Network Penetration Testing
External attack surface and internal network testing, scoped by your Rules of Engagement.
Network testing answers two questions: what an attacker on the internet can reach and exploit, and what an attacker who is already inside — a compromised laptop, a malicious insider, a phished account — can do next.
Both engagements are scoped in advance. The Rules of Engagement define authorized targets, testing windows, source IPs and, critically, what exploitation is permitted. Nothing is exploited outside those limits.
Ideal for
- Companies with public infrastructure beyond a single web app
- Organizations with an office or corporate network and directory services
- PCI DSS programs requiring external and internal testing
- Teams validating segmentation between environments
Testing may include, depending on the agreed scope:
Depending on the agreed scope, testing may include the areas below. Scope and the Rules of Engagement determine which targets are in scope, when testing takes place and what exploitation is permitted.
External network penetration testing
- External attack surface discovery and service enumeration
- Exposed network services and administrative interfaces
- TLS configuration and certificate hygiene
- Authentication on exposed services
- Known vulnerabilities in exposed components
- Misconfiguration of perimeter services
- Controlled exploitation where permitted by the Rules of Engagement
Internal network penetration testing
- Internal attack surface and reachable services
- Active Directory where applicable
- Credential exposure and weak authentication
- Privilege escalation
- Lateral movement
- Network segmentation between zones
- Insecure services and legacy protocols
- Trust relationships and misconfigurations
How we work on this engagement.
Exploitation within limits
Proof of impact matters, but so does availability. Exploitation is performed only where the Rules of Engagement permit it, with agreed stop conditions and emergency contacts.
Attack paths, not just findings
Internal reports describe the path — from initial foothold to the objective — so you can fix the chain, not just the individual hosts.
Segmentation evidence
Where segmentation is in scope, the report documents which zones were reachable from where, which supports PCI DSS and customer segmentation questions.
What you receive.
Security assessments represent a point-in-time evaluation and do not constitute a guarantee that the assessed systems remain secure or free from vulnerabilities after the assessment.
- 01Executive summary
- 02Technical report with host- and service-level findings
- 03Attack path narrative for internal engagements
- 04Severity ratings with CVSS scores
- 05Evidence and reproduction steps
- 06Remediation guidance
- 07Retest results
How is internal testing performed remotely?
Typically through a customer-provided VPN account or a small testing device placed on the network, agreed during pre-engagement. Both options are described in the Rules of Engagement.
Will testing disrupt production?
Denial-of-service testing is excluded by default. Testing windows, throttling and stop conditions are agreed in advance to minimize operational risk.
Request a security assessment.
Tell us what you need tested, when, and which evidence you need at the end. We reply with scoping questions, not a sales deck.