Engagements we have actually run: what the client needed, how Nebula went about it, and what came out the other end. Everything identifying is stripped. No client names, no sectors, no domains, no addresses, no data.
What the client came to us for, and where the tooling they already had ran out of road.
How it worked the target, and the exploit chain in full where there was one worth showing.
Every surface in scope and the classes of issue tested against each.
UK Enterprise (anonymised) · Enterprise
We were asked to test a UK enterprise end to end: their public website, their external footprint, and a sizeable internal Windows and Linux estate running Active Directory. Nebula ran the whole engagement on its own and came back with more than 100 issues. Every one backed by evidence.
100+
Findings
Across external, web & internal
3
Surfaces Tested
External · Web · Internal / AD
Domain
Admin Achieved
Full AD compromise, confirmed
Like a lot of fast-growing businesses, they'd outgrown their tooling. Scanners covered the obvious external surface, but nobody had taken a proper look at the internal network or Active Directory in a while. They didn't want another wall of CVSS numbers. They wanted to know what a real attacker could actually do, and what to fix first.
Nebula went in black-box, with no inside knowledge, and worked across all three fronts at once. It mapped the attack surface, picked the right specialist for each job, ran real offensive tooling in a throwaway sandbox, and stitched individual weaknesses into full attack paths. Nothing destructive. And every finding came with the proof to back it up.
External & OSINT
Mapped the public footprint, exposed services, and edge configuration from the outside in. Zero prior knowledge.
Web Application
Authenticated and unauthenticated testing of the customer portal. Auth, access control, injection, and business logic.
Internal & Active Directory
Assessed the internal Windows/Linux estate and AD. Access, identity, segmentation, and privilege paths.
Prove & Report
Every finding validated with a real, non-destructive proof in a sandbox, scored with CVSS 4.0, and mapped to remediation.
From a single low-privileged account. No admin rights. Nebula chained six real weaknesses into full Active Directory compromise, executed live and non-destructively on production.
Low-privileged foothold
TA0001 · Initial AccessStarted from a single low-privileged domain account on an internal segment. No administrative rights at the outset.
Technique confirmed in a scoped engagement. Commands and identifiers withheld.
Anonymous enumeration
T1087 · Account DiscoveryAn unauthenticated SMB null session on a domain controller returned the full domain user list. Hundreds of accounts, with descriptions that flagged the privileged ones.
Technique confirmed in a scoped engagement. Commands and identifiers withheld.
Coercion → DC auth capture
T1187 · Forced AuthenticationDFSCoerce (MS-DFSNM) forced the domain controller’s machine account to authenticate to an attacker host; Responder captured its NetNTLMv1.
Technique confirmed in a scoped engagement. Commands and identifiers withheld.
Machine-account hash recovery
T1110 · Credential CrackingThe NetNTLMv1 response (static challenge) was cracked to recover the domain controller’s machine-account NT hash.
Technique confirmed in a scoped engagement. Commands and identifiers withheld.
Pass-the-hash DCSync
T1003.006 · DCSyncPass-the-hash as the DC machine account ran a DCSync that pulled every domain account hash, including krbtgt. All reached from the low-privileged start.
Technique confirmed in a scoped engagement. Commands and identifiers withheld.
Golden Ticket. Validated live
T1558.001 · Golden TicketA Golden Ticket forged offline from the krbtgt AES256 key (unrotated ~10 years) was validated live against the production domain controller. Full ADMIN$/C$/SYSVOL access. Then deleted per cleanup rules.
Technique confirmed in a scoped engagement. Commands and identifiers withheld.
Executed live on production (2026-05-14) from a single low-privileged account. No admin credentials at the start. The coercion → hash-recovery → pass-the-hash DCSync chain ran in about a minute (~15:00 BST); the Golden Ticket was forged and validated live against the production domain controller (11:12 BST), then deleted with no persistent artefacts. All identifiers (domain, hosts, IPs, accounts) are masked.
Web Application
Authentication, access control, injection, and multi-step business-logic testing.
Active Directory & Identity
Anonymous access, coercion surfaces, account hygiene, and privilege paths.
Network & Exposed Services
Open ports, cleartext protocols, unauthenticated data stores, and management interfaces.
Sensitive Data Exposure
Over-permissive files and logs containing sensitive operational data.
Hardening & Patch Hygiene
Password policy, end-of-life software, security headers, and misconfiguration.
External Footprint
Edge/WAF bypass exposure, header gaps, and information disclosure.
The full engagement produced 100+ findings with reproducible proof-of-concept steps, CVSS 4.0 scoring, and remediation mapped to OWASP, PCI-DSS, ISO 27001, and NIST. Delivered as a board- and auditor-ready report.
Same starting point every time: a domain, no inside knowledge, and the whole estate in scope. Web, mobile, cloud, APIs, internal networks and infrastructure. Findings arrive with the evidence behind them, and a UK engineer signs off every report before it reaches you.