Northstar Industries
A fictional demonstration assessment, built to show exactly what a real engagement produces — not a features list.
External attack surface
Asset inventory (excerpt)
A small excerpt from the full asset inventory delivered as part of the report.
| Asset | Type | First observed | Exposure | Status |
|---|---|---|---|---|
| portal.northstar-example.com | Web Application | Discovery phase | Authentication Surface | Reviewed |
| api.northstar-example.com | API | Discovery phase | Public API | Finding |
| legacy.northstar-example.com | Legacy Application | Discovery phase | Unexpected Asset | Investigate |
| vpn.northstar-example.com | Remote Access | Discovery phase | Authentication Surface | Reviewed |
| stg-checkout.northstar-example.com | Staging Environment | Discovery phase | Unexpected Asset | Investigate |
| mail.northstar-example.com | Mail Infrastructure | Discovery phase | Mail Surface | Reviewed |
| status.northstar-example.com | Third-Party Hosted | Discovery phase | Information Disclosure | Reviewed |
Full reports include the complete inventory, asset ownership notes, and technology fingerprints for every discovered asset.
Legacy customer portal to business impact
Evidence
Authenticated screenshots, request/response captures, and a reproducible step-by-step chain, included in full in the technical appendix.
Affected asset
legacy.northstar-example.com — legacy customer portal, not in known inventory.
Impact
Potential unauthorized access to customer records held within the legacy portal.
Recommended action
Decommission or isolate the legacy portal; if retained, patch the outdated component and remediate the authentication weakness.
Attack hypothesis AH-04
Not every tested scenario produces a finding — and that is itself useful evidence.
Can the externally exposed remote-access infrastructure provide a viable initial-access path?
Not validated during the assessmentEvidence
- Expected authentication controls present
- No material externally exploitable weakness identified within scope
- Relevant exposed services reviewed
- No viable attack path demonstrated
Interpretation
An assessment does not need a critical finding to provide value. Knowing which attack scenarios were tested and resisted provides evidence about your external security posture.
What's included beyond this excerpt
- Executive Summary for leadership
- Complete external attack surface overview
- Full discovered asset inventory
- All attack hypotheses tested, validated or not
- Evidence for every validated finding
- Prioritized remediation recommendations
- Positive security observations
- Assessment limitations, stated honestly
- Technical appendix
- Live debrief / results call