en

Case Study: Pentest with Red Teaming Elements

Client:
Medium-sized distribution company
Industry:
Software Development
Focus:
Assessment of digital security for the company’s office and web resources
Main challenge:
Conduct a scheduled security assessment of the office and web resource with subdomains
Market:
Regional (within one oblast of Ukraine)
Services provided:
Black-box penetration test with elements of Red Teaming
Key Takeaways
  • 21 vulnerability identified: 8 medium, 12 low, and 1 informational
  • Simulated internal attack: Wi-Fi password successfully cracked
  • Black-box penetration test with elements of Red Teaming conducted
  • Detailed report prepared with recommendations for improving security
  • 21
    vulnerabilities identified
    1
    attack simulated
    100%
    on-time delivery
    Case Study: Pentest with Red Teaming Elements
    Does a cybersecurity assessment matter for a wholesale company that distributes food products? Absolutely yes. A distribution company initiated a scheduled security assessment of its office and web resources. Black-box testing with elements of Red Teaming revealed 21 vulnerabilities. The provided recommendations helped eliminate a number of risks.

    A regional distribution company wholesales food products within one of Ukraine’s oblasts. Around 150 employees are involved in the client's digital infrastructure.

    The specifics of the industry and the processing of confidential data make security a critically important issue for the company.

    Tasks and challenges
    The client initiated a scheduled security assessment of the office infrastructure and online resources, including the corporate website and its subdomains.
    The task was to identify potential vulnerabilities that could pose risks to a company operating in an industry with high security and trust requirements.
     
    • Conduct a scheduled security assessment of the company’s office and internet resources, including subdomains
       
    • Detect and identify potential vulnerabilities in the internal network and on the company's web resources
       
    • Prepare a detailed penetration testing report with technical findings and recommendations for security improvement
       
    icon
    Security testing
    Black-box testing with elements of Red Teaming
    icon
    Vulnerability discovery
    Analysis of identified threats in the company’s infrastructure
    icon
    Report and recommendations
    In-depth penetration test report with recommendations
    Our approach

    Datami performed black-box testing with elements of Red Teaming. The assessment covered office infrastructure, Wi-Fi network, web resource, and subdomains. A standard toolset was used, including both automated and manual testing methods.

    The team simulated an attack without access to the company’s internal systems. Special attention was given to Wi-Fi, authentication, access control, as well as the detection of weak passwords and default configurations that could be exploited by attackers.

    Black-box
    Black-box
    This approach made it possible to simulate a real external attack and identify vulnerabilities without access to internal information.
     
    Key work stages and solutions

    During project implementation, the Datami team focused on an effective testing model, following a defined structure.

    After thorough preparation for the assessment of the targets, we simulated an attack, scanned the network and web resources.

    Based on the discovery and analysis of identified vulnerabilities, a report with recommendations to enhance security was prepared.

    • Preparation
      Review of objectives, definition of scope and testing scenarios, selection of testing tools.
    • Security testing
      Execution of black-box penetration testing with Red Teaming elements: assessment of the office, web resource, and subdomains.
    • Analysis and reporting
      Presentation of results in a detailed report: vulnerability categorization and remediation recommendations.
       
    How we can help you?

    Every cybersecurity case study we solve involves deep analysis, tailored solutions, and measurable results.
    Datami has already helped over 600 companies strengthen their digital defenses — and we can do the same for your business.
    Ready to take action?

    Let’s start with a free consultation!
    Results  and recommendations
    Results and recommendations

    At the start of the project, the client’s digital infrastructure had several hidden weak points. Although the overall risk level was initially assessed as low, the Datami team identified 21 vulnerabilities during the black-box penetration test — including entry points into the internal network via weak passwords and default configurations.

    During a simulated attack, the team successfully cracked the office Wi-Fi password, which allowed scanning of the internal network. In the Afterlogic system, the testers discovered a default account that granted access to internal resources.

    Based on the test results, the client was advised to:

    1. Eliminate authentication and configuration vulnerabilities
    2. Strengthen office network protection, particularly Wi-Fi
    3. Implement strong password policies and access control
    4. Regularly conduct security testing using modern approaches

    The project was completed within the planned timeframe. Thanks to timely security testing, the identified vulnerabilities did not result in any critical incidents.

    Our certificates
    Key project results

    Thanks to the scheduled assessment, the company received an objective view of its cybersecurity posture and actionable recommendations for strengthening the protection of its infrastructure and digital assets.

    Datami identified 8 medium, 12 low, and 1 informational vulnerability — this case study confirms the effectiveness and relevance of scheduled security assessments, even for companies with an apparently stable situation.

    Direction
    Before the project
    After implementation
    Security status
    Externally stable, but without office network assessment
    21 vulnerabilities identified, report prepared
    Vulnerabilities
    Potentially unknown
    8 medium, 12 low, 1 informational
    Critical vectors
    Not identified
    Access gained via Wi-Fi and default account
    Access control
    Access policies not reviewed
    Technical recommendations provided to strengthen access control and compliance
    More success stories with Datami
    Browse other project case studies
    Pentest and Protection of Platform from DDoS

    Pentest and Protection of Platform from DDoS

    • Discovered 30 vulnerabilities in two web applications
    • Implemented DataGuard and Cloudflare for DDoS protection
    Services:
    Black-box web app pentesting, implementation of Dataguard
    Jul 8, 2025
    P2P Platform Case Study: GDPR Compliance Audit

    P2P Platform Case Study: GDPR Compliance Audit

    • Improved GDPR compliance and avoided potential losses
    • Identified 10 vulnerabilities, including 3 critical ones
    Services:
    Penetration testing, smart contract audit, code security review
    Jun 27, 2025
    Case Study: Consulting Company Security Test

    Case Study: Consulting Company Security Test

    • Identified 19 vulnerabilities, including 1 critical, and 8 medium
    • Provided security compliance recommendations
    Services:
    Black-box pentest of web resources and infrastructure
    Jun 6, 2025
    Security image
    Ready to assess your project's security?
    Contact Datami — we’ll help you identify risks, strengthen your cybersecurity, and confidently pass certification.
    Datami articles
    Automation vs. Pentesters: Can AI Replace Humans? Datami Newsroom
    Datami Newsroom

    Automation vs. Pentesters: Can AI Replace Humans?

    Every year, companies are increasingly integrating automated tools into their cybersecurity processes. Automation is just one auxiliary tool that comes with both advantages and disadvantages that must be kept in mind.

    Jul 25, 2025 3 min
    Aviation and Cyber Threats: TOP Hacker Attacks on Airports and Aircraft Datami Newsroom
    Datami Newsroom

    Aviation and Cyber Threats: TOP Hacker Attacks on Airports and Aircraft

    The aviation industry is one of the most technologically advanced sectors, significantly influenced by digitalization. At the same time, this increases its vulnerability to cyber threats, which can have catastrophic consequences.

    Jul 23, 2025 3 min
    TOP-5 Cyber Threats for Gamers: What You Need to Know in 2025 Datami Newsroom
    Datami Newsroom

    TOP-5 Cyber Threats for Gamers: What You Need to Know in 2025

    Gaming is a billion-dollar market with big money in circulation, which makes gamers a prime target for cybercriminals. Even in a game, users can lose personal data, money, or access to their accounts.

    Jul 21, 2025 3 min
    Order a free consultation
    We value your privacy
    We use cookies to enhance your browsing experience, serve personalized ads or content, and analyze our traffic. By clicking "Accept All", you consent to our use of cookies. Cookie policy