Sample Engagement

480 findings in. 6 that matter out.

A walkthrough of how Crimson turns a raw vulnerability scan into a short list of genuinely exploitable, validated findings — and the proof behind each one. This is an illustrative sample built to show the method, not a real client engagement.

Illustrative sample. Hosts, findings, and figures below are synthetic and do not represent a real client or engagement — they show the method Crimson applies on every test.

The problem

A scan is a starting point, not an answer

A single authenticated scan of a mid-size estate came back with 480 findings across 214 hosts — 137 of them flagged “Critical.” Handed that spreadsheet, most teams either try to patch everything at once or freeze. Neither answers the only question that matters: which of these could an attacker actually use, and how far would it get them?

The method

How 480 became 6

01

Score for exploitability

Crimson’s machine-learning models rank every host by likelihood of successful exploitation — not raw CVSS. Printers, workstations, and dead-end hosts drop down the queue; domain controllers and exposed services rise. 214 hosts → 47 worth a closer look.

02

Enrich with live intelligence

Each candidate CVE is enriched from our threat-intelligence platform — EPSS probability, CISA KEV status, exploit maturity, known modules, ransomware associations. Findings with no real-world exploit path fall away. 47 → 12 candidate targets.

03

Validate by exploitation

The remaining targets are put to the test through a controlled, consultant-directed exploitation workflow. A finding only makes the final list if it was actually reachable and actually worked. 12 → 6 proven.

04

Report what an attacker could do

The six are written up with the evidence, the impact, and the fix — plus the three chained paths that led to domain admin. That is the deliverable: a fix list ranked by consequence, not a 480-row export.

The proof

The six that were exploitable — and validated

Host Weakness CVSS EPSS KEV Crimson Validated result
SRV-DC01 Unauthenticated RCE in a file-sharing service 9.80.94KEV98 Domain administrator
VPN-EDGE1 Authentication bypass in a remote-access gateway 9.40.88KEV91 Internal network foothold
SRV-APP03 Deserialization RCE in a web application 9.10.72KEV88 Shell + cached credentials
SRV-SQL02 Service-account credential reuse 8.10.1076 Lateral movement to DC01
WEB-DMZ2 Exposed admin interface with default credentials 8.60.3071 Application compromise
FILE-07 SMB signing disabled — credential relay 7.50.0564 Credential relay to SRV-SQL02

Note the last three rows: two carry a modest CVSS and a low EPSS, and none are on the KEV list — a severity-only triage would rank them far down. Crimson surfaced them because, in this environment, they were the links that chained a foothold all the way to the domain.

The story the list doesn’t tell

Three findings, chained, gave up the domain

1 · Foothold

The auth bypass on VPN-EDGE1 put a tester on the internal network with no credentials — the front door, not the wall.

2 · Relay

Disabled SMB signing on FILE-07 allowed a credential relay that landed a service account on SRV-SQL02 — a “medium” the scanner nearly buried.

3 · Domain

That account’s reuse reached SRV-DC01, where the unauthenticated RCE completed the path to domain administrator.

The scanner marked 137 findings “Critical.” Six were reachable and exploitable. Three, chained together, reached domain admin. That gap — between what is flagged and what is provable — is the entire point of a Crimson-driven test.

How We Help

Turn this into your engagement

Penetration testing

Our testing runs on this method end to end — every finding you receive was reachable and demonstrated, not inferred from a severity label.

How Crimson works

See the engine behind the funnel — the exploitability scoring, live intelligence, and controlled exploitation that produced this short list.

See this run against your environment

This is the shape of every Crimson-driven penetration test: less noise, validated findings, and a fix list ranked by what an attacker could actually do. Tell us what is in scope and we will size the work.