Tier-2 user → ADCS ESC1 → DA
Tier-0 reach proven; ransomware blast radius modelled
Walk the same paths an attacker would once they have a foothold — Active Directory, Entra ID, Linux estates and segmented networks — production-safe and evidence-backed.
Annual pentests sample. Tier-0 assumptions go unchecked for months. Service accounts accumulate privilege; ADCS templates drift; jump-host hygiene erodes. None of it surfaces until ransomware finds the path.
The gap is not detection. It is validation that the controls actually break the chain.
KeenSafe internal agents operate from a low-privileged starting point and reason about lateral movement, credential abuse and privilege escalation against your real environment.
Every validated chain ships with full reproducibility — exact technique, exact path, exact evidence.
Tier-0 / Tier-1 / Tier-2 boundaries tested in practice — domain controllers, service accounts, jump hosts, admin tier crossings.
NTLM relay, Kerberos delegation, SMB / RPC / WinRM hopping, jump-host abuse — chained end-to-end.
Local-to-DA chains. Kerberoasting, AS-REP roasting, ADCS ESC1–ESC11, golden-ticket validation.
Cloud-to-on-prem trust paths, Conditional Access bypass, federated identity abuse, OAuth permission elevation.
SSH key reuse, sudo misconfig, capabilities abuse, container escape, LDAP-bound user enumeration.
East-west segmentation tested with real exploitation — VLAN hopping, ACL bypass, microsegmentation evasion.
Internal attack paths nearly always abuse identity. The interesting question is which combination of cred reuse, delegation abuse, ADCS misconfig and trust crossing chains end-to-end in your environment, today.
Tier-0 reach proven; ransomware blast radius modelled
Linux foothold reaches Windows DC via federated identity
Most environments find at least one Tier-0 path on first run.
AD, Entra ID, Linux, segmentation, jump-host hygiene, ADCS.
Kerberoasting and AS-REP roasting under detection thresholds.
Every chain replay-deterministic.
Most enterprises operate a Tier-0 / Tier-1 / Tier-2 model on paper. KeenSafe answers the question every audit committee asks but no one can prove: "Does the model hold?"
Quarterly proof: how many Tier-2-to-Tier-0 paths existed, how many were closed, residual count.
A scope-bounded agent on an approved jump-host walks identity, network and host paths under production-safe constraints. ADCS, Kerberos, NTLM and SMB tradecraft applied with throttling.
A guided session shows the shortest validated chain to Domain Admin — and the controls that should have broken it.