Findings

A finding marks the moment an administrative gap, missing credential control, or unauthenticated protocol may turn into traversable network authority. Within a flat network, findings such as absent local administrator password randomisation, Group Policy Preferences credentials, and roastable service accounts may together clear a path to domain administration.

An industrial cell hosting human-machine interface project files on an unauthenticated share may also contain programmable logic controllers requiring no authentication, potentially allowing logic to be read and, depending on controller configuration, later overwritten from any host that can route to them.

An over-permissioned cloud role combined with Instance Metadata Service Version 1 (IMDSv1) and publicly exposed secrets can expose temporary credentials and enable direct data lake reads where a request forgery flaw reaches the metadata service.

A web application vulnerability such as server-side request forgery, an insecure direct object reference, or a deserialisation sink can extend reach into underlying services, databases, or the hosting environment.

Each finding carries a weight and a provenance, and some rest on inference alone: response timing, error wording, or what a model’s own answers give away about its training data.

Draw it as an edge in Mapping, or spend it now where a finding already yields position.