24/7 ONLINE · 09:00–00:00◆Hacettepe Teknokent / Ankara
+90 536 662 38 09[email protected]
DSETDoğanay Siber Emniyet
  • Services
  • Academy
  • Simulator
  • Blog
    BlogArticles · technical write-ups · guidesAnnouncementsLatest DSET news · bulletinsVideo GalleryTraining · demos · cyber security videos
  • About Us
    About UsThe DSET story · vision · teamSimulators and ToolsFree interactive calculators, simulators and diagnosis wizardsSector SolutionsFinance · Healthcare · Public Sector · E-Commerce · 7 industriesReference CasesReal DSET cases · industry outcomesIn the PressDSET in the national pressSite SearchAll content · articles · services · casesFrequently Asked QuestionsCommon questions · quick answersContactPhone · WhatsApp · address · form
  • Tracking System
    Customer LoginAccount dashboard · request trackingForensics RequestDigital evidence · examination requestData Recovery RequestDisk · RAID · recovery requestPrice CalculatorATK 2026 reference · 9 services
KAOS
TREN
DSETCustomer Panel

Sign in to your account

Request tracking, quote approval and your history in one panel.

Loading security verification...
DSET Customer Panel AES 256 GCM encrypted session
DSET AI
//Finance · 2025
Finance · Case 2025

A 9-day Red Team engagement at one of Turkey's top 5 banks

A 9-day Black Box Red Team engagement for a mega-bank. Phishing → endpoint → AD → core banking jump server. 12 critical · 28 high findings. All vulnerabilities were closed in 30 days · stayed clean for 18 months.

Duration
9 days + 21 days of reporting
Scope
Top 5 bank · 50,000-endpoint scope
Customer Satisfaction
★★★★★

01 The Challenge

The bank's internal security team requested an external Red Team for the annual audit. The goal: how would a real APT or organized crime group attack? The rules: no scope restrictions · the prod environment included · the internal team unaware. The question: 'Through which door of the bank can we get in, and from there can we reach core banking?'

02 DSET's Approach

01

Day 0 · OSINT

LinkedIn · GitHub · pastebin · darkweb scanning. 3 employee e-mails + 1 leaked credential were identified. The bank's AWS S3 bucket was misconfigured · no data but structural information exposed.

02

Day 1-2 · Initial access

A targeted phishing campaign · the CFO's secretary clicked · the payload bypassed AppLocker (using LOLBins). Persistence was established.

03

Day 3-4 · Privilege escalation

Local admin obtained · LSASS dump · 3 different domain user credentials. A service account hash via Kerberoasting · offline crack.

04

Day 5-6 · Lateral movement

4 different jump paths to reach Domain Admin access. The shortest: core banking subnet access in 11 hops.

05

Day 7-8 · Core access

The core banking jump server was accessed · a screenshot was taken (evidence) · no transaction was performed (rule).

06

Day 9 · Detection check

Which steps did the bank's SOC team detect over the 9 days? Only the phishing raised an alarm on day 2 · no alarm afterward.

03 Results in Numbers

12 critical · 28 high
Findings
17% (improved → 78%)
Detection Rate
30 days
Critical Closure
All critical closed · 0 new
Re-test Result
18 months (re-test success)
Clean Period
21 new detection rules
SOC Improvement

04 Customer Testimonial

"

Reaching core banking in 9 days was discouraging but necessary. Now an annual Red Team engagement is our corporate policy. The professionalism of the DSET team is unmatched.

CISO
One of Turkey's Top 5 Banks
★★★★★

05 Key Takeaways

Phishing alone can cause a 6-day detection delay
Service account Kerberoasting is still the most frequently missed vulnerability
Network segmentation is in place but the auditing of jump paths is lacking
An annual Red Team · gives the CISO and CFO concrete improvement metrics

06 Services Used in This Case

KVKK-GDPR Consultancy

A compliance process is sustainable compliance.

Cyber Security

Cognitive solutions.

Incident Simulator & Threat Heatmap

Not hours of deliberation · but minutes of interactive simulation.

Your case can end just as well.

Free assessment · detailed response within 48 hours.

Call Now Contact form

Other Cases

Automotive Manufacturing

Ransomware on 800 endpoints at an automotive supplier · full recovery in 9 days

View
Public Administration

Detection and cleanup of a 14-month APT intrusion at a metropolitan municipality

View
Healthcare

Ransomware at a 250-bed private hospital · full recovery within 48 hours

View
DSETDoğanay Siber Emniyet

Digital Forensics · Data Recovery · Cyber Security · Information Security · Technical Examination · Expert Opinion · KVKK & GDPR Compliance · Digital Transformation Consulting · advanced training programs offered by DSET Academy.

+90 536 662 38 09[email protected]Hacettepe Teknokent · Üniversiteler Mah. 1596. Cad. 6. AR-GE Blokları C Blok No:6C Z.Kat · Beytepe · Çankaya · ANKARAOur Google Business Profile7/24 Online · 09.00 → 00.00 · Pazartesi · Pazar

Our Services

  • Digital Forensics
  • Data Recovery
  • KAOS Local Artificial Intelligence
  • Cyber Security
  • KVKK-GDPR Consultancy
  • DSET Academy
  • Incident Simulator & Threat Heatmap
  • Website Security
  • Information Security
  • Adli Bilişim Benchmark'ı

Support & Help

  • About Us
  • Press Room
  • Price Calculator
  • Frequently Asked Questions
  • Contact
  • EU AI Act Article 4 Guide
  • Sector Solutions
  • KVKK Disclosure Statement
  • GDPR · EU Data Rights
  • Privacy Policy
  • Cookie Policy
  • Terms of Service

Quick Links

  • Solutions
  • DFB Benchmark
  • Blog
  • Video Gallery
  • DSET Academy
  • Case Simulator
  • Reference Cases
  • Site Search
  • DSET AI Assistant
  • Digital Forensics Request Form
  • Data Recovery Request Form
  • Customer Login

Ecosystem

  • Hacettepe Teknokent
  • Cyber Security Cluster
  • USOM · National Cyber Incident Response
  • KVKK Authority
  • llms.txt
© 2026 dset.com.tr · Doğanay Siber Emniyet Teknolojileri · All rights reserved.
“Kalite asla tesadüf değildir...”
TREN
Home
References
Privacy
KVKK
GDPR
Cookies
Terms