Infrastructure

Network Penetration Testing

Internal and external testing that identifies exploitable misconfigurations, unpatched systems, and the attack paths that let one foothold turn into full domain compromise.

Security tester conducting a network penetration test
Scope

External vs. Internal Testing

External Network

Everything reachable from the internet: perimeter firewalls, VPN gateways, exposed services, DNS, and mail infrastructure. Finds what an anonymous internet attacker could reach without any prior access.

Internal Network

Simulates a foothold already inside your network — a compromised laptop, a rogue device, or a malicious insider — and tests lateral movement, privilege escalation, and Active Directory attack paths.

Coverage

What We Test

Unpatched Services

Known CVEs in exposed services and outdated software versions.

Credential Weaknesses

Default, weak, and reused credentials across services and devices.

Insecure Protocols

SMBv1, Telnet, unencrypted LDAP, and other legacy protocols still in use.

Firewall & ACL Review

Misconfigured rules, overly broad access, and missing segmentation.

Active Directory Attack Paths

Kerberoasting, AS-REP roasting, NTLM relay, and misconfigured delegation.

Lateral Movement

How far a single compromised host can reach across your network.

VPN & Remote Access

Gateway configuration, authentication strength, and split-tunneling risk.

Network Segmentation

Whether sensitive zones (e.g. a cardholder data environment) are genuinely isolated.

Wireless (Optional)

Rogue access points, weak encryption, and client isolation, where in scope.

Delivery

Remote or On-Site

Remote

External testing is always remote. Internal testing can run remotely too, using a small drop-box device shipped to your site or a VPN connection into the internal network segment.

On-Site

Available for engagements that specifically require physical network access, wireless testing, or where your policy requires testers on-premises.

FAQ

Network Testing Questions

Do you need domain-admin credentials for internal testing?

No. We typically start with no credentials or a standard low-privilege domain account, matching what a realistic attacker would have, then attempt to escalate.

Will this affect production network availability?

We avoid intentionally disruptive techniques (denial-of-service, unthrottled brute force) unless explicitly authorized in the rules of engagement, and agree a testing window in advance.

How many IPs or hosts can be tested?

Any size — pricing scales with host count and complexity. Tell us your rough IP range or host count when requesting a quote.

Ready to Test Your Network?

Tell us your environment and we'll scope the right engagement.