Network Penetration
Testing
for Real Attack Paths

Manual network penetration testing for Indian SaaS and fintech teams. We assess the external perimeter and internal attack surface, validate exploitable weaknesses under controlled conditions, and turn findings into remediation work your team can act on.

Authorised testing only · Scope and rules of engagement agreed before testing

recon.log
paths.log
report.txt
engagement$ map --scope external,internal # Illustrative output — not a client system 198.51.100.24 443/tcp open https 198.51.100.24 22/tcp open ssh internal-segment → domain-services [!] Segmentation path requires manual validation engagement$ report --priority business-impact # Evidence + remediation guidance + retest
01 / approach
Manual-firstAutomation helps establish coverage; reported issues are manually validated.
02 / scope
External + internalAssess the attack surface that matches your agreed rules of engagement.
03 / output
Actionable reportingEvidence, impact context and remediation guidance for technical teams.
04 / closure
Retest includedVerify remediation after fixes are deployed, subject to the agreed scope.
why network testing

Find the path, not just the vulnerability.

A network penetration test is most useful when it answers a practical question: if an attacker gets a foothold, what can they reach next?

Grey Shield combines reconnaissance, enumeration, vulnerability analysis and controlled manual exploitation to understand exposed services, trust boundaries, access paths and opportunities for lateral movement within the agreed scope.

For SaaS and fintech environments, network findings can also be considered alongside application and API exposure when the engagement requires it. Where those surfaces need separate testing, we recommend scoping the relevant web application penetration testing or API work rather than mixing unrelated objectives into one test.

Useful questions the assessment can answer

  • Which internet-facing services are actually exposed?
  • Are segmentation boundaries enforcing the intended isolation?
  • What can a compromised internal host reach?
  • Which weaknesses can be chained into greater access?
  • Which fixes should the infrastructure team prioritise?
assessment scope

What We Test

The exact scope is defined before testing. Choose the surfaces that match your threat model rather than buying a generic checklist.

external.scopeEXTERNAL
External Network Penetration Testing

Assess internet-facing hosts and services for exploitable weaknesses, unsafe exposure and configuration issues that could provide an external foothold.

PUBLIC ASSETSSERVICESPERIMETER
internal.scopeINTERNAL
Internal Network Penetration Testing

Assess what an attacker with internal access could discover, exploit and reach, including privilege escalation and lateral movement where authorised.

LATERAL MOVEMENTPRIVILEGESEGMENTATION
ad.scopeOPTIONAL
Active Directory Assessment

Where AD is in scope, review authentication, permissions, trust relationships and attack paths that could allow escalation from a lower-privileged account.

ADACCESSATTACK PATHS
segmentation.scopeOPTIONAL
Segmentation & Boundary Testing

Validate whether network boundaries behave as intended between production, corporate, guest, cloud-connected and other scoped segments.

VLANACLTRUST BOUNDARIES
wireless.scopeOPTIONAL
Wireless Security Testing

If wireless infrastructure is included, assess authentication, segmentation and configuration weaknesses within the agreed test window.

WI-FISEGMENTATIONAUTH
edge.scopeOPTIONAL
Network Device & Protocol Review

Review exposed management interfaces, services and protocols within the agreed scope, with manual validation of issues that could affect real attack paths.

FIREWALLSVPNPROTOCOLS
how we work

A structured testing process

Grey Shield's broader penetration-testing methodology uses defined scope, reconnaissance, analysis, manual exploitation, impact analysis, reporting and retesting. The network engagement applies that process to the agreed infrastructure.

PHASE 01

Scoping & Rules of Engagement

Define IP ranges, environments, access assumptions, testing windows, exclusions and escalation contacts before testing begins.

PHASE 02

Reconnaissance & Enumeration

Map hosts, ports, services and relevant attack surface to understand what an attacker can discover from the agreed starting point.

PHASE 03

Vulnerability Analysis

Correlate observed services and configurations with known weaknesses, then prioritise issues by exploitability and business impact.

PHASE 04

Manual Validation & Exploitation

Manually validate candidate findings under controlled conditions to distinguish exploitable weaknesses from scanner noise.

PHASE 05

Impact & Attack-Path Analysis

Where authorised, determine how access can be escalated or moved across the environment and explain the business consequence.

PHASE 06

Reporting, Remediation & Retest

Deliver evidence-backed findings and remediation guidance, then re-test after fixes to confirm the agreed findings are addressed.

Read the full Grey Shield methodology →
relevant proof

A real network case study

Grey Shield publishes anonymised engagement details where client consent allows it. This example is already available on the case-studies page.

Network · Active Directory · Healthcare

One Reused Password From Every Patient Report

An anonymised diagnostics-chain engagement assessing whether a compromised reception system could reach patient data.

Read the case study →

What the published case study shows

The assessment found a shared local administrator password across more than 40 machines. From a reception workstation, that credential provided access to a file server containing patient reports.

  • Internal network scope across selected centres and head office.
  • Passive traffic analysis identified the reused credential.
  • Access to the report server was validated without relying on a software exploit.
  • Remediation included per-machine password rotation and tighter AD permissions.
Source: Grey Shield case studies · anonymised client engagement
deliverables

What your team gets

The purpose of the report is not to give you a longer vulnerability list. It is to give your team enough evidence and context to fix the right problems.

findings_report

Technical Findings Report

Documented findings with affected assets, evidence, severity/context and remediation guidance appropriate to the agreed scope.

attack_path

Attack-Path Context

Where an issue can be chained with other weaknesses, explain the path and why the combination matters to the environment.

exec_summary

Executive Summary

A concise view of the highest-priority risks and remediation themes for stakeholders who do not need packet-level detail.

remediation_retest

Remediation Guidance & Retest

After fixes are deployed, re-test the agreed findings and document the verification outcome.

technical_debrief

Technical Debrief

Walk your team through the important findings, attack paths and practical hardening priorities.

scope_notes

Scope & Assumptions

Keep the engagement boundaries, exclusions and access assumptions clear so the report can be interpreted correctly.

frequently asked

Common Questions

Straight answers about scope, safety, deliverables and how to start a network penetration test.

What is network penetration testing?
Network penetration testing is an authorised security assessment that evaluates network infrastructure for exploitable weaknesses and validates practical impact under agreed rules of engagement. It is different from a vulnerability scan because the assessment includes human-led validation and controlled exploitation.
What is the difference between external and internal testing?
External testing evaluates internet-facing assets from an outside perspective. Internal testing evaluates what an attacker could do after obtaining network access, including segmentation, privilege escalation and lateral movement where those activities are in scope.
Does the assessment include Active Directory?
It can, when Active Directory is included in the agreed internal-network scope. The exact access assumptions, techniques and depth are defined during scoping.
Will testing disrupt our production network?
Testing is performed under agreed rules of engagement. Testing windows, exclusions, escalation contacts and any high-risk techniques should be agreed before the engagement begins.
What will we receive after testing?
You receive evidence-backed findings, impact context and remediation guidance, followed by a retest after fixes are deployed. The exact report format and scope are agreed during engagement scoping.
How do we start?
Start with the assets or IP ranges you want assessed, the environment, access assumptions, testing window and any exclusions. Grey Shield's scoping process can turn those details into a practical engagement plan.
// scope the right assessment

Know what your network exposes.

Tell us what you want assessed — external perimeter, internal network, segmentation, Active Directory or a combined scope. We'll help define the rules of engagement and deliverables before testing starts.