Skip to content
AttackVector

What damage can an insider do?

Internal penetration test

An internal penetration test simulates an attacker who is already inside your network, such as a phished employee or a compromised laptop. It measures how far that foothold can travel and what it can reach before anyone notices.

Point in timeTargets: TechnologyTypically 1 to 3 weeks on site or via a shipped test device

What you get

  • Paths from one workstation to domain-wide control
  • Segmentation and access-control gaps
  • Detection blind spots your monitoring did not catch

Overview

Starting from a foothold inside your network, we move the way malware or a malicious employee would: privilege escalation, lateral movement, Active Directory abuse, and access to the systems that matter. The goal is to show how far a single compromise can travel.

Scope

What is typically in scope. The final list is agreed with you before testing starts.

  • Internal network ranges and VLANs, including segmentation boundaries
  • Active Directory and identity infrastructure
  • Servers, file shares, databases, and internal applications
  • Workstation build and endpoint hardening
  • Privileged access paths and service accounts
  • Detection and response visibility during the test (optional purple team overlay)

Methodology

Phases run in this order. Each one produces evidence that feeds the next.

  1. Foothold

    We start from an agreed position: a standard user laptop, a network jack, or a VPN account, matching a realistic compromise.

  2. Discovery

    Hosts, services, shares, and identity relationships are mapped to find the paths that matter.

  3. Privilege escalation

    Misconfigurations, weak credentials, and legacy protocols are used to gain higher privileges, all documented step by step.

  4. Lateral movement

    We move toward the crown jewels defined in scoping, testing segmentation and access controls along the way.

  5. Objective and reporting

    We demonstrate impact on the agreed objectives, then rank every finding by how much it shortened the path.

Deliverables

  • Executive summary and risk rating
  • Attack path diagrams from foothold to objective
  • Technical findings with evidence and severity
  • Active Directory and segmentation review
  • Detection gap notes where your monitoring did not fire
  • Prioritized remediation roadmap
  • One retest of remediated findings

Sample report excerpt

One finding, in the structure every finding follows. The content is illustrative.

AttackVector · Internal penetration test · Technical findingsIllustrative excerpt
HighFinding 1 of 19

Domain administrator reachable through legacy name resolution

Severity
High
Status
Open, retest pending
Affected assets
Listed in appendix A

Impact

Any user on the office network could capture and relay authentication traffic to obtain privileged access, ending in control of the domain.

Evidence

Captured relayed authentication from a standard workstation to a server without signing enforced, followed by a privileged session on a domain controller.

Screenshot and request/response evidence appear here

Remediation

Disable legacy name resolution protocols, enforce SMB and LDAP signing, reduce the number of privileged accounts that log on to workstations, and enable protected users groups.

Verification

Retested after remediation. Result and date are recorded here and reflected in the attestation letter.

Every finding follows this structure.Download the full sample report

Timeline

Typical duration

Typically 1 to 3 weeks on site or via a shipped test device

What affects it

Duration scales with the number of sites, domains, and objectives. Remote testing through a small appliance is the most common setup.

Compliance drivers

Need this for an audit or renewal? This test provides accepted evidence for PCI DSS, HIPAA, ISO 27001, CMMC, NYDFS.

See the full requirement mapping

Frequently asked questions

How long does an internal penetration test take?

Typically one to three weeks depending on the size of the network, the number of domains, and the objectives agreed in scoping.

Do you need to be on site?

Usually not. We ship a small test device that connects out to us, or use a VPN account you provide. On-site testing is available for segmented or air-gapped environments.

Is a retest included?

Yes. One retest of remediated findings is included and reflected in an updated report.

What is the difference between internal and external testing?

External testing starts with no access and asks whether an outsider can get in. Internal testing assumes they already did and measures how far the compromise can spread.

Will you touch production systems?

Yes, carefully. We agree on exclusions and windows, avoid destructive techniques, and coordinate any sensitive step with your named contact in real time.

Ready to scope a internal penetration test?

Tell us about your environment and timelines. You will talk to the people who run the engagement and hear back within one business day.