Network penetration testing

Two questions, answered concretely: what can someone reach from the internet, and what happens once they are inside. Both are tested by hand, and the answer arrives with the evidence attached.

Scope

What we actually test

External perimeter

Full discovery of internet-facing assets — including the ones missing from your inventory — then service enumeration, version and configuration review, and exploitation of anything reachable.

  • Asset discovery
  • Perimeter

Internal network

From an assumed-breach position on your LAN or VPN: enumeration, relay and poisoning attacks, credential capture, and the path from a standard user to domain administrator.

  • Assumed breach
  • Lateral movement

Active Directory

Kerberoasting, AS-REP roasting, delegation abuse, ACL paths, GPO permissions and the misconfigurations that make privilege escalation a single command.

  • Kerberos
  • ACL paths
  • Delegation

Credential attacks

Password spraying within agreed lockout limits, credential reuse across systems, and hunting for credentials left in shares, scripts and configuration files.

  • Spraying
  • Credential reuse

Segmentation validation

Whether your network zones actually hold — cardholder, production and corporate segments tested for reachability against what the diagram claims.

  • PCI segmentation

Egress & detection

What data can leave, over which protocols, and whether your monitoring notices while it happens.

  • Exfil paths
  • Detection

Every engagement ships with

  • Executive summary written for leadership
  • Technical report with reproducible proof-of-concept for every finding
  • CVSS v3.1 vectors and a plain-English business-impact narrative
  • Prioritised, concrete remediation guidance
  • Same-day alerting on anything critical
  • Live debrief with your engineering team
  • Free retest of every finding within 90 days
  • Signed attestation letter for auditors and customers

FAQ

Questions about this service

Do you need to be on site?

No. Internal testing is normally run from a VPN connection or a small virtual appliance we provide, which is faster to arrange and costs you nothing in travel.

Will password spraying lock out our users?

Not if it is scoped properly. We read your lockout policy first and stay well inside it, spraying slowly across a long window. Account lockout thresholds are agreed in the rules of engagement before anything runs.

Can you validate PCI segmentation specifically?

Yes — segmentation testing is scoped and documented to satisfy PCI DSS requirement 11.4.5, with the evidence your QSA will expect.

Next step

Find out what an attacker would find.

Tell us what you have built. You get a reply within one business day, an NDA, and a free 30-minute scoping call with the person who will do the testing.