Skip to main content

Research notes

Notes from the engagements we are allowed to talk about.

Written by the consultants running the work, anonymised so we can be specific about technique without being specific about clients. No product announcements, no recycled vendor content.

  • Attack Surface

    7 min read

    Your attack surface drifts faster than your test cycle

    An annual penetration test measures the estate as it stood on one morning in March. Cloud accounts, DNS records and third party integrations change every week, so the gap between that report and reality starts widening the day it is delivered. Continuous discovery is what keeps the gap small.

    Read the note

    Principal Security Consultant

  • Engagement Design

    8 min read

    Red team or penetration test: choosing the right engagement

    A penetration test asks how much of a system is broken. A red team engagement asks whether anyone would notice a competent operator coming for a specific objective. Choosing the wrong one wastes the budget and produces a report nobody can act on.

    Read the note

    Red Team Practice Lead

  • Internal Testing

    8 min read

    Five Active Directory misconfigurations that hand over domain admin

    Most internal assessments reach domain admin through configuration rather than a missing patch. Kerberoastable service accounts, permissive certificate templates, wide delegation, available NTLM relay and forgotten access control entries account for most of the paths we walk. All five are fixable in house.

    Read the note

    Lead Penetration Tester

  • Reporting

    6 min read

    Writing a penetration test report engineers will act on

    A report sorted by CVSS and delivered on a Friday afternoon has done half the job. What decides whether anything gets fixed is whether an engineer can reproduce the finding in ten minutes and knows exactly which change makes it go away. That is a writing problem more than a testing one.

    Read the note

    Head of Application Security

  • Supply Chain

    7 min read

    Your build pipeline is the internal network nobody tests

    The build pipeline holds cloud credentials, registry push rights and signing material, and it runs code that dozens of people can change. External tests stop at the perimeter and internal tests start on the corporate network, so the pipeline is usually the most privileged environment nobody has assessed.

    Read the note

    Cloud Security Consultant

  • Social Engineering

    6 min read

    Phishing simulations that teach instead of punish

    A simulation that produces a click rate and a list of names measures people instead of teaching them. We design campaigns around report rate, one specific lesson per lure, and a written agreement that no individual result reaches a manager. The programme gets quieter and the reporting gets faster.

    Read the note

    Social Engineering Lead

Start here

Want this run against your own environment?

Most of these notes started as a finding in an estate that looked well managed from the outside. If any of them sound uncomfortably familiar, that is usually a good reason to book a scoping call.