Network penetration testing
External edge to
Domain Admin.
Two tests, usually sold separately, that answer one question together: can someone get in from outside, and once inside, how far do they get. We run both and show you the join.
The perimeter is not the test. The blast radius is.
Most organisations pass an external test and still fall over internally in a day. One reused local administrator password, one over permissioned service account, one certificate template nobody reviewed, and the estate is gone. We test the part that actually decides how bad a breach becomes.
The perimeter,
as an attacker sees it.
Your real external surface is bigger than your asset inventory. It usually includes things no one has owned for years.
Surface
Attack surface discovery
Subdomain enumeration, forgotten staging hosts, expired but still resolving records, and cloud assets spun up outside the change process.
Edge
Edge service exploitation
VPN concentrators, mail gateways, file transfer appliances and remote access portals. The devices that terminate untrusted traffic and hold credentials.
Credentials
Credential exposure
Breach corpus reuse against your portals, password spraying within lockout policy, and tokens leaked in public repositories or job adverts.
Seen in the field
What it looks like
in practice.
An illustrative example of the class of issue this engagement is built to find, and what changes after it.
Illustrative example, not client data
BeforeWhat we found
# coerce a host to authenticate, relay it onward $ ntlmrelay -t ldap://dc01.corp.local [*] Authentication relayed: CORP\FS01$ [*] Target signing: not enforced [*] Channel binding: not enforced [+] Added machine account OWL01$ [+] Delegation rights written
AfterAfter the fix
# same coercion, signing now enforced $ ntlmrelay -t ldap://dc01.corp.local [*] Authentication received: CORP\FS01$ [!] LDAP signing required [!] Channel binding enforced [-] Relay refused by target
NTLM relay. Nothing here is a missing patch. Authentication was coercible and the domain controller accepted relayed sessions because signing was never enforced. Two policy settings end the entire class of attack.
Inside the estate,
the way it falls.
We start from an assumed foothold, which is what a phishing email or a compromised laptop actually buys an attacker, then move.
01
Active Directory attack paths
Kerberoasting, AS-REP roasting, unconstrained and constrained delegation, ACL abuse and certificate services misconfiguration. See the AD method.
02
Credential harvesting and reuse
Local administrator password reuse across the estate, cached credentials, service accounts with weak passwords and excessive rights, and secrets in scripts and shares.
03
Relay and coercion
NTLM relay, authentication coercion, and signing that was left unenforced on the exact hosts where it mattered most.
04
Lateral movement
Moving host to host with the access we have, escalating where a path exists, and reaching the systems that would actually hurt you to lose.
05
Segmentation testing
Proving whether your network boundaries are real. Can a compromised workstation reach the card environment, the backup network or the manufacturing floor.
06
Detection checkpoints
We log what should have alerted and when. If nothing fired for any of it, that is a finding in its own right. Read the field guide.
Scope the network test.
Request a quoteExternal, internal,
or both.
Most teams should run both at least annually. Here is how they differ and what each one answers.
| External network test | Internal network test | |
|---|---|---|
| Starting point | The public internet, no access | An assumed foothold inside the network |
| Question it answers | Can an attacker get in from outside | How far does an attacker get once inside |
| Typical duration | Three to five days | One to two weeks |
| Usual outcome | A small number of high value edge findings | A full path to Domain Admin, plus the reasons it worked |
| Run it when | The perimeter changed, or annually | Annually, and after any acquisition or major migration |
Questions
The usual
questions.
What is the difference between this and your network assessment?
The network assessment is the engagement wrapper: external and internal together under one contract, with the scoping, reporting and retest model. This page describes the testing methodology itself. If you want both halves under one fixed price, start with the assessment.
Do you need to be on site for an internal test?
No. Internal testing runs from a small virtual machine or a device we ship, connected to the segment in scope. Remote delivery is the default and it does not reduce coverage.
Will you actually try to reach Domain Admin?
Yes, if the scope allows it, because proving the path is the point. We agree escalation limits in writing first and we stop at the agreed boundary.
Is this the same as a vulnerability scan?
No. A scan lists missing patches. A penetration test chains findings into a working path to something that matters. We use scanning as an input, never as the deliverable. See VAPT services if you need both.
How disruptive is internal testing?
Low. We avoid destructive techniques by default, agree safety rules up front, and coordinate test windows for anything sensitive. We have never taken a client environment down.
Scope the network test.
A senior operator replies within one business day. No sales pipeline, no bot.