Internal & External

Network Penetration Testing

Internal and external network security testing to identify firewall weaknesses, vulnerable services, and lateral movement opportunities.

Coverage

Network Security Testing Areas

Comprehensive infrastructure security assessment

External Testing

Perimeter security assessment including firewall rules, exposed services, and internet-facing assets

Internal Testing

Insider threat simulation, lateral movement, and internal network segmentation testing

Active Directory

AD security assessment, Kerberos attacks, GPO analysis, and privilege escalation paths

Vulnerability Scanning

Comprehensive scanning for known vulnerabilities across network infrastructure

Wireless Testing

WiFi security assessment, rogue access point detection, and wireless attack simulation

Social Engineering

Phishing simulations and physical security testing when combined with network assessments

Process

Network Testing Methodology

Following PTES and OSSTMM standards

1

Reconnaissance

OSINT, DNS enumeration, and external footprint mapping

2

Scanning

Port scanning, service identification, and vulnerability detection

3

Enumeration

Deep dive into discovered services and user enumeration

4

Exploitation

Attempt to exploit vulnerabilities and gain initial access

5

Post-Exploitation

Privilege escalation, lateral movement, and persistence

6

Reporting

Attack path documentation and remediation guidance

Deliverables

What You Receive

  • Network architecture security review
  • Vulnerability assessment with severity ratings
  • Attack path documentation and diagrams
  • Active Directory security analysis
  • Segmentation effectiveness report
  • Prioritized remediation roadmap
How it works

What a Network Penetration Test Looks Like

External and internal testing that goes past the scanner report

Scoping external and internal separately

External tests are scoped on the internet-facing IP ranges and hostnames you own, including cloud-hosted services and third-party-managed edges. Internal tests are scoped on the number of subnets and hosts, the directory environment, and the starting position we agree: a network port with no credentials, a standard user account, or a compromised workstation.

  • Typical effort: 3 to 5 testing days for an external test of a small to medium perimeter; 5 to 10 days for an internal test of a single site with an Active Directory or Entra-joined estate.
  • Access we need for internal testing: a VPN or on-site drop, or a test device we ship, plus a low-privilege domain account for the authenticated phase.
  • Safety: exploitation is confirmed on non-production systems where possible, and anything that could affect availability is agreed in advance.

Attack chains, not vulnerability lists

Scanners produce the starting inventory. The test itself is about chaining: a weak service on the perimeter into a foothold, a foothold into credentials, credentials into lateral movement, and lateral movement into domain or data compromise. We stop at the agreed objective and document every hop so the defensive lesson is clear.

Reporting for infrastructure and identity teams

Findings are grouped by the team that owns the fix: perimeter and firewall, server and patching, identity and directory, and detection. Each carries the affected hosts, evidence, CVSS score, and a remediation at the configuration or policy level. A detection timeline shows which of our actions your monitoring caught.

Retest and attestation

Critical and high findings are retested within 30 days at no cost, with a letter of attestation suitable for PCI DSS, cyber-insurance, and customer assurance.

Coverage

Vulnerability Classes We Test For

The weaknesses that decide whether a perimeter or an internal network holds

External perimeter

Exposed management interfaces, unpatched services with public exploits, weak VPN and remote-access configuration, mail and DNS hardening, TLS weaknesses, and credential spraying against externally reachable authentication. Cloud-hosted assets and forgotten subdomains are enumerated and included.

Active Directory and identity

Kerberoasting and AS-REP roasting, password policy and reuse, delegation misconfigurations, Active Directory Certificate Services abuse, group policy weaknesses, privileged accounts logged on to workstations, and paths to domain administrator from an ordinary user. Hybrid estates are tested for synchronisation and Entra-side escalation.

Lateral movement and segmentation

Relay attacks, credential reuse across tiers, reachable administrative protocols between segments, flat networks where operational technology or finance systems are exposed, and jump-host controls that can be bypassed.

Servers, services, and endpoints

Missing patches with working exploits, default and weak credentials on infrastructure devices, insecure file shares holding credentials or sensitive data, and endpoint protection that can be evaded or is not enforced.

Detection and response

Which of our actions generated alerts, how quickly, and whether anyone responded. The gap between what was exploitable and what was noticed is one of the most useful outputs of an internal test.

Compliance

Standards and Compliance Mapping

Frameworks the test is mapped to

Every finding is tagged to the control it evidences, so the report drops straight into an audit pack instead of needing a second translation exercise. For network engagements the mappings we deliver by default are:

  • PCI DSS v4.0 Requirement 11.4: external and internal penetration testing on a defined methodology, with retest evidence for exploitable findings.
  • ISO/IEC 27001:2022 Annex A 8.8 (management of technical vulnerabilities) and A 8.29 (security testing in development and acceptance).
  • SOC 2 Common Criteria CC7.1 and CC4.1: vulnerability identification and independent evaluation of control effectiveness.
  • OWASP Web Security Testing Guide, OWASP ASVS, and PTES as the underlying methodology references cited in the report.
  • Regulatory expectations for reasonable security safeguards, including data-protection regimes such as the GDPR and India's DPDP Act, where the application handles personal data.

What auditors receive

The report includes a methodology statement, tester attestation, scope and exclusions, a findings register with CVSS v3.1 scores, evidence for each finding, and a signed retest letter once fixes are verified. Customers use the same pack for customer security questionnaires, cyber-insurance renewals, and procurement due diligence.

Further reading: Penetration testing vs vulnerability assessment · Zero trust architecture for the enterprise · Risk-based vulnerability management

FAQ

Common Questions

Strengthen Your Network Defenses

Know your network vulnerabilities before attackers exploit them.

Get Started