Network penetration testing

External edge to
Domain Admin.

Two tests, usually sold separately, that answer one question together: can someone get in from outside, and once inside, how far do they get. We run both and show you the join.

The perimeter is not the test. The blast radius is.

Most organisations pass an external test and still fall over internally in a day. One reused local administrator password, one over permissioned service account, one certificate template nobody reviewed, and the estate is gone. We test the part that actually decides how bad a breach becomes.

The perimeter,
as an attacker sees it.

Your real external surface is bigger than your asset inventory. It usually includes things no one has owned for years.

Surface

Attack surface discovery

Subdomain enumeration, forgotten staging hosts, expired but still resolving records, and cloud assets spun up outside the change process.

Edge

Edge service exploitation

VPN concentrators, mail gateways, file transfer appliances and remote access portals. The devices that terminate untrusted traffic and hold credentials.

Credentials

Credential exposure

Breach corpus reuse against your portals, password spraying within lockout policy, and tokens leaked in public repositories or job adverts.

Seen in the field

What it looks like
in practice.

An illustrative example of the class of issue this engagement is built to find, and what changes after it.

Illustrative example, not client data

operator@overwatch: internal engagement, relay chain Illustrative example

BeforeWhat we found

# coerce a host to authenticate, relay it onward
$ ntlmrelay -t ldap://dc01.corp.local

[*] Authentication relayed: CORP\FS01$
[*] Target signing:  not enforced
[*] Channel binding: not enforced
[+] Added machine account OWL01$
[+] Delegation rights written

AfterAfter the fix

# same coercion, signing now enforced
$ ntlmrelay -t ldap://dc01.corp.local

[*] Authentication received: CORP\FS01$
[!] LDAP signing required
[!] Channel binding enforced
[-] Relay refused by target

NTLM relay. Nothing here is a missing patch. Authentication was coercible and the domain controller accepted relayed sessions because signing was never enforced. Two policy settings end the entire class of attack.

Inside the estate,
the way it falls.

We start from an assumed foothold, which is what a phishing email or a compromised laptop actually buys an attacker, then move.

01

Active Directory attack paths

Kerberoasting, AS-REP roasting, unconstrained and constrained delegation, ACL abuse and certificate services misconfiguration. See the AD method.

02

Credential harvesting and reuse

Local administrator password reuse across the estate, cached credentials, service accounts with weak passwords and excessive rights, and secrets in scripts and shares.

03

Relay and coercion

NTLM relay, authentication coercion, and signing that was left unenforced on the exact hosts where it mattered most.

04

Lateral movement

Moving host to host with the access we have, escalating where a path exists, and reaching the systems that would actually hurt you to lose.

05

Segmentation testing

Proving whether your network boundaries are real. Can a compromised workstation reach the card environment, the backup network or the manufacturing floor.

06

Detection checkpoints

We log what should have alerted and when. If nothing fired for any of it, that is a finding in its own right. Read the field guide.

Scope the network test.

Request a quote

External, internal,
or both.

Most teams should run both at least annually. Here is how they differ and what each one answers.

External network testInternal network test
Starting pointThe public internet, no accessAn assumed foothold inside the network
Question it answersCan an attacker get in from outsideHow far does an attacker get once inside
Typical durationThree to five daysOne to two weeks
Usual outcomeA small number of high value edge findingsA full path to Domain Admin, plus the reasons it worked
Run it whenThe perimeter changed, or annuallyAnnually, and after any acquisition or major migration

Questions

The usual
questions.

What is the difference between this and your network assessment?

The network assessment is the engagement wrapper: external and internal together under one contract, with the scoping, reporting and retest model. This page describes the testing methodology itself. If you want both halves under one fixed price, start with the assessment.

Do you need to be on site for an internal test?

No. Internal testing runs from a small virtual machine or a device we ship, connected to the segment in scope. Remote delivery is the default and it does not reduce coverage.

Will you actually try to reach Domain Admin?

Yes, if the scope allows it, because proving the path is the point. We agree escalation limits in writing first and we stop at the agreed boundary.

Is this the same as a vulnerability scan?

No. A scan lists missing patches. A penetration test chains findings into a working path to something that matters. We use scanning as an input, never as the deliverable. See VAPT services if you need both.

How disruptive is internal testing?

Low. We avoid destructive techniques by default, agree safety rules up front, and coordinate test windows for anything sensitive. We have never taken a client environment down.

Scope the network test.

A senior operator replies within one business day. No sales pipeline, no bot.