Skip to content
The //Zyber// Security
All services

05 · Perimeter · Foothold · Lateral · Domain

Internal / External Network Penetration Testing

Prove what a real attacker could reach.

Adversary emulation of your network perimeter (external) and your lateral-movement exposure (internal). We run the full chain — initial access → foothold → escalation → objectives — so you know exactly how far a real threat actor could get, and hand your SOC the detections to stop the next one.

Outcomes

  • +Confirmed initial-access vectors from the open internet
  • +Full internal lateral-movement + privilege-escalation paths
  • +Domain-compromise / kingdom-key access paths, quantified
  • +Detection-engineering guidance for every TTP we used

01Scope

What we cover

In scope

  • +External: every internet-facing IP, VPN, mail, remote-access, RDP/SSH exposure
  • +Internal: assumed-breach lateral movement from a starter foothold host
  • +Active Directory / Entra ID enumeration + escalation paths
  • +Kerberos / NTLM / LLMNR / mDNS abuse
  • +Cloud-hybrid scenarios (AWS/GCP/Azure identity boundaries)
  • +Payload delivery + evasion against your EDR

Out of scope

  • Physical-security testing (available separately)
  • Social engineering of employees (available separately)
  • DoS testing of production infrastructure

02Approach

How the engagement runs

01

External reconnaissance

Passive OSINT, TLS-fingerprint enumeration, exposed-service inventory. What's reachable from the internet right now?

02

Enumeration

Services, versions, and trust relationships across the perimeter and, on assumed breach, the internal estate.

03

Vulnerability Analysis

Exposure confirmed and prioritized; AI triage focuses operator time on what actually yields a foothold.

04

Exploitation — initial access

Public-facing exploitation, credential attacks, exposed-panel abuse. A foothold on documented evidence, never speculation.

05

Post-exploitation — lateral + domain

Assumed-breach from a starter host: enumerate the AD/Entra estate, escalate, pivot, and quantify kingdom-key access.

06

Report + detection guidance

Every TTP mapped to detections your SOC can build in Splunk, Sentinel, Datadog, or Elastic. Purple-team debrief included.

03Deliverables

What you receive

Every artifact is defensible under external audit and actionable for engineering.

  • 01External + Internal Pen Test Report (executive + technical)
  • 02MITRE ATT&CK matrix mapping
  • 03Attack-path graph (external → foothold → domain)
  • 04Detection-engineering guide for your SIEM
  • 05Purple-team debrief session with your SOC

04Frameworks

Regulator-defensible mapping

MITRE
ATT&CK EnterpriseATT&CK CloudD3FEND
NIST
SP 800-115SP 800-53 CA-8, RA-5
OSSTMM
3.0 Full protocol

05Timeline

Typical engagement pace

Phase 01

Scoping + ROE

1–2 weeks

Phase 02

External testing

2 weeks

Phase 03

Internal / assumed-breach

2–3 weeks

Phase 04

Reporting

1–2 weeks

06FAQ

Common questions

Different question? Raise it on a scoping call — we'd rather flag surprises early.

Can you do assumed-breach without a real employee?+

Yes. We ship a hardened jump host that you place on your internal network, and we test from there. No employee credentials required.

Will you set off our EDR?+

Some tests intentionally will (to measure detection). Some tests intentionally won't (to measure evasion). Both are documented in the ROE and reported.

Do you test hybrid cloud identity boundaries?+

Yes. AD ↔ Entra ID sync abuse, cross-tenant guest paths, cloud-role escalation — all in scope for modern engagements.

Know your real perimeter.

60-minute scoping, engagement letter within a week, kickoff within two. Full report inside 8–10 weeks.

Book a scoping call