Blog

Do You Know What Is Happening in Your Network?

July 28, 2026 / Jonas Mönnig

It is a typical Monday afternoon. We are on-site with a client and have already obtained domain admin privileges in the internal network. No one has noticed—even though we have not exactly been discreet.

This is where one of the main differences between a real attacker and a penetration tester becomes clear: an attacker has time. We do not. While an attacker tries to remain as inconspicuous as possible, we take more of a brute-force approach. After all, our goal is to uncover as many vulnerabilities as possible within a limited testing period.

Our activities are therefore often clearly visible. Nevertheless, there are still cases where no one at the client notices anything.

Even though there would have been more than enough warning signs.

Warning Sign Number One: Password Spraying

In a password-spraying attack, we try a small number of particularly common passwords across all user accounts. Examples include Winter2026!, CompanyName2026!, or combinations following the pattern username = password.

A real attacker proceeds slowly to avoid attracting attention. We test as quickly as possible. The result: hundreds of failed login attempts from a single IP address. This is obviously suspicious behavior, yet it often fails to trigger an alert.

Suspicious Access to Active Directory

To quickly gain an overview, we use tools that retrieve extensive information from Active Directory and prepare it for analysis. Attackers use these tools as well, so their behavior on the network is correspondingly unusual.

Here, too, there is often no response.

Intensive Scans Across the Entire Network

During our internal penetration tests, we also use an automated vulnerability scanner. It thoroughly checks every reachable host for known vulnerabilities.

This kind of network traffic is hard to miss. Especially when it originates from an unknown system, there is usually no legitimate reason for it. Nevertheless, the scan generally fails to trigger an alert as well.

Accessing Credentials

The warning signs become particularly clear when we obtain local administrator privileges on a Windows system. At that point, there are several ways to extract credentials from SAM, LSA, or DPAPI.

Such access is a strong indicator of an attack. Modern EDR systems can detect and block it. Nevertheless, we repeatedly succeed in extracting credentials and using them to access additional systems—sometimes all the way to domain admin privileges.

Blocked Does Not Mean Resolved

In many cases, the existing security solutions even block some of our activities. However, that alone is not enough. If no one sees the alert, assesses it, and responds, we can simply try the next attack method.

That is exactly what real attackers do as well.

The crucial question is therefore not only: does your security solution detect an attack? It is also: does anyone notice that an attack is currently taking place?

Who Monitors the Network Outside Business Hours?

The sobering answer is that most medium-sized companies do not have the personnel required to monitor their systems around the clock. Attackers know this. They deliberately shift their activities to nighttime or weekends. By the time the internal IT team responds on the next business day, it is often already too late.

An external Security Operations Center (SOC) can close this gap. An SOC provider has the technical and human resources to monitor IT systems around the clock, assess suspicious activity, and respond quickly to a security incident.

As part of our Managed SOC offering, we can support you in this effort together with our partner Eye Security. Please feel free to contact us if you have any questions.