[ Infrastructure ]
Internal Network Penetration Testing
- Typical duration
- 5-10 days
- Starting price
- Scoped
- You provide
- Network access, standard user account
[ 01 / The engagement ]
Assume somebody clicked the link. Internal testing starts from that position, a single machine on your network, with the access an ordinary employee has, and measures how far it goes. In most networks the honest answer is domain admin in under a day, and the reason is almost never a missing patch. It is flat segmentation, cached credentials and a service account nobody has rotated since 2019.
[ 02 / Coverage ]
What we test, in practice.
This is the working checklist, not a marketing list. Anything your scope adds gets written into the engagement letter before we start.
Methodology
- 01Network segmentation and VLAN boundary validation
- 02LLMNR, NBT-NS and mDNS poisoning with relay
- 03SMB signing, NTLM relay and coerced authentication
- 04Credential harvesting from memory, shares and Group Policy
- 05Lateral movement and pivot mapping to crown-jewel systems
- 06Legacy protocol and unsupported operating system exposure
- 07Data exfiltration paths out of the environment
[ 03 / What you get ]
Four things land at the end of every engagement.
Technical report
Every finding with CVSS v4.0 score, evidence, reproduction steps and a specific fix, written for the engineer who has to close it.
Executive summary
Two pages your board can read. Risk in business terms, with the three things that matter most called out.
Letter of attestation
A shareable document proving the test happened and what it covered, for customers and auditors who should not see the full report.
Free retest
Once you have fixed things, the same tester verifies each finding and reissues the report. Included for 90 days.
[ 04 / Questions ]
Before you commit.
Rarely. We ship a hardened testing device that dials out to us, or work from a VM on your hypervisor. On-site is available where policy requires it.
That is your call. We do not run destructive attacks, so a standard test will not knock anything over whether your SOC knows or not. Tell them and you get clean coverage with no noise. Keep them in the dark and you also get a free read on how well they detect real activity. If measuring detection is the whole point, that is a red team engagement and we scope it that way.
Often scoped together
All services →External Network Penetration Testing
Everything of yours that answers from the internet, including what you forgot.
Active Directory Security Assessment
The attack paths from any user to Domain Admin, mapped and proven.
Cloud Penetration Testing
AWS, Azure and GCP, IAM paths, workload escape and the blast radius of one key.
Scope a internal network penetration testing.
Send us the target and the deadline. You get a written scope and a fixed price, usually within one working day.