Skip to content
← All services

Penetration testing service

Internal Network & Active Directory Assessment

An assumed-breach assessment of everything reachable from inside your network: Active Directory, shared resources, infrastructure, and the estate that rarely gets tested — cameras, door controllers, printers and management interfaces.

What the test covers

  • Network access control bypass — 802.1X and NAC evasion, VLAN hopping, and what an unmanaged device plugged into a reception or meeting-room port can reach
  • Full internal discovery: host and service enumeration, SMB and NetBIOS exposure, SNMP with default community strings, LDAP anonymous bind, null sessions
  • Domain controller configuration and hardening review, including replication, DNS integration and secure channel settings
  • Active Directory attack paths mapped end to end: Kerberoasting, AS-REP roasting, unconstrained and constrained delegation, resource-based constrained delegation
  • ACL and DACL abuse — shadow admins, dangerous rights over privileged objects, and paths to DCSync
  • Active Directory Certificate Services misconfiguration (the ESC template and CA abuse classes), which is now one of the most reliable routes to domain compromise

Deliverables

  • Executive summary written for a non-technical reader
  • Documented attack chains from initial foothold to domain compromise, with each step evidenced
  • Active Directory attack path graph showing every route to a privileged object
  • CVSS-scored findings with reproduction steps, ordered by real risk and by effort to remediate
  • Segmentation results as a matrix: which zones actually reach which
  • Detection and response timeline — what triggered an alert and what did not
  • Full asset inventory as discovered, including systems not on the original scope list
  • One retest round with a signed closure letter

Out of scope

  • Destructive testing, and anything that risks production availability
  • Denial-of-service and volumetric load testing
  • Active exploitation of OT, ICS or SCADA equipment — these are enumerated and assessed read-only unless separately scoped with the vendor present
  • Door controllers and access systems are enumerated and tested for exposure, but never actuated: no locks are opened, released or disabled
  • Physical intrusion and social engineering of staff, unless separately agreed in writing
  • Camera footage is never viewed, retrieved or retained — exposure is demonstrated without accessing recordings