Internal network penetration test
How far can an attacker get inside your network?
What happens if someone gains control of a workstation, network connection or user account? We examine which routes lead to sensitive data and critical systems.
From access to impact
Three questions we answer
- What is accessible from the chosen starting point?
- Which permissions and weaknesses allow further steps?
- Where can you effectively interrupt an attack?
When is this relevant?
Examine what an attacker could reach after gaining initial access.
Within an organisation, systems, accounts and administration processes are connected. We examine what those connections mean once an attacker has gained an initial foothold.
- You want to know what a regular user account can access.
- You have changed segmentation, access management or the workstation environment.
- You want to examine what someone could do with a compromised account or workstation.
- You need insight into risks around shared files and administrator privileges.
The assessment
What do we assess?
Your environment and assessment question determine the content. We agree in advance which elements we will examine.
01
Starting point and accessibility
From the agreed connection or test account, we map which systems, services and network environments are accessible. This shows which boundaries work in practice.
02
Identities and permissions
We examine access for users and service accounts, available permissions and relevant settings in systems such as Active Directory. Where can additional privileges be obtained or existing permissions be used unintentionally?
03
Data and attack paths
We test accessible services and file locations for vulnerabilities and unintentionally accessible information. We consider findings together: which steps could bring an attacker closer to sensitive data?
04
Containment and remediation
We substantiate the access obtained and the impact within the scope. The advice focuses on breaking attack paths and limiting consequences for the organisation.
Defining the scope together
A scope that fits your question.
The starting point determines what we examine. We can begin with a network connection, a user account or a simulated situation in which an attacker already has access.
What do we agree in advance?
- Network segments, locations and critical systems.
- Starting position, available prior knowledge and test accounts.
- Permitted further steps and handling of data encountered.
- Testing windows, contacts and arrangements for serious findings.
Would you also like to know whether the attack is detected and followed up? We then include Detection & Response Validation as an additional assessment in the scope.
The result
Insight you can act on.
01
Insight into attack paths
Which steps were possible, which boundaries held and where the risk is concentrated.
02
Technical evidence
Findings with evidence, impact and remediation advice for network, workstation and identity administration.
03
A targeted improvement agenda
Priorities for restricting access, securing accounts and breaking vulnerable dependencies.
Our approach
From the initial question to follow-up.
01
Defining the starting point
We discuss the environment and choose a scenario that fits your assessment question.
02
Investigating and verifying
Our ethical hackers test access and further steps within the agreed scope.
03
Discussing the results
We explain what has been demonstrated and what it means for your systems and processes.
04
Testing improvements
You implement measures. Any retest is agreed separately.
Frequently asked questions
What you need to know in advance.
Do you need an account?
That depends on the scenario. We can start with a network connection or a supplied test account. A combination is possible if you want to test both initial access and what a user can do.
Is an internal penetration test the same as a red team assessment?
An internal penetration test focuses on the agreed internal environment and attack paths. A red team assessment may have a broader objective, a longer duration and different arrangements for detection and prior knowledge. During intake, we determine which approach fits your question.
Does the assessment have to take place on site?
A local connection may be needed to replicate the chosen starting position. If the scenario allows it, we can also use an agreed remote connection.
Will we also see what our security stopped?
We describe the course of the assessment and relevant boundaries encountered. For a full assessment of detection and follow-up, we make additional arrangements for logging and cooperation with your administrators or SOC.
Our approach
From assessment to clear next steps.
Read how we define the scope, carry out the assessment and discuss the results with you. With a dedicated secure data room and evidence-based reporting.
Discuss your situation
Know what an attacker could do after that initial access.
Tell us which systems and data matter. Together, we choose the starting point and scope of your internal penetration test.
The form is currently unavailable. Use our general contact form or call 036 5367 573.
We use your details to handle your enquiry. Read our privacy policy.