services / network-penetration-testing

Breach It
Before
They Do

We attack your network the way a real adversary would — scanning, enumerating, and exploiting your external perimeter, internal infrastructure, and wireless environment to prove exactly how far a breach could go.

recon.sh
enum.log
bloodhound.log
root@engagement:~$ nmap -sV -p- 10.20.4.0/24 # Scanning 254 hosts across the internal segment... 10.20.4.11 445/tcp open microsoft-ds SMB SIGNING DISABLED 10.20.4.11 139/tcp open netbios-ssn 10.20.4.22 3389/tcp open ms-wbt-server 10.20.4.30 22/tcp open OpenSSH 6.6.1 CVE-2016-0777 root@engagement:~$ responder -I eth0 -wrf [+] Poisoned answer sent — captured NTLMv2 hash: DOMAIN\\jsmith root@engagement:~$ bloodhound-python -d corp.local -c All [!] Attack path found: jsmith → DOMAIN ADMIN (4 hops) # ✅ Remediation: enforce SMB signing, tier admin accounts, # disable NTLM relay via LDAP signing + channel binding
attack surface

What We Attack

Every engagement is scoped to your environment — from internet-facing perimeter systems to internal Active Directory and wireless networks.

external-perimeter.scope CRITICAL
External Network Penetration Testing

Attack your internet-facing footprint the way outside adversaries would — firewalls, VPN gateways, exposed services, mail servers, and public-facing infrastructure — to find footholds reachable from the open internet.

PerimeterVPNFirewall
internal-network.scope CRITICAL
Internal Network Penetration Testing

Simulate an attacker or malicious insider who already has network access — chaining misconfigurations, weak credentials, and unpatched services into lateral movement and full domain compromise.

Lateral MovementPrivilege Escalation
active-directory.scope CRITICAL
Active Directory Attack Path Mapping

Map every path from a standard domain user to Domain Admin — Kerberoasting, AS-REP roasting, ACL abuse, unconstrained delegation, and GPO misconfigurations — using BloodHound-driven analysis.

KerberosBloodHoundGPO
wireless-network.scope HIGH
Wireless Penetration Testing

Assess Wi-Fi security posture — rogue access points, WPA2/WPA3 handshake attacks, evil-twin attacks, captive portal bypasses, and segmentation between guest and corporate wireless networks.

WPA2/WPA3Rogue AP
segmentation.scope HIGH
Firewall & Network Segmentation Testing

Validate that VLAN boundaries, firewall ACLs, and zero-trust policies actually enforce isolation between production, corporate, guest, and OT/IoT network segments — not just on paper.

VLANZero TrustOT/IoT
credential-attacks.scope MEDIUM
Credential & Protocol Attacks

LLMNR/NBT-NS poisoning, SMB relay attacks, password spraying against exposed services, default and weak credential discovery, and legacy protocol abuse (SNMP, Telnet, FTP).

ResponderSMB Relay
how we work

Testing Methodology

Aligned to PTES and NIST SP 800-115 — structured, repeatable, and mapped directly to your compliance requirements.

// PHASE 01

Scoping & Reconnaissance

Define IP ranges, in-scope subnets, and rules of engagement. Passive and active OSINT to map your external footprint — DNS records, exposed services, and employee-linked infrastructure.

// PHASE 02

Scanning & Enumeration

Full port and service enumeration across every in-scope host. Fingerprint operating systems, running services, and software versions to build a complete attack surface map.

// PHASE 03

Vulnerability Analysis

Correlate scan data against known CVEs, misconfigurations, and weak protocols. Prioritise targets by exploitability and business impact rather than raw CVSS score alone.

// PHASE 04

Exploitation

Manually exploit identified weaknesses to gain an initial foothold — proving real impact rather than reporting theoretical risk. All exploitation is safe, controlled, and logged.

// PHASE 05

Post-Exploitation & Lateral Movement

From initial access, pivot through the network — harvesting credentials, escalating privileges, and mapping the shortest path to Domain Admin or your most sensitive systems.

// PHASE 06

Reporting & Retest

Deliver a prioritised findings report with attack path diagrams and exact remediation steps. Free retest included once fixes are deployed to confirm closure.

tools & frameworks

What We Use

Industry-standard tooling backed by manual, human-led exploitation — no report is ever a raw scanner export.

Nmap Nessus Metasploit BloodHound Responder Impacket CrackMapExec / NetExec Burp Suite Hydra Aircrack-ng Kismet Wireshark Mimikatz Cobalt Strike Rubeus Empire
deliverables

What You Get

findings_report.pdf

Detailed Findings Report

Every vulnerability documented with affected host, CVSS score, exploitation evidence, and step-by-step remediation guidance mapped to your infrastructure team's workflow.

attack_path_map.svg

Attack Path Diagram

A visual map of every path from initial foothold to domain compromise — showing exactly which misconfigurations, when chained together, create critical business risk.

exec_summary.pdf

Executive Summary

A non-technical risk summary for leadership and board reporting — overall network security posture, top risks, and prioritised investment recommendations.

retest_confirmation.pdf

Free Retest

After remediation, we re-test every finding and issue a signed confirmation letter verifying closure — useful for compliance audits and cyber insurance renewals.

debrief_call.cal

Technical Debrief Session

A live walkthrough with your IT and security team explaining how each attack path was achieved, with Q&A and hardening advice specific to your environment.

compliance_mapping.csv

Compliance Mapping

Findings mapped against PCI DSS, ISO 27001, SOC 2, and NIST controls — ready to hand directly to auditors as evidence of testing.

frequently asked

Common Questions

Straight answers about scope, timelines, and what a network penetration test actually involves.

What is network penetration testing?
Network penetration testing is an authorised, simulated cyberattack against your network infrastructure — servers, firewalls, routers, switches, and endpoints — used to identify exploitable vulnerabilities before real attackers can find and abuse them. Unlike an automated vulnerability scan, it involves manual exploitation to prove real-world impact.
What is the difference between internal and external network penetration testing?
External testing simulates an internet-based attacker targeting public-facing assets like VPNs, firewalls, and exposed servers. Internal testing simulates an attacker or insider who already has network access, focusing on lateral movement, privilege escalation, and Active Directory compromise.
How long does a network penetration test take?
Most engagements take 5 to 15 business days depending on the size of the IP range and whether internal, external, and wireless testing are combined. A full report typically follows within 3 to 5 business days after testing concludes.
How often should we run a network penetration test?
Most compliance frameworks — including PCI DSS, ISO 27001, and SOC 2 — require testing at least annually, and again after any significant infrastructure change such as new firewall rules or a data centre migration.
Does this include Active Directory testing?
Yes. Internal testing includes Active Directory attack path analysis covering Kerberoasting, AS-REP roasting, ACL abuse, delegation misconfigurations, and privilege escalation paths from a standard domain user to Domain Admin.
Will testing disrupt our production network?
Testing is scoped and controlled to avoid disruption. Denial-of-service style techniques are excluded by default, high-risk exploits are agreed upon in advance, and a direct communication channel stays open with your team throughout the engagement.
// know your real exposure

Find the Path
Before an Attacker Does

Send us your scope — we'll simulate a real intrusion against your network and hand back a prioritised, evidence-backed remediation plan. Most engagements start within 5 business days.