One Phished Laptop to Domain Admin.
We start from a single workstation foothold and walk the chain a real adversary would: Kerberoasting, ACL abuse, certificate-services misconfiguration, lateral movement, and the domain-dominance path to the data you cannot lose.
Definition Internal network penetration testing is manual, authorized adversarial testing from inside the network perimeter, simulating a workstation-compromise scenario to test Active Directory, identity, and lateral-movement controls.
Last reviewed:
File 01 · Definition
What It Is
Internal network testing is an assume-breach exercise. We provision a low-privileged workstation on your network and ask one question: how far does it go, and how fast.
We map your Active Directory and identity surface, abuse the misconfigurations that grant escalation, harvest credentials, and pivot toward your crown-jewel systems and regulated data.
Reports tie each attack path to the specific identities, ACLs, and configurations that enabled it, mapped to SOC 2, ISO 27001, and CMMC evidence where applicable.
Perimeter security is now assume-breach, and the question that decides modern programs is what happens after the first phish lands. Most networks fail internally not because of CVEs but because of identity misconfiguration: Kerberoasting, ACL abuse, and certificate-services flaws that stay exploitable in environments passing external pentests cleanly, until one workstation becomes domain admin.
File 02 · Threat Model
Why Companies Need This
- 01 You have an Active Directory environment. AD misconfiguration, not a CVE, is the most common path from one workstation to domain admin.
- 02 Your threat model assumes breach but no one has run the scenario. Assuming the first phish lands is the easy part. We show you how far it travels and how fast before anyone reacts.
- 03 You invested in EDR. Internal testing tells you whether it actually fires on Kerberoasting, credential dumping, and lateral movement, or just on commodity malware.
- 04 You need SOC 2, ISO 27001, or CMMC evidence beyond an external scan.
File 03 · Deliverables
What You Get
Detailed technical report
CVSS scoring, attack narratives, and proof-of-concept evidence
Executive summary
Findings translated into business risk, not CVSS noise.
Remediation guidance
Prioritized, actionable fixes, not just a list of CVEs
Real-time comms
Dedicated Slack channel for the engagement.
Compliance documentation
Mapped to SOC 2, PCI DSS, HIPAA, ISO 27001, and CMMC
File 04 · Methodology
Our Process
Foothold Setup
Assumed-breach workstation provisioning, network position validation, scope confirmation.
AD & Identity Enumeration
BloodHound-driven AD mapping, Kerberoasting, ACL abuse paths, certificate services analysis.
Privilege Escalation
Local and domain privilege escalation, credential harvesting, token impersonation.
Lateral Movement & Impact
Pivoting to crown-jewel systems, data access demonstration, domain compromise where applicable.
Reporting & Retest
Attack-path narratives mapped to identities and configurations. Verification retest included.
File 05 · Intel Brief
Frequently Asked Questions
Q1 Is internal testing safe in production?
Yes, with operator discipline. We coordinate noisy operations and avoid destructive testing without explicit approval.
Q2 Do you need a domain admin account to start?
No. We start from a low-privileged workstation, just like an adversary.
Q3 How long does an internal pentest take?
Typical engagements run two to four weeks depending on AD complexity and environment size.
Talk to an Operator
Assume the Perimeter Is Gone. Find Out What They Would Reach Next.
Tell us your domain count and how your tier-zero assets are segmented. We will scope the foothold and the path we would walk from it.
Related
Where internal testing connects
How the internal foothold is reached, where the attack path goes next, and who needs this most.
External network penetration testing
The perimeter an attacker crosses to reach the internal network.
Wireless penetration testing
A common way onto the internal LAN without crossing the perimeter.
Adversary simulation
End-to-end emulation that chains internal compromise into objectives.
Manufacturing & OT security
IT/OT segmentation and lateral movement to production.
CMMC Level 2 penetration testing
Internal control evidence for the defense industrial base.