Skip to content
REDMAW

Capability

Assume breach. Now what?

The useful question after an attacker gains an internal foothold is not whether the perimeter failed. It is what the foothold can become. RedMaw works outward from an authorized foothold to establish which servers, routers and switches it can actually get into, which credentials and privilege boundaries give way, and which critical assets sit behind them. Where access is obtained it is demonstrated and reported. Nothing is disrupted, encrypted or destroyed.

The question this answers

If an attacker gains access to this internal service or credential, what high-value systems could become reachable next?

Example attack path
  1. Initial Foothold
  2. Internal Service
  3. Privileged Credential
  4. Critical System
  5. Sensitive Data

Each hop validated by successful exploitation

The framing

Initial access is the beginning of the internal attack.

An internal foothold can come from many places:

  • A compromised application
  • A stolen credential
  • A developer secret
  • A VPN or remote-access account
  • A compromised endpoint
  • An authorized assumed-breach test

Once inside, an attacker looks for leverage. Which services are reachable? Which credentials are exposed? Which privileges are broader than intended? Which systems lead toward high-value data or administrative control?

Prioritization

Reachability before severity

Internal environments often contain thousands of weaknesses that are individually difficult to prioritize. A technically severe issue on an isolated system may matter less than a modest weakness sitting directly on the route to a high-value asset.

What can be reached from this foothold, and what changes if the attacker succeeds at the next step?

Credentials are usually the bridge.

Internal attacks frequently become dangerous when one system exposes a credential that works somewhere else. The value comes from validating whether the credential or privilege relationship materially changes attacker reachability, not from counting exposed strings.

Privilege boundaries

Privilege should create friction for an attacker. When access is broader than intended, that friction disappears.

RedMaw tests the boundaries between ordinary and privileged access within the approved environment, and connects those findings to the systems that become reachable.

Connectivity

Controlled internal access

Internal validation requires explicit authorization. RedMaw uses a secure outbound connector for authorized internal reach rather than requiring uncontrolled inbound exposure.

The connector is part of the operating boundary. It defines how RedMaw reaches the approved environment, and lets the organization keep internal testing constrained to systems and actions that have been authorized.

After the finding

Validated findings enter the RedMaw findings-state layer. They can be pushed to Jira, GitHub Issues, Slack or email with proof and remediation guidance attached.

After the fix, RedMaw re-tests the issue. The finding closes when the exploit no longer works.

Typical questions

What RedMaw is trying to answer here

  • Which authorized internal services are reachable from the foothold?
  • Which credentials or secrets become available?
  • Where are privilege boundaries weaker than intended?
  • Which critical assets sit behind the reachable systems?

What RedMaw tests

Tested adversarially, not inventoried

Each area below is exercised by attempting exploitation within authorized scope, and the result is recorded as evidence.

Reachability

  • Authorized internal services reachable from a foothold
  • Network segmentation in practice, not on paper
  • Critical assets sitting behind reachable systems

Credentials

  • Reused and service credentials
  • Secrets available to the wrong workload
  • Privileged account exposure
  • Keys or tokens that provide another access route

Hosts and network devices

  • Access to in-scope servers from an authorized foothold
  • Access to in-scope routers and switches
  • Management interfaces reachable from the internal network
  • Default, reused or weak device credentials

Privilege boundaries

  • Users and administrative functions
  • Services and privileged resources
  • Credentials and high-value workloads
  • Operational accounts and sensitive infrastructure

Evidence

What proof looks like

An internal finding becomes useful when it can establish:

  • The original authorized foothold
  • The system or credential involved
  • The privilege or trust boundary affected
  • What becomes reachable
  • Why the path is material
  • What should be remediated
  • Whether the exposure is gone after retest

Boundaries

Where this stops

Adversarial testing is only credible when its limits are explicit.

Roadmap: not shipped

These capabilities are part of the platform direction. They are not shipped today and are not part of what a current engagement delivers.
  • Automated Active Directory attack-path discovery
  • Cross-surface attack-path chaining
Internal testing requires a deployed secure outbound connector and explicit authorization.
RedMaw does not perform unrestricted internal movement outside approved scope.
Access is demonstrated and reported. RedMaw does not disrupt, encrypt or destroy anything it reaches.
Cross-surface automated chaining is a platform direction, not a current blanket claim.

One platform

This surface is not tested in isolation

The same engine, evidence model and findings state run across all four surfaces.

Technical reference

Related reading

Attack LibraryInternal Infrastructure

Kerberoasting

Any domain account can ask for the tickets. The weakness is the password behind the service account.

· 6 min read
Attack LibraryInternal Infrastructure

AS-REP Roasting

An account setting chosen for convenience becomes an offline attack opportunity.

Attack LibraryInternal Infrastructure

NTLM Relay

The credential is never cracked. It is simply forwarded somewhere it still works.

Attack LibraryInternal Infrastructure

ADCS Certificate Abuse

A certificate authority that will issue a certificate for anyone is an identity provider for attackers.

Attack LibraryInternal Infrastructure

DCSync

The directory is asked to replicate. It has no reason to refuse.

Attack LibraryInternal Infrastructure

Unconstrained Delegation

One over-trusted host collects credentials from everyone who visits it.

Stop assuming you are secure. Prove it.

Continuously test what an attacker can actually reach across your applications, SaaS identities, internal infrastructure and AI systems.