Back to portfolio

Case study · 03 · Security assessment

DataKing Penetration Test

A structured external penetration test conducted exactly the way an attacker would: from public information and breached credentials to a valid login, internal network access, and a full professional findings report with remediation.

What I did

Think like an attacker, write like an engineer.

The goal was to evaluate an organization's external security posture the way a real attacker would — no inside knowledge, no allowances, just the public attack surface. Every phase followed a defined methodology, and every result fed a report the client could act on.

  • Planned the engagement around the NIST SP 800-115 Technical Guide to Information Security Testing, the OWASP Testing Guide (v4), and customized testing frameworks.
  • Gathered open-source intelligence, including employee information and historical breached credentials, to use against external login services.
  • Performed scanning and enumeration to identify vulnerabilities, then confirmed them through controlled exploitation.
  • Executed credential stuffing and password spraying attacks against the Outlook Web App, eventually gaining valid credentials and access to the internal network through the VPN portal.
  • Documented every finding with a CVSS-based severity rating, impact, affected system, and NIST control references.
  • Delivered a full findings report with step-by-step remediation: MFA on external services, restricted logon attempts, and a stronger password policy.

How the test unfolded

Four steps from public data to full access.

No single exploit broke the network. Three ordinary policy gaps — reused credentials, unrestricted attempts, and a guessable password pattern — chained together into a critical path.

01

Open-source intelligence

Collected historical breached-credential dumps and employee information tied to the company — 868 account credentials in total — and flagged the risk of staff reusing work emails as logins on other services.

02

Credential stuffing & enumeration

Tried the breached credentials against the Outlook Web App login. The stuffing attack itself failed, but inconsistent error messages allowed username enumeration — a list of valid accounts to aim the next attack at.

03

Password spraying

Tested a predictable seasonal password pattern (season + year + special character) against every valid account. Because logon attempts were unrestricted, the pattern eventually matched — yielding a successful login to OWA.

04

Internal network access

Leveraged the valid credentials to log into the client VPN portal, reaching the internal network — and demonstrating how three small gaps combine into a critical, full-compromise path.

Findings & remediation

Every weakness came with a fix.

Findings were rated by CVSS severity, tied to NIST control references, and paired with specific, prioritized remediation steps the IT team could implement.

Missing multi-factor authentication

High

VPN and OWA logins accepted valid credentials with no second factor. Recommendation: implement and enforce MFA across all external-facing login services.

Weak password policy

High

A seasonal password pattern succeeded against valid accounts. Recommendation: 14+ character passwords, unique per account, no dictionary words or proper names — plus employee training and checks against known-breached passwords.

Unrestricted logon attempts

Critical

Unlimited attempts on external logins made brute force and password guessing practical. Recommendation: restrict logon attempts and automatically lock accounts, per NIST SP 800-53 AC-7(1).

Username enumeration

Moderate

The login page revealed which accounts existed. Recommendation: synchronize valid and invalid account messages so failures are indistinguishable.

What the client did right: SIEM monitoring

The internal security team detected the vulnerability scanning within minutes, identified the attacker's IP address, and blacklisted it from further scanning. Detection and response worked — the gaps were in authentication policy, not visibility.

Assessment

External penetration test · Simulated attacker with no inside knowledge

Frameworks

NIST SP 800-115 · OWASP Testing Guide v4 · CVSS severity ratings

Findings

1 critical · 1 high · 1 moderate · 1 low · Informational

Deliverable

Security Assessment Findings Report with remediation plan

Skills applied

NIST SP 800-115OWASP Testing GuideOSINTVulnerability scanningCredential attacksCVSS scoringRemediation planningTechnical writing

Want the full picture?

This assessment sits alongside my broader security work — risk analysis, tooling, and systems.