PXL Security LTD, Sofia, Bulgaria Offensive security since 2014[email protected]

Case studies

What good testing actually changes.

Real engagements, fully anonymised. Client names and identifying details are withheld — we work under NDA by default — but every finding, chain and outcome below happened. Each is also available as a one-page PDF.

Enterprise SaaS / CRMMobile app pentest (Android, iOS, Windows)

A shipped mobile app that was a credential vault

1C / 5Hfindings across 3 platforms
3OS platforms tested
0customer records exfiltrated

The challenge

An enterprise SaaS vendor needed its cross-platform hybrid CRM client — shipped to customers who hold live customer records — validated across Android, iOS and Windows.

How it unfolded

  1. Treated the shipped app as an archive, not a program — unpacked and read the binary.
  2. Found hardcoded backend credentials compiled into the bundle.
  3. Confirmed (read-only) they granted a live, authenticated session to an internal customer-data API.
  4. Recovered the at-rest database key from device-derivable material (weak, unsalted key derivation).
  5. Decrypted the offline data store; bypassed jailbreak detection with a single runtime hook.
  6. Showed an MDM default silently disabled TLS pinning — enabling full session interception.

Impact

A motivated attacker with nothing but the public app could reach a live customer-data API and decrypt the offline store — on all three platforms.

Outcome

One Critical and five High issues with end-to-end runtime proof, a prioritised “rotate now” credential list, and concrete key-derivation, pinning and token-handling fixes. Testing stopped at proof — no customer records were exfiltrated.

Financial-data processor (multi-bank)Internal / container-escape pentest

From a web foothold to the entire data tier

1container foothold
millionsrows reachable across tenants
0rows read or exfiltrated

The challenge

A processor of regulated banking data for multiple tenant banks wanted to know the real blast radius available to an attacker who achieves code execution inside the production application container.

How it unfolded

  1. Started from a simulated foothold inside one production app container.
  2. Read decrypted secrets left in plaintext at container start.
  3. Found the app's database account was a cluster superuser, reachable from the app.
  4. Proved read/write across dozens of tenant databases, a central credit-risk dataset and the shared SSO store.
  5. Recovered the production session-signing key — proven offline by reproducing a real signature — enabling forgery of any user, role or tenant.
  6. Also recovered a GitOps deploy key and partner transfer keys (and their passphrases) from the same readable config.

Impact

A single container compromise escalated to cross-tenant data access, session forgery for any account, and a foothold back into the software supply chain.

Outcome

A fully-proven, step-by-step chain with a 24-hour P0 remediation plan: rotate the signing key, demote the database account, rotate deploy and partner keys. All capability was documented via metadata only — no customer rows were read.

Retail bankRed team: phishing + assumed breach

The decade-old password behind Domain Admin

0 / 2phishing campaigns succeeded
1path to Domain Admin found
dozensAS-REP-roastable accounts

The challenge

A retail bank wanted to test its resilience to phishing, and to an attacker who has obtained a standard domain user on a virtual-desktop host.

How it unfolded

  1. Ran two phishing campaigns — one blocked at the gateway, one delivered but ignored by well-trained staff.
  2. Switched to assumed breach: a standard domain user on a virtual-desktop host.
  3. Enumerated the domain with living-off-the-land native tooling only.
  4. Identified a Domain Admin service account with a password unchanged for over a decade, carrying Kerberos SPNs.
  5. Kerberoasted it for offline cracking; found dozens of AS-REP-roastable accounts and a stale never-expiring admin.
  6. Segmentation between the virtual desktops and on-prem directory meaningfully limited further reach.

Impact

A single ordinary account could put a path to full-domain compromise within reach — while the bank's email controls, staff awareness and network segmentation all held as defence-in-depth.

Outcome

A clear privileged-account-hygiene and Kerberos-hardening roadmap, plus independent validation that the bank's phishing, awareness and segmentation controls were genuinely working.

Retail bank — payment operationsAuthenticated web app pentest

Hardened, but not finished: a payment operations app

16findings
1operator could reroute payments alone
0injection/authz flaws

The challenge

A bank asked for a gray-box test of a payment-operations web application from the perspective of its highest standard administrative role.

How it unfolded

  1. Tested from the highest standard admin role (gray-box).
  2. Confirmed the core controls — injection resistance, object authorization — were genuinely solid.
  3. Found a routine profile field exported as a live spreadsheet formula, executing on whoever opened the export.
  4. Found a role labelled benign “self-service profile” that actually granted full user and role administration.
  5. Found high-impact payment-engine operations (date roll, resend, suspend, routing, start/stop) with no maker/checker approval.

Impact

Strong technical defences were undercut by segregation-of-duties gaps that would let one insider — or one compromised operator — move or stop payments unilaterally.

Outcome

Sixteen findings centred on segregation of duties, role-label accuracy and safe data export, giving the bank a concrete path to second-actor approval and least-privilege role redesign in a high-value payment environment.

ManufacturingExternal network pentest + OSINT

A tight perimeter — and a live attack in progress

2Critical issues
livecredential-stuffing caught in progress
tightotherwise well-firewalled

The challenge

A manufacturer wanted its small, heavily-firewalled internet-facing surface and identity exposure assessed.

How it unfolded

  1. Mapped a genuinely tight, well-firewalled perimeter.
  2. Found an internet-facing remote-access gateway running an out-of-support server OS as an AD authentication boundary.
  3. Confirmed it leaked internal domain and host names via an NTLM challenge.
  4. Detected an active external credential-stuffing campaign in progress against several cloud-mailbox accounts.
  5. Confirmed breach-corpus passwords were present but already rotated (a defensive positive); handed over provider trace IDs for log correlation.
  6. Found a B2B file-transfer listener still negotiating legacy weak ciphers without mutual TLS.

Impact

The company was one unpatched gateway, or one reused password, away from a foothold — and was already being probed while we tested.

Outcome

A prioritised remediation list (retire the end-of-life gateway, close the credential-stuffing exposure, add DMARC, mutual TLS and modern ciphers) plus actionable intelligence on an attack already underway.

Healthcare SaaS (patient data)Authenticated web + API pentest

A 24-hour token in all the wrong places

1token class, exposed 3 ways
24haccess window per token
0tokens revoked on logout

The challenge

A multi-tenant healthcare platform handling patient data needed an authenticated, multi-role test of its web and API product and its OAuth identity layer.

How it unfolded

  1. Tested the web + API product across multiple roles and the OAuth identity layer.
  2. Found a long-lived (24-hour) patient-data API token returned in a URL fragment during SSO handoff.
  3. Found the same token class embedded in a page-level JavaScript global.
  4. Found it obtainable via an enabled resource-owner-password grant with long-lived refresh tokens on a public client.
  5. Confirmed tokens were not revoked on logout — widening the window for theft and reuse.
  6. Found a disabled-but-leaky GraphQL endpoint disclosing schema, and an order workflow accepting client-supplied status and dates.

Impact

A single client-side foothold translated into a full day of access to patient records.

Outcome

A token-lifecycle redesign (authorization-code + PKCE, short lifetimes, server-side revocation, no tokens in URLs or globals) and server-side workflow validation — closing the chain at its root.

Industrial manufacturing (IT + OT)Internal network pentest (assumed on-network)

On-network to full directory compromise, one relay at a time

10hosts reached by one relay
hundredsusers enumerated anonymously
multipleEOL/OT systems found

The challenge

A manufacturer with a flat-ish network mixing modern Windows AD, end-of-life midrange systems and operational-technology devices wanted to know the blast radius from an on-network foothold.

How it unfolded

  1. Poisoned name resolution (LLMNR/NBT-NS/mDNS) and captured cleartext credentials from a legacy HTTP-Basic service.
  2. Found SMB signing disabled broadly and proved NTLM relay end-to-end — a relayed machine account authenticated to around ten hosts.
  3. Found LDAP signing and channel binding not enforced on the domain controllers; relayed to LDAP for a full authenticated directory dump.
  4. Enumerated the domain anonymously via null session — hundreds of users and the password policy — and mapped grossly excessive privileged-group membership.
  5. Catalogued EOL and OT exposure (an unauthenticated AJP file read on an EOL server, cleartext protocols and SMBv1 on a legacy midrange OS, and a vulnerable OT controller line).

Impact

A chain from an unauthenticated on-network foothold to a path to full Active Directory compromise — with OT systems reachable on the same network.

Outcome

A layered hardening plan: enforce SMB/LDAP signing and channel binding, disable LLMNR/NBT-NS, clean up privileged groups, decommission EOL systems and segment IT from OT — with a scoped second window for delegation and AD-CS paths.

Transport & logisticsExternal network pentest (black-box, ~80 hosts)

A clean bill of health — and the proof to back it

~80public hosts tested
0exploitable Critical/High
7+headline CVEs proven non-exploitable

The challenge

A logistics firm wanted a large internet-facing estate validated against current high-impact CVEs — reporting only vulnerabilities with a demonstrated, exploitable vector, not version-banner noise.

How it unfolded

  1. Enumerated and fingerprinted roughly eighty public hosts across the testing window.
  2. Actively tested each high-severity candidate CVE (mail-server RCE, edge-gateway memory-leak classes, device and portal CVEs, default-credential and service exposures).
  3. Verified each was patched or non-exploitable — the edge gateway leaked no memory, the RCE vector wasn't reachable, reflected input was blocked by content-type and CSP.
  4. Confirmed the few real, demonstrable issues: an exposed trace handler, anonymous FTP to an empty share, and missing SPF/DMARC.
  5. Flagged one network block that was app-layer filtered to the tester's source and needs an allow-listed vantage to re-cover.

Impact

The perimeter was materially hardened; residual risk was limited to information disclosure and email spoofing.

Outcome

High assurance that the headline CVEs were genuinely patched — proven, not assumed — plus a short, exploit-validated fix list and a retest plan for the filtered block. We report the good news too, with evidence.

Public-sector impersonation (threat intel)Threat-intel investigation & kit reverse-engineering

Taking apart a smishing kit that beat SMS 2FA

9sensitive field types harvested by the kit
real-timeOTP/PIN relay defeating SMS-2FA
0data submitted to attacker infra

The challenge

A smishing campaign impersonating a national e-services / fine-payment portal was harvesting payment and identity data. The goal was attribution and takedown evidence — without touching victims or submitting any data.

How it unfolded

  1. Collected and hash-sealed infrastructure and the live page kit for chain-of-custody.
  2. Reverse-engineered the single-page-app kit and mapped the victim funnel and the full set of harvested fields.
  3. Identified real-time exfiltration over a same-origin websocket, with the hosting server itself acting as the operator backend.
  4. Assessed capability: live PIN and OTP relay indicated an interactive operator defeating SMS-2FA and 3-D Secure in real time — a high-capability kit, not a static dump.
  5. Clustered the infrastructure and attributed it to a phishing-as-a-service operation reused across multiple countries and lures.

Impact

Active, scaled theft of payment cards and identity data from citizens, with two-factor authentication bypassed in real time.

Outcome

Hashed, court-ready evidence and multi-party takedown packages (registrar, hosting, national CERT, browser blocklists, certificate authority) suitable for law-enforcement handover. All analysis was retrieval-only — no data was ever submitted to the attacker's infrastructure.

Your project could be the next one.

Send a short description of your environment and goals. A senior tester, not a salesperson, will reply with questions, a proposed approach and a quote.

Prefer email? Write to [email protected]. We reply within one business day.