Network

Network Penetration Testing

Internal and external network testing — the perimeter an attacker sees first, and how far they could move once inside. Manual testing and validated exploitation, not just an unauthenticated scan.

See pricing

What's included

  • External perimeter testing
  • Internal network testing
  • Service misconfiguration testing
  • Network segmentation validation
  • Credential attacks where in scope
  • Lateral movement validation

Deliverables

  • Executive summary for leadership
  • Technical report, CVSS-rated findings
  • Evidence for every finding
  • Prioritised remediation roadmap
  • Live debrief walkthrough

Timeline

3–10 business days, depending on host count and whether external, internal, or both are in scope.

External vs. internal — and why both matter

External testing answers "what can someone on the internet see and reach?" — exposed services, forgotten subdomains, management interfaces that shouldn't be public, VPN and remote-access endpoints. Internal testing answers a different question: "if someone got a foothold — a phished laptop, a compromised contractor account — how far could they get?" Most real breaches start externally and do their real damage internally, so testing only one side leaves a genuine blind spot.

Methodology

Enumeration with Nmap and service-specific tooling to map the real attack surface, manual verification of every finding before it's reported, exploitation validation with Metasploit and NetExec where safe to do so, and — where segmentation is meant to isolate sensitive systems — explicit testing of whether that isolation actually holds. This is the same methodology published in the NetExec reference in the public Arsenal.

Windows domain in scope?

If your network runs Active Directory and you want attack-path testing specific to it — Kerberoasting, ADCS misconfigurations, ACL abuse — that's covered in more depth under Active Directory Penetration Testing, either standalone or combined with a general network test.

Questions about network testing

This engagement covers the network and infrastructure layer — perimeter exposure, internal host misconfigurations, service-level vulnerabilities, and segmentation — for environments that don't necessarily run Windows Active Directory, or where AD-specific attack-path testing (Kerberoasting, ADCS, ACL abuse) isn't the focus. If your environment is AD-centric, the dedicated Active Directory Penetration Testing engagement goes deeper on that specific attack surface.

Both are available, scoped separately or together. External testing covers what's exposed to the internet — perimeter services, exposed management interfaces, VPN endpoints. Internal testing simulates a foothold already inside the network and covers lateral movement, internal service misconfigurations, and how far an intruder could get from a single compromised host.

Yes — validating that network segments (production vs. corporate, a cardholder data environment, an isolated VLAN) actually hold under attack rather than just being configured as documented is a standard part of scope when segmentation is in place.

Common findings: exposed or outdated services (SMB, RDP, FTP, SNMP), weak or default credentials, missing network segmentation, unpatched systems with known exploits, and misconfigured services that leak information useful for further attacks. Tools used include Nmap for enumeration, Metasploit and NetExec for exploitation and validation.

3 to 10 business days depending on host count and whether both external and internal testing are in scope. Exact timeline confirmed in your written proposal.

From $1,500, scoped to host count and whether external, internal, or both are included. See the pricing page for details.

Find out what's actually reachable from outside

Free scoping call, fixed-price proposal within 24 hours.

See pricing