Fortune 500 Bank — Domain Compromise in Under 4 Hours
Initial access via spearphish → credential harvesting → lateral movement → domain admin in 3h 47m. Zero detection by SOC or EDR.
Objective
Full adversary simulation targeting the organization's crown jewels — the core banking platform. Rules of engagement: no physical, no social engineering of executives.
Approach
Recon identified a misconfigured dev subdomain leaking internal email formats. Custom phishing payload bypassed email gateway using a zero-day in their email filtering appliance. Harvested credentials via fake SSO portal, pivoted through unpatched internal Jenkins server.
Impact
Achieved domain admin, demonstrated access to wire transfer systems and customer PII. Exfiltrated 2TB of simulated data through DNS tunneling without triggering DLP.
Outcome
Client restructured SOC monitoring, deployed network segmentation for banking systems, and implemented conditional access policies. Follow-up engagement showed 92% improvement in detection coverage.