Capabilities
Breadth of Attack Surface Coverage
SystemDown operators maintain active capability development across all major attack domains. Our tooling and techniques are current, tested in live environments, and continuously updated as the threat landscape evolves.
NET
Network & Infrastructure
- Network protocol exploitation
- VPN / firewall appliance attacks
- BGP & routing manipulation
- Wireless (802.11, Bluetooth, ZigBee)
- Network device firmware analysis
- VLAN hopping & segmentation bypass
IDN
Identity & Active Directory
- Kerberoasting & AS-REP roasting
- DCSync & credential dumping
- Constrained / unconstrained delegation
- Azure AD & hybrid join attacks
- ADCS ESC1-ESC13 exploitation
- Pass-the-hash / Pass-the-ticket
CLD
Cloud Infrastructure
- AWS / Azure / GCP attack paths
- IAM privilege escalation
- SSRF to metadata endpoint attacks
- Container escape & Kubernetes attacks
- Serverless function exploitation
- Cloud storage exfiltration
APP
Application Security
- SQL injection & NoSQL injection
- Broken Object Level Authorization
- OIDC / OAuth token abuse
- Deserialization exploitation
- GraphQL introspection abuse
- WebSocket & API attack chains
EPD
Endpoint & EDR Evasion
- LOLBin / living off the land
- Process injection techniques
- Kernel callback manipulation
- Userland EDR bypass methods
- Reflective DLL loading
- AMSI / ETW bypass
PHY
Physical & Social
- Physical access simulation
- RFID / badge cloning
- Spear phishing with device delivery
- Vishing operations
- Tailgating & piggybacking
- USB implant deployment
OT
OT / ICS
- Modbus / DNP3 protocol attacks
- IT/OT boundary crossing
- Engineering workstation exploitation
- SCADA historian compromise
- PLC firmware analysis
- Industrial protocol replay
R&D
Custom Tooling & Research
- C2 framework development
- Custom implant development
- Zero-day discovery
- Exploit porting & weaponization
- Capability deconfliction tooling
- Purple team automation