ISECURION Case Studies

Real engagements from our VAPT, Red Team, DFIR, and compliance audit practices

Active Directory Penetration Test Case Study: From Low-Privileged User to Domain Admin | ISECURION
Case Study

From a Standard Domain Account to Domain Administrator: An AD Penetration Test Walkthrough

A real ISECURION grey-box Active Directory penetration test - a single low-privileged domain account led to full Domain Administrator compromise through password reuse, credentials exposed on open file shares, LLMNR/NBT-NS poisoning, and an unmonitored outbound tunnel. See the full attack chain, MITRE ATT&CK mapping, seven CVSS-scored findings, and the remediation roadmap delivered.

Read More →
CERT-In & RBI Cybersecurity Framework Audit Case Study: IS Audit of a Co-operative Bank by ISECURION
Case Study

CERT-In & RBI Cybersecurity Framework Audit Case Study: IS Audit of a Co-operative Bank

A real ISECURION IS audit engagement: five days on-site, 59 individual controls assessed against the RBI Cybersecurity Framework for Primary (Urban) Co-operative Banks. Nearly half the controls were fully implemented, but governance and vendor-risk gaps - no designated CISO, an unaligned Cyber Crisis Management Plan, undocumented Board reviews, and a password policy that didn't match its own documented standard - told a different story than the technical controls alone.

Read More →
Red Team Engagement Case Study: Cloud & Kubernetes Compromise via Hardcoded Credentials - RCE, Container Exploitation, AWS Token Abuse, Database Exposure and Phishing Simulation by ISECURION
Case Study

Red Team Engagement Case Study: Cloud & Kubernetes Compromise

A real-world red team engagement walkthrough: from a hardcoded credential in a public JavaScript file to full cloud compromise. Remote code execution via a mock API service, root-level container access, overprivileged AWS token abuse, database exposure, and a controlled phishing simulation conducted through compromised SMTP infrastructure. Four weeks, nine exploitable attack vectors, and critical findings across cloud, container, and human security posture.

Read More →
Architectural Limits of Kernel-Level EDR - Detecting In-Memory Execution in Modern Windows Systems - Kernel Driver Blueprint, PE Parsing, Memory Scanning and Detection Ceilings by ISECURION
Technical Research

Architectural Limits of Kernel-Level EDR: Detecting In-Memory Execution

A technical breakdown of how Windows kernel-mode EDR sensors are built – driver lifecycle, PE header parsing, section-table analysis, race-safe telemetry, and event-driven memory scanning for RW→RX protection swaps – and the three architectural ceilings that stop any purely kernel-resident sensor from fully detecting reflective loading, process hollowing, and other in-memory execution techniques. Includes how ETW Threat-Intelligence, AMSI, and Red Team validation close the gap, from ISECURION’s CERT-In empanelled security research practice.

Read More →
Microsoft 365 Account Takeover Case Study - Session Hijacking, Business Email Compromise & Attempted Wire Fraud Investigation by ISECURION DFIR Team using Entra ID, Exchange Online and SharePoint Forensics
Case Study

Microsoft 365 Account Takeover Case Study: Session Hijacking & BEC Fraud Investigation

A real ISECURION DFIR case study reconstructing a ten-day Microsoft 365 account takeover – session token persistence after a password reset, fraudulent internal identity creation, directory role escalation, secure link abuse on financial documents, a deleted fraudulent bank-detail email, and inbox rule deployment across three mailboxes. Covers the forensic timeline, technical analysis, root cause findings and remediation delivered by ISECURION’s CERT-In empanelled DFIR team across Entra ID, Exchange Online, the Unified Audit Log and SharePoint/OneDrive.

Read More →
AI Voice Banking Red Team Case Study - ReKYC Security Assessment, OWASP LLM & MITRE ATLAS Mapped Findings by ISECURION
Case Study

AI Red Teaming Case Study: Red Teaming an AI Voice Banking Assistant - When the Model Isn’t the Weakest Link

ISECURION red-teamed an outbound AI voice ReKYC assistant deployed by an Indian bank. The LLM resisted prompt injection, jailbreaks, OTP extraction, and model fingerprinting - but six critical and high-severity findings emerged at the identity verification, telephony trust, and business logic layers, including authentication bypass via name acknowledgement, speaker substitution across fabricated personas, pre-auth data disclosure, call non-termination, ignored fraud signals, and vishing indistinguishability. Findings mapped to OWASP LLM Top 10 and MITRE ATLAS by ISECURION’s CERT-In empanelled AI Red Team practice, serving BFSI, fintech, healthcare, and enterprise clients across India, the US, UK, EU, GCC, Singapore, and Australia.

Read More →
WhatsApp