HomeDemosProjectsCase StudiesPentest-Ref
← Back to Portfolio
CASE STUDY

From Credential Exposure to Full System Compromise in Under 10 Minutes

Target: Cloud Infrastructure Provider
Vector: Screenshare Credential Leak
Impact: Full System Takeover

During a routine video conference, an employee inadvertently exposed cloud VM credentials via screenshare. Within minutes, a simulated threat actor leveraged these credentials to establish persistent access, disable security controls, and achieve NT AUTHORITY\SYSTEM privileges — demonstrating how a single moment of carelessness can lead to complete infrastructure compromise.

Initial Access Vector

The incident began during a team collaboration call where an employee shared their screen while troubleshooting a cloud VM connection issue. The screenshare inadvertently exposed:

Exposed Information CWE-200 / CWE-798
# Public cloud VM endpoint (not RFC1918 private) labvm-prod-33uzbfr7im.australiaeast.cloudapp.azure.com # Default credentials visible in connection dialog User: adminvm1 Pass: [REDACTED]

Critical issues identified:

Attack Chain

1
Credential Capture
Threat actor captures exposed credentials from screenshare. Public endpoint + default password = immediate access.
CWE-200: Information Exposure
2
Initial Access via RDP/SSH
Attacker connects to cloud VM using captured credentials. No MFA, no IP allowlist — direct access granted.
CWE-798: Hard-coded Credentials
3
Persistence via SSH Installation
Attacker installs OpenSSH server for persistent backdoor access. SSH survives reboots and provides encrypted C2 channel.
T1098: Account Manipulation
4
Defender Evasion
Real-Time Protection disabled. Exclusion paths added for attacker tools. Security controls neutralized.
T1562: Impair Defenses
5
Reverse Shell Establishment
PowerShell reverse shell deployed to attacker's VPS. Full interactive command execution achieved.
T1059: Command and Scripting Interpreter
6
Privilege Escalation to SYSTEM
Attacker escalates from local admin to NT AUTHORITY\SYSTEM using token impersonation. Highest privilege level achieved.
T1134: Access Token Manipulation
7
Ownership Takeover
Using icacls, attacker removes all user/admin ACLs and takes full ownership of files. Legitimate users locked out of their own data.
T1222: File and Directory Permissions Modification

Technical Evidence

Persistence: SSH Installation PowerShell
# Install OpenSSH Server for persistent access Add-WindowsCapability -Online -Name OpenSSH.Server~~~~0.0.1.0 Start-Service sshd Set-Service -Name sshd -StartupType 'Automatic'
Defense Evasion: Disable Defender PowerShell
# Disable Real-Time Protection Set-MpPreference -DisableRealtimeMonitoring $true # Add exclusion for attacker tools Add-MpPreference -ExclusionPath "C:\Users\Public\Downloads" Add-MpPreference -ExclusionProcess "powershell.exe"
Privilege Escalation: SYSTEM Access PowerShell
# Verify SYSTEM privileges whoami nt authority\system # Take ownership and remove user access takeown /f C:\Users\victim\Desktop /r /d y icacls C:\Users\victim\Desktop /remove Users icacls C:\Users\victim\Desktop /remove Administrators # Create proof of compromise echo "PWNED BY THREAT ACTOR" > C:\Users\victim\Desktop\PWNED.txt
Attacker terminal showing SYSTEM shell and victim desktop with PWNED files
Dual-view: Attacker C2 panel (top) and compromised victim desktop (bottom) showing PWNED files created as NT AUTHORITY\SYSTEM

Attack Timeline

T+0:00
Credentials exposed via screenshare during team call
T+0:30
Attacker captures credentials, initiates RDP connection
T+1:00
Initial access achieved, reconnaissance begins
T+2:00
SSH server installed for persistence
T+3:30
Windows Defender disabled, exclusions added
T+5:00
Reverse shell established to attacker VPS
T+7:00
Privilege escalation to NT AUTHORITY\SYSTEM
T+9:00
Full system ownership — users locked out of own files

Impact Assessment

Confidentiality
CRITICAL

Full access to all files, credentials, and sensitive data on compromised system.

Integrity
CRITICAL

Attacker can modify, delete, or encrypt any data. ACLs stripped from user files.

Availability
CRITICAL

Legitimate users locked out. System fully controlled by attacker.

Time to Compromise
<10 min

From credential exposure to full SYSTEM access in under 10 minutes.

Video Demonstration

The following video demonstrates the attack from both perspectives — attacker terminal and victim machine — showing real-time compromise:

Lessons Learned

✓ Never share screens with credential dialogs visible. Treat screenshares as public broadcasts.
✓ Cloud VMs are WAN-accessible. They are not private networks. Anyone with credentials can connect from anywhere.
✓ Rotate credentials immediately if exposed, even accidentally. Assume compromise.
✓ Implement MFA on all remote access. Passwords alone are insufficient.
✓ Use IP allowlists for cloud management interfaces where possible.
✓ Monitor for SSH server installation — it's a common persistence mechanism.
✓ Humans are the weakest link. Social norms (asking for help) can override security awareness.