Case Study - Threat-Based Testing (Test Like Your Actual Adversary)
Generic pentest: “all good”. Threat-based test using the ransomware crew targeting Indonesian banks: domain admin in 2 days.
INTEL
Sector TTPs
SCENARIO
ATT&CK chain
TEST
Emulate & validate
Client Context
Commercial bank — recently named in ransomware leak-site chatter targeting SEA finance. Board asked: “could they get in?” Existing VA said patched.
Challenge
Use threat intelligence and adversary TTPs (MITRE ATT&CK) as the basis for test scenarios — not generic checklists — covering initial access → persistence → exfiltration → impact relevant to banking.
Scope - Snipeyes Threat-Based Testing
- Intel profiling: finance-sector crews, brokers, recent Indonesian incidents; TTP shortlist (phishing, VPN exploit, LOLBins, AD abuse, exfil over DNS/HTTPS)
- 4 scenarios: phishing-led, VPN-exploit-led, vendor-led, insider-led — scoped, authorized, monitored with SOC (purple-team option)
- Detection + prevention measured per TTP (blocked / alerted / missed)
- Output: threat-informed test cases + detection-gap matrix
Key Findings (redacted)
- Phishing → DA in 26h: Macro-less LNK + Teams message bypassed filter; AMSI bypass → Colek kredensial → unconstrained delegation → DA (SOC missed 7 of 11 steps)
- VPN path: Patched version but stale STUN/TURN exposed same AD creds via NTLM relay
- Mean detection time 9h; 2 persistence mechanisms survived “remediation” reboot drill
Outcome
- EDR policy + mail gateway + AD hardening (delegation, LAPS, tiering) — re-run blocked at step 2 with SOC alert in 11 min
- Detection rules + runbooks shipped for the 7 missed TTPs; tabletop with board risk committee
- Quarterly threat-profile refresh now drives test plan
Relevance for you: If your threat is a specific crew, not “hackers generally” — test their playbook.