UnlockSec

Sample Assessment Report

Redacted for confidentiality

Q2 2025

Red Teaming

Adversarial Simulation & Red Team Operations

Client

Confidential Client — Tier 1 Financial Institution

Scope

Full organisation — internet-facing infrastructure, social engineering (phishing + vishing), physical access attempts (2 offices), internal network post-compromise, Active Directory environment, cloud estate (AWS)

Duration

30 business days

Standard

MITRE ATT&CK Enterprise v14

Executive Summary

UnlockSec conducted a 30-day intelligence-led red team operation simulating an advanced persistent threat (APT) actor targeting the organisation's core banking systems. The red team achieved initial access via a targeted spear-phishing campaign, escalated to Domain Admin within 11 days, accessed the SWIFT transaction system, and exfiltrated a simulated dataset equivalent to 2 years of transaction records — all without detection by the internal security team or SOC.

Methodology

MITRE ATT&CK Enterprise v14TIBER-EU FrameworkCBEST Intelligence-Led TestingCustom C2 Infrastructure (OPSEC-hardened)

Sample Findings

RT-001

Initial Access — Spear-Phishing with Credential Harvesting

Critical

Description

A targeted spear-phishing campaign leveraging LinkedIn reconnaissance achieved credential capture for 3 employees (12% success rate). The campaign used a convincing Microsoft 365 login page with organisation-specific branding. MFA was present but bypassed using an adversary-in-the-middle (AiTM) proxy that relayed session cookies in real time.

Recommendation

Deploy phishing-resistant MFA (FIDO2 hardware keys or passkeys) for all privileged and remote access users. Implement anti-phishing browser extensions and enforce managed device policies. Conduct quarterly phishing simulations with tailored, role-specific lures.

RT-002

Privilege Escalation — Domain Admin in 11 Days

Critical

Description

From initial foothold on a workstation, the red team achieved Domain Administrator through a chain: Kerberoasting a service account (SPN) → cracking the RC4-encrypted ticket → pivoting to a server with unconstrained delegation → DCSync attack extracting all domain credential hashes. The entire escalation path was completed without triggering any EDR or SIEM alerts.

Recommendation

Disable RC4 for Kerberos authentication (enforce AES256). Identify and remediate all unconstrained delegation configurations. Enable Protected Users security group for all privileged accounts. Implement Tiered Administration model.

RT-003

Mission Success — SWIFT System Access Achieved

Critical

Description

Using domain admin credentials, the red team accessed the SWIFT Alliance Access server, authenticated using harvested operator credentials, and simulated the initiation of a high-value international transfer (testing-flagged, not executed). The SWIFT system lacked dedicated Privileged Access Workstations and operator session monitoring.

Recommendation

Implement Privileged Access Workstations (PAWs) for all SWIFT operator access. Deploy SWIFT Customer Security Programme (CSP) controls in full. Enable out-of-band transaction verification for all high-value transfers. Implement SWIFT inspector monitoring.

RT-004

Data Exfiltration — 2 Years of Transaction Records Undetected

Critical

Description

A simulated dataset equivalent to 2 years of transaction records (14GB) was staged and exfiltrated over 3 days via encrypted HTTPS to an attacker-controlled cloud storage bucket, using DNS tunnelling as a secondary channel. No DLP alert, proxy alert, or network detection alert was generated throughout the exfiltration.

Recommendation

Deploy data loss prevention (DLP) with financial record fingerprinting. Implement strict egress filtering — block uploads to personal/unmanaged cloud storage. Enable network behaviour analytics to detect volumetric data transfers. Configure UEBA rules for after-hours bulk data access.

* Showing 4 of 35 total findings. Full report provided upon engagement.

Risk Summary

Critical7
High12
Medium9
Low4
Info3
Total Findings35

Deliverables Included

  • Full red team narrative report (attack timeline, kill chain, evidence)
  • MITRE ATT&CK Navigator heatmap of all techniques employed
  • Executive briefing deck (board-level, non-technical)
  • Detection gap analysis with SOC tuning recommendations
  • Purple team debrief workshop (red team + blue team joint session)
  • Unlimited retests on all critical findings

Ready for a real assessment?

Get a tailored Red Teaming engagement led by certified operators with unlimited retests.

Request AssessmentView All Services