ACME Bank — External perimeterENG · ACME-EXT-04
Authorized
SR
Always on
Continuously checking · iterating · chaining — last pass 2s ago
1,247Assets watched
3,204Checks today
128Chains explored
6Exploits validated
41,980Iterations total
Critical path · awaiting you ACME-EXT-04 · external perimeter · chain F-118

One chain reaches your customer-records database. Four hops proven, one waiting on you.

Five findings that are only Medium on their own. The operator connected them, validated every hop with the least-intrusive check available — and stopped before the last one, because confirming it touches your systems.

8Critical
3Proven chains
1,247Assets swept
1Needs you
1,247assets swept
22under active test
Operator active
Live attack paths3 reach a crown jewel · 1 held for you
Reaches

Customer records DB

Held
01 · Initial accessValidated
vpn-old.acme.sa
Citrix Bleed CVE-2023-49669.4
02 · ExecutionValidated
jenkins-ci.acme.sa
Log4Shell CVE-2021-4422810.0
03 · Lateral moveConfirmed
Reused CI token → cloud tenant
Credential reuse · non-destructive
04 · ObjectiveAwaiting you
records-db-01.acme.sa
2.4M customer records · NOT REACHED
Reaches

Domain Admin

Priv-esc
01 · Credential access3 / 47 cracked
dc01.corp.acme.sa
Kerberoast · offline · non-destructive
02 · DiscoveryFlagged
pki-ca01.corp.acme.sa
AD CS · ESC1 template · SAN-specifiable
03 · Privilege escalationIn progress
Enrol cert as alt subject
low-priv user → DA identity
04 · ObjectiveGated
Domain Admin
DA cert request · awaiting approval
Reaches

Internal knowledge base

Chaining
01 · Prompt injectionIngested
copilot.acme.sa
Indirect injection LLM01 via retrieved doc
02 · Info disclosureConfirmed
System prompt + tool schema
Sensitive disclosure LLM06
03 · Excessive agencyTesting 22 / 140
Unsafe tool-use
Agent tool-call abuse LLM08
04 · ObjectiveProbing
Internal knowledge base
Unscoped retrieval · read-only
Sweeping 1,247 assets · 3,204 checks today · nothing intrusive runs without you

AI reasoning core

Reasoning · chaining
Reasoning
local model · zero egress · in-Kingdom
2,140Hypotheses evaluated
128Candidate chains
1,247Assets modelled
18.4kTokens / sec
Live reasoning stream
Working hypothesis Dangling CNAME on promo-bf.acme.sa → subdomain takeover → phishing-trusted origin conf82%

Exploit chain — internet → domain crown jewel

Open chain graph
5 findings that are only Medium on their own chain into one Critical path to the customer-records database. No single scanner would have connected them.
01 · Recon
Forgotten asset
CT-log discovery
vpn-old.acme.sa — legacy Citrix, still resolvable
Mapped
02 · Initial access
Session hijack
CVE-2023-4966 · 9.4
Citrix Bleed on the EOL gateway
Validated
03 · Execution
Foothold on CI
CVE-2021-44228 · 10.0
Log4Shell on an internal Jenkins
Validated
04 · Lateral
Reused service token
Credential reuse
CI token also valid in the cloud tenant
Chaining now
05 · Priv-esc
Over-privileged role
IAM misconfiguration
deploy-bot role → data-plane access
Awaiting approval
06 · Objective
Customer records DB
Crown jewel
2.4M records — impact if reached
Not reached

Attack surface intelligence

accumulated over ~14 years · continuously re-mapped
1,247DNS records
341Subdomains
58Live services
23EOL / legacy
9Dangling DNS
6Shadow IT
9 subdomain-takeover-prone 23 end-of-life software 11 exposed non-prod 17 expired TLS 3 public storage
vpn-old.acme.safirst seen 2018 · owner unknownCitrix NetScaler · EOL firmwareExploitable CVE
legacy-blog.acme.safirst seen 2014 · marketing (former)WordPress 4.2.1 · 14 plugin CVEsEnd-of-life
promo-bf.acme.saCNAME → deleted S3 bucketDangling CNAMETakeover-prone
jenkins-ci.acme.sainternal-ish · internet-reachableJenkins · Log4j presentRCE · in chain
autodiscover.acme.safirst seen 2013Exchange 2013 · unpatchedProxyShell
staging-payments.acme.sanon-prod · exposedStaging env · debug onInternet-reachable
wiki-2019.acme.safirst seen 2019Confluence · unpatchedOGNL RCE
ftp.acme.safirst seen 2014Plaintext FTPCleartext creds
app-ios-beta.acme.saCNAME → dead Heroku appDangling CNAMETakeover-prone
careers-2019.acme.saorphaned micrositeUnmanaged · no ownerShadow IT
s3-acme-backupspublic ACLObject storage · readablePublic exports
intranet-old.acme.safirst seen 2015Forgotten intranet · expired TLSExpired cert

High & critical CVEs found

CVSS 7.0–10.0 · 8 of 34 shown
CVSSCVEVulnerabilityAssetStatus
10.0CVE-2021-44228Apache Log4j2 RCE “Log4Shell” KEVIn chainjenkins-ci.acme.saValidated
10.0CVE-2017-5638Apache Struts2 content-type RCE KEVapps-legacy.acme.saFound
9.8CVE-2023-34362MOVEit Transfer SQLi → RCE KEVfiletransfer.acme.saAwaiting approval
9.8CVE-2021-34473MS Exchange “ProxyShell” KEVautodiscover.acme.saFound
9.8CVE-2019-0708RDP “BlueKeep” pre-auth RCE KEVts-old.acme.saFound
9.8CVE-2022-26134Atlassian Confluence OGNL RCE KEVIn chainwiki-2019.acme.saIn chain
9.4CVE-2023-4966Citrix NetScaler “Citrix Bleed” KEVWeaponizedvpn-old.acme.saValidated
7.5CVE-2014-3704Drupal “Drupalgeddon” SQLi KEVnews-cms.acme.saFound

Awaiting your approval

1 gate
Human approval required

Advance chain step 05 — priv-esc

The operator wants to confirm the over-privileged deploy-bot role reaches the records data-plane. It will use the least-intrusive read-only check.

Non-destructive · no data read or exfiltrated

Operator activity

Live
Chaining — testing reused CI token against cloud tenant
now · step 04 of proven chain
Awaiting approval to advance chain step 05Gate
1m ago · needs operator sign-off
Validated CVE-2021-44228 on jenkins-ci — foothold confirmed10.0
4m ago · non-destructive
9 dangling DNS records flagged — subdomain-takeover risk
7m ago · continuous re-map
341 subdomains recovered from certificate-transparency logsDone
12m ago · read-only
Retest passed — F-102 remediation verified, finding closed
31m ago · now remediated

Findings by severity

34 open
Critical8
High9
Medium10
Low7

Coverage by layer

this engagement
Recon & surface98%
Web & app logic84%
Identity & access72%
Cloud posture68%
AI / LLM systems45%