Testing scope

Penetration testing of
internal infrastructure

We assume the attacker is already inside: a laptop taken over through phishing, or a cable plugged into a meeting room socket. The question is how far they get. We measure how many steps separate an ordinary employee account from domain administrator rights and access to the backups.

  • Active Directory escalation paths presented as a diagram
  • Verification of network segmentation and EDR effectiveness
  • A real attack chain instead of an automatically generated list

Internal infrastructure

Duration
usually 5-12 working days
We work to
  • PTES
  • OSSTMM
  • MITRE ATT&CK Enterprise
  • CIS Benchmarks

What exactly we check

We tailor the scope to your environment, but these areas are always covered.

1

Active Directory

Kerberoasting and AS-REP roasting, unsafe delegation, object ACL permissions, GPO mistakes, service accounts with ageing passwords, trust relationships between domains.

2

Escalation and lateral movement

Passwords in logon scripts and network shares, reused local administrator passwords, missing LAPS, credential interception on the network (Responder, NTLM relay), taking over further workstations.

3

Network segmentation

Whether the user network can reach the server room, the backups, industrial systems and the management network. Effectiveness of VLAN separation, internal firewall rules, access from the guest network.

4

Workstations

System hardening, local privileges, application control (AppLocker), disk encryption, USB media, EDR effectiveness against common attacker techniques.

5

Internal services

File servers and share permissions, databases, backup systems, network printers, device administration panels, services left with default credentials.

6

Passwords and authentication

Password policy analysis based on controlled cracking of hashes from the domain database, non-expiring accounts, second factor on remote access and on administrative operations.

What we find most often

Examples from our projects in this area. Client names and technical details stay in the reports.

  • A path from an ordinary employee to domain administrator in three steps
  • Administrator password in a logon script on the SYSVOL share
  • The same local administrator account on every workstation
  • A service account with domain privileges and a password several years old
  • No segmentation: the backup server is reachable from the guest network
  • NTLM relay made possible by disabled SMB signing
  • Backups writable by an ordinary user
  • EDR not recording a memory dump of the LSASS process

Selected tools

BloodHoundImpacketNetExecResponderhashcatnmap

Tools take care of the repetitive work. The conclusions and attack chains are built by hand.

How the test runs and what you get

The testing process, the report format and the retest rules are the same across every scope.

See the full process and report contents

Frequently asked questions

How does such a test work in practice?

We need access to the network: a visit to your site, our device plugged in, or a virtual machine inside your environment. We usually start from an ordinary employee account to reproduce the most likely scenario.

Should the IT team know about the test?

That is your call. The announced variant is faster and focuses on vulnerabilities. The variant where only a small group knows also verifies whether your team and detection systems notice the attack at all.

Can anything break?

Potentially destructive actions are agreed with you before execution, and we exclude critical systems if you prefer. Controlled password cracking runs on our own hardware, against hashes, never against the live domain.

How is this different from advanced attack simulation?

An internal pentest aims to find as many vulnerabilities as possible in the agreed time. A Red Team simulation follows a specific adversary scenario and measures detection, usually quietly and over a longer period.