What damage can an insider do?
Internal penetration test
An internal penetration test simulates an attacker who is already inside your network, such as a phished employee or a compromised laptop. It measures how far that foothold can travel and what it can reach before anyone notices.
What you get
- Paths from one workstation to domain-wide control
- Segmentation and access-control gaps
- Detection blind spots your monitoring did not catch
Overview
Starting from a foothold inside your network, we move the way malware or a malicious employee would: privilege escalation, lateral movement, Active Directory abuse, and access to the systems that matter. The goal is to show how far a single compromise can travel.
Scope
What is typically in scope. The final list is agreed with you before testing starts.
- Internal network ranges and VLANs, including segmentation boundaries
- Active Directory and identity infrastructure
- Servers, file shares, databases, and internal applications
- Workstation build and endpoint hardening
- Privileged access paths and service accounts
- Detection and response visibility during the test (optional purple team overlay)
Methodology
Phases run in this order. Each one produces evidence that feeds the next.
Foothold
We start from an agreed position: a standard user laptop, a network jack, or a VPN account, matching a realistic compromise.
Discovery
Hosts, services, shares, and identity relationships are mapped to find the paths that matter.
Privilege escalation
Misconfigurations, weak credentials, and legacy protocols are used to gain higher privileges, all documented step by step.
Lateral movement
We move toward the crown jewels defined in scoping, testing segmentation and access controls along the way.
Objective and reporting
We demonstrate impact on the agreed objectives, then rank every finding by how much it shortened the path.
Deliverables
- Executive summary and risk rating
- Attack path diagrams from foothold to objective
- Technical findings with evidence and severity
- Active Directory and segmentation review
- Detection gap notes where your monitoring did not fire
- Prioritized remediation roadmap
- One retest of remediated findings
Sample report excerpt
One finding, in the structure every finding follows. The content is illustrative.
Domain administrator reachable through legacy name resolution
- Severity
- High
- Status
- Open, retest pending
- Affected assets
- Listed in appendix A
Impact
Any user on the office network could capture and relay authentication traffic to obtain privileged access, ending in control of the domain.
Evidence
Captured relayed authentication from a standard workstation to a server without signing enforced, followed by a privileged session on a domain controller.
Remediation
Disable legacy name resolution protocols, enforce SMB and LDAP signing, reduce the number of privileged accounts that log on to workstations, and enable protected users groups.
Verification
Retested after remediation. Result and date are recorded here and reflected in the attestation letter.
Timeline
Typical duration
Typically 1 to 3 weeks on site or via a shipped test device
What affects it
Duration scales with the number of sites, domains, and objectives. Remote testing through a small appliance is the most common setup.
Compliance drivers
Need this for an audit or renewal? This test provides accepted evidence for PCI DSS, HIPAA, ISO 27001, CMMC, NYDFS.
See the full requirement mappingFrequently asked questions
How long does an internal penetration test take?
Typically one to three weeks depending on the size of the network, the number of domains, and the objectives agreed in scoping.
Do you need to be on site?
Usually not. We ship a small test device that connects out to us, or use a VPN account you provide. On-site testing is available for segmented or air-gapped environments.
Is a retest included?
Yes. One retest of remediated findings is included and reflected in an updated report.
What is the difference between internal and external testing?
External testing starts with no access and asks whether an outsider can get in. Internal testing assumes they already did and measures how far the compromise can spread.
Will you touch production systems?
Yes, carefully. We agree on exclusions and windows, avoid destructive techniques, and coordinate any sensitive step with your named contact in real time.
Related
Often paired with
External penetration test
Can an outsider get in?
Your internet-facing perimeter, tested from the outside in.
Learn moreSocial engineering test
Will someone hand over the keys?
Phishing, vishing, and pretexting campaigns that measure your people.
Learn moreRed team operation
Would we notice a determined attacker?
A goal-driven adversary simulation against people, process, and technology.
Learn moreReady to scope a internal penetration test?
Tell us about your environment and timelines. You will talk to the people who run the engagement and hear back within one business day.