Skip to content
Surface · Internal

Test the blast radius, not just the perimeter

A sealed appliance inside your network lets ShieldView emulate an intruder who's already through the door, mapping how far they could actually get, continuously and under approval.

Outbound
Only, no inbound ports
24/7
Continuous internal testing
0
Console access to the appliance

Perimeter testing tells you how someone gets in. Internal testing tells you what happens next. ShieldView deploys a lightweight appliance into your environment that connects outbound-only over a secure overlay (no inbound ports, no console access) and continuously exercises the paths a real intruder would walk once inside.

shieldview · internal kill chain
assumed breach → DA
Entry: sealed in-network appliance, assumed-breach foothold
  1. T1087.002AD account & ACL discovery
    ReconMap objects, groups and delegation
  2. T1557.001LLMNR / NBT-NS poisoning
    Cred AccessPoison broadcast name resolution
  3. T1110.002Offline hash cracking
    Cred AccessCrack captured hashes at scale
  4. T1558.003Kerberoasting
    Cred AccessRequest and crack SPN tickets
  5. T1550.002Pass-the-hash
    LateralAuthenticate to hosts with the hash
  6. T1003.006DCSync replication
    Domain DominanceReplicate secrets from the DC
ImpactDomain Admin · full domain compromise
Capabilities

Inside Internal & infrastructure

Active Directory attack paths

Maps the routes from an ordinary foothold to Domain Admin, the misconfigurations and trust relationships attackers chain together.

Lateral movement

Emulates an intruder pivoting host to host across your internal network, showing exactly what each foothold reaches.

Privilege escalation

Finds and safely proves the local and domain escalation paths that turn a low-privilege user into full control.

Internal service & secret discovery

Enumerates internal hosts and services and surfaces exposed secrets and credentials before an attacker can.