Network penetration testing
External testing shows what the internet can reach. Internal testing shows how far an attacker gets once inside, whether through a phished laptop or a device plugged into a conference room. We focus on realistic paths to your critical systems, which usually run through Active Directory.
What we test
- External perimeter: exposed services, VPNs, remote access, and edge devices
- Internal network: lateral movement and privilege escalation
- Active Directory: Kerberoasting, certificate services abuse, delegation, and ACL paths
- Credential attacks: password spraying, relaying, and hash cracking
- Network segmentation validation
- Wireless: WPA2/WPA3-Enterprise, rogue access points, and guest isolation
- Unsupported and unpatched systems
- Default and weak credentials on infrastructure and appliances
How we approach it
External tests run from our infrastructure. Internal tests run through a small virtual appliance you deploy, or on-site. We start the way an attacker would, with nothing but network access, and work toward the objectives you care about, such as domain admin or a specific database.
What you get
- Executive summary written for leadership and customers
- Technical findings with CVSS scores, evidence, and reproduction steps
- Specific remediation guidance for each finding
- One retest of reported findings within 90 days, with an updated report
- Attestation letter you can share with customers and auditors
Typical use cases
- Annual testing for SOC 2, HIPAA, ISO 27001, or cyber insurance
- Mergers, acquisitions, and new office build-outs
- Validating segmentation after network changes
- Measuring how far a compromised workstation can reach
Often paired with
Tell us what you need tested.
Send a few details and we'll set up a short scoping call, then follow up with a fixed-fee proposal.