Legal Eagles, Social Spies

Social engineering operation gaining unauthorized access to government-adjacent legal offices through trust building and pretexting.

Our capabilities

While we steer clear of tick box exercises, the groupings below will give an insight into our capabilities at TrethTec. By working with us in an ongoing engagement, we will assess your largest vulnerabilities and work with you to secure them over time.

This was a physical access two-hander, navigating access to a government adjacent legal department. The operators not only secured unauthorised access to a restricted office area but also won over a senior manager, gaining unprecedented trust. This rapport allowed them to conduct interviews with the entire office staff, subtly extracting sensitive passwords. Their successful integration culminated in an extraordinary level of access: being entrusted to lock up the office, which they leveraged to discreetly pick the locks of restricted filing cabinets. This operation underscored the potent combination of trust-building, pretexting and a little sleight of hand.

Related case studies

Lorem ipsum dolor sit amet, consectetur adipiscing elit.

Blog title heading will go here

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Suspendisse varius enim in eros.

Blog title heading will go here

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Suspendisse varius enim in eros.

Blog title heading will go here

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Suspendisse varius enim in eros.

Blog title heading will go here

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Suspendisse varius enim in eros.
No items found.

Digital Heist

Web application test revealing exposed source code leading to cloud environment access and payment system vulnerability. Capability used: Web application testing, source code analysis, payment systems security

Breaking Dawn, Breaking In

A 48-hour physical penetration test spanning manufacturing facility and headquarters, demonstrating vulnerabilities across physical, technical and human security layers.

Case studies FAQs

Please feel free to reach out with any other questions. We treat all enquiries with upmost confidentiality and professional care.

Can you provide references or case studies of previous security testing projects?

Given the sensitive nature of our work, most of our customers prefer to remain anonymous, which can make providing references challenging. However, we have a range of anonymised case studies showcasing our experience across various testing disciplines and industries. These demonstrate the depth of our expertise and the value we provide to organisations facing diverse security challenges. Let us know your area of interest, and we’d be happy to share relevant examples.

How long does a security test usually take?

The duration of a security test varies significantly depending on the provider and the scope of the engagement. Traditional tests can last anywhere from a single day to several months, depending on the complexity and budget. Managed services, such as CounterSOC, typically operate on a continuous basis with year-long contracts. For meaningful security work, we generally advise against engagements shorter than a week, unless the scope is genuinely minimal or involves only a few minor checks. Attempting to compress complex security operations into a short timeframe often leads to poorer results and, in the worst case, a false sense of security.

Your roadmap with Trethtec

The process you can expect when beginning a CounterSOC, ongoing engagement with us. Including monthly and annual roundups with strategic insights and executive alignment.

Month 1

Onboarding and Initial Engagement

Month 1-2

Security Foundation Established: Comprehensive Security Assessment

Month 3

Strategic Security Roadmap Developed: Development of Tailored Security Roadmap

Month 4-12

Continuous Improvement and Adaptation: Implementation of Continuous Adversarial Simulations

Month 4-12

Internal Teams Empowered and Trained: Hands-On Training and Knowledge Transfer