Network

Internal network pentest

An assumed-breach test: we start where a phished employee or a stolen laptop would, and work out how far that gets — usually measured by how quickly it becomes domain-wide control.

9
areas covered
5
stages, scoping to retest
In-house
testers, never subcontracted
portal.cyberlysecure.com/acme-health/coverage
Acme Health — Test coverage4 practices · 15 services · one team
In-house
Web app
API
SaaS
Mobile
Client-side
External
Internal
Segment test
Wireless
Cloud config
Hardware & IoT
AI & LLM
Social eng.
Physical
Red team
ApplicationsNetworkCloud & devicesPeople & premises
6 in scope · one team · one report
In-house testers 0 subcontracted
Every surface one team
What this is

What the test covers.

The question is not whether someone can get inside. It is what happens next. Most internal networks are built for people to work in, and the same convenience that makes work possible makes lateral movement easy.

We start from a standard user on a standard device, and we document the path — every step, every credential, every misconfiguration that made the next step possible — so you can break the chain wherever it is cheapest.

PTES NIST SP 800-115 MITRE ATT&CK

What we test

  • Active Directory enumeration, trust relationships and privilege paths
  • Kerberos attacks: Kerberoasting, AS-REP roasting and delegation abuse
  • NTLM relay, coercion and authentication downgrade
  • Active Directory Certificate Services misconfiguration
  • Credential harvesting from memory, shares, scripts and group policy
  • Lateral movement and local administrator reuse across the estate
  • Sensitive data discovery on open file shares
  • Segmentation between user, server and management networks
  • What your endpoint protection and logging actually noticed
How it runs

From scoping call to retest, here’s what happens.

Typically one to two weeks, depending on the size of the estate.

1

Scope and authorize

We agree the starting position — standard user, unauthenticated device or both — and what is off limits.

2

Start where an attacker starts

On-site or through a connected device, we begin with exactly the access a new employee would have.

3

Follow the paths

We enumerate the domain, collect what is reachable and escalate along real, evidenced paths rather than theoretical ones.

4

Note what was seen

We record which actions your tooling detected and which it did not — useful whether or not detection was in scope.

5

Report, readout and retest

The report shows the full attack path with the cheapest place to break it, followed by a readout and a retest.

What it surfaces

The kind of thing this test tends to find.

Real examples of what this engagement uncovers — anonymized, and never every time. What matters is that you find out before somebody else does.

A path from a standard user account to full domain control

Service accounts with weak passwords and far more rights than the service needs

Local administrator passwords shared across hundreds of machines

Certificate templates that let any user request a certificate as anyone else

File shares holding credentials, exports and backups readable by everyone

Getting started

What you get, and what we need from you.

What you get

  • Technical report — Every finding, the evidence behind it and clear guidance your engineers can act on.
  • Executive summary — Your risk explained in plain language for leadership and the board.
  • Attestation letter — Signed confirmation of testing to hand your auditors.
  • Readout call — A walkthrough with the people who tested your systems.
  • Retest — Confirmation your fixes worked, documented for whoever needs to see it.

What we need from you

  • A network drop, a VPN account or a shipped testing device
  • One standard domain user account (and optionally an unauthenticated start)
  • Confirmation of any systems that must not be touched
  • An escalation contact available during the test window

Missing something on this list? Bring it to the call — we scope around what you have.

Free attack-surface snapshot

Give us a domain. See what an attacker sees.

Not sure where to start? One of our testers reviews your internet-facing footprint and sends you a short summary of what an attacker would see — free. Nothing you don’t own is ever touched, and there’s no sales sequence.

  • Internet-facing hosts
  • Exposed services
  • Leaked credentials
  • TLS certificate hygiene

Request your snapshot

Free. No obligation.

We only ever test assets you own, with your written authorization.