How do you manage scope on a large internal Active Directory engagement, and how does that differ from scoping a large web application assessment?
Anonymous
Walked through starting from a proper scoping call to define boundaries and understand the environment, threat modelling where possible, and confirming what's explicitly in and out of scope - then how that plays out differently for AD versus web, including which checks stay relevant (authorisation, session management, IDORs) even when authentication sits with an out of scope external identity provider.
Check out your Company Bowl for anonymous work chats.