Protecting what matters most

Ghosthunter

Bespoke security solutions

A boutique security consultancy. We test the way an adversary would, across the physical and the digital together, then build the capability that outlasts the engagement.

Start a conversation
Act I · The estate

Security fails at the seams.

Network and physical security are run by different teams, and what is deployed drifts from what the documentation says. We read the whole estate as one surface, the way an adversary does.

Act II · The hunt

We test the way an adversary would.

We find the alarm panel that sits on the corporate VLAN, the executive whose home address appears in a public filing, and the vehicle tracker still on its default credential. The routes in red are the ones an adversary would walk: over the wall and up the facade, then in through the front door.

Act III · The capability

Then we build what outlasts the engagement.

We report the few things that would be used against you and fix them in order. The routes are closed and the findings retested, and what we build has to run without us.

Scroll
Capability

Five disciplines assessed together

Most clients start in one area and find that it connects to the others.

01

Offensive Security

We attack your organisation the way a motivated adversary would, then hand you the map they would have used.

  • Full-scope red team and adversary simulation
  • Internal and external network penetration testing
  • Active Directory and identity attack path mapping
+10 more in scope
02

Defensive Architecture

Networks, systems and devices designed so that a single compromise is contained where it starts.

  • Network architecture review and redesign
  • Zero trust architecture planning and phased rollout
  • Active Directory hardening and tiered administration
+8 more in scope
03

Protective Operations

Discreet protection for people, vehicles and premises, planned by people who also understand the digital attack surface attached to them.

  • Executive close protection for high-net-worth individuals
  • Vehicle telematics, tracking and CAN bus security
  • Protective surveillance and counter-surveillance
+10 more in scope
04

Forensics & Insider Risk

Reconstructing what actually happened on a compromised estate or device, or inside your own organisation.

  • Post-incident forensic reconstruction
  • Malware analysis and reverse engineering
  • Insider threat assessment and internal exposure review
+5 more in scope
05

Specialist Operations

Close protection and close quarters capability across land, sea and air, planned by one team as a single continuous task.

  • Close quarters instruction for protective teams and household staff
  • Hard room specification and rehearsed hold procedures
  • Residential and estate protective posture
+10 more in scope

Not the right fit for everything

We do not run a 24/7 SOC or resell licences, and we will not bid for work that needs a capability we do not hold. We keep to a narrow set of things and do them properly.

01 T1566.001 T+0 MAILBOX LOW × SANDBOXING 02 T1204.002 T+3m WORKSTATION LOW × MACRO RULE 03 T1003.001 T+41m CACHED CREDS MEDIUM × LSASS ALERT 04 T1021.002 T+2h FILE SERVER MEDIUM × ADMIN LOGON 05 T1005 T+19h FINANCE OBJECTIVE EDR BLOCKED SEGMENTED NO SINGLE FINDING ABOVE MEDIUM · CHAIN COMPLETED IN UNDER ONE DAY · × MARKS A DETECTION OPPORTUNITY THAT EXISTED AND WAS NOT TAKEN
Fig. 01Attack path: chained findingsHover or focus a stage to see what it involved.
FLAT SINGLE BROADCAST DOMAIN · VLAN 1 COMPROMISED ONE COMPROMISE REACHES EVERYTHING SEGMENTED VLAN 20 | VLAN 30 L3 ACL · DENY BY DEFAULT COMPROMISED BLAST RADIUS: ONE ZONE THE INTRUSION IS IDENTICAL IN BOTH CASES · ONLY THE ARCHITECTURE DIFFERS
Fig. 02Containment: isolating a compromised host
01 SYSMON / EDR ENDPOINT NO AGENT 02 SYSLOG / WEF COLLECTOR NOT FORWARDED 03 SENTINEL / QRADAR SIEM NO RULE 04 KQL / CORRELATION ALERT NOT TRIAGED 05 TRIAGE QUEUE ANALYST WE VERIFY EACH HOP · TELEMETRY BELIEVED COLLECTED IS ROUTINELY NOT ARRIVING
Fig. 03Telemetry pipeline: where signal is lostHover or focus a stage to see where signal is lost.
PHYSICAL DIGITAL THE SEAM VEHICLE TELEMETRY / KEYLESS ENTRY RESIDENCE NVR ON CORPORATE VLAN PRINCIPAL OPEN-SOURCE FOOTPRINT WE ASSESS BOTH COLUMNS · AN ADVERSARY USES WHICHEVER IS WEAKER
Fig. 04Convergence: physical assets and their digital surfaceHover or focus a row to see how the two surfaces connect.
Technical annex

The schematics behind the disciplines

These are the same figures we put in front of clients. Drag a wireframe to orbit it, and select any marked feature to read what it exposes.

Offensive Security

PERIMETERUSER SEGMENTSERVER SEGMENTRESTRICTED 01 02 03 04 05
Fig. 08 Attack path: traversal across network segments
  1. A phishing email is delivered and opened at the perimeter. In isolation it is rated low, because one click by one user gains no privilege.
  2. Code runs in the user segment under their own context. There is no elevation, and a parallel attempt here was stopped by endpoint control, so the rating stays low.
  3. A reused local-administrator secret is recovered from memory. It is rated medium, and every later step in the chain depends on it.
  4. The reused secret opens the server segment, a second medium finding. A further lateral attempt from here was contained by segmentation.
  5. The restricted zone is reached. No single finding was rated above medium, and the chain completed in under a day.

Defensive Architecture

VLAN 10 · USERVLAN 20 · SERVERVLAN 30 · RESTRICTEDL3 ACL · DENY BY DEFAULT 01 02 03 04
Fig. 09 Blast radius: contained at a boundary
  1. EXPOSURE: one compromised host. The event is the same in both architectures, which differ in what the attacker can reach afterwards.
  2. EXPOSURE: every host sharing the broadcast domain is reachable from that foothold. On a flat network this is the entire estate.
  3. A layer-3 boundary that denies by default and permits only the flows the business needs. Lateral attempts terminate here.
  4. Zones beyond the boundary are untouched, so the incident does not become a breach.

Forensics & Insider Risk

FIRMWARE / UEFIKERNEL / DRIVERSFILESYSTEMAPPLICATIONSUSER DATA 01 02 03 04 05
Fig. 10 Where the evidence actually lives
  1. EXPOSURE: the layer everyone thinks of as “the evidence”, and the first thing a reimage removes. On its own it rarely answers when an intrusion began.
  2. EXPOSURE: execution history, cached credentials and browser artefacts. This layer is volatile and frequently overwritten in normal use, and a rebuild removes it entirely.
  3. Journal, master file table and timestamps. This layer survives deletion of the files themselves and is where a reliable timeline is built.
  4. Loaded modules and service records. Persistence that survives a reboot has to touch this layer, so we look for it here.
  5. This sits below the operating system, and therefore below a reinstall. Compromise here is rare and serious, and no tool that only looks at the disk can see it.

Protective Operations

A · Huracán Performante

01 02 03 04 05 06 07 08
  1. Forward-facing radar and object detection, flagging threats and obstructions ahead before the driver registers them.
  2. Multi-layer laminated and ballistic-rated glass bonded into reinforced frames, resisting forced entry and small-arms fire.
  3. Anti-hijack immobilisation: the engine can be cut covertly and the vehicle brought to a controlled, safe stop.
  4. An independent GPS/GSM tracker on its own power and aerial, hidden apart from anything a thief checks first.
  5. Run-flat inserts and reinforced sidewalls, so the vehicle stays mobile at speed after a blow-out or a spike strip.
  6. EXPOSURE: the factory keyless system will answer a relayed challenge from a key inside the house. It is the most common theft route on a performance vehicle, and it needs no contact with the car.
  7. EXPOSURE: the OBD port can program a replacement key in minutes. Physical access for seconds is enough, and the port sits within reach of the door aperture.
  8. EXPOSURE: none from the factory. The 2017 to 2019 Performante has no factory LTE, so any uplink on this car is an aftermarket tracker or dongle. Those are permanent network endpoints, frequently shipped with weak credentials and rarely updated after sale.

B · 812 N-Largo

01 02 03 04 05 06 07 08
  1. Forward-facing radar and object detection mounted behind the N-⁠Largo’s lower mesh grille, flagging threats and obstructions ahead before the driver registers them.
  2. Multi-layer laminated and ballistic-rated glass bonded into reinforced frames, resisting forced entry and small-arms fire. The 812’s raked screen and fastback rear glass are the two largest apertures on the car.
  3. Anti-hijack immobilisation on the V12’s engine management: the engine can be cut covertly and the car brought to a controlled, safe stop. The factory alarm and fuel inertia switch cannot be triggered remotely.
  4. An independent GPS/GSM tracker on its own power and aerial, hidden apart from anything a thief checks first. The 812 left the factory with no tracking unit. UK cover normally demands a Thatcham S5 fit on top.
  5. Run-flat inserts and reinforced sidewalls in the 275/30 R21 and 335/25 R22 P Zeros. The 25-series rear carries roughly 84 mm of sidewall, so on a stock tyre a blow-out or spike strip puts the car on its rim at speed. With the inserts fitted it stays mobile.
  6. EXPOSURE: the keyless start fires the V12 on a 125 kHz challenge relayed to a key inside the house. There is no hands-free entry on the 812 (that came with the Roma), so the door needs the 433 MHz remote or the glass. Once inside, starting needs no contact with the key.
  7. EXPOSURE: the OBD-II port programs a replacement key in minutes. Seconds of physical access are enough, because Ferrari mounts it on its own bracket under the dash, inside the door aperture.
  8. EXPOSURE: none from the factory. The 812 Superfast shipped without an embedded modem, and MyFerrari Connect only reached MY2023 cars. Any uplink on this car is an aftermarket tracker, dongle or CarPlay retrofit, and those are the endpoints shipped with weak credentials and never updated.

C · Brabus 800 (G 63)

01 02 03 04 05 06 07 08
  1. Forward-facing radar and object detection behind the Brabus mesh grille, flagging threats and obstructions ahead before the driver registers them.
  2. Multi-layer laminated and ballistic-rated glass bonded into reinforced frames, resisting forced entry and small-arms fire. The G-class has a large area of glass, and its upright, flat panes are the easiest of the three to armour.
  3. Anti-hijack immobilisation on the V8’s engine management: the engine can be cut covertly and 2.5 t of vehicle brought to a controlled, safe stop. The factory FBS4 immobiliser only stops a car that has no valid key present.
  4. An independent GPS/GSM tracker on its own power and aerial, hidden apart from the factory unit. The car ships with Mercedes me Vehicle Tracker, but that runs on the same LTE module and account a thief disables first. UK cover normally demands a Thatcham S5 fit on top.
  5. Run-flat inserts and reinforced sidewalls in the 305/35 R23s. The 35-series carries about 107 mm of sidewall, more than either supercar, but 2.5 t on a rim at speed is worse, so the inserts matter more on this car.
  6. EXPOSURE: with KEYLESS-GO, door and start answer a 125 kHz challenge relayed to a key inside the house. Mercedes keys from mid-2018 stop transmitting after about two minutes at rest. A relay still works inside that window, and ADAC rates the measure as not ideal.
  7. EXPOSURE: the OBD-II port under the driver’s dash is the coding endpoint for every module on the car. FBS4 means a thief cannot program a key here in 30 seconds, but a dongle left on the port is a live CAN foothold, and the port sits within reach of the door aperture.
  8. EXPOSURE: of the three cars, only this one has a factory uplink. An embedded LTE module and Mercedes me connect from launch (MY2019+) give remote unlock, live vehicle tracking, geofencing, theft notification and stolen-vehicle location. The car’s position and locks are reachable from any device holding the owner’s Mercedes me credentials.
Fig. 11 Vehicles: physical and electronic attack surface of the Huracán Performante (A), 812 N-Largo (B) and Brabus 800 G 63 (C)
Spec A B C Note
Length 4,506 mm 4,657 mm 4,873 mm (incl. tailgate spare) C longest · +367 mm on A, +216 mm on B
Width 1,924 mm 2,110 mm (rear arches) 2,084 mm (Widestar flares) B widest at the arches · C +100 mm on its 1,984 mm body
Height 1,165 mm 1,241 mm (−35 mm springs) 1,966 mm C stands ~0.8 m over both · optional RideControl −45 mm
Wheelbase 2,620 mm 2,720 mm 2,890 mm C +270 mm on A, +170 mm on B
Engine & layout 5.2 L V10 · mid-rear · 640 PS 6.5 L V12 · front-mid · 840 PS 4.0 L V8 biturbo · front · 800 PS C the only turbocharged, front-engined, ladder-frame vehicle of the three
Drive AWD RWD · 4WS AWD 40:60 · 9-spd · 3 locks · low range A and C AWD · B alone RWD
Dry weight 1,382 kg 1,525 kg (base) 2,485 kg kerb (stock G 63) C quoted at kerb weight · Brabus 800 kerb unpublished · ≈ +1.0 to 1.1 t on A/B
Tyres 245/30 R20 · 305/30 R20 275/30 R21 · 335/25 R22 305/35 R23 · 305/35 R23 C 35-series carries ~107 mm of sidewall vs B’s ~84 mm
Keyless 125 kHz LF · relayable Keyless start · 125 kHz LF · 433 MHz fob Keyless-Go entry + start · 125 kHz LF · 433 MHz fob Relay opens and starts C · only inside the key’s ~2 min awake window
Factory telematics None (2017 to 2019) None (2017 to 2020) LTE module · Mercedes me connect (MY2019+) C carries a factory uplink · remote unlock and live tracking
OBD-II location Under dash · door aperture Under dash · OBD bracket Under dash · driver footwell Parity on placement · FBS4 blocks OBD key programming on C
Tracker fit Covert aftermarket unit Covert aftermarket unit · Thatcham S5 Covert aftermarket unit · Thatcham S5 Parity · C’s factory Vehicle Tracker shares the LTE module a thief pulls first
01 02 03 04 05 06
Fig. 12 Residence: perimeter, approach and interior
  1. Boundary sensing and lighting arranged to remove dead ground, so an approach is detected at the fence line rather than at the door.
  2. Door and gate specification, credential management and delivery procedure: the routine points where strangers are legitimately admitted.
  3. Camera placement mapped against actual approach routes, with each blind spot identified and stated in the report.
  4. A defensible internal space with independent communications, assessed for the hold time it would achieve in a real incident.
  5. EXPOSURE: the rear approach is unlit, unobserved and screened by planting. It goes undefended because it cannot be seen, and a rehearsed approach starts there.
  6. EXPOSURE: the recorder and alarm controller every electronic measure depends on, sitting unsegmented on the household network and rarely patched after installation.

Specialist Operations

CORRIDORHARD ROOMSTAIR 01 02 03 04 05
Fig. 13 Close quarters: the geometry of a confined space
  1. EXPOSURE: a doorway compresses everyone who uses it into one predictable line, and that line can be covered from inside before the door is ever opened. It is the most dangerous geometry in any building, and the reason entries are rehearsed.
  2. EXPOSURE: every room holds ground invisible from its doorway. Someone has to clear it physically and in sequence, which takes time a team under pressure is inclined not to spend, and a rushed entry is found out on this ground.
  3. EXPOSURE: a stair gives away height, sound and direction of travel, offers almost no cover, and can be dominated from above by one person. Moving between floors is planned as a separate phase.
  4. One controlled door, no glazing onto the approach, independent communications, and enough supply to hold in place. For most in-building incidents the correct answer is to hold somewhere prepared and extract only once it is safe.
  5. The line the team works, off the centre of the corridor and never through an uncleared threshold. It is rehearsed with the household in advance, so that nobody walks it for the first time in an incident.
01 02 03 04 05
Fig. 14 Sea: Benetti Oasis 40M berthed stern-⁠to, with one way on and a long wait for help
  1. EXPOSURE: berthed stern-⁠to, the hydraulic passerelle is the one controlled way aboard. The watch has a single point to cover, but everyone aboard also shares one route off, and anyone on the quay can see where it lands.
  2. EXPOSURE: the Oasis deck lies open at water level, 90 square metres with the wings down, with no bulwark and no stair from it to the upper decks. Stern-⁠to it faces the quay, and it is overlooked from the quay, the buildings behind it and the neighbouring decks.
  3. EXPOSURE: a stern-⁠to berth is a fixed, predictable place on a public quay anyone may walk, with the yacht’s name and position broadcast on AIS. Most hostile reconnaissance is done from that quay in daylight, by someone who looks like everyone else there.
  4. Controlled access to the wheelhouse, bridge systems on a network kept apart from the crew and guest Wi-Fi, satellite communications that do not depend on the shore, and a crew brief that treats position and itinerary as protected information and keeps both off social media.
  5. Help is minutes away in port and hours away offshore. A UK coastguard helicopter reaches just over 200 nautical miles, about 18 hours of steaming at the yacht’s 11-knot economical speed. Medical capability, redundant communications and a crew rehearsed to hold are carried aboard, and the plan does not rely on outside assistance arriving.
01 02 03 04 05
Fig. 15 Air: Gulfstream G650ER on the apron, where the exposure lies
  1. EXPOSURE: everyone boards through one door, the Type I entry on the port side forward, which folds down into its own airstair. The walk between vehicle and cabin is short, in the open and predictable to the minute, on an apron run by a handling agent who does not work for the principal.
  2. EXPOSURE: fuel into the wing tanks, ground power, catering, cleaning and baggage through the aft hold door all arrive with third-party staff, vetted to someone else’s standard on rosters you do not see. The aircraft itself is the strongest link in this chain and the least likely to be attacked.
  3. EXPOSURE: the registration is public record, and the Mode S transponder broadcasts the airframe’s unique address and position over ADS-⁠B Out to anyone with a receiver. Blocking programmes are partial and independent networks publish what they receive, so an arrival stops being private well before the aircraft lands.
  4. In the air this is the most controlled space the principal occupies all day: a known passenger list, 19 at most, a single entry door, and hours at up to 51,000 ft during which nobody on the ground can reach them. The security work is done on the ground at either end.
  5. Airside vehicle access agreed with the handler in advance, an FBO route that is not the published one, arrival timed so nothing idles on the apron, and a receiving team at destination briefed before departure. The two ground ends are planned together, because an adversary uses whichever is weaker.
Mobile security & forensics

The handset is the most complete record of a principal’s life

It holds their messages, movements, contacts and the keys to most of the accounts they use. It is also the most exposed device they carry, connected all day and regularly out of their hands. We assess that exposure in advance, and examine the handset after an incident.

01

Executive handset review

Configuration, apps, linked accounts and paired devices reviewed against how the principal uses the phone, and hardening agreed with them so it stays in place.

02

Spyware and stalkerware triage

A suspect phone is checked with the owner’s consent, before anything is removed, and the result names the indicator sets and the date of the check.

03

iOS and Android forensics

Each extraction is the fullest the device state allows and is corroborated in a second tool. Analysis gives a timeline with evidence attached to each step.

04

Lost or seized device review

We establish what a lost or seized handset gives up in the state it was in, and which accounts and sessions to revoke first.

05

App and MDM assessment

We test mobile apps for how they store and transmit data, and check MDM policy and BYOD boundaries against how staff use their phones.

06

Expert reporting

Findings are stated at the level the evidence supports and no further. Method and tool output are documented so another examiner can check every conclusion.

01 OS REQUEST LOGICAL CONTACTS · CALLS SMS · MEDIA 02 BACKUP SERVICE BACKUP + APP DATA · SETTINGS + MORE IF ENCRYPTED 03 PARTIAL SET FILE SYSTEM + DELETED REMNANTS + SYSTEM RECORDS 04 COMPLETE SET FULL FILE SYSTEM + THIRD-PARTY CHATS + LOCATION HISTORY 05 CHIP-OFF / JTAG PHYSICAL RAW STORAGE IMAGE READS AS CIPHERTEXT × LEFT ON A NETWORK · CAN BE WIPED REMOTELY × REBOOTED · LOCKS AGAIN, KEYS EVICTED × KEPT IN USE · DELETED RECORDS OVERWRITTEN OFF DEVICE OFTEN OUTLIVES A WIPE EACH NEEDS ITS OWN AUTHORITY OR CONSENT CLOUD BACKUP SYNCED ACCOUNTS PAIRED DEVICES VEHICLE × BARS SPAN THE LEVELS EACH LOSS COSTS · WHAT SURVIVES IS DECIDED AT SEIZURE · A HANDSET THAT IS ON STAYS ON, KEPT CHARGED
Fig. 18Acquisition: what each level recoversHover or focus a level to see what it recovers.
01 FARADAY BAG ISOLATE POWER IN BAG NO RESTART 02 BACKUP + HASH PRESERVE RESET BEFORE CAPTURE EVIDENCE DESTROYED 03 MVT / STIX2 CHECK 04 BELKASOFT X / AXIOM TIMELINE INSTALL CONFIG NETWORK 05 DATED FINDING VERDICT NO KNOWN INDICATOR SUSPICIOUS COMPROMISED 06 AGREED PLAN REMEDIATION BRIEF PRINCIPAL REPLACE HANDSET ROTATE ACCOUNTS INDICATOR MATCH THE PRINCIPAL CONSENTS TO EACH STAGE · NOTHING IS REMOVED UNTIL THE HANDSET IS CAPTURED
Fig. 19Triage: a principal’s handset, checked for spywareHover or focus a stage to see what it establishes.
01 02 03 04 05 06 07 08
Fig. 20 Handset: where a principal’s life is kept
  1. EXPOSURE: messages, photos, movements and the tokens that keep every account signed in all sit in one package on the board. It is encrypted at rest, and none of it can be read without the keys the secure element holds.
  2. EXPOSURE: the modem keeps the handset reachable all day, and a message is received and parsed by the system before anyone opens it. That is the route commercial spyware has used to land on a handset without a single tap.
  3. EXPOSURE: the charging socket is also the data socket, and the handset cannot tell a charger from a computer by the plug alone. A principal’s handset should be set to refuse new data connections while locked, which current handsets allow.
  4. EXPOSURE: Wi-Fi, Bluetooth and NFC are up whenever the handset is on. Through them it can be found in a room, and it pairs with a car or a watch that then keeps its own copy of part of the record.
  5. A separate processor with its own memory holds the roots of the encryption keys and counts passcode attempts. The keys never leave it, so the storage cannot simply be copied off and read on another machine.
  6. Face or fingerprint unlock is a convenience layered over the passcode, which stays the root of everything else. After a restart only the passcode opens the handset, and its length decides how long a locked handset holds out.
  7. Once the passcode has been entered, the keys for most app data stay available until the next restart. Left locked for long enough, a current handset can restart itself and close them again.
  8. The SIM carries the phone number, and moved to another handset it takes that number’s calls and one-time codes with it. A PIN on the SIM itself, separate from the passcode, stops that.
01 02 03 04 05 06 07
Fig. 21 Forensic bench: isolate, then acquire
  1. The handset is worked inside an RF-shielded enclosure through gauntlet ports, so no remote wipe can reach it and no new traffic arrives. Its charger sits inside the shield, because a flat battery and a restart would lock away data that was readable at seizure.
  2. USB reaches the workstation through a filtered bulkhead in the enclosure wall, because a plain cable fed through a shield behaves as an antenna. The enclosure is tested on a schedule and the results are logged.
  3. The workstation runs offline on its own switch, with no route to the building network or the internet. The toolset is validated before use, and anything that matters is confirmed in a second tool.
  4. Each extraction is hashed at capture and verified again before analysis, so any alteration shows. Two extractions of the same live handset may not produce the same hash, which is why the examination runs on the verified image.
  5. Exhibits are sealed in bags with numbered tamper tags, signed across the seal. Every transfer is logged as it happens, naming who took possession and when.
  6. EXPOSURE: a handset left in a pocket or on a desk after seizure keeps syncing, and a remote wipe can arrive within minutes. Incoming messages can also overwrite records the case depends on.
  7. EXPOSURE: a charger on an office PC is enough to change what is on the device. The PC may pair with it, start a sync or a backup, and none of that is in the custody log.

Toolset

The team works in these tools and checks findings in more than one of them. Naming a tool here implies no partnership or endorsement.

Forensic suitesBelkasoft X, Magnet AXIOM, Oxygen Forensic Detective
Extraction & decodingCellebrite UFED and Physical Analyzer, MSAB XRY
Compromise triageMobile Verification Toolkit (MVT), against published indicator sets
Artefact parsersiLEAPP and ALEAPP, open source, run as a cross-check
Selected work

What the work actually looks like

Real engagements, written up in full, from the brief to what changed afterwards. Every case is anonymised, and stays that way whether or not the client would mind.

Private client · Protective operations

One surface across four scopes

The client commissioned four workstreams across family, residence, business and digital footprint. We audited them as one attack surface, because that is how an adversary reads it.

Retail · Forensics & insider risk

A siege conducted entirely on someone else’s platform

A thirty-two day extortion campaign across three social platforms, ending in the takeover of the client’s primary brand account, and a recovery that had to work around a moderation system actively assisting the attacker.

Retail · Forensics & insider risk

You cannot patch access you have already granted

A routine consultation surfaced a second, internal threat: a former supplier whose technical access had never been revoked, and who had already used it. What began as an access-hygiene finding was, by the end of the audit, an active incident.

INITIAL ACCESS T+0 MAIL + PROXY PERSISTENCE T+2h REGISTRY LATERAL T+3d EVENT LOG COLLECTION T+9d PREFETCH / MFT EXFILTRATION T+16d NETFLOW ALERT FIRED T+18d 18 DAYS RECONSTRUCTED FROM ARTEFACTS · NONE OF IT ALERTED AT THE TIME EACH EVENT RECONSTRUCTED FROM THE ARTEFACT CLASS SHOWN · REIMAGING THE HOST DESTROYS EVERYTHING LEFT OF THE ALERT
Fig. 05Dwell time: 18 days from initial access to the alertHover or focus a point to see what happened, and when.
RESIDENCEOUTBUILDINGBUSINESS UNITOPEN SOURCE 01 02 03 04 05
Fig. 16 One surface: the route across four scopes
  1. EXPOSURE: a street-level image of an outbuilding exterior, matched against an interior photograph posted from inside the property. Together they identify which building holds the asset, what it is, and what surrounds it. That one inference, made from a browser and without breaking any law, replaces an entire reconnaissance phase.
  2. EXPOSURE: adequate height, and to any passer-by a functioning barrier. The height delays an opportunist, but the fence yielded to hand tools in under a minute and will not stop anyone who comes prepared.
  3. EXPOSURE: a handle mechanism that could be forced from outside without triggering a contact or a glass-break sensor. The component cost under twenty pounds, and it was the last thing on the route.
  4. EXPOSURE: a perimeter firewall blocking a remote-access trojan aimed at one mobile operating system, and a device fleet running that same system years behind on patches, on the same estate. Each is a medium finding alone, and assessed as one surface they combine into a critical one.
  5. Covert cameras replace several visible units at lower cost and cover the actual approach better. Anyone rehearsing an approach gets no signal about where they are being watched.
Approach

Every engagement runs through the same six stages

Security consultancy has a credibility problem, and it is largely self-inflicted: unverifiable claims, reports optimised for length, and findings that arrive too late to act on. The six stages below are how we avoid them.

01

Scoping

A conversation about what you are actually worried about, which is often not what the enquiry said. There is no charge and no obligation.

02

Authorisation

Written scope, rules of engagement, and authorisation from someone empowered to give it. Work does not begin without it.

03

Delivery

Executed by the people who scoped it. Anything critical is escalated by telephone the moment it is found, without waiting for the final report.

04

Reporting

Two documents: an executive summary a board can act on, and a technical report your engineers can use to reproduce and verify every finding themselves.

05

Remediation support

We walk your team through the findings, help prioritise against the resources you have, and stay reachable while the work is done.

06

Verification

We retest the findings, so no fix is assumed to work until it has been verified. Retesting is included as standard on assessment engagements.

01 SCOPING 02 AUTHORISATION 03 DELIVERY 04 REPORTING 05 REMEDIATION 06 VERIFICATION REPEATS UNTIL FINDINGS CLOSE NO WORK BEGINS BEFORE STAGE 02 · CRITICAL FINDINGS ESCALATE BY TELEPHONE AT ONCE
Fig. 06Engagement lifecycleHover or focus a stage to see what it involves.
Reporting

What a finding looks like

Every finding we issue answers six questions, in this order, because a finding that stops at the first two is not actionable.

Severity is assigned on exploitability and business impact together. A medium-severity issue forming the second link in a working attack chain outranks an unreachable critical, and our reports say so.

ConfidentialityClient identities never used in marketing without explicit written permission, and never for protective work
IndependenceNo vendor partnerships, resale agreements or commissions
Duty of careFindings indicating active compromise stop the engagement and are reported immediately

The anatomy of a finding

Training

An engagement shows where you stand, and training moves you on from there.

Each programme’s syllabus, lab environment, exercise library and assessment are written from a blank sheet against the capability you need, and nothing is licensed from a catalogue and rebranded. The measure of success is that the programme runs without us.

Red Team Operator Development Programme

300 hours · multi-phase

A multi-phase programme that takes technically capable people to working red team operator standard, built from a blank sheet and delivered to national-level cohorts.

Detection Engineering & SOC Workshops

Modular · 2 to 5 days per workshop

Practical workshops for defensive teams covering threat intelligence and advanced detection engineering, taught in the SIEM your analysts use.

Capability Architecture

Programme-length · months, phased

For organisations that need a standing training function built from nothing, with its own syllabus, lab, exercise library and assessment.

Network Security Foundations

60 hours

The groundwork offensive and defensive training both assume and rarely teach: how networks actually behave, and why that determines what is possible on them.

01 NETWORK FOUNDATIONS 60 HOURS 02 OPERATOR PROGRAMME 300 HOURS 03 CAPABILITY ARCHITECTURE PROGRAMME-LENGTH DETECTION WORKSHOPS RUNS IN PARALLEL THE MEASURE OF SUCCESS IS STAGE 03 RUNNING WITHOUT US
Fig. 07Training pathwayHover or focus a programme to see what it covers.
OBSERVATIONTARGET ESTATEOPERATOR 01 02 03 04 05
Fig. 17 The range: a target estate under observation
  1. The cohort works from outside the estate, against an objective, under the same constraints as a real engagement.
  2. The estate is monitored, patched unevenly, and segmented in places and not in others. Operators have to work out which is which before deciding anything.
  3. Every action below arrives here as telemetry. Operators run the technique, then look at what it generated, and discuss how a competent defender would have caught it.
  4. EXPOSURE: this host produces no telemetry, and the gap is deliberate. Recognising where an estate stops watching is a skill, and it is taught by making the cohort find it.
  5. EXPOSURE: movement across the segment boundary. Phase-gated assessment is built around actions like this one: the technique, what it left behind, and whether it should have been attempted at all.
Commitments

If a supplier is showing you someone else’s engagement, assume they will show yours.

From every engagement letter we issue
Clients

The sector matters more than the name.

Ongoing relationships across national government, UK financial services, defence and professional services, named here with permission. Everything about the engagements themselves stays confidential.

His Majesty’s GovernmentNational governmentSecurity capability development, covered by clearance and non-disclosure
Nationwide Building SocietyFinancial servicesRed team operations and detection engineering, to CBEST standard
Northrop GrummanDefenceEngagement details available on request, subject to non-disclosure
Justa & CoProfessional servicesSecurity function delivery and network architecture
LVMHLuxury goodsExecutive and asset protection, secure movement of high-value assets
Compagnie Financière RichemontLuxury goodsExecutive and asset protection, secure movement of high-value assets
RolexLuxury goodsExecutive and asset protection, secure movement of high-value assets
Automotive marquesAutomotivePhysical and electronic vehicle protection for Lamborghini, Ferrari, Mercedes-Benz, Rolls-Royce Motor Cars, McLaren, Bugatti, Aston Martin, Land Rover and Audi, delivered in our workshop, and connected-services and telematics hardening for Tesla

Not every client appears here. Protective work for private individuals is never referenced publicly, and several engagements cannot be named at all.

Assessment regimes delivered to

The frameworks these engagements run under. This is methodology alignment and delivery experience rather than a claim of accreditation held by this firm.

CBESTBank of England intelligence-led testing, in UK financial services
DORAThreat-led penetration testing and compliance activity
PCI DSSPenetration testing requirements, in a CREST and CHECK environment
HMG SPF · NCSCSecurity Policy Framework and NCSC guidance, within national government
ISO 27001 · NIST · OWASP · ATT&CKAcross assessment and detection work
About

A deliberately small firm

The gap we kept finding was that nobody owned the whole picture. Network security is procured by IT and physical security by facilities or a family office. Neither party reads the other’s report, and the failures we find sit in the space between them.

GHOSTHUNTER was founded to assess that space as one problem. It is why our service lines look unusual next to each other: offensive testing and protective operations are rarely sold by the same firm, and adversaries exploit that separation.

Staying small is a deliberate choice, and we do not intend to grow out of it. It means the people who scope your engagement deliver it, and that we can decline work we are not right for.

What we are not for

  • 24/7 managed detection and response. We design the telemetry but do not staff the console.
  • Licence resale or product implementation on a vendor’s behalf.
  • Compliance box-ticking where the certificate is the only objective.
  • Anything requiring capability or authority we do not hold. We will refer you on.
Founded2023
BaseUnited Kingdom
ModelDelivered by the consultants who scoped it, with no handover after signature
CapacityA limited number of concurrent engagements, by design
CredentialsEvidenced directly on request, under NDA where appropriate
BiographiesNot published, because your supplier is part of your attack surface
Get in touch

Start a conversation.

Initial discussions are confidential and carry no obligation. If we are not the right fit for what you need, we will tell you and point you somewhere that is.

Answered by a person, usually within one working day · No sales sequence or automated follow-up

Live incident? Telephone rather than email: your mail may be monitored by whoever is in your environment.