Offensive Scoping & Threat Modelling

Scoping assessments around the client's threats

I scoped external, internal and assumed-breach assessments around attack-surface discovery, Active Directory, email defences and EDR/network visibility, informed by incident-response work.

Growing MSSP with Offensive ServicesSecurity Engineer2 min read

I scoped assessments across healthcare, cargo, hospitality, managed service providers, trading businesses and private-equity firms. The business model and technology estate changed the threat questions: healthcare scopes, for example, included AI chatbot testing requirements. I discussed that context with managers and executives before defining the offensive work.

I used blind external attack-surface mapping and perimeter probing to establish the outside view of an environment. That discovery informed priorities across layered email protection, common Active Directory attack paths, the update state of critical components, and the coverage provided by endpoint detection and network monitoring.

I also performed internal and assumed-breach assessments to examine weaknesses from an attacker's position inside the environment. My SOC and incident-response experience connected those findings to detection and response planning: which activity the organisation could observe, and what action the relevant teams would need to take.

The scope could continue through web-application testing, examination of software-development processes and repeated surface mapping as systems changed. I carried the environment-specific threat context into delivery, reporting and recommendations so the assessment remained relevant to the systems the client operated.

Closer to the work

Business context changes the scope

I shaped the threat discussion around the organisation's systems and operating model, including healthcare AI chatbot testing requirements, cargo operations, hotels, MSPs, trading businesses, private equity and a humanitarian organisation. I included the chatbot application in the assessment requirements.

Open this detail ↗
An external view of the environment

I used blind external surface mapping and perimeter probing to understand what an outside party could discover and approach. This supplied an evidence base for prioritising subsequent assessment work and comparing the exposed attack surface with the intended scope.

Open this detail ↗
Email, identity and critical components

I considered layered email defences, common Active Directory attacks and the update state of critical components when defining assessment priorities and recommendations. I used these priorities to shape the tests and subsequent control recommendations.

Open this detail ↗
Detection and response coverage

I considered endpoint detection and response (EDR) and network visibility alongside the response required for relevant intrusion techniques. SOC and incident-response experience helped me connect offensive findings to what the organisation could detect, investigate and act on. Recommendations for coverage are distinct from a verified state of complete coverage.

Open this detail ↗
Internal and assumed-breach assessment

I performed internal and assumed-breach assessments, examining weaknesses from a position within the environment and using the findings to inform response planning. I grounded the threat model in the client's environment and likely intrusion paths.

Open this detail ↗
Testing as the environment evolves

I included continuing web-application testing, examination of software-development processes and repeated attack-surface mapping where the work required it. This kept assessment planning connected to changing systems and exposure rather than treating the initial perimeter view as permanent.

Open this detail ↗

Skills established through this work

This work connects to

Offensive security

Your exploration

Viewed history

Saved only in this browser.

Ask my portfolio

Ask about my work.

Skills, achievements, technical detail. Follow the evidence.

Every answer links to the work.
How this works

When AI is connected, your question, recent questions and relevant published pages are sent to MiniMax to select supporting passages. Otherwise, this searches the site directly. Answers quote the saved website and link to their sources. This website does not save chat transcripts. Clearing or leaving the page clears this conversation.