What the chains actually looked like
Each of these reconstructs a chain from real B-52 engagements: what was done, what each step handed to the next, and what changed afterwards. Every step carries the weakness it maps to and the severity it was rated.
They are composites, and no customer is named on any of them. The engagement archive is usable for exactly this, anonymised to sector, industry and geography — so that is what you get, and the techniques are the part that transfers anyway.
The set
Five chains, five classes
Ordered by how much of the platform each one exercises rather than by date. The class column links to what that coverage class does in full.
| Engagement | Sector | Coverage class | Chain |
|---|---|---|---|
| Tenant isolation on a SaaS platform | Multi-tenant SaaS | Web applications | 4 steps |
| A valid user of one tenant reaching another tenant’s records, through an identifier the server resolved without asking who owned it. | |||
| Account takeover in a payments flow | Payments | APIs | 4 steps |
| A login endpoint that answered differently for a known account than an unknown one, and what that difference was worth to somebody patient. | |||
| From an exposed secret to code execution | Retail e-commerce | External network | 4 steps |
| A credential reachable without authenticating, still valid somewhere it should never have worked, and the execution that followed. | |||
| Internal foothold to domain admin | Manufacturing | Active Directory | 5 steps |
| A service account recovered from where it was left, reused where it should not have been, and the path to privilege that opened. | |||
| A mobile binary and the API behind it | Banking | Mobile apps | 5 steps |
| What a decompiled package said about the server behind it, and what the server accepted once somebody had read it. | |||
Tenant isolation on a SaaS platform
- Sector
- Multi-tenant SaaS
- Coverage class
- Web applications
- Chain
- 4 steps
A valid user of one tenant reaching another tenant’s records, through an identifier the server resolved without asking who owned it.
Account takeover in a payments flow
- Sector
- Payments
- Coverage class
- APIs
- Chain
- 4 steps
A login endpoint that answered differently for a known account than an unknown one, and what that difference was worth to somebody patient.
From an exposed secret to code execution
- Sector
- Retail e-commerce
- Coverage class
- External network
- Chain
- 4 steps
A credential reachable without authenticating, still valid somewhere it should never have worked, and the execution that followed.
Internal foothold to domain admin
- Sector
- Manufacturing
- Coverage class
- Active Directory
- Chain
- 5 steps
A service account recovered from where it was left, reused where it should not have been, and the path to privilege that opened.
A mobile binary and the API behind it
- Sector
- Banking
- Coverage class
- Mobile apps
- Chain
- 5 steps
What a decompiled package said about the server behind it, and what the server accepted once somebody had read it.
What is not here
The classes with no chain published yet
B-52 covers eleven coverage classes. 6 of them have no composite on this page yet, and naming them is more useful than letting the absence read as coverage:
Each of those is covered by the platform and has its own page. What it does not have is a chain written up here, which is a statement about this page rather than about the class.
Point it at something of yours
One application or one target, $500, and the report carries the same request, response and steps to reproduce that every chain on this page was written from.