Penetration testing
Internal Network Testing
We assume the perimeter already failed, then find out how far that gets someone inside your network.
Why it matters
What this protects you from
-
The perimeter will eventually fail
One phished credential or one unpatched host is enough. The question that matters is what happens next.
-
Flat networks turn incidents into disasters
Segmentation that exists on a diagram but not in the firewall rules is how one workstation becomes every workstation.
-
Active Directory is the real prize
Most internal compromises end in domain privilege. The paths there are usually configuration, not exploits.
-
Insider risk is the same attack surface
A contractor with ordinary access and a compromised laptop look identical from the network's point of view.
Coverage
What we test
-
Active Directory attack paths
Kerberos abuse, delegation misconfiguration, ACL weaknesses and privilege relationships that lead toward domain compromise.
-
Credential exposure and harvesting
Credentials in shares, scripts and Group Policy, plus in-memory credential exposure on reachable hosts.
-
Lateral movement
How far a single compromised account or host reaches, and which controls actually stop it rather than log it.
-
Network segmentation
Whether declared boundaries between user, server, management and sensitive environments hold when tested directly.
-
Host and service configuration
Patch levels, weak service configuration, legacy protocols and unnecessary local privilege on reachable systems.
-
Detection and response opportunities
Which of our actions generated telemetry, so you learn where visibility exists and where it does not.
Approach
Three ways to run it
-
Assumed breach
We start with standard user credentials on a domain-joined host. The most realistic and most common starting point.
-
Unauthenticated internal
We start with network access only and no credentials, mirroring an unmanaged device plugged into your network.
-
White box
Credentials plus network documentation and Group Policy, so intended design can be compared against enforced reality.
Process
How the engagement runs
-
Scoping and authorisation
We agree environments, host ranges, credential starting points, exclusions and testing windows in writing before anything begins.
-
Internal discovery
Enumeration of reachable hosts, services, domains, shares and trust relationships from the agreed starting position.
-
Credential and privilege analysis
Identification of credential exposure, privilege relationships and misconfiguration that create paths toward higher access.
-
Lateral movement and escalation
Controlled movement along confirmed paths to establish genuine reach, stopping at the boundaries agreed during scoping.
-
Reporting and remediation
Findings written as attack paths rather than isolated issues, so you can see which single fix breaks the whole chain.
-
Retest
After remediation we retest the affected paths and issue a retest summary confirming they are broken.
Standards
What we test against
- NIST SP 800-115
- The assessment structure follows the NIST technical guide, which is what procurement and audit teams expect referenced.
- OSSTMM
- Methodology discipline and scope control, which matters more internally, where the blast radius of a mistake is larger.
- MITRE ATT&CK
- Every technique used is mapped, so your defensive team can compare our activity against what their tooling detected.
- PTES
- Execution standard for post-exploitation and lateral movement, keeping the work systematic rather than opportunistic.
Deliverables
What lands in your inbox
- Executive summary
A plain-language account of how far an intruder gets and what it would cost, written for a non-technical reader.
- Overall security grade
A single grade derived from the most severe confirmed finding, using published thresholds.
- Attack path narrative
The route from starting position to highest access reached, step by step, with the break points marked.
- Detailed technical findings
Every finding with CVSS vector, CWE classification, affected hosts and reproduction steps.
- Detection observations
Which actions should have generated alerts, so gaps in visibility are addressed alongside the findings themselves.
- Retest summary
Issued after remediation, confirming which attack paths are closed.