← All services
Penetration testing service
Internal Network & Active Directory Assessment
An assumed-breach assessment of everything reachable from inside your network: Active Directory, shared resources, infrastructure, and the estate that rarely gets tested — cameras, door controllers, printers and management interfaces.
What the test covers
- Network access control bypass — 802.1X and NAC evasion, VLAN hopping, and what an unmanaged device plugged into a reception or meeting-room port can reach
- Full internal discovery: host and service enumeration, SMB and NetBIOS exposure, SNMP with default community strings, LDAP anonymous bind, null sessions
- Domain controller configuration and hardening review, including replication, DNS integration and secure channel settings
- Active Directory attack paths mapped end to end: Kerberoasting, AS-REP roasting, unconstrained and constrained delegation, resource-based constrained delegation
- ACL and DACL abuse — shadow admins, dangerous rights over privileged objects, and paths to DCSync
- Active Directory Certificate Services misconfiguration (the ESC template and CA abuse classes), which is now one of the most reliable routes to domain compromise
- Group Policy review: GPO permissions, Group Policy Preferences passwords, and startup and logon script contents in SYSVOL
- Domain and forest trust relationships, and whether compromise in one boundary reaches another
- Krbtgt password age and golden-ticket resilience, machine account quota, and Protected Users and tiered administration coverage
- User and service account hygiene: stale and orphaned accounts, non-expiring passwords, accounts with SPNs, privileged group membership, and shared administrative accounts
- Password policy and lockout policy tested in practice, followed by controlled password spraying to measure real-world credential strength
- Credential exposure: LLMNR, NBT-NS and mDNS poisoning with NTLM relay, SMB signing enforcement, cached credentials, and secrets left in scripts, shares and configuration files
- LAPS or equivalent local administrator password management — whether it is deployed, and whether coverage has gaps
- Shared resources reviewed for both permission and content: SMB and NFS shares, share and NTFS permission drift, and sensitive data sitting in the open — credentials, backups, personal data, key material
- Printers and multifunction devices, which routinely hold LDAP service credentials, stored documents and an unauthenticated administrative interface
- Out-of-band management — iDRAC, iLO and IPMI interfaces, where default credentials give complete control of the underlying server
- Hypervisor and virtualisation management (vCenter, Hyper-V) and backup infrastructure, both of which are frequently domain-admin equivalent and rarely in scope
- Network device management planes: switches, routers, wireless controllers and firewalls — default credentials, legacy protocols, and SNMP write access
- Core infrastructure services: DNS zone transfer and dynamic update handling, DHCP, NTP, and internal certificate trust
- Physical security systems on the network — door controllers, badge readers and building management — which are commonly deployed flat, unpatched and on vendor default credentials
- IP cameras, NVR and CCTV platforms: exposed interfaces, default credentials, firmware currency, and whether footage is reachable from a standard user VLAN
- VoIP handsets, PBX and conference-room AV systems, which often sit outside the standard build and patch process entirely
- Workstation and server build review across a sampled set: local privilege escalation, weak service permissions, unquoted paths, DLL hijacking, missing patches, disk encryption and removable media controls
- Lateral movement and privilege escalation to domain administrator, documented as a full attack chain from initial foothold
- Local administrator password reuse across the estate, and how far a single recovered hash travels
- Segmentation testing between zones — user VLAN to server, to DMZ, to management, and to any OT or card-data environment — to confirm the boundaries actually hold
- Endpoint detection coverage and blind spots, plus a detection and response assessment: what your team saw, what alerted, and how long it took
Deliverables
- Executive summary written for a non-technical reader
- Documented attack chains from initial foothold to domain compromise, with each step evidenced
- Active Directory attack path graph showing every route to a privileged object
- CVSS-scored findings with reproduction steps, ordered by real risk and by effort to remediate
- Segmentation results as a matrix: which zones actually reach which
- Detection and response timeline — what triggered an alert and what did not
- Full asset inventory as discovered, including systems not on the original scope list
- One retest round with a signed closure letter
Out of scope
- Destructive testing, and anything that risks production availability
- Denial-of-service and volumetric load testing
- Active exploitation of OT, ICS or SCADA equipment — these are enumerated and assessed read-only unless separately scoped with the vendor present
- Door controllers and access systems are enumerated and tested for exposure, but never actuated: no locks are opened, released or disabled
- Physical intrusion and social engineering of staff, unless separately agreed in writing
- Camera footage is never viewed, retrieved or retained — exposure is demonstrated without accessing recordings