Skip to content

Internal Penetration Test

How far can an attacker get in your network?


An internal penetration test simulates an assumed breach scenario: What happens when an attacker already has access to your internal network – whether through compromised credentials, an infected workstation, or a malicious insider? We show you how far an attacker can get and which critical systems are at risk.

Why an Internal Pentest?


Most organizations invest heavily in securing their perimeter – firewalls, email filters, and endpoint protection. But what happens when this line of defense has already been breached? Studies show that after initial access, attackers can often gain Domain Admin privileges within hours if the internal infrastructure is not hardened.

Our internal penetration test starts from the perspective of an attacker who is already inside the network. We systematically test Active Directory configurations, network segmentation, internal services, and permission structures. We use the same techniques as real attackers: Kerberoasting, AS-REP Roasting, NTLM relay attacks, Pass-the-Hash, and many more.

The goal is clear: We identify vulnerabilities and attack paths before real attackers do – and provide you with concrete recommendations for hardening your internal environment.

Who Is This For?


Our Methodology


01
Network Reconnaissance

Identification of active hosts, open services, network topology, and Active Directory structures.

02
Privilege Escalation

Exploitation of misconfigurations and vulnerabilities to escalate privileges – locally and within Active Directory.

03
Lateral Movement

Movement through the network to additional systems by exploiting trust relationships and stolen credentials.

04
Objective Achievement

Demonstrating impact through access to critical systems, sensitive data, or Domain Admin privileges.

05
Reporting & Debrief

Detailed report with documented attack paths, risk ratings, and prioritized remediation measures.

What We Test


Active Directory

Kerberoasting, AS-REP Roasting, DCSync, GPO abuse, delegation vulnerabilities, and other AD-specific attack vectors.

Network Segmentation

Assessment of VLAN configurations, firewall rules between segments, and whether critical systems are adequately isolated.

Internal Services

Databases, file shares, intranet applications, management interfaces, and other internally exposed services for vulnerabilities and misconfigurations.

Credential Hygiene

Password strength, credential reuse, stored credentials in scripts, group policies, and network shares.

Backup Systems

Access control on backup infrastructure, encryption of backup data, and protection against ransomware scenarios.

Endpoint Security

Effectiveness of EDR/AV solutions, local admin rights, patch levels, and hardening of workstations and servers.

From Our Engagements


Anonymized engagement example

A Swiss services company. Standard workstation. Domain Admin in under 6 hours.

LLMNR deactivation, network segmentation, and certificate services overhaul implemented. After retest: same attack path to Domain Admin no longer possible.

Domain Admin in 6h 23 passwords cracked Six attack paths documented
Industry: Services company
Environment: On-Prem, Active Directory
Duration: 7 days

A Swiss services company wants to test internal security after an external pentest. Starting point: network access via a standard workstation — simulating a compromised employee.

Key Findings
  • Critical LLMNR/NBT-NS poisoning allows interception of NTLMv2 hashes. Cracking with Hashcat yields 23 valid passwords within 4 hours.
  • Critical Through Kerberoasting and an ESC8 vulnerability in the Certificate Authority, Domain Admin can be achieved
  • High Missing network segmentation allows direct access from workstation to sensitive business data

Your Deliverables


Upon completion of the internal penetration test, you will receive a comprehensive report containing the following elements:

Management Summary

Summary of the key findings and overall risk for executive leadership.

Attack Path Documentation

Detailed description of each attack path from initial access to objective achievement, including screenshots and evidence.

Risk Ratings

Each vulnerability is rated by criticality (CVSS) and business impact.

Remediation Roadmap

Prioritized action plan with concrete recommendations for remediating the identified vulnerabilities.

from CHF 7,500

Typical duration: 5–10 days

Inquire Now

Why Manual Testing?


Frequently Asked Questions


Typically, you provide us with VPN access or we work on-site at your premises. In the scoping meeting, we jointly define the access method and starting scenario – e.g., an attacker with simple network access without special privileges (assumed breach).

Yes, Active Directory is a central component of our internal pentests. We test for Kerberoasting, AS-REP Roasting, NTLM relay, DCSync, GPO abuse, and other AD-specific attack vectors. On request, we also include Azure AD / Entra ID and hybrid identity infrastructures in the test.

For critical vulnerabilities that pose an immediate risk, we notify you immediately – even during the ongoing test. This allows you to take urgent action without waiting for the final report. All details are subsequently documented in the report.

Yes, small companies in particular benefit greatly from an internal pentest. Dedicated IT security resources are often lacking, meaning Active Directory misconfigurations, weak passwords, or missing network segmentation go undetected. A focused internal test can uncover these risks quickly and cost-effectively.
Request a Quote