Internal Penetration Test
We simulate a breach scenario — attacker already inside via a compromised workstation, phishing link, stolen VPN credential or physical network access. We don't assess the perimeter. We answer the question that actually matters: how far can an attacker get once they're in? The output is a precise attack chain from unprivileged domain user to full domain compromise.
Active host discovery, open port enumeration and service fingerprinting. OS and version identification. VLAN and segmentation mapping, management interfaces (iDRAC, IPMI, web consoles).
- TCP/UDP port scanning, service enumeration
- SNMPv1 community string enumeration
- Default credentials on network devices and management interfaces
- Detection of cleartext internal protocols (Telnet, FTP, HTTP)
The most common path to full compromise. BloodHound maps every route to Domain Admin — then we validate each one manually against your environment.
- Kerberoasting and AS-REP Roasting (service account hash cracking)
- NTLM relay, Pass-the-Hash, Pass-the-Ticket
- Active Directory Certificate Services (ADCS) — ESC1 through ESC8
- Misconfigured GPO, ACL and permission delegation
- Misconfigured domain trusts and SID history abuse
Firewalls, switches, routers, printers and VPN gateways are a chronically overlooked attack surface. We test every misconfiguration and unnecessarily exposed interface.
- Unauthorised access to management interfaces (web GUI, SSH, SNMP)
- ACL and firewall rule misconfigurations
- Printers and IoT devices as pivot points into the rest of the network
- VPN gateways — authentication, encryption and session management
Starting from a compromised workstation — we escalate privileges, move laterally and reach the data that matters to your business.
- DLL Hijacking, Unquoted Service Path, token impersonation
- AV/EDR evasion (AMSI bypass, Living-off-the-Land binaries)
- Lateral movement via SMB, WMI, PsExec, RDP, WinRM
- Access to databases, file servers and backup systems
- Data exfiltration simulation within agreed scope