review including identity systems, network segmentation, data classification, and monitoring capabilities. Mapped current state against ZT maturity model. Red team validation of proposed architecture.

Deliverables

18-month phased roadmap, technical specifications for identity-aware proxies, microsegmentation design, and continuous verification architecture. All deliverables met FedRAMP and CMMC Level 3 requirements.

18mo Implementation Roadmap
NIST 800-207 Aligned
CMMC Level 3 Ready
85% Attack Surface Reduction

Outcome

Agency completed Phase 1 (identity and access management) ahead of schedule. Post-implementation red team showed 85% reduction in lateral movement pathways. Project cited as a model implementation by oversight body.

Want results like these?

Every engagement is unique. Let's discuss your specific security challenges and how our team can help.

Start a Conversation