Skip to content
ISO 27001, SOC 2, the DPDP Act and manual VAPT.
Part of VAPT7 services in this practice area

External, Internal, Lateral

Network Penetration Testing

We test your network from the outside in and the inside out. From the internet edge we look for the way in; from inside we show how far an attacker moves once they have a foothold.

See the engagement path, 6 phasesSee the full VAPT service index

Backlog And Ageing, Estate Wide

Worked example

A vulnerability management product view. Illustrative snapshot of a typical programme, not a named client. Headline figures for the quarter across 1,340 in-scope assets and 40 web applications: 4,812 open findings, of which 288 are past their internal SLA; 37 critical findings open; blended mean time to remediate 84 days, computed from the 3,371 closures this quarter, 24 critical at 21 days each, 391 high at 38, 2,100 medium at 74 and 856 low at 130, which is 282,042 finding-days over 3,371 closures; SLA compliance 68 percent, 2,292 of 3,371 closures within SLA. Open findings by CVSS v3.1 band: Critical 37, which is 0.8 percent; High 412, 8.6 percent; Medium 1,954, 40.6 percent; Low 2,409, 50.1 percent. A further 1,106 informational findings are excluded from that total. 19 open findings are listed on the CISA Known Exploited Vulnerabilities catalogue and 4 of those are past their CISA BOD 22-01 due date. Findings over 13 weeks: 2,993 new against 3,371 remediated, so the open backlog fell from 5,190 to 4,812, with a spike of 402 new findings in week 6 when the quarterly authenticated scan ran. Mean time to remediate by severity against target: Critical 21 days against a 15-day target, High 38 against 30, Medium 74 against 90, Low 130 against 180. The table lists 13 representative findings ranked by exploitability, led by CVE-2024-3400, GlobalProtect OS command injection, CVSS 10.0, EPSS 0.944, on KEV, 13 days old and open; CVE-2023-4966, NetScaler session token leak, CVSS 9.4, on KEV, 41 days old and in progress; and CVE-2021-44228, Log4j2 JNDI remote code execution on a legacy build host, CVSS 10.0, on KEV, 402 days old and still open.

SecureRoot VAPTVulnerability Management

4,812

Open

288 past SLA

37

Critical

19 on KEV

84d

MTTR

3,371 closed

68%

Within SLA

2,292 of 3,371

By Severity, 4,812 Open

Critical 37High 412Medium 1,954Low 2,409

19 on CISA KEV, 4 past their CISA due date.

Illustrative snapshot of a typical programme, not a named client.

How an estate backlog is tracked: a worked example with 4,812 open findings, the 288 past SLA and the 37 criticals counted, not averaged away. Illustrative figures, not a named client.

Overview

A network infrastructure VAPT covers your external perimeter and your internal environment, including Active Directory. Externally we look for exposed services, weak configuration and paths through the edge. Internally we simulate an attacker who already has a foothold and show how they escalate privileges and move laterally toward domain control and your crown-jewel systems. You see the real blast radius of a single compromised device.

Methodology

How the Engagement Runs

Every phase has a named output, so you always know what is being worked on and what lands on your side of the table.

The Engagement, End to End

6 Phases, 6 Named Handovers

Flow

Flow chart of the Network Infrastructure engagement, 6 phases in order, each one selectable. Phase 1, Scoping and Rules of Engagement. We agree external ranges, internal segments and any excluded systems, and set testing windows and emergency contacts. Activities: Confirm external ranges and internal segments; Agree excluded and fragile systems; Set testing windows; Exchange emergency contacts. Hands over Signed Rules of Engagement. Phase 2, Reconnaissance and Mapping. We discover live hosts, open ports and services across the in-scope ranges and build a map of the attack surface. Activities: Discover live hosts across the ranges; Scan for open ports and services; Fingerprint operating systems and versions; Build the attack surface map. Hands over Attack Surface Map. Phase 3, Vulnerability Discovery. We combine authenticated and unauthenticated scanning with manual review to find weak services, patches and configuration. Activities: Run authenticated and unauthenticated scans; Manually review scan results; Identify missing patches and weak services; Flag risky configuration and protocols. Hands over Candidate Finding List. Phase 4, Manual Exploitation. We exploit findings to gain a foothold, capturing credentials and abusing exposed services and protocols like SMB and LLMNR. Activities: Exploit weak services to gain a foothold; Capture credentials with Responder; Abuse SMB, LLMNR and NBT-NS; Confirm access and rule out false positives. Hands over Initial Foothold with Proof. Phase 5, Post-Exploitation and Lateral Movement. We escalate privileges, map Active Directory attack paths and move laterally toward domain admin and critical systems. Activities: Escalate local and domain privileges; Map AD attack paths with BloodHound; Move laterally between hosts; Reach domain admin and crown-jewel systems. Hands over Mapped Attack Paths to Domain Control. Phase 6, Reporting and Verified Retest. You get a report with attack paths and prioritised fixes, and we retest once you remediate to confirm the paths are closed. Activities: Document attack paths and prioritised fixes; Produce an executive summary; Walk your team through the results; Retest fixes and confirm the paths are closed. Hands over Final Report and Verified Retest. Each phase begins from the artefact the phase before it produced.

Phase 01 Scoping and Rules of Engagement

We agree external ranges, internal segments and any excluded systems, and set testing windows and emergency contacts.

What Happens In This Phase

  • Confirm external ranges and internal segments
  • Agree excluded and fragile systems
  • Set testing windows
  • Exchange emergency contacts

The Handover

Signed Rules of Engagement

The next phase starts from this.

Read the handover cards on their own and you have the paper trail. Select a phase to see what happens inside it.
  1. 01

    Scoping and Rules of Engagement

    We agree external ranges, internal segments and any excluded systems, and set testing windows and emergency contacts.

    OutputSigned Rules of Engagement

    Activities

    • Confirm external ranges and internal segments
    • Agree excluded and fragile systems
    • Set testing windows
    • Exchange emergency contacts
  2. 02

    Reconnaissance and Mapping

    We discover live hosts, open ports and services across the in-scope ranges and build a map of the attack surface.

    OutputAttack Surface Map

    Activities

    • Discover live hosts across the ranges
    • Scan for open ports and services
    • Fingerprint operating systems and versions
    • Build the attack surface map
  3. 03

    Vulnerability Discovery

    We combine authenticated and unauthenticated scanning with manual review to find weak services, patches and configuration.

    OutputCandidate Finding List

    Activities

    • Run authenticated and unauthenticated scans
    • Manually review scan results
    • Identify missing patches and weak services
    • Flag risky configuration and protocols
  4. 04

    Manual Exploitation

    We exploit findings to gain a foothold, capturing credentials and abusing exposed services and protocols like SMB and LLMNR.

    OutputInitial Foothold with Proof

    Activities

    • Exploit weak services to gain a foothold
    • Capture credentials with Responder
    • Abuse SMB, LLMNR and NBT-NS
    • Confirm access and rule out false positives
  5. 05

    Post-Exploitation and Lateral Movement

    We escalate privileges, map Active Directory attack paths and move laterally toward domain admin and critical systems.

    OutputMapped Attack Paths to Domain Control

    Activities

    • Escalate local and domain privileges
    • Map AD attack paths with BloodHound
    • Move laterally between hosts
    • Reach domain admin and crown-jewel systems
  6. 06

    Reporting and Verified Retest

    You get a report with attack paths and prioritised fixes, and we retest once you remediate to confirm the paths are closed.

    OutputFinal Report and Verified Retest

    Activities

    • Document attack paths and prioritised fixes
    • Produce an executive summary
    • Walk your team through the results
    • Retest fixes and confirm the paths are closed

Specification

What We Run, and What We Measure You Against

The tooling our engineers use on this work, and the published standards the findings and evidence are mapped to.

Scope

What Is Examined, and What it Is Measured Against

Map

Map of the Network Infrastructure scope, running left to right in three stages. Stage one, what we run, 8 tools and techniques: Nmap, Nessus, Metasploit, CrackMapExec, Responder, BloodHound, Wireshark, Impacket. Stage two, findings from all of it are proven by hand and written up once. Stage three, measured against 6 published standards: PTES, NIST SP 800-115, MITRE ATT&CK, OSSTMM, CIS Benchmarks, CVSS v4.0.

What We Run

8 tools

  • Nmap
  • Nessus
  • Metasploit
  • CrackMapExec
  • Responder
  • BloodHound
  • Wireshark
  • Impacket

Converges On

One Set of Proven Findings

Every issue is reproduced by hand before it is written down, and it is written down once.

Measured Against

6 standards

  • PTES
  • NIST SP 800-115
  • MITRE ATT&CK
  • OSSTMMISECOM
  • CISBenchmarks
  • CVSS v4.0
One pass of testing and analysis, one set of findings, then that single set is graded against every standard on the right. You are not paying for the same work once per framework.

Deliverables

What You Receive

  • Findings report with mapped attack paths
  • Executive summary
  • Remediation guidance
  • Verified retest report
  • Attestation letter

Scope This Engagement

Tell us about your environment, your timelines and any audit dates you are working to. We come back with scope, effort and a start date.

Questions

What Clients Ask Us

Something here not covered? Ask Us Directly.

What is the difference between external and internal testing?

External testing looks at what an attacker sees from the internet. Internal testing assumes they are already inside, through phishing or a rogue device, and shows how far they get. Most clients want both.

Do you test Active Directory?

Yes, and it is usually where the interesting paths are. We map AD relationships with tools like BloodHound and show the realistic routes from a normal user to domain admin.

Is internal testing safe to run on our live network?

Yes. We avoid denial-of-service and destructive actions, work in agreed windows and stay in contact with your team, so testing reflects real risk without disrupting operations.

Keep Moving Through VAPT

Service 5 of 7 in this practice area