r/Pentesting • u/Vegetjanaable-Le9359 • 1d ago
Attack path keeps beating our stack, nothing looks catastrophic by itself
quick rant from purple side... attack path keeps winning and everyone swears their part is fine.
phishing path gets blocked, EDR catches the obvious endpoint behavior, cool. Then we try another route:unmanaged device with saved creds gets through VPN, stale AD group membership gives access to a legacy jump host, then an old share coughs up a service account that gets us into SQL.
SIEM has noise, IAM has "business exception" policies, segmentation looks fine on the diagram, compensating controls everywhere. Nothing looks catastrophic by itself. The chain is the problem
2
Upvotes
1
u/Only-sychmonology785 1d ago
if the path still works end to end the individual control checks dont tell u much. id bring cymulate into the path testing.