Case Study - Threat-Based Testing (Test Like Your Actual Adversary)

Generic pentest: “all good”. Threat-based test using the ransomware crew targeting Indonesian banks: domain admin in 2 days.

ILLUSTRATION — INTEL → SCENARIO → TEST
🕵️
INTEL
Sector TTPs
→
🎭
SCENARIO
ATT&CK chain
→
🎯
TEST
Emulate & validate

Client Context

Commercial bank — recently named in ransomware leak-site chatter targeting SEA finance. Board asked: “could they get in?” Existing VA said patched.

Challenge

Use threat intelligence and adversary TTPs (MITRE ATT&CK) as the basis for test scenarios — not generic checklists — covering initial access → persistence → exfiltration → impact relevant to banking.

Scope - Snipeyes Threat-Based Testing

  • Intel profiling: finance-sector crews, brokers, recent Indonesian incidents; TTP shortlist (phishing, VPN exploit, LOLBins, AD abuse, exfil over DNS/HTTPS)
  • 4 scenarios: phishing-led, VPN-exploit-led, vendor-led, insider-led — scoped, authorized, monitored with SOC (purple-team option)
  • Detection + prevention measured per TTP (blocked / alerted / missed)
  • Output: threat-informed test cases + detection-gap matrix

Key Findings (redacted)

  • Phishing → DA in 26h: Macro-less LNK + Teams message bypassed filter; AMSI bypass → Colek kredensial → unconstrained delegation → DA (SOC missed 7 of 11 steps)
  • VPN path: Patched version but stale STUN/TURN exposed same AD creds via NTLM relay
  • Mean detection time 9h; 2 persistence mechanisms survived “remediation” reboot drill

Outcome

  • EDR policy + mail gateway + AD hardening (delegation, LAPS, tiering) — re-run blocked at step 2 with SOC alert in 11 min
  • Detection rules + runbooks shipped for the 7 missed TTPs; tabletop with board risk committee
  • Quarterly threat-profile refresh now drives test plan

Relevance for you: If your threat is a specific crew, not “hackers generally” — test their playbook.