Internal Penetration Testing
Senior-led, assumed-breach testing of your internal network and Active Directory. We start from a realistic foothold — a phished laptop, a rogue device, a malicious insider — and manually chain privilege escalation, credential harvesting and lateral movement toward Domain Admin, then hand you a prioritised, evidence-backed report and a free retest to prove every fix holds.
- Assumed-breach & Active Directory specialists
- OSCP / OSCE-certified testers
- Manual exploitation — never a scan-and-send
- Free remediation retest included
One phished laptop is one hop from Domain Admin.
Most breaches don't start at the firewall — they start with one compromised workstation, one reused password, one over-permissioned service account. From there, an attacker doesn't need a zero-day; they need Active Directory misconfigurations most environments already have. An assumed-breach test starts exactly where the real attacker ends up, and proves how far that foothold actually reaches.
Full coverage of the paths that lead from foothold to Domain Admin.
Structured around how real intrusions actually unfold inside a Windows/Active Directory environment — from initial foothold, through privilege escalation, to full domain compromise.
-
Active Directory Attacks
Kerberoasting, AS-REP roasting, delegation abuse and ACL misconfigurations across the domain.
-
Privilege Escalation
Local and domain privilege-escalation paths from a standard user to administrator.
-
Credential Harvesting & Reuse
Cached credentials, password reuse, and pass-the-hash / pass-the-ticket attacks.
-
Lateral Movement & Pivoting
Moving between hosts and network segments using the same legitimate tools and protocols attackers rely on.
-
Network Segmentation
Whether VLANs, firewalls and trust boundaries actually contain a breach once it starts.
-
Workstation & Server Hardening
Local misconfigurations, unpatched services and insecure defaults an attacker pivots through.
-
Sensitive Data Access
What an attacker can reach on file shares, databases and internal applications once inside.
-
Detection & Logging Gaps
Whether your SOC, EDR and logging would actually see and stop the attack chain we used.
From assumed foothold to retest — a disciplined, four-phase engagement.
-
01
Scope & rules of engagement
We agree the assumed-breach starting point — a foothold or standard-user credentials — the domain(s) in scope, and safe testing windows.
-
02
Internal recon & AD mapping
We enumerate the domain — users, groups, trusts and misconfigurations — to build the full picture of possible attack paths.
-
03
Exploitation, priv-esc & lateral movement
We hand-chain real techniques to escalate privilege and move across the network, and — where authorised — reach Domain Admin.
-
04
Report & free retest
You get a prioritised, evidence-backed attack-path report; after you remediate, we retest to confirm every path is closed — at no extra cost.
A report your IT team can act on — and your auditors accept.
-
Prioritised findings
Every attack path risk-rated by real business impact and ordered so you close what matters first.
-
Reproducible evidence
Step-by-step reproduction for each technique and escalation path — no vague, unverifiable claims.
-
IT-ready remediation
Specific, actionable hardening guidance written for your sysadmins and IT team, not a generic checklist.
-
Executive summary
A plain-language overview for leadership, boards and clients requesting assurance.
-
Free remediation retest
We re-test your fixes and confirm they hold — included with every engagement.
-
Attestation letter
A summary letter you can share with customers, partners and auditors on request.
Evidence that maps to the frameworks you report against.
One engagement, structured so its output slots straight into the assurance work you already have to do.
| Framework | How this engagement maps |
|---|---|
| PCI-DSS 11.4.3 / 11.4.5 | Satisfies the annual internal penetration-testing and network-segmentation-testing requirements for cardholder-data environments. |
| SOC 2 | Provides the independent internal pentest evidence auditors expect for the Security trust-services criteria. |
| ISO 27001 (A.8.8 / A.8.29) | Supports the technical-vulnerability-management and security-testing controls in your ISMS. |
| Essential Eight (ASD) | Validates patching, privileged-access-management and application-control controls the maturity model expects to be exercised. |
| MITRE ATT&CK | Attack paths are mapped to real ATT&CK tactics and techniques, giving you a technique-level view of exposure. |
What teams ask before an internal test.
What's the difference between an internal penetration test and a black-box (external) test?
A black-box test starts outside your perimeter; an internal, assumed-breach test starts inside — from a foothold like a phished workstation or a malicious insider — and focuses on privilege escalation and lateral movement rather than perimeter defences.
Do you test on-site, or remotely via VPN?
Most internal engagements run remotely through a secure VPN implant device shipped to your office or a jump host you provide. On-site testing is available where required.
Is it safe to run this against our production network?
Yes. We work within agreed rules of engagement, avoid destructive actions by default, and coordinate any higher-risk techniques — such as domain-wide password spraying — with you in advance.
Is the goal always to reach Domain Admin?
Not always. Domain Admin (or an equivalent crown-jewel) is a common objective because it proves worst-case impact, but the objective and any stopping points are agreed with you at scoping.
How long does an internal penetration test take?
Most engagements run one to two weeks, depending on network size and domain complexity. We confirm timing at scoping.
Can we use the report for SOC 2, PCI-DSS or Essential Eight assurance?
Yes. The report and optional attestation letter are written to satisfy auditor and customer requirements across SOC 2, PCI-DSS and the Essential Eight.
Get a fixed-price scoping quote.
A senior tester scopes the right engagement and sends a fixed quote — no automated sales funnel, no obligation.