Assume the perimeter will be crossed
External and internal testing that answers the question which actually matters — once an attacker has any foothold at all, how far do they get, and what stops them?
What this covers
- External perimeter and every internet-facing service
- Internal testing from an assumed-breach starting position
- Active Directory enumeration and Kerberos abuse
- Privilege escalation on Windows and Linux hosts
- Lateral movement and cross-domain trust relationships
- Segmentation and firewall rule validation, proven not assumed
- Remote access, VPN and wireless where in scope
- Validation of scanner output rather than a scanner dump
Scanners find candidates, testers find paths
The internal test is the honest one
Active Directory is still the main prize
What you get beyond a findings list
Questions about network testing
Much less than people fear. We avoid denial-of-service techniques, agree any risky action in advance, and can work entirely from a read-only position if you prefer. The noisiest part is usually the initial scan, which we will run in a window you choose.
Ideally yes — a single standard, non-privileged user account. That is the most realistic starting position and gives by far the most useful result. If you would rather we start from a network port with no credentials at all, we can do that too, and we will tell you it is a harder test.
For network testing, no — the network is production. What we can do is constrain the scope tightly: named subnets, agreed hours, a documented list of prohibited actions, and a direct line to your team so we can stop immediately if anything looks unstable.
Ready to look at this properly?
A 30-minute call, no pitch deck. We will tell you whether we are the right fit — and if we are not, we will point you somewhere better.