Skip to content
Mockingjay

From the internet edge to domain admin.

External and internal network pentests that show how an attacker gets in, moves laterally and escalates, step by step. You get the full attack path, the hosts involved and the fix that breaks the chain soonest.

ENG-2026-019 · External + internal · assumed breachAttack path AP-02 · Internet to Domain Admin in 6 steps
Hosts
1,412
Services
3,860
Internet-exposed
46
Paths to DA
3
  1. EntryInternetExposed VPN portal accepts password spraying
  2. Step 1vpn.example.comValid account from a reused password
  3. Step 2WS-114 · workstationLLMNR/NBT-NS poisoning captures hashes
  4. Step 3Relay to FS-02SMB signing disabled, NTLM relay succeeds
  5. Step 4FS-02 · file serverLocal admin, cached service credentials
  6. Step 5svc_backupKerberoasted, weak password cracked
  7. GoalDomain AdminDCSync rights on corp.example.local
Break the chain earliestEnforcing SMB signing domain-wide (step 3) removes this path and 2 others.
Hosts on the attack path
HostAddressOSOpen servicesTop issueSeverity
DC-0110.20.0.10Windows Server 201953, 88, 389, 445, 636Unconstrained delegation on legacy service accountCritical
FS-0210.20.4.22Windows Server 2016135, 139, 445, 3389SMB signing not requiredHigh
vpn.example.com203.0.113.24Appliance443, 4433No lockout or MFA on portal loginHigh
BKP-0110.20.9.5Ubuntu 20.0422, 873, 9000Unauthenticated rsync exposes backupsHigh
PRN-3F10.20.12.40Embedded80, 443, 9100Default admin credentialsMedium
Illustrative product view · sample data

Test from outside the wall, and from behind it.

Black, grey or white box.

Start with nothing, a standard domain user, or full network documentation. Choose per segment.

Black box
IP ranges only. Shows exactly what an outsider can discover and exploit with no prior knowledge.
Grey box
A standard domain user or VPN account. The most realistic assumed-breach scenario for most organisations.
White box
Network diagrams, firewall rule sets and admin access, for a full configuration review alongside exploitation.

Network testing questions

How do you test internal networks remotely?
We ship a preconfigured testing appliance or provide a lightweight virtual machine you deploy inside the network. Access is encrypted, logged and removed when testing ends.
Will testing disrupt production?
Disruptive techniques are excluded unless you approve them. We agree testing windows, rate limits and an emergency contact before we start.
Do you cover segmentation for PCI DSS?
Yes. We validate that segmentation controls isolate the cardholder data environment and report against PCI DSS requirement 11.4.
How long does a network test take?
Typically 5–15 business days, depending on the number of ranges, sites and Active Directory domains in scope.

How far could an attacker get today?

Find out with a scoped external or internal test, delivered with attack paths your infrastructure team can act on.

Book a demo