Does access to one system prove access to the wider network?¶
No. Segmentation, permissions, authentication and firewalls may confine a foothold to one device, account, application or network segment.
Define the opportunity from the first foothold¶
Reconstruct routes, reachable services, credentials, mapped shares, active sessions and management tools available at the relevant time. Those artefacts can increase opportunity but do not show that any route was used.
Credentials may be expired, a reachable service may reject authentication and a network path may allow only limited traffic. Map the actual controls rather than treating connectivity diagrams as proof of access.
Prove each later transition¶
Look for connections and authentication on both source and target. Matching records strengthen the conclusion, while incomplete logging should be stated as a limitation rather than converted into proof or disproof.
Keep technical possibility, attempted connection, accepted authentication and resulting target activity separate. Only systems supported by those records should be described as accessed; connected but untested systems remain potential scope, not confirmed compromise.
Key takeaway
Define what the first foothold could reach, then prove each later connection and authentication instead of assuming network-wide access.