From the internet edge to domain admin.
External and internal network pentests that show how an attacker gets in, moves laterally and escalates, step by step. You get the full attack path, the hosts involved and the fix that breaks the chain soonest.
- External perimeter
- VPN & remote access
- Internal network
- Active Directory
- Segmentation testing
- Assumed breach
ENG-2026-019 · External + internal · assumed breachAttack path AP-02 · Internet to Domain Admin in 6 steps
- Hosts
- 1,412
- Services
- 3,860
- Internet-exposed
- 46
- Paths to DA
- 3
- EntryInternetExposed VPN portal accepts password spraying
- Step 1vpn.example.comValid account from a reused password
- Step 2WS-114 · workstationLLMNR/NBT-NS poisoning captures hashes
- Step 3Relay to FS-02SMB signing disabled, NTLM relay succeeds
- Step 4FS-02 · file serverLocal admin, cached service credentials
- Step 5svc_backupKerberoasted, weak password cracked
- GoalDomain AdminDCSync rights on corp.example.local
Break the chain earliestEnforcing SMB signing domain-wide (step 3) removes this path and 2 others.
| Host | Address | OS | Open services | Top issue | Severity |
|---|---|---|---|---|---|
| DC-01 | 10.20.0.10 | Windows Server 2019 | 53, 88, 389, 445, 636 | Unconstrained delegation on legacy service account | Critical |
| FS-02 | 10.20.4.22 | Windows Server 2016 | 135, 139, 445, 3389 | SMB signing not required | High |
| vpn.example.com | 203.0.113.24 | Appliance | 443, 4433 | No lockout or MFA on portal login | High |
| BKP-01 | 10.20.9.5 | Ubuntu 20.04 | 22, 873, 9000 | Unauthenticated rsync exposes backups | High |
| PRN-3F | 10.20.12.40 | Embedded | 80, 443, 9100 | Default admin credentials | Medium |
Test from outside the wall, and from behind it.
- External network
What the internet can reach.
We enumerate your public footprint and attack it the way an opportunistic or targeted adversary would.
- Asset and subdomain discovery
- Exposed services and management interfaces
- VPN, remote access and email gateways
- Credential attacks against login portals
- Known-vulnerability exploitation, safely
- Internal network
What happens after the first foothold.
From a workstation, VPN account or network drop, we try to move laterally and take control of what matters.
- Active Directory and Kerberos attacks
- Credential capture, relay and reuse
- Privilege escalation and lateral movement
- Segmentation and firewall rule validation
- Access to crown-jewel systems and data
Black, grey or white box.
Start with nothing, a standard domain user, or full network documentation. Choose per segment.
- Black box
- IP ranges only. Shows exactly what an outsider can discover and exploit with no prior knowledge.
- Grey box
- A standard domain user or VPN account. The most realistic assumed-breach scenario for most organisations.
- White box
- Network diagrams, firewall rule sets and admin access, for a full configuration review alongside exploitation.
Network testing questions
- How do you test internal networks remotely?
- We ship a preconfigured testing appliance or provide a lightweight virtual machine you deploy inside the network. Access is encrypted, logged and removed when testing ends.
- Will testing disrupt production?
- Disruptive techniques are excluded unless you approve them. We agree testing windows, rate limits and an emergency contact before we start.
- Do you cover segmentation for PCI DSS?
- Yes. We validate that segmentation controls isolate the cardholder data environment and report against PCI DSS requirement 11.4.
- How long does a network test take?
- Typically 5–15 business days, depending on the number of ranges, sites and Active Directory domains in scope.
How far could an attacker get today?
Find out with a scoped external or internal test, delivered with attack paths your infrastructure team can act on.
