APOLLOSEC

Infrastructure and network penetration testing

We show how far an attacker could get from the internet, and from inside your network, then tell you what to fix first.

Two questions, one answer

External and internal testing answer different questions. External testing asks what someone on the internet can reach: firewalls, VPN gateways, mail servers, remote access and anything exposed by mistake. Internal testing assumes an attacker is already in, through a phished laptop or a compromised supplier account, and asks how far they can go.

Inside most networks the answer is decided by Active Directory. Weak service account passwords, over-privileged groups, legacy protocols and misconfigured certificate services can turn one compromised account into control of the whole domain. We test those paths the way real intrusions use them.

What we test

  • External perimeter

    Internet-facing hosts and services, VPN and remote access gateways, mail and DNS, and firewall rules over IPv4 and IPv6.

  • Internal network

    Host and service discovery, missing patches, default credentials, and file shares with sensitive data left in reach.

  • Active Directory

    Kerberoasting, delegation, ACL abuse, certificate services (AD CS), password policy and privileged group membership.

  • Lateral movement

    Credential reuse, NTLM relay, local admin sprawl and the routes between workstations, servers and domain controllers.

  • Segmentation

    Whether separated networks really are separate: payment environments, operational technology, guest and management networks.

  • Build reviews

    On request, configuration reviews of workstation and server builds against recognised hardening benchmarks.

How the engagement runs

  1. Scope

    We agree ranges, hosts and any fragile systems to avoid. For internal tests we agree how we connect: on site, over a VPN, or through a test device you plug in.

  2. Discover

    We map live hosts, services and trust relationships, starting externally with the same discovery an attacker would run.

  3. Exploit with care

    We confirm vulnerabilities by exploiting them where it is safe and agreed, and stop short of anything that risks availability.

  4. Report and retest

    Findings appear in the portal as we go, the report follows within five working days, and we retest once you have fixed them.

What you get

  • Attack paths, not just a list. How individual weaknesses chain together into a route to your critical systems.
  • Fixes in order. Starting with the changes that break the most paths.
  • Evidence and retest results for every finding.

When to commission it

  • After network changes, mergers, or a move to new offices or data centres.
  • Before and after replacing firewalls, VPNs or remote access.
  • When cyber insurance, a customer contract or a standard such as PCI DSS requires it.
  • Yearly as a minimum for internal networks, with external exposure watched continuously through attack surface management.

Questions we get asked

Should we start with internal or external testing?

If you have never tested either, start externally: it is what everyone on the internet can already see. If your perimeter is mature, internal testing usually finds more, because most of the damage in a breach happens after initial access.

Do you need to be on site for an internal test?

Usually not. Most internal tests run remotely, over a VPN or through a small test device you connect to your network. We come on site when the scope needs it, for example to test segmentation between physical networks.

Will you take our systems down?

We avoid techniques likely to affect availability and agree in advance how to handle fragile or legacy systems. Denial of service testing is out of scope unless you ask for it.

Do you test Active Directory and Entra ID?

On-premises Active Directory is part of every internal test. Hybrid identity, Entra ID and Microsoft 365 can be added, and are covered in depth by our cloud assessments.

Find out how far an attacker would get.

Talk to us