Network Penetration Testing
External, internal, and the path between them.
Perimeter, internal estate and Active Directory. The route from your front door — or from one foothold — to your crown-jewel data, and the control that should have stopped it.
What it is
External testing answers what could someone do from the internet? Internal testing answers the harder question: what could a contractor laptop do once it is on the wire?
Both, in whichever order matches your risk model. Where it helps, results chain into one narrative — internet to domain admin in N steps — so the failure mode is legible to a board, not just the finding list.
Compliance-scoped variants: PCI-DSS segmentation testing to validate cardholder-data isolation, and ISO/IEC 27001:2022 Annex A or NIS2 evidence scopes, with the controls named at scoping, so the report drops into your evidence pack.
Method
- External: attack-surface enumeration via DNS, ASN and certificate transparency
- External: exposed service identification, version analysis, known-CVE validation
- External: VPN, mail, perimeter device and remote-access testing
- External: password spraying and credential stuffing, in scope only
- Internal: Active Directory enumeration and attack-path mapping
- Internal: relay attacks, Kerberos abuse, ADCS certificate-template review
- Internal: segmentation validation across business and OT networks, if in scope
- Lateral movement to named targets, with documented blast radius
What you get
- Attack-path narratives for external and internal, in one report
- Attack-path graphs for the most damaging chains
- Patch and configuration fixes, prioritised by exploitability
- Retest by agreement
Related services
Cloud Penetration Testing
AWS, Azure, GCP. Assumed breach, IAM blast radius, real attacker paths.
View service →Vulnerability Assessment
Breadth-first sweep, manual triage, prioritised by exploitability.
View service →Red Teaming and Adversary Emulation
Named objectives, one threat actor, MITRE ATT&CK, detection-gap analysis.
View service →Ready to scope this engagement?
One email is enough to start. Tell us roughly what you want tested and we'll come back with a scoping call slot inside one business day.