05 · Perimeter · Foothold · Lateral · Domain
Internal / External Network Penetration Testing
Prove what a real attacker could reach.
Adversary emulation of your network perimeter (external) and your lateral-movement exposure (internal). We run the full chain — initial access → foothold → escalation → objectives — so you know exactly how far a real threat actor could get, and hand your SOC the detections to stop the next one.
Outcomes
- +Confirmed initial-access vectors from the open internet
- +Full internal lateral-movement + privilege-escalation paths
- +Domain-compromise / kingdom-key access paths, quantified
- +Detection-engineering guidance for every TTP we used
01Scope
What we cover
In scope
- +External: every internet-facing IP, VPN, mail, remote-access, RDP/SSH exposure
- +Internal: assumed-breach lateral movement from a starter foothold host
- +Active Directory / Entra ID enumeration + escalation paths
- +Kerberos / NTLM / LLMNR / mDNS abuse
- +Cloud-hybrid scenarios (AWS/GCP/Azure identity boundaries)
- +Payload delivery + evasion against your EDR
Out of scope
- −Physical-security testing (available separately)
- −Social engineering of employees (available separately)
- −DoS testing of production infrastructure
02Approach
How the engagement runs
External reconnaissance
Passive OSINT, TLS-fingerprint enumeration, exposed-service inventory. What's reachable from the internet right now?
Enumeration
Services, versions, and trust relationships across the perimeter and, on assumed breach, the internal estate.
Vulnerability Analysis
Exposure confirmed and prioritized; AI triage focuses operator time on what actually yields a foothold.
Exploitation — initial access
Public-facing exploitation, credential attacks, exposed-panel abuse. A foothold on documented evidence, never speculation.
Post-exploitation — lateral + domain
Assumed-breach from a starter host: enumerate the AD/Entra estate, escalate, pivot, and quantify kingdom-key access.
Report + detection guidance
Every TTP mapped to detections your SOC can build in Splunk, Sentinel, Datadog, or Elastic. Purple-team debrief included.
03Deliverables
What you receive
Every artifact is defensible under external audit and actionable for engineering.
- 01External + Internal Pen Test Report (executive + technical)
- 02MITRE ATT&CK matrix mapping
- 03Attack-path graph (external → foothold → domain)
- 04Detection-engineering guide for your SIEM
- 05Purple-team debrief session with your SOC
04Frameworks
Regulator-defensible mapping
05Timeline
Typical engagement pace
Scoping + ROE
1–2 weeks
External testing
2 weeks
Internal / assumed-breach
2–3 weeks
Reporting
1–2 weeks
06FAQ
Common questions
Different question? Raise it on a scoping call — we'd rather flag surprises early.
Can you do assumed-breach without a real employee?+
Yes. We ship a hardened jump host that you place on your internal network, and we test from there. No employee credentials required.
Will you set off our EDR?+
Some tests intentionally will (to measure detection). Some tests intentionally won't (to measure evasion). Both are documented in the ROE and reported.
Do you test hybrid cloud identity boundaries?+
Yes. AD ↔ Entra ID sync abuse, cross-tenant guest paths, cloud-role escalation — all in scope for modern engagements.
Know your real perimeter.
60-minute scoping, engagement letter within a week, kickoff within two. Full report inside 8–10 weeks.
Book a scoping call