External, Internal, Lateral
Network Penetration Testing
We test your network from the outside in and the inside out. From the internet edge we look for the way in; from inside we show how far an attacker moves once they have a foothold.
See the engagement path, 6 phasesSee the full VAPT service index
Backlog And Ageing, Estate Wide
Worked example
A vulnerability management product view. Illustrative snapshot of a typical programme, not a named client. Headline figures for the quarter across 1,340 in-scope assets and 40 web applications: 4,812 open findings, of which 288 are past their internal SLA; 37 critical findings open; blended mean time to remediate 84 days, computed from the 3,371 closures this quarter, 24 critical at 21 days each, 391 high at 38, 2,100 medium at 74 and 856 low at 130, which is 282,042 finding-days over 3,371 closures; SLA compliance 68 percent, 2,292 of 3,371 closures within SLA. Open findings by CVSS v3.1 band: Critical 37, which is 0.8 percent; High 412, 8.6 percent; Medium 1,954, 40.6 percent; Low 2,409, 50.1 percent. A further 1,106 informational findings are excluded from that total. 19 open findings are listed on the CISA Known Exploited Vulnerabilities catalogue and 4 of those are past their CISA BOD 22-01 due date. Findings over 13 weeks: 2,993 new against 3,371 remediated, so the open backlog fell from 5,190 to 4,812, with a spike of 402 new findings in week 6 when the quarterly authenticated scan ran. Mean time to remediate by severity against target: Critical 21 days against a 15-day target, High 38 against 30, Medium 74 against 90, Low 130 against 180. The table lists 13 representative findings ranked by exploitability, led by CVE-2024-3400, GlobalProtect OS command injection, CVSS 10.0, EPSS 0.944, on KEV, 13 days old and open; CVE-2023-4966, NetScaler session token leak, CVSS 9.4, on KEV, 41 days old and in progress; and CVE-2021-44228, Log4j2 JNDI remote code execution on a legacy build host, CVSS 10.0, on KEV, 402 days old and still open.
4,812
Open
288 past SLA
37
Critical
19 on KEV
84d
MTTR
3,371 closed
68%
Within SLA
2,292 of 3,371
By Severity, 4,812 Open
19 on CISA KEV, 4 past their CISA due date.
Illustrative snapshot of a typical programme, not a named client.
Overview
A network infrastructure VAPT covers your external perimeter and your internal environment, including Active Directory. Externally we look for exposed services, weak configuration and paths through the edge. Internally we simulate an attacker who already has a foothold and show how they escalate privileges and move laterally toward domain control and your crown-jewel systems. You see the real blast radius of a single compromised device.
Methodology
How the Engagement Runs
Every phase has a named output, so you always know what is being worked on and what lands on your side of the table.
6 Phases, 6 Named Handovers
Flow
Flow chart of the Network Infrastructure engagement, 6 phases in order, each one selectable. Phase 1, Scoping and Rules of Engagement. We agree external ranges, internal segments and any excluded systems, and set testing windows and emergency contacts. Activities: Confirm external ranges and internal segments; Agree excluded and fragile systems; Set testing windows; Exchange emergency contacts. Hands over Signed Rules of Engagement. Phase 2, Reconnaissance and Mapping. We discover live hosts, open ports and services across the in-scope ranges and build a map of the attack surface. Activities: Discover live hosts across the ranges; Scan for open ports and services; Fingerprint operating systems and versions; Build the attack surface map. Hands over Attack Surface Map. Phase 3, Vulnerability Discovery. We combine authenticated and unauthenticated scanning with manual review to find weak services, patches and configuration. Activities: Run authenticated and unauthenticated scans; Manually review scan results; Identify missing patches and weak services; Flag risky configuration and protocols. Hands over Candidate Finding List. Phase 4, Manual Exploitation. We exploit findings to gain a foothold, capturing credentials and abusing exposed services and protocols like SMB and LLMNR. Activities: Exploit weak services to gain a foothold; Capture credentials with Responder; Abuse SMB, LLMNR and NBT-NS; Confirm access and rule out false positives. Hands over Initial Foothold with Proof. Phase 5, Post-Exploitation and Lateral Movement. We escalate privileges, map Active Directory attack paths and move laterally toward domain admin and critical systems. Activities: Escalate local and domain privileges; Map AD attack paths with BloodHound; Move laterally between hosts; Reach domain admin and crown-jewel systems. Hands over Mapped Attack Paths to Domain Control. Phase 6, Reporting and Verified Retest. You get a report with attack paths and prioritised fixes, and we retest once you remediate to confirm the paths are closed. Activities: Document attack paths and prioritised fixes; Produce an executive summary; Walk your team through the results; Retest fixes and confirm the paths are closed. Hands over Final Report and Verified Retest. Each phase begins from the artefact the phase before it produced.
Phase 01 Scoping and Rules of Engagement
We agree external ranges, internal segments and any excluded systems, and set testing windows and emergency contacts.
What Happens In This Phase
- Confirm external ranges and internal segments
- Agree excluded and fragile systems
- Set testing windows
- Exchange emergency contacts
The Handover
Signed Rules of Engagement
The next phase starts from this.
Phase 01 Scoping and Rules of Engagement
We agree external ranges, internal segments and any excluded systems, and set testing windows and emergency contacts.
What Happens In This Phase
- Confirm external ranges and internal segments
- Agree excluded and fragile systems
- Set testing windows
- Exchange emergency contacts
The Handover
Signed Rules of Engagement
The next phase starts from this.
- 01
Scoping and Rules of Engagement
We agree external ranges, internal segments and any excluded systems, and set testing windows and emergency contacts.
OutputSigned Rules of EngagementActivities
- Confirm external ranges and internal segments
- Agree excluded and fragile systems
- Set testing windows
- Exchange emergency contacts
- 02
Reconnaissance and Mapping
We discover live hosts, open ports and services across the in-scope ranges and build a map of the attack surface.
OutputAttack Surface MapActivities
- Discover live hosts across the ranges
- Scan for open ports and services
- Fingerprint operating systems and versions
- Build the attack surface map
- 03
Vulnerability Discovery
We combine authenticated and unauthenticated scanning with manual review to find weak services, patches and configuration.
OutputCandidate Finding ListActivities
- Run authenticated and unauthenticated scans
- Manually review scan results
- Identify missing patches and weak services
- Flag risky configuration and protocols
- 04
Manual Exploitation
We exploit findings to gain a foothold, capturing credentials and abusing exposed services and protocols like SMB and LLMNR.
OutputInitial Foothold with ProofActivities
- Exploit weak services to gain a foothold
- Capture credentials with Responder
- Abuse SMB, LLMNR and NBT-NS
- Confirm access and rule out false positives
- 05
Post-Exploitation and Lateral Movement
We escalate privileges, map Active Directory attack paths and move laterally toward domain admin and critical systems.
OutputMapped Attack Paths to Domain ControlActivities
- Escalate local and domain privileges
- Map AD attack paths with BloodHound
- Move laterally between hosts
- Reach domain admin and crown-jewel systems
- 06
Reporting and Verified Retest
You get a report with attack paths and prioritised fixes, and we retest once you remediate to confirm the paths are closed.
OutputFinal Report and Verified RetestActivities
- Document attack paths and prioritised fixes
- Produce an executive summary
- Walk your team through the results
- Retest fixes and confirm the paths are closed
Specification
What We Run, and What We Measure You Against
The tooling our engineers use on this work, and the published standards the findings and evidence are mapped to.
What Is Examined, and What it Is Measured Against
Map
Map of the Network Infrastructure scope, running left to right in three stages. Stage one, what we run, 8 tools and techniques: Nmap, Nessus, Metasploit, CrackMapExec, Responder, BloodHound, Wireshark, Impacket. Stage two, findings from all of it are proven by hand and written up once. Stage three, measured against 6 published standards: PTES, NIST SP 800-115, MITRE ATT&CK, OSSTMM, CIS Benchmarks, CVSS v4.0.
What We Run
8 tools
- CrackMapExec
- Responder
- Impacket
Converges On
One Set of Proven Findings
Every issue is reproduced by hand before it is written down, and it is written down once.
Measured Against
6 standards
- PTES
- OSSTMMISECOM
- CIS
Deliverables
What You Receive
- Findings report with mapped attack paths
- Executive summary
- Remediation guidance
- Verified retest report
- Attestation letter
Scope This Engagement
Tell us about your environment, your timelines and any audit dates you are working to. We come back with scope, effort and a start date.
What is the difference between external and internal testing?
External testing looks at what an attacker sees from the internet. Internal testing assumes they are already inside, through phishing or a rogue device, and shows how far they get. Most clients want both.
Do you test Active Directory?
Yes, and it is usually where the interesting paths are. We map AD relationships with tools like BloodHound and show the realistic routes from a normal user to domain admin.
Is internal testing safe to run on our live network?
Yes. We avoid denial-of-service and destructive actions, work in agreed windows and stay in contact with your team, so testing reflects real risk without disrupting operations.
Keep Moving Through VAPT
Service 5 of 7 in this practice area
Practice Area
More in VAPT
- Web ApplicationManual testing of your web apps against the OWASP WSTG
- Mobile ApplicationAndroid and iOS app testing against the OWASP MASVS
- APIREST, GraphQL and SOAP testing against the OWASP API Top 10
- Thick Client ApplicationDesktop app testing across binary, traffic and backend
- IoT and EmbeddedDevice testing across firmware, hardware and radio
- CloudConfiguration and IAM testing across AWS, Azure and GCP