24Hack Express

The 24Hack Express Service emulates opportunistic attack scenarios.

The purpose of this exercise is to demonstrate whether and how a threat actor could harm the company’s business and, consequently, to verify whether the company’s security strategy is effective in countering a next-generation cyberattack.

Unlike other testing services—such as: Penetration Testing, Application Penetration Testing, Vulnerability Assessment, and Red Team Exercises, this service does not aim to provide comprehensive and detailed information on the security status of all assets, but rather to identify and exploit the fastest route to compromise the corporate perimeter and reach critical targets within a clearly defined 24-hour timeframe.

Overview

In the context of 24Hack Express, scope of activities, objective and carriers are defined

An opportunistic attack is an operation that is not directed at a specific target and does not require any special investments or resources to carry out.

The category of opportunistic attacks includes all attacks that are not directed at a specific entity and do not require significant investment or resources to carry out. This type of attack is often carried out by threat actors whose primary goal is to extort money from organizations. The most common consequences of this type of attack include: data exfiltration (data leaks), file encryption for ransom (ransomware), and the establishment of a persistent channel to intercept a company’s financial or operational information (APT).

The scenarios that the Service considers are:

  • Unfaithful employee who uses his technical capabilities to cause harm to the organization (exfiltrate data, compromise systems) or who in turn allows an external Threat Actor to exploit his device as an attack vector (bridge);
  • Compromising a workstation through a phishing campaign or malicious file operated without the employee’s explicit consent;
  • Use of illegally obtained corporate access credentials;
  • Exploitation of a critical vulnerability, allowing access to the corporate perimeter;
  • Supply chain compromise (ex. VPN site-to-site with partner or supplier).

In the context of 24Hack Express, the scope of activities, the objective (to compromise the systems as deeply and extensively as possible), and the vectors (the starting point of the scenarios to be simulated) are defined.

Frequent use cases

Of a computer system lacking objective evaluation.

Of an opportunistic cyber attack in a single day of operation.

Of the exploitability of vulnerabilities present in a specific perimeter.

Of response to an opportunistic cyber attack.

Of the company in case a given scenario occurs

Of a third-party managed detection and response (MDR) service.

The advantages of 24Hack Express
1
Effective security

Let’s put the organization to the test in a real, opportunistic attack scenario, within a clearly defined 24-hour timeframe.

2
Objectivity

We assess the organization’s IT security level for further analysis, as well as its ability to respond to an opportunistic cyberattack.

3
Operational continuity

We reduce the risk of a loss of data, financial or reputational damage.

Success stories
We tell you about some of our projects
CONTACTS

We’re here to listen to you.
Write to us—we’re here to help.