1. Home
  2. Services
  3. Penetration testing

Network penetration testing

External testing shows what the internet can reach. Internal testing shows how far an attacker gets once inside, whether through a phished laptop or a device plugged into a conference room. We focus on realistic paths to your critical systems, which usually run through Active Directory.

What we test

  • External perimeter: exposed services, VPNs, remote access, and edge devices
  • Internal network: lateral movement and privilege escalation
  • Active Directory: Kerberoasting, certificate services abuse, delegation, and ACL paths
  • Credential attacks: password spraying, relaying, and hash cracking
  • Network segmentation validation
  • Wireless: WPA2/WPA3-Enterprise, rogue access points, and guest isolation
  • Unsupported and unpatched systems
  • Default and weak credentials on infrastructure and appliances

How we approach it

External tests run from our infrastructure. Internal tests run through a small virtual appliance you deploy, or on-site. We start the way an attacker would, with nothing but network access, and work toward the objectives you care about, such as domain admin or a specific database.

What you get

  • Executive summary written for leadership and customers
  • Technical findings with CVSS scores, evidence, and reproduction steps
  • Specific remediation guidance for each finding
  • One retest of reported findings within 90 days, with an updated report
  • Attestation letter you can share with customers and auditors

Typical use cases

  • Annual testing for SOC 2, HIPAA, ISO 27001, or cyber insurance
  • Mergers, acquisitions, and new office build-outs
  • Validating segmentation after network changes
  • Measuring how far a compromised workstation can reach

Tell us what you need tested.

Send a few details and we'll set up a short scoping call, then follow up with a fixed-fee proposal.

Request a quote