Customer story · Healthcare & Life Sciences
The Needle They Almost Missed
A healthcare organization with more than a year of clean annual pentests had Foresite run NodeZero autonomous testing. In 17 hours it exploited 254 attack paths, compromised 319 credentials and reached 739 items of protected PII.

About A healthcare organization handling regulated member data
The client is a healthcare organization that handles regulated member data, including Social Security Numbers and Individual Taxpayer Identification Numbers, and is subject to the HIPAA Security Rule. Its environment spans roughly 100 hosts with three domain controllers. The organization had run annual penetration tests for more than a year, every one of which came back clean, and Foresite serves it as a virtual CISO, providing strategic leadership, program oversight, policy development and compliance guidance.
The challenge
For more than a year the organization ran annual penetration tests, and every one came back clean. Compliance boxes were checked, the security program was well run, and by every available indicator the environment was secure. Annual testing also satisfied the HIPAA Security Rule requirement for technical evaluation, producing reports, finding lists and remediation plans that satisfied auditors.
The problem was structural. A clean test only means a weakness was not found inside that engagement window. Testers work within a defined scope, time window and methodology, and no tester can simultaneously evaluate every credential, protocol, relay opportunity and attack-chain combination across roughly 100 hosts in a single engagement. Conditions that are transient, timing-dependent or that require chaining many simultaneous variables slip through point-in-time testing regardless of its quality.
At stake was regulated member data. Under HIPAA, unauthorized access to protected health information is a breach that triggers notification to affected individuals, to the Department of Health and Human Services and in some cases to the media. Had a real attacker found what the clean tests missed, the organization likely would not have known until members reported identity theft or a ransom note appeared on its file servers.
The solution
Foresite ran an internal test using the NodeZero autonomous penetration testing platform, with no human attacker and no prior knowledge of the environment. In 17 hours NodeZero exploited 254 attack paths, compromised 319 credentials and accessed 739 items of protected personally identifiable information. It did not find one catastrophic flaw; it found three systemic weaknesses that amplified each other, the same pattern a capable attacker would identify and chain.
The first was weak and reused credentials: 32 credentials cracked by dictionary attack, three domain service accounts sharing one password, 140 instances of local credential reuse across database infrastructure and one privileged account cracked in under eight minutes. The second was SMB signing not required on 76 services, combined with three NTLM coercion techniques (PetitPotam, DFSCoerce and PrinterBug) that forced all three domain controllers to hand over machine account hashes, which were relayed to compromise 19 hosts without any password cracking. The third was inadequate endpoint controls, which allowed 137 credentials to be harvested from the Security Account Manager database and LSASS memory.
Foresite then built a prioritized remediation roadmap ordered by leverage: rotate compromised credentials, require SMB signing via Group Policy, apply RPC filters on domain controllers and disable Print Spooler on non-print servers immediately; migrate to Group Managed Service Accounts, deploy LAPS, enforce a 12-character minimum password and verify EDR within 30 days; and on an ongoing basis enable Extended Protection for Authentication, reduce NTLM use and run NodeZero weekly at minimum inside a formal fix, rescan, document workflow. Foresite delivers this NodeZero-powered testing as part of its vCISO and continuous security validation services, so strategy and ground truth work together.
The results
- 254 attack paths exploited, 319 credentials compromised and 739 PII items accessed in 17 hours with no human attacker
- Exposure had been reachable from any foothold inside the network through more than a year of clean annual tests
- Three root causes identified: weak and reused credentials, SMB signing not required with NTLM coercion, and inadequate endpoint controls
- A follow-up scan two weeks later came back clean with nothing fixed, showing why point-in-time testing misses timing-dependent chains
- Prioritized remediation roadmap delivered, with NodeZero scheduled weekly at minimum to verify closure and catch configuration drift
Get the full case study
Download the original document as published by Foresite (PDF, 192.5 KB).
Your story could be next
Want results like these?
Every result on this page started with one conversation — let's have yours.


