Field Report

Anatomy of an Internal Network Assessment

How a routine internal scan surfaced a critical exposure the client never knew was there.

The Engagement

A small business retained Black Flag Security Group for an internal network vulnerability assessment — an authorized, on-site scan of their office LAN to find what an attacker already inside the network could reach. Eleven active devices were in scope: workstations, printers, streaming devices, and networking gear.

1
Critical
2
High
2
Medium
2
Low
11
Hosts

What We Found

Critical

An exposed camera system

An internet-of-things camera recorder was running on the network with no authentication and factory-default settings — streaming a live interior video feed that any device on the network could pull up with zero credentials. It was also running end-of-life firmware with multiple publicly documented remote-code-execution vulnerabilities, from the same device family implicated in past large-scale botnet attacks. The kind of device that gets plugged in once and forgotten — and the single most serious exposure on the network.

High

Credential-relay exposure on workstations

Windows machines were configured in a way that left them open to a well-known internal credential-relay technique, allowing an attacker already on the network to gain access without ever knowing a password.

Medium

Legacy office hardware

Networked printers were running firmware over a decade out of date, with weak access controls that let any device on the network intercept or inject print jobs.

Low

Housekeeping

Networking gear left in a factory-default state, and an unrecognized device on the network worth verifying.

Redacted still from an unauthenticated interior camera feed captured during the assessment; faces obscured.
Evidence — captured live during the assessment. A still pulled from the unauthenticated camera feed, reachable by any device on the network with no credentials. Faces have been redacted; all identifying network and client details withheld. This is the exposure in plain terms: a live window into the workspace, open to anyone who reached the network.

How We Reported It

Every finding was delivered with a plain-language explanation, a severity rating, proof it was real, and step-by-step remediation — plus a prioritized roadmap sequencing the fixes from “do this today” to “longer-term hardening.” No jargon dumps. The client walked away knowing exactly what to fix first and why.

The Outcome

The critical camera exposure was flagged for immediate isolation, and the client received a clear, prioritized roadmap to close every gap. What looked like a healthy network on the surface had a live window into their workspace open to anyone within reach — now found, documented, and shut.

Wondering what's exposed on your network?

Most organizations have more open than they think. Let's find it before someone else does.

Request an Assessment