Skip to main content
Real engagements

Penetration testing case studies,
written up in full.

Engagements we have actually run: what the client needed, how Nebula went about it, and what came out the other end. Everything identifying is stripped. No client names, no sectors, no domains, no addresses, no data.

The format

Every study follows the same three-part structure.

The challenge

What the client came to us for, and where the tooling they already had ran out of road.

What Nebula did

How it worked the target, and the exploit chain in full where there was one worth showing.

Areas covered

Every surface in scope and the classes of issue tested against each.

UK Enterprise (anonymised) · Enterprise

Full-SpectrumWeb · Internal · ADBlack-BoxProven Exploits

Full-Spectrum Assessment. External, Web & Internal

We were asked to test a UK enterprise end to end: their public website, their external footprint, and a sizeable internal Windows and Linux estate running Active Directory. Nebula ran the whole engagement on its own and came back with more than 100 issues. Every one backed by evidence.

100+

Findings

Across external, web & internal

3

Surfaces Tested

External · Web · Internal / AD

Domain

Admin Achieved

Full AD compromise, confirmed

The challenge

Like a lot of fast-growing businesses, they'd outgrown their tooling. Scanners covered the obvious external surface, but nobody had taken a proper look at the internal network or Active Directory in a while. They didn't want another wall of CVSS numbers. They wanted to know what a real attacker could actually do, and what to fix first.

What Nebula did

Nebula went in black-box, with no inside knowledge, and worked across all three fronts at once. It mapped the attack surface, picked the right specialist for each job, ran real offensive tooling in a throwaway sandbox, and stitched individual weaknesses into full attack paths. Nothing destructive. And every finding came with the proof to back it up.

External & OSINT

Mapped the public footprint, exposed services, and edge configuration from the outside in. Zero prior knowledge.

Web Application

Authenticated and unauthenticated testing of the customer portal. Auth, access control, injection, and business logic.

Internal & Active Directory

Assessed the internal Windows/Linux estate and AD. Access, identity, segmentation, and privilege paths.

Prove & Report

Every finding validated with a real, non-destructive proof in a sandbox, scored with CVSS 4.0, and mapped to remediation.

Proof: Full Domain Takeover

Confirmed executed

From a single low-privileged account. No admin rights. Nebula chained six real weaknesses into full Active Directory compromise, executed live and non-destructively on production.

  1. 1

    Low-privileged foothold

    TA0001 · Initial Access

    Started from a single low-privileged domain account on an internal segment. No administrative rights at the outset.

    Technique confirmed in a scoped engagement. Commands and identifiers withheld.

  2. 2

    Anonymous enumeration

    T1087 · Account Discovery

    An unauthenticated SMB null session on a domain controller returned the full domain user list. Hundreds of accounts, with descriptions that flagged the privileged ones.

    Technique confirmed in a scoped engagement. Commands and identifiers withheld.

  3. 3

    Coercion → DC auth capture

    T1187 · Forced Authentication

    DFSCoerce (MS-DFSNM) forced the domain controller’s machine account to authenticate to an attacker host; Responder captured its NetNTLMv1.

    Technique confirmed in a scoped engagement. Commands and identifiers withheld.

  4. 4

    Machine-account hash recovery

    T1110 · Credential Cracking

    The NetNTLMv1 response (static challenge) was cracked to recover the domain controller’s machine-account NT hash.

    Technique confirmed in a scoped engagement. Commands and identifiers withheld.

  5. 5

    Pass-the-hash DCSync

    T1003.006 · DCSync

    Pass-the-hash as the DC machine account ran a DCSync that pulled every domain account hash, including krbtgt. All reached from the low-privileged start.

    Technique confirmed in a scoped engagement. Commands and identifiers withheld.

  6. 6

    Golden Ticket. Validated live

    T1558.001 · Golden Ticket

    A Golden Ticket forged offline from the krbtgt AES256 key (unrotated ~10 years) was validated live against the production domain controller. Full ADMIN$/C$/SYSVOL access. Then deleted per cleanup rules.

    Technique confirmed in a scoped engagement. Commands and identifiers withheld.

Executed live on production (2026-05-14) from a single low-privileged account. No admin credentials at the start. The coercion → hash-recovery → pass-the-hash DCSync chain ran in about a minute (~15:00 BST); the Golden Ticket was forged and validated live against the production domain controller (11:12 BST), then deleted with no persistent artefacts. All identifiers (domain, hosts, IPs, accounts) are masked.

Areas covered

Web Application

Authentication, access control, injection, and multi-step business-logic testing.

Active Directory & Identity

Anonymous access, coercion surfaces, account hygiene, and privilege paths.

Network & Exposed Services

Open ports, cleartext protocols, unauthenticated data stores, and management interfaces.

Sensitive Data Exposure

Over-permissive files and logs containing sensitive operational data.

Hardening & Patch Hygiene

Password policy, end-of-life software, security headers, and misconfiguration.

External Footprint

Edge/WAF bypass exposure, header gaps, and information disclosure.

The full engagement produced 100+ findings with reproducible proof-of-concept steps, CVSS 4.0 scoring, and remediation mapped to OWASP, PCI-DSS, ISO 27001, and NIST. Delivered as a board- and auditor-ready report.

Find out what it turns up on yours.

Same starting point every time: a domain, no inside knowledge, and the whole estate in scope. Web, mobile, cloud, APIs, internal networks and infrastructure. Findings arrive with the evidence behind them, and a UK engineer signs off every report before it reaches you.