You're exploring Lakewood Unified School District — a sample K-12 district with real attack paths. No sign-up required.See your district's attack paths →
Sample District · Read-only

Lakewood Unified School District

580 Windows endpoints · 1,400 Chromebooks · 6 servers · 420 staff · Last scan: Monday 6:00 AM
Upload your district's data →
4
Attack Paths
2
Critical Paths
1,986
Devices Monitored
5
Scans This Week
🛡 Monday Morning BriefFix these first
1
Student VLAN can reach SIS server via SMB (port 445)
CVE-2023-46604 · CVSS 9.8 · Meraki + Tenable · sis-server-01.lusd.local
Block port 445 between student VLAN (10.10.0.0/16) and server VLAN (10.20.0.0/16) in Meraki firewall policy.
CRITICAL
2
Domain Controller exposed via unpatched staff endpoint
CVE-2023-23397 · CVSS 9.8 · Active Directory + Defender · staff-laptop-042
Patch CVE-2023-23397 on all Windows endpoints. 47 unpatched devices identified in Defender export.
CRITICAL
3
Vendor remote access path to internal network
Meraki policy gap · vendor-vpn-gateway → sis-server-01.lusd.local · 2 hops
Restrict vendor VPN to specific IPs and required ports only. Current policy allows unrestricted LAN access.
HIGH
4
18 Chromebooks offline 45+ days — unmanaged
Google Admin · possible lost or stolen devices · last seen: 2026-05-12
Remotely wipe or disable in Google Admin. Re-enroll before granting network access if recovered.
MEDIUM
5
3 stale admin accounts — 90+ days inactive
Active Directory · svc_print_admin, j.torres.admin, backup_svc · last login: Jan 2026
Disable or remove these accounts. Stale admin accounts are a common lateral movement enabler.
MEDIUM
Attack Paths Detected4 of 4 K-12 paths active
AP-K12-001CRITICAL
Staff Phishing → Active Directory Takeover
Microsoft DefenderActive Directory
AP-K12-002CRITICAL
Vendor VPN → PowerSchool SIS Database
MerakiTenable
AP-K12-003HIGH
Unpatched Internet-Facing Server → Ransomware
TenableMeraki
AP-K12-004HIGH
Student Chromebook → Server VLAN Pivot
MerakiGoogle Admin
AP-K12-001Most common K-12 path
CRITICAL

Staff Phishing → Active Directory Takeover

A phishing email harvests staff credentials. CVE-2023-23397 on an unpatched Windows endpoint enables lateral movement to the Domain Controller, giving the attacker administrative access to all district systems including FERPA-protected student records.

staff-laptop-042
CVE-2023-23397 · CVSS 9.8
dc-01.lusd.local
Domain Controller · AD admin
student-records-db
FERPA data · 42,000 records
Recommended fix
Patch CVE-2023-23397 on all Windows endpoints (47 affected). Enable MFA on all admin accounts. Segment DC from general staff network.
AP-K12-002PowerSchool breach pattern
CRITICAL

Vendor VPN → PowerSchool SIS Database

A third-party vendor has VPN access with unrestricted LAN privileges. Combined with CVE-2023-46604 on the SIS server, an attacker with vendor credentials can reach the PowerSchool database directly — the exact pattern from the December 2024 breach affecting 60M+ student records.

vendor-vpn-gateway
Unrestricted LAN access
sis-server-01.lusd.local
CVE-2023-46604 · CVSS 9.8
PowerSchool DB
60M+ record breach pattern
Recommended fix
Patch CVE-2023-46604 immediately. Restrict vendor VPN to specific IPs and required ports. Enable firewall logging on all vendor traffic.
AP-K12-003Internet-exposed RCE
HIGH

Unpatched Internet-Facing Server → Ransomware

sis-server-01.lusd.local is internet-facing with CVE-2023-46604 unpatched — a remote code execution vulnerability with CVSS 9.8. An external attacker can exploit this to deploy ransomware across the district network with no credential theft required.

Internet
No authentication required
sis-server-01.lusd.local
CVE-2023-46604 · RCE · internet-facing
Ransomware deployment
Full district network at risk
Recommended fix
Patch CVE-2023-46604. Remove internet exposure — SIS servers should not be directly internet-facing. Place behind a reverse proxy with WAF.
AP-K12-004Flat network risk
HIGH

Student Chromebook → Server VLAN Pivot

The Meraki firewall allows unrestricted traffic from the student VLAN (10.10.0.0/16) to the server VLAN (10.20.0.0/16) on port 445. A compromised student Chromebook — or a student probing the network — can reach file servers and the SIS server directly.

student-chromebook-*
Student VLAN · 1,400 devices
Meraki firewall gap
Port 445 allowed across VLANs
Server VLAN
File servers + SIS reachable
Recommended fix
Add Meraki deny rule: block all from VLAN 10.10.0.0/16 to VLAN 10.20.0.0/16 port 445. Allow only specific ports required for classroom tools.

Does your district look like Lakewood?

Upload one CSV from Defender, Google Admin, or Tenable. Your first attack path appears in under 10 minutes.

$4/device/year · SLCGP grant eligible · No new agents required