Network Testing Web App Recon

Meridian Bank — External Network Assessment

A regional bank asked me a simple question: what can the internet reach? Four weeks later I handed them a path from a forgotten marketing subdomain to domain admin — and a plan to close it for good.

Bank building exterior mapped during perimeter enumeration

The challenge

Years of mergers had left the bank with a sprawling perimeter: legacy VPN concentrators, a marketing site nobody owned, and MFA rolled out everywhere except the three systems that mattered most. Previous automated scans reported "no criticals" — leadership suspected the scanners were missing the seams between systems.

My approach

I enumerated 400+ subdomains and certificate-transparency records, found an unclaimed marketing subdomain pointing at a decommissioned host, and used it to harvest session tokens from a legacy SSO flow. From there: password-spray against the VPN (no lockout), LLMNR poisoning on a misconfigured segment, and a Kerberoasting chain that ended at a backup-service account with domain replication rights.

  • 11 validated findings: 3 critical, 5 high, 3 medium — zero scanner-only noise.
  • Full attack-path graph from internet to domain admin, step by step.
  • Detection notes handed to the SOC for every technique used.
Hacker typing on a laptop while documenting validated attack paths

The outcome

All three criticals were remediated within one quarter and verified in a free retest. The bank retired 60% of its public-facing hosts, enforced phishing-resistant MFA on every remote entry point, and now runs this assessment annually before audit season.

Operation facts

  • Sector: regional banking, 2,000+ employees.
  • Duration: 4 weeks, external-only.
  • Services: network testing, web app testing, recon.
  • Retest: all criticals closed and verified.

Related operation

Worried about your perimeter?

Find out what the internet can reach — before someone else does.

Start Your Assessment