When this is relevant
- To validate segmentation and the administrative access model
- After infrastructure changes, migrations or environment consolidation
- When existing privilege controls need independent assurance
We assess how an attacker could develop initial access inside the organization, gain privileges and reach critical systems.