Core Service
FILE · OIU-SVC

One Phished Laptop to Domain Admin.

We start from a single workstation foothold and walk the chain a real adversary would: Kerberoasting, ACL abuse, certificate-services misconfiguration, lateral movement, and the domain-dominance path to the data you cannot lose.

Definition Internal network penetration testing is manual, authorized adversarial testing from inside the network perimeter, simulating a workstation-compromise scenario to test Active Directory, identity, and lateral-movement controls.

Last reviewed:

File 01 · Definition

What It Is

Internal network testing is an assume-breach exercise. We provision a low-privileged workstation on your network and ask one question: how far does it go, and how fast.

We map your Active Directory and identity surface, abuse the misconfigurations that grant escalation, harvest credentials, and pivot toward your crown-jewel systems and regulated data.

Reports tie each attack path to the specific identities, ACLs, and configurations that enabled it, mapped to SOC 2, ISO 27001, and CMMC evidence where applicable.

Perimeter security is now assume-breach, and the question that decides modern programs is what happens after the first phish lands. Most networks fail internally not because of CVEs but because of identity misconfiguration: Kerberoasting, ACL abuse, and certificate-services flaws that stay exploitable in environments passing external pentests cleanly, until one workstation becomes domain admin.

File 02 · Threat Model

Why Companies Need This

  • 01 You have an Active Directory environment. AD misconfiguration, not a CVE, is the most common path from one workstation to domain admin.
  • 02 Your threat model assumes breach but no one has run the scenario. Assuming the first phish lands is the easy part. We show you how far it travels and how fast before anyone reacts.
  • 03 You invested in EDR. Internal testing tells you whether it actually fires on Kerberoasting, credential dumping, and lateral movement, or just on commodity malware.
  • 04 You need SOC 2, ISO 27001, or CMMC evidence beyond an external scan.

File 03 · Deliverables

What You Get

Unlimited remediation validation included. No time cap, no per-finding charge. How it works

Detailed technical report

CVSS scoring, attack narratives, and proof-of-concept evidence

Executive summary

Findings translated into business risk, not CVSS noise.

Remediation guidance

Prioritized, actionable fixes, not just a list of CVEs

Real-time comms

Dedicated Slack channel for the engagement.

Compliance documentation

Mapped to SOC 2, PCI DSS, HIPAA, ISO 27001, and CMMC

File 04 · Methodology

Our Process

01 FOOTHOLD

Foothold Setup

Assumed-breach workstation provisioning, network position validation, scope confirmation.

02 MAP

AD & Identity Enumeration

BloodHound-driven AD mapping, Kerberoasting, ACL abuse paths, certificate services analysis.

03 ESCAL

Privilege Escalation

Local and domain privilege escalation, credential harvesting, token impersonation.

04 LATERAL

Lateral Movement & Impact

Pivoting to crown-jewel systems, data access demonstration, domain compromise where applicable.

05 VALIDATE

Reporting & Retest

Attack-path narratives mapped to identities and configurations. Verification retest included.

File 05 · Intel Brief

Frequently Asked Questions

Q1 Is internal testing safe in production?

Yes, with operator discipline. We coordinate noisy operations and avoid destructive testing without explicit approval.

Q2 Do you need a domain admin account to start?

No. We start from a low-privileged workstation, just like an adversary.

Q3 How long does an internal pentest take?

Typical engagements run two to four weeks depending on AD complexity and environment size.

Talk to an Operator

Assume the Perimeter Is Gone. Find Out What They Would Reach Next.

Tell us your domain count and how your tier-zero assets are segmented. We will scope the foothold and the path we would walk from it.