Skip to content

Bankowość i finanse

|

CS.105

Identity and Access Management System Testing

Penetration testing and configuration analysis of Active Directory, ADFS, and PKI at a critical infrastructure organization.

Client

Critical infrastructure organization of strategic importance to national security

Challenge

A breach of identity management systems - Active Directory, ADFS, and PKI - could lead to operational paralysis and a threat to national infrastructure. The client needed an objective security assessment of these systems.

Approach

01

Penetration testing

External and internal testing of AD, ADFS, and PKI systems.

02

Configuration analysis

Configuration review using Nessus and CIS Benchmark.

03

Consent Phishing test

Simulation of an attack where a user grants permissions to a fraudulent application - verifying resilience against this vector.

04

Reporting and workshops

Detailed report with findings and red/blue team workshops to enhance the client team's competencies.

Results

01

Objective security overview of AD, ADFS, and PKI

02

Detection of configuration gaps posing real threats

03

Remediation plan with prioritized actions

04

Enhanced team competencies through red/blue team workshops

We'll discuss scope, methodology, and timeline.

Book a consultation

Free consultation, no strings attached.