Skip to main content
All insights
Assumed BreachActive DirectoryDetection & Response

Anatomy of an Assumed Breach: 96 Hours Inside an Enterprise Network

X-Gen Research TeamJun 18, 20269 min read

The first hour

Every assumed-breach engagement begins where a real one usually does: an ordinary workstation, ordinary credentials, and no special access. The initial-access phase is a solved problem for motivated adversaries — a matter of time and budget — so we skip it and spend the engagement measuring what actually matters: how far a foothold travels and how fast anyone notices.

The first hour is pure situational awareness, and it is deliberately quiet. Before touching anything noisy, we map what the compromised identity can already see: group memberships, reachable shares, cached credentials, and the trust relationships that the endpoint exposes for free. Most of this is read-only and blends perfectly into a normal working day.

Mapping the terrain

With a foothold established, we build a graph of the environment. Tooling like BloodHound turns thousands of individual permissions into a small number of attack paths — the shortest routes from where we are to where we want to be. In most enterprises those paths are surprisingly short, because privilege accretes over years and no one prunes it.

Two classic techniques do most of the work here: abusing misconfigured access-control entries, and Kerberoasting service accounts whose passwords never rotate. Neither requires exploiting a software vulnerability. They exploit configuration — the accumulated 'temporary' exceptions that became permanent.

The quiet escalation

Lateral movement is where discipline separates a red team from a smash-and-grab. We move along the paths the graph revealed, harvesting credentials from memory and the local secret stores as we go, always preferring techniques that look like legitimate administration over ones that trip obvious alarms.

The recurring failure we find is tiering: administrative accounts that log into ordinary workstations, leaving high-value credentials sitting in memory on machines an attacker reaches early. Once tier-0 and tier-1 identities mix on the same host, escalation stops being a challenge and becomes a formality.

What the SOC saw

The most valuable artifact from an assumed breach is not the attack path — it is the comparison between the attacker timeline and the defender timeline. We reconstruct both, hour by hour, and lay them side by side. The gaps between 'we did X' and 'a detection fired for X' are the findings that change budgets.

Frequently the telemetry existed but nothing acted on it: the logs were collected, the alert never fired, or it fired into a queue no one triaged. Visibility without response is not detection — it is archaeology.

Closing the gap

The remediation story is rarely 'buy another tool.' It is tiered administration enforced properly, credential hygiene on privileged accounts, honeytokens and canaries seeded along the exact paths we walked, and detections written against the specific techniques we used — then validated by re-running them.

That last step is the point of working with an offensive team that also does defense: the findings become detections, and a purple-team retest proves the detections actually fire. An assumed breach that ends in a PDF is half an engagement. One that ends in validated coverage is the whole thing.

About X-Gen Research

Field notes from across the X-Generation Cyber Labs practice — drawn from real engagements, sanitized for publication.

Meet the team

Curious about your security posture? We'll identify potential weaknesses and walk you through them. No obligation, no sales theater.