← All Labs Active Directory Labs › Meridian Financial Group Medium
Meridian Financial Group

Story

Meridian Financial Group is a mid-sized investment advisory firm headquartered in Brussels, managing portfolios for private clients and small institutional investors across the Benelux region. They handle everything from wealth management and pension funds to corporate treasury advice — the kind of data that makes a ransomware operator's eyes light up.

The IT department is a two-man team that's been running the same infrastructure since 2017. They migrated to Windows Server 2022 last year for compliance reasons but never touched the AD configuration. Default GPOs, no tiering model, half the service accounts still have passwords set at deployment. The CISO role was filled six months ago — she's still writing the security policy.

You're in — connected to the internal network as an external contractor with temporary LAN access. No domain account, no credentials. Just a foothold and a network segment full of noise. LLMNR broadcasts are flying around, service accounts are waiting to be roasted, and the ACLs look like nobody's touched them since deployment. Build your user list, crack what you can, and chain it all the way to Domain Admin.

Domain Tree
MERIDIANFG.LOCAL MFG-DC01 Windows Server 2022 192.168.57.20 MFG-WS01 Windows 10 Pro 192.168.57.21 · jwhitfield MFG-WS02 Windows 10 Pro 192.168.57.22 · mvenneman
Hostname OS IP Account
MFG-DC01 Windows Server 2022 192.168.57.20 MERIDIANFG\Administrator
MFG-WS01 Windows 10 Pro 192.168.57.21 jwhitfield
MFG-WS02 Windows 10 Pro 192.168.57.22 mvenneman