Hop til hovedindhold

Engagement case catalog

When you build a mission you pick the engagement cases you want covered. Each case is a well-defined slice of testing with a typical depth. The Principal uses your selection to focus the sub-agents on what matters for this target.

Cases are organized into eight domains:

Depth legend: Light = quick, non-intrusive · Standard = normal test depth · Deep = thorough, higher-impact (weighted toward Attacker mode).

Network

CaseWhat it coversDepth
LAN host discoveryMap live hosts, open ports, and service banners on the authorized LAN.Light
Network vulnerability sweepOutdated services, weak configs, and known CVEs on authorized hosts.Standard
External perimeterInternet-facing IPs and domains: recon, TLS, mail, VPN portals, exposed admin panels.Standard
Internal pivot pathsAfter a foothold: lateral-movement paths, trust relationships, jump hosts.Deep
VPN / remote access portalsSSL-VPN, RDP gateways, and VDI portals: versions, auth flaws, MFA gaps.Standard
Email & DNS securitySPF/DKIM/DMARC, zone transfers, and subdomain-takeover candidates.Light
TLS / crypto postureWeak ciphers, expired certs, HSTS, and mixed content on in-scope HTTPS.Light
Segmentation / zero-trust gapsWhether unauthorized lateral paths exist across VLANs and microsegments.Deep
IoT / OT light reconDiscover ICS/IoT banners and default services (non-destructive).Light

Web / API

CaseWhat it coversDepth
Web application (OWASP)Auth, injection, XSS, SSRF, access control, and business-logic checks.Standard
API / GraphQL assessmentSchema discovery, authorization gaps, mass assignment, rate limits, injection.Standard
Mobile app / backend APICertificate-pinning gaps, API authorization, deep links, backend abuse.Deep

Identity / AD

CaseWhat it coversDepth
SMB / Active Directory surfaceShares, null sessions, LDAP, and Kerberos/NTLM exposure.Deep
Credential & secret hygieneDefault/weak credentials, leaked secrets, and reuse patterns.Standard
Password spray (authorized)Low-and-slow, lockout-aware spray against an authorized directory only.Deep

Cloud

CaseWhat it coversDepth
Cloud misconfigurationPublic buckets, over-permissive IAM, metadata SSRF, exposed keys.Standard
Container / KubernetesEscape paths, RBAC, secrets mounts, and exposed dashboards.Deep

Endpoint

CaseWhat it coversDepth
Linux privilege escalationMisconfigs, SUID, sudo, kernels, cron, and container escapes.Deep
Windows privilege escalationToken abuse, services, UAC, and GPO gaps.Deep
CI/CD & supply chainPipeline secrets, dependency-confusion risk, artifact integrity.Standard
Printers & MFDSNMP strings, open admin panels, stored jobs and address books.Light

Wireless

CaseWhat it coversDepth
Wireless assessmentEncryption strength, rogue APs, captive portals, client isolation.Standard

People / awareness

CaseWhat it coversDepth
Phishing resilience (controlled)A controlled awareness campaign or mailbox/header analysis — never real-user harm without mandate.Light

Data exposure

CaseWhat it coversDepth
Sensitive data exposure pathsReachable PII/secret backups, open shares, and exfiltration channels.Deep
Database exposureOpen Redis/Mongo/Postgres/MySQL/Elastic with weak auth or no TLS.Standard
Backup & recovery exposureAccessible backups, snapshots, and NAS shares that leak credentials or PII.Standard
Defaults per mode

Auditor mode pre-selects the light and standard cases; Attacker mode pre-selects everything, including the deep cases. You can always adjust the selection before launching a mission.

Next: why AgentRidge is local-first →