Australia Based · Operating Internationally · OSCE / OSCP Certified
☏ 1300 859 443
Internal penetration testing

Internal Penetration Testing

Senior-led, assumed-breach testing of your internal network and Active Directory. We start from a realistic foothold — a phished laptop, a rogue device, a malicious insider — and manually chain privilege escalation, credential harvesting and lateral movement toward Domain Admin, then hand you a prioritised, evidence-backed report and a free retest to prove every fix holds.

  • Assumed-breach & Active Directory specialists
  • OSCP / OSCE-certified testers
  • Manual exploitation — never a scan-and-send
  • Free remediation retest included
Maps to SOC 2 ISO 27001 PCI-DSS 11.4 Essential Eight MITRE ATT&CK
Why it matters

One phished laptop is one hop from Domain Admin.

Most breaches don't start at the firewall — they start with one compromised workstation, one reused password, one over-permissioned service account. From there, an attacker doesn't need a zero-day; they need Active Directory misconfigurations most environments already have. An assumed-breach test starts exactly where the real attacker ends up, and proves how far that foothold actually reaches.

Assumed breach
We start from a realistic foothold — the same position a real attacker reaches after one successful phish.
Free
Remediation retest included — we confirm each fix actually holds.
What we test

Full coverage of the paths that lead from foothold to Domain Admin.

Structured around how real intrusions actually unfold inside a Windows/Active Directory environment — from initial foothold, through privilege escalation, to full domain compromise.

  • Active Directory Attacks

    Kerberoasting, AS-REP roasting, delegation abuse and ACL misconfigurations across the domain.

  • Privilege Escalation

    Local and domain privilege-escalation paths from a standard user to administrator.

  • Credential Harvesting & Reuse

    Cached credentials, password reuse, and pass-the-hash / pass-the-ticket attacks.

  • Lateral Movement & Pivoting

    Moving between hosts and network segments using the same legitimate tools and protocols attackers rely on.

  • Network Segmentation

    Whether VLANs, firewalls and trust boundaries actually contain a breach once it starts.

  • Workstation & Server Hardening

    Local misconfigurations, unpatched services and insecure defaults an attacker pivots through.

  • Sensitive Data Access

    What an attacker can reach on file shares, databases and internal applications once inside.

  • Detection & Logging Gaps

    Whether your SOC, EDR and logging would actually see and stop the attack chain we used.

How an engagement runs

From assumed foothold to retest — a disciplined, four-phase engagement.

  1. 01

    Scope & rules of engagement

    We agree the assumed-breach starting point — a foothold or standard-user credentials — the domain(s) in scope, and safe testing windows.

  2. 02

    Internal recon & AD mapping

    We enumerate the domain — users, groups, trusts and misconfigurations — to build the full picture of possible attack paths.

  3. 03

    Exploitation, priv-esc & lateral movement

    We hand-chain real techniques to escalate privilege and move across the network, and — where authorised — reach Domain Admin.

  4. 04

    Report & free retest

    You get a prioritised, evidence-backed attack-path report; after you remediate, we retest to confirm every path is closed — at no extra cost.

What you get

A report your IT team can act on — and your auditors accept.

  • Prioritised findings

    Every attack path risk-rated by real business impact and ordered so you close what matters first.

  • Reproducible evidence

    Step-by-step reproduction for each technique and escalation path — no vague, unverifiable claims.

  • IT-ready remediation

    Specific, actionable hardening guidance written for your sysadmins and IT team, not a generic checklist.

  • Executive summary

    A plain-language overview for leadership, boards and clients requesting assurance.

  • Free remediation retest

    We re-test your fixes and confirm they hold — included with every engagement.

  • Attestation letter

    A summary letter you can share with customers, partners and auditors on request.

Compliance mapping

Evidence that maps to the frameworks you report against.

One engagement, structured so its output slots straight into the assurance work you already have to do.

How this engagement maps to common compliance frameworks
Framework How this engagement maps
PCI-DSS 11.4.3 / 11.4.5 Satisfies the annual internal penetration-testing and network-segmentation-testing requirements for cardholder-data environments.
SOC 2 Provides the independent internal pentest evidence auditors expect for the Security trust-services criteria.
ISO 27001 (A.8.8 / A.8.29) Supports the technical-vulnerability-management and security-testing controls in your ISMS.
Essential Eight (ASD) Validates patching, privileged-access-management and application-control controls the maturity model expects to be exercised.
MITRE ATT&CK Attack paths are mapped to real ATT&CK tactics and techniques, giving you a technique-level view of exposure.
Common questions

What teams ask before an internal test.

What's the difference between an internal penetration test and a black-box (external) test?

A black-box test starts outside your perimeter; an internal, assumed-breach test starts inside — from a foothold like a phished workstation or a malicious insider — and focuses on privilege escalation and lateral movement rather than perimeter defences.

Do you test on-site, or remotely via VPN?

Most internal engagements run remotely through a secure VPN implant device shipped to your office or a jump host you provide. On-site testing is available where required.

Is it safe to run this against our production network?

Yes. We work within agreed rules of engagement, avoid destructive actions by default, and coordinate any higher-risk techniques — such as domain-wide password spraying — with you in advance.

Is the goal always to reach Domain Admin?

Not always. Domain Admin (or an equivalent crown-jewel) is a common objective because it proves worst-case impact, but the objective and any stopping points are agreed with you at scoping.

How long does an internal penetration test take?

Most engagements run one to two weeks, depending on network size and domain complexity. We confirm timing at scoping.

Can we use the report for SOC 2, PCI-DSS or Essential Eight assurance?

Yes. The report and optional attestation letter are written to satisfy auditor and customer requirements across SOC 2, PCI-DSS and the Essential Eight.

Get a scoping call

Get a fixed-price scoping quote.

A senior tester scopes the right engagement and sends a fixed quote — no automated sales funnel, no obligation.

Core Sentinel Contact Form

A senior tester replies personally — no obligation, no automated sales funnel.