Field Notes
Anonymised findings and attack paths from real StrikeCyber engagements. Practical intelligence, no client identifiers.
Field Notes: The Air Gap That Was Not There
An anonymised field note on an IT to OT attack path: how flat segmentation, a dual-homed host and shared credentials let a corporate network reach an OT environment everyone believed was air-gapped, and how to safely prevent it.
Field Notes: Phishing That Bypassed MFA
An anonymised red team field note on phishing that bypasses MFA: how an adversary-in-the-middle proxy captured a live session token, what it reached, and the controls that would have stopped it.
Field Notes: SSRF to Cloud Takeover
An anonymised web and cloud engagement against a mid-market fintech where a single server-side request forgery flaw reached the cloud metadata endpoint, harvested temporary credentials and opened a path toward full account takeover. Here is how the SSRF cloud metadata attack unfolded, and the layered controls that would have contained it.
Field Notes: Domain Admin in a Day
An anonymised internal engagement against a national logistics firm where our operators moved from a single low-privileged foothold to full Domain Admin control inside a working day. Here is how attackers reach domain admin, what went wrong, and the practical controls that would have broken the chain.
Ready to take the offensive?
StrikeCyber specialises in penetration testing and red teaming engagements that deliver actionable findings. Connect with us for a free consultation.
No obligation, no sales pressure. A senior operator replies within one business day.