Infrastructure and network penetration testing
We show how far an attacker could get from the internet, and from inside your network, then tell you what to fix first.
Two questions, one answer
External and internal testing answer different questions. External testing asks what someone on the internet can reach: firewalls, VPN gateways, mail servers, remote access and anything exposed by mistake. Internal testing assumes an attacker is already in, through a phished laptop or a compromised supplier account, and asks how far they can go.
Inside most networks the answer is decided by Active Directory. Weak service account passwords, over-privileged groups, legacy protocols and misconfigured certificate services can turn one compromised account into control of the whole domain. We test those paths the way real intrusions use them.
What we test
External perimeter
Internet-facing hosts and services, VPN and remote access gateways, mail and DNS, and firewall rules over IPv4 and IPv6.
Internal network
Host and service discovery, missing patches, default credentials, and file shares with sensitive data left in reach.
Active Directory
Kerberoasting, delegation, ACL abuse, certificate services (AD CS), password policy and privileged group membership.
Lateral movement
Credential reuse, NTLM relay, local admin sprawl and the routes between workstations, servers and domain controllers.
Segmentation
Whether separated networks really are separate: payment environments, operational technology, guest and management networks.
Build reviews
On request, configuration reviews of workstation and server builds against recognised hardening benchmarks.
How the engagement runs
Scope
We agree ranges, hosts and any fragile systems to avoid. For internal tests we agree how we connect: on site, over a VPN, or through a test device you plug in.
Discover
We map live hosts, services and trust relationships, starting externally with the same discovery an attacker would run.
Exploit with care
We confirm vulnerabilities by exploiting them where it is safe and agreed, and stop short of anything that risks availability.
Report and retest
Findings appear in the portal as we go, the report follows within five working days, and we retest once you have fixed them.
What you get
- Attack paths, not just a list. How individual weaknesses chain together into a route to your critical systems.
- Fixes in order. Starting with the changes that break the most paths.
- Evidence and retest results for every finding.
When to commission it
- After network changes, mergers, or a move to new offices or data centres.
- Before and after replacing firewalls, VPNs or remote access.
- When cyber insurance, a customer contract or a standard such as PCI DSS requires it.
- Yearly as a minimum for internal networks, with external exposure watched continuously through attack surface management.
Questions we get asked
Should we start with internal or external testing?
Do you need to be on site for an internal test?
Will you take our systems down?
Do you test Active Directory and Entra ID?
Related
Web applications and APIs
Manual web application and API penetration testing. We find the authentication, access control and business logic flaws that automated scanners miss.
Read more →Cloud: AWS, Azure, Google Cloud
Cloud security assessments and penetration testing for AWS, Azure, Google Cloud and Microsoft 365: identity, storage, network and real attack paths.
Read more →Attack surface management
Continuous external attack surface management. Discover every internet-facing asset, including shadow IT, and get alerted to new exposures as they appear.
Read more →SavountLiving on the Edge: An Adversary Playground
A walk through an engagement: how edge devices, leaked cloud keys and an open Trello board gave an attacker a path in, one step at a time.
Read the article →