Case Study - Attack Path Analysis (Connect the Dots Attackers Connect)

6 “mediums” nobody prioritized = 1 path from guest Wi-Fi to core banking DB. We walked it in staging.

ILLUSTRATION — PROVEN PATH (REDACTED)
📶 Guest Wi-Fi→ 🖨️ Printer panel→ 🔑 NTLM relay→ 🖥️ Jump host→ 💎 Core DB (read PoC)

Client Context

Manufacturing + finance conglomerate — corporate IT + plant OT + core banking subsidiary sharing IAM. Red team budget limited; needed to know which paths matter most.

Challenge

Single findings looked “medium”. Combined, they were critical. Need to link weaknesses into attack paths from entry point to critical assets — and prove which paths are real vs theoretical.

Scope - Snipeyes Attack Path Analysis

  • Identity + network + app graph: users, hosts, trusts, sessions, ACLs, vulns correlated
  • Path enumeration to crown jewels (DC, core DB, HMI, payment switch) ranked by steps + noise + controls
  • Controlled validation of top paths in lab/staging (no prod impact)
  • Output: attack paths with choke points + fix that breaks most paths cheapest

Key Findings (redacted)

  • 14 paths to Tier-0, 3 fully validated; cheapest break: 2 fixes (SMB signing + tiered admin) killed 11 paths
  • Guest Wi-Fi → printer → NTLM relay → jump host → DB read (6 mediums chained)
  • Service account with *ALLOBJ-equivalent + password in deployment script = instant domain path

Outcome

  • 2 fixes broke 79% of paths; remaining paths required 4+ steps with detection — SOC tuned to choke points
  • Board finally understood “medium” risk: one diagram did more than 40 pages
  • Path graph re-runs monthly; new paths alert within 24h of infra change

Relevance for you: If you fix findings one-by-one — map the paths and break the graph instead.