Skip to content

ISO 27001, SOC 2, the DPDP Act and manual VAPT. Book a Free Scoping Call

Part of VAPT7 services in this practice area

External, Internal, Lateral

Network Penetration Testing

We test your network from the outside in and the inside out. From the internet edge we look for the way in; from inside we show how far an attacker moves once they have a foothold.

See the engagement path, 6 phasesSee the full VAPT service index

Backlog And Ageing, Estate Wide

Worked example

A vulnerability management product view. Illustrative snapshot of a typical programme, not a named client. Headline figures for the quarter across 1,340 in-scope assets and 40 web applications: 4,812 open findings, of which 288 are past their internal SLA; 37 critical findings open; blended mean time to remediate 84 days, computed from the 3,371 closures this quarter, 24 critical at 21 days each, 391 high at 38, 2,100 medium at 74 and 856 low at 130, which is 282,042 finding-days over 3,371 closures; SLA compliance 68 percent, 2,292 of 3,371 closures within SLA. Open findings by CVSS v3.1 band: Critical 37, which is 0.8 percent; High 412, 8.6 percent; Medium 1,954, 40.6 percent; Low 2,409, 50.1 percent. A further 1,106 informational findings are excluded from that total. 19 open findings are listed on the CISA Known Exploited Vulnerabilities catalogue and 4 of those are past their CISA BOD 22-01 due date. Findings over 13 weeks: 2,993 new against 3,371 remediated, so the open backlog fell from 5,190 to 4,812, with a spike of 402 new findings in week 6 when the quarterly authenticated scan ran. Mean time to remediate by severity against target: Critical 21 days against a 15-day target, High 38 against 30, Medium 74 against 90, Low 130 against 180. The table lists 13 representative findings ranked by exploitability, led by CVE-2024-3400, GlobalProtect OS command injection, CVSS 10.0, EPSS 0.944, on KEV, 13 days old and open; CVE-2023-4966, NetScaler session token leak, CVSS 9.4, on KEV, 41 days old and in progress; and CVE-2021-44228, Log4j2 JNDI remote code execution on a legacy build host, CVSS 10.0, on KEV, 402 days old and still open.

SecureRoot VAPTVulnerability Management

4,812

Open

288 past SLA

37

Critical

19 on KEV

84d

MTTR

3,371 closed

68%

Within SLA

2,292 of 3,371

By Severity, 4,812 Open

Critical 37High 412Medium 1,954Low 2,409

19 on CISA KEV, 4 past their CISA due date.

Illustrative snapshot of a typical programme, not a named client.

How an estate backlog is tracked: a worked example with 4,812 open findings, the 288 past SLA and the 37 criticals counted, not averaged away. Illustrative figures, not a named client.

Overview

A network infrastructure VAPT covers your external perimeter and your internal environment, including Active Directory. Externally we look for exposed services, weak configuration and paths through the edge. Internally we simulate an attacker who already has a foothold and show how they escalate privileges and move laterally toward domain control and your crown-jewel systems. You see the real blast radius of a single compromised device.

Methodology

How the Engagement Runs

Every phase has a named output, so you always know what is being worked on and what lands on your side of the table.

The Engagement, End to End

6 Phases, 6 Named Handovers

Flow

Flow chart of the Network Infrastructure engagement, 6 phases in order, each one selectable. Phase 1, Scoping and Rules of Engagement. We agree external ranges, internal segments and any excluded systems, and set testing windows and emergency contacts. Activities: Confirm external ranges and internal segments; Agree excluded and fragile systems; Set testing windows; Exchange emergency contacts. Hands over Signed Rules of Engagement. Phase 2, Reconnaissance and Mapping. We discover live hosts, open ports and services across the in-scope ranges and build a map of the attack surface. Activities: Discover live hosts across the ranges; Scan for open ports and services; Fingerprint operating systems and versions; Build the attack surface map. Hands over Attack Surface Map. Phase 3, Vulnerability Discovery. We combine authenticated and unauthenticated scanning with manual review to find weak services, patches and configuration. Activities: Run authenticated and unauthenticated scans; Manually review scan results; Identify missing patches and weak services; Flag risky configuration and protocols. Hands over Candidate Finding List. Phase 4, Manual Exploitation. We exploit findings to gain a foothold, capturing credentials and abusing exposed services and protocols like SMB and LLMNR. Activities: Exploit weak services to gain a foothold; Capture credentials with Responder; Abuse SMB, LLMNR and NBT-NS; Confirm access and rule out false positives. Hands over Initial Foothold with Proof. Phase 5, Post-Exploitation and Lateral Movement. We escalate privileges, map Active Directory attack paths and move laterally toward domain admin and critical systems. Activities: Escalate local and domain privileges; Map AD attack paths with BloodHound; Move laterally between hosts; Reach domain admin and crown-jewel systems. Hands over Mapped Attack Paths to Domain Control. Phase 6, Reporting and Verified Retest. You get a report with attack paths and prioritised fixes, and we retest once you remediate to confirm the paths are closed. Activities: Document attack paths and prioritised fixes; Produce an executive summary; Walk your team through the results; Retest fixes and confirm the paths are closed. Hands over Final Report and Verified Retest. Each phase begins from the artefact the phase before it produced.

Phase 01 Scoping and Rules of Engagement

We agree external ranges, internal segments and any excluded systems, and set testing windows and emergency contacts.

What Happens In This Phase

  • Confirm external ranges and internal segments
  • Agree excluded and fragile systems
  • Set testing windows
  • Exchange emergency contacts

The Handover

Signed Rules of Engagement

The next phase starts from this.

Read the handover cards on their own and you have the paper trail. Select a phase to see what happens inside it.
  1. 01

    Scoping and Rules of Engagement

    We agree external ranges, internal segments and any excluded systems, and set testing windows and emergency contacts.

    OutputSigned Rules of Engagement

    Activities

    • Confirm external ranges and internal segments
    • Agree excluded and fragile systems
    • Set testing windows
    • Exchange emergency contacts
  2. 02

    Reconnaissance and Mapping

    We discover live hosts, open ports and services across the in-scope ranges and build a map of the attack surface.

    OutputAttack Surface Map

    Activities

    • Discover live hosts across the ranges
    • Scan for open ports and services
    • Fingerprint operating systems and versions
    • Build the attack surface map
  3. 03

    Vulnerability Discovery

    We combine authenticated and unauthenticated scanning with manual review to find weak services, patches and configuration.

    OutputCandidate Finding List

    Activities

    • Run authenticated and unauthenticated scans
    • Manually review scan results
    • Identify missing patches and weak services
    • Flag risky configuration and protocols
  4. 04

    Manual Exploitation

    We exploit findings to gain a foothold, capturing credentials and abusing exposed services and protocols like SMB and LLMNR.

    OutputInitial Foothold with Proof

    Activities

    • Exploit weak services to gain a foothold
    • Capture credentials with Responder
    • Abuse SMB, LLMNR and NBT-NS
    • Confirm access and rule out false positives
  5. 05

    Post-Exploitation and Lateral Movement

    We escalate privileges, map Active Directory attack paths and move laterally toward domain admin and critical systems.

    OutputMapped Attack Paths to Domain Control

    Activities

    • Escalate local and domain privileges
    • Map AD attack paths with BloodHound
    • Move laterally between hosts
    • Reach domain admin and crown-jewel systems
  6. 06

    Reporting and Verified Retest

    You get a report with attack paths and prioritised fixes, and we retest once you remediate to confirm the paths are closed.

    OutputFinal Report and Verified Retest

    Activities

    • Document attack paths and prioritised fixes
    • Produce an executive summary
    • Walk your team through the results
    • Retest fixes and confirm the paths are closed

Specification

What We Run, and What We Measure You Against

The tooling our engineers use on this work, and the published standards the findings and evidence are mapped to.

Scope

What Is Examined, and What it Is Measured Against

Map

Map of the Network Infrastructure scope, running left to right in three stages. Stage one, what we run, 8 tools and techniques: Nmap, Nessus, Metasploit, CrackMapExec, Responder, BloodHound, Wireshark, Impacket. Stage two, findings from all of it are proven by hand and written up once. Stage three, measured against 6 published standards: PTES, NIST SP 800-115, MITRE ATT&CK, OSSTMM, CIS Benchmarks, CVSS v4.0.

What We Run

8 tools

  • Nmap
  • Nessus
  • Metasploit
  • CrackMapExec
  • Responder
  • BloodHound
  • Wireshark
  • Impacket

Converges On

One Set of Proven Findings

Every issue is reproduced by hand before it is written down, and it is written down once.

Measured Against

6 standards

  • PTES
  • NIST SP 800-115
  • MITRE ATT&CK
  • OSSTMMISECOM
  • CISBenchmarks
  • CVSS v4.0
One pass of testing and analysis, one set of findings, then that single set is graded against every standard on the right. You are not paying for the same work once per framework.

Deliverables

What You Receive

  • Findings report with mapped attack paths
  • Executive summary
  • Remediation guidance
  • Verified retest report
  • Attestation letter

Scope This Engagement

Tell us about your environment, your timelines and any audit dates you are working to. We come back with scope, effort and a start date.

What It Costs

Indicative Ranges, Before You Ask

Every figure below is an indicative range, not a quote. Where you land in it depends on scope, and we confirm a fixed price only once scoping is done.

  • Indicative rangeDepends on scope

    Network infrastructure VAPT

    ₹50,000 to ₹4 lakh, retest included

    Range as of 2 September 2026

    What sets the figure

    • External, internal or both, with Active Directory attack paths where you have a domain
    • The number of hosts, sites and network segments in scope sets where you land in the range
    • Findings mapped to MITRE ATT&CK with fixes, and a retest once you remediate

Indicative ranges in INR; the final quote depends on scope, and each range is dated on its own card.

Get a Fixed Price for Your Scope

Tell us what is in scope and when you need it. You get a written scope and a fixed price, not a band.

Request an Assessment

Questions

What Clients Ask Us

Something here not covered? Ask Us Directly.

What is the difference between external and internal network testing, and do we need both?

External testing works from the internet against the addresses you publish; internal testing starts from a position inside the network and asks how far that position travels. They answer different questions. External work tells you what an attacker reaches with no help: exposed services, forgotten hosts on a range nobody reviews, weak edge configuration, a login portal that gives away more than it should. Internal work assumes the edge has already failed, through a phished user or a device somebody plugged in, and measures blast radius instead: privilege escalation, lateral movement between hosts, and the routes through Active Directory that lead from an ordinary account toward domain control. If you are buying one, buy the one that matches the worry that brought you here. If the driver is an audit or a customer questionnaire, the honest answer is usually both, because a hard perimeter wrapped around a flat interior is the pattern that hurts most in a real incident.

What do you need from us before testing starts, and how much access does an internal test involve?

For external work we need the address ranges and hostnames you own, written down and confirmed, plus somebody with authority to say yes to testing them. For internal work we need a foothold that matches the scenario: a VPN account reaching the segments in scope, or time on site with a network port and a desk, or a jump host we can connect to. We also ask which segments you want reached, which systems are excluded, the testing windows that suit your change calendar, and escalation contacts on both sides. That material becomes the Rules of Engagement, signed before anything is touched. What we do not need is your production data or a standing administrative account handed over informally. Where credentials are required they are created for the test, scoped to the test, and disabled at the end of it. The scoping call, usually 30 to 45 minutes, is where this list gets settled.

Should the internal test be credentialed or uncredentialed, and which gives the truer picture?

Run both where the scope allows it, and where it does not, run credentialed. Uncredentialed testing shows what an attacker sees before they own anything: services answering on the network, weak protocols, hosts exposing their age at the surface. It is the more dramatic exercise and the thinner one, because a host that refuses to talk anonymously looks safe and may not be. Credentialed testing gives us a low-privilege domain account, the kind a phished employee has, and from there we can see what is actually installed, which patches are missing behind the service banner, and which relationships in the directory turn that ordinary account into something dangerous. Those findings read as duller and are far more useful to fix. In practice the credentialed pass produces the attack paths, and the uncredentialed pass tells you which of those paths an outsider could start on without any help from your staff.

Our network carries legacy and fragile devices. How do you test it without knocking something over?

We name those devices during scoping and treat them differently, rather than promising nothing will ever wobble. Ageing gateways, old printers, manufacturing and medical equipment and unsupported appliances can fall over on an ordinary port scan, so in Phase 1 you tell us what is fragile and we agree in writing whether each one is excluded, examined passively, or tested in a window with somebody who owns it watching. Where a device stays in scope we slow the scanning down, drop the aggressive checks, and confirm the finding by inspection rather than by exploiting it. We avoid denial-of-service and destructive actions as a matter of policy, and we stay reachable on an agreed escalation contact for the duration, so a problem becomes a phone call rather than a paragraph in a report weeks later. A system you exclude stays excluded.

How is this different from the vulnerability scan our IT team already runs each month?

A scan lists what might be wrong; this engagement proves what is wrong and shows what it would cost you. Your scanner is doing useful work, and we scan too, in the discovery phase, as a way of widening coverage. The difference is what happens next. Scanner output is a list of candidates ranked by a generic severity score, with false positives left in and no sense of what chains together. Our engineers take that list, discard what does not hold, exploit what does, and then keep going: credentials captured on the wire, one host reused to reach another, a directory relationship that turns a helpdesk account into domain control. Each finding is reproduced by hand before it is written down, carries a proof of concept, and is ranked by the damage it does rather than by a number. Critical findings reach you within three hours of discovery, and a retest is part of the engagement.

Keep Moving Through VAPT

Service 5 of 7 in this practice area