Full-scope adversary emulation against a platform that maps the internet.
When your product is internet-wide scanning infrastructure, the interesting attack surface is not the login page.
The client asked for an objective-driven engagement rather than a checklist: start from the position of an ordinary customer and reach the scanning infrastructure.
The approach
We bought a subscription. Everything after that came from the product itself — the API, the query language, the export pipeline, and the assumptions each of them made about who was asking.
- Tenant isolation review across the query and export paths.
- Cloud infrastructure assessment from an authenticated foothold.
- Detection validation — we told them what we did and when, and compared it to what their team saw.
Detection
Half the value was the purple-team debrief. Six of our nineteen actions were already alerting. Four more became alerts during the engagement. The rest turned into detection engineering work with a written rationale for each.
ASEC