Skip to content

Penetration testing

Internal Network Testing

We assume the perimeter already failed, then find out how far that gets someone inside your network.

Why it matters

What this protects you from

  • The perimeter will eventually fail

    One phished credential or one unpatched host is enough. The question that matters is what happens next.

  • Flat networks turn incidents into disasters

    Segmentation that exists on a diagram but not in the firewall rules is how one workstation becomes every workstation.

  • Active Directory is the real prize

    Most internal compromises end in domain privilege. The paths there are usually configuration, not exploits.

  • Insider risk is the same attack surface

    A contractor with ordinary access and a compromised laptop look identical from the network's point of view.

Coverage

What we test

  • Active Directory attack paths

    Kerberos abuse, delegation misconfiguration, ACL weaknesses and privilege relationships that lead toward domain compromise.

  • Credential exposure and harvesting

    Credentials in shares, scripts and Group Policy, plus in-memory credential exposure on reachable hosts.

  • Lateral movement

    How far a single compromised account or host reaches, and which controls actually stop it rather than log it.

  • Network segmentation

    Whether declared boundaries between user, server, management and sensitive environments hold when tested directly.

  • Host and service configuration

    Patch levels, weak service configuration, legacy protocols and unnecessary local privilege on reachable systems.

  • Detection and response opportunities

    Which of our actions generated telemetry, so you learn where visibility exists and where it does not.

Approach

Three ways to run it

  • Assumed breach

    We start with standard user credentials on a domain-joined host. The most realistic and most common starting point.

  • Unauthenticated internal

    We start with network access only and no credentials, mirroring an unmanaged device plugged into your network.

  • White box

    Credentials plus network documentation and Group Policy, so intended design can be compared against enforced reality.

Process

How the engagement runs

  1. Scoping and authorisation

    We agree environments, host ranges, credential starting points, exclusions and testing windows in writing before anything begins.

  2. Internal discovery

    Enumeration of reachable hosts, services, domains, shares and trust relationships from the agreed starting position.

  3. Credential and privilege analysis

    Identification of credential exposure, privilege relationships and misconfiguration that create paths toward higher access.

  4. Lateral movement and escalation

    Controlled movement along confirmed paths to establish genuine reach, stopping at the boundaries agreed during scoping.

  5. Reporting and remediation

    Findings written as attack paths rather than isolated issues, so you can see which single fix breaks the whole chain.

  6. Retest

    After remediation we retest the affected paths and issue a retest summary confirming they are broken.

Standards

What we test against

NIST SP 800-115
The assessment structure follows the NIST technical guide, which is what procurement and audit teams expect referenced.
OSSTMM
Methodology discipline and scope control, which matters more internally, where the blast radius of a mistake is larger.
MITRE ATT&CK
Every technique used is mapped, so your defensive team can compare our activity against what their tooling detected.
PTES
Execution standard for post-exploitation and lateral movement, keeping the work systematic rather than opportunistic.

Deliverables

What lands in your inbox

  • Executive summary

    A plain-language account of how far an intruder gets and what it would cost, written for a non-technical reader.

  • Overall security grade

    A single grade derived from the most severe confirmed finding, using published thresholds.

  • Attack path narrative

    The route from starting position to highest access reached, step by step, with the break points marked.

  • Detailed technical findings

    Every finding with CVSS vector, CWE classification, affected hosts and reproduction steps.

  • Detection observations

    Which actions should have generated alerts, so gaps in visibility are addressed alongside the findings themselves.

  • Retest summary

    Issued after remediation, confirming which attack paths are closed.

Find out what an attacker would find first.