Meridian Bank — External Network Assessment
A regional bank asked me a simple question: what can the internet reach? Four weeks later I handed them a path from a forgotten marketing subdomain to domain admin — and a plan to close it for good.
The challenge
Years of mergers had left the bank with a sprawling perimeter: legacy VPN concentrators, a marketing site nobody owned, and MFA rolled out everywhere except the three systems that mattered most. Previous automated scans reported "no criticals" — leadership suspected the scanners were missing the seams between systems.
My approach
I enumerated 400+ subdomains and certificate-transparency records, found an unclaimed marketing subdomain pointing at a decommissioned host, and used it to harvest session tokens from a legacy SSO flow. From there: password-spray against the VPN (no lockout), LLMNR poisoning on a misconfigured segment, and a Kerberoasting chain that ended at a backup-service account with domain replication rights.
- 11 validated findings: 3 critical, 5 high, 3 medium — zero scanner-only noise.
- Full attack-path graph from internet to domain admin, step by step.
- Detection notes handed to the SOC for every technique used.
The outcome
All three criticals were remediated within one quarter and verified in a free retest. The bank retired 60% of its public-facing hosts, enforced phishing-resistant MFA on every remote entry point, and now runs this assessment annually before audit season.
Operation facts
- Sector: regional banking, 2,000+ employees.
- Duration: 4 weeks, external-only.
- Services: network testing, web app testing, recon.
- Retest: all criticals closed and verified.
Related operation
Worried about your perimeter?
Find out what the internet can reach — before someone else does.