Multi-forest environment recovered in isolation How they were breached Teams social engineering Initial access via remote forest Users phished to reset passwords Credential compromise on spoofed site AD trusts exploited across forests Lateral movement to production Admin accounts exposed on endpoints Privilege escalation
<2 hours Isolation and recovery with ADFR Environment and scope Vertical: Oil & gasScope: On-prem AD recoveryFootprint: Multiple forests across multiple locationsCustomer: Existing DSP customerBreached by social engineering via Teams and phishing
4 - 5 days Estimated time without ADFR The ADFR advantage Multi-forest recovery in under two hoursOne automated restore across every forest at onceMalware-free recovery means lowered risk of reintroducing the threat
16 Domain controllers recovered How they were breached External Teams call + screen share Initial access via social engineering Kerberoasting on an SPN account Credential threat Lateral movement to find DA credentials Privilege escalation DLL hijacking / library injection Malicious payload
<30 mins DCs restored with ADFR Environment and scope Vertical: TransportationScope: On-prem AD recoveryFootprint: 16 DCs across 3-4 regions nationwideCustomer: Existing customerBreached by social engineering via external Teams call
1 week+ Estimated time without ADFR The ADFR advantage Full environment operational within ~4 hours (isolation + restore)All 16 DCs restored, no in-site travelOne automated restore across every region at onceMalware-free recovery means lowered risk of reintroducing the threat