NETWORK SECURITY

Internal Network Penetration Testing

Your perimeter has already been crossed by someone, somewhere. We operate from inside your network — mapping every path from a compromised workstation to your crown jewels.

CORPORATE LAN ATTACKER WORKSTAT. CORE SWITCH DOMAIN CTRL FILE SERVER DB SERVER
Assumed Breach Testing

What Happens After the Perimeter Falls

Modern breach statistics are unambiguous: attackers dwell inside networks for weeks before detection. The question is no longer whether someone gets in — it's how far they can travel once they do. Internal network penetration testing answers that question with evidence, not assumptions.

Privilege Zero operates from an agreed starting position — a standard domain workstation, VPN access, or VLAN membership — and methodically attacks internal hosts, authentication infrastructure, and network devices to demonstrate true lateral movement potential.

We don't stop at "we found open SMB". We chain vulnerabilities into complete attack paths and show your board exactly what a determined adversary would reach from a single compromised laptop.

LAN+WAN
Including VLAN Segments & Remote Access
Full Lateral Movement Chain Documentation
DA
Domain Admin Escalation Attempted Every Engagement
Graph
BloodHound Attack Path Visualisation Included
Attack Phases

How We Move Through Your Network

01
Scoping & Assumed Breach Position

Define in-scope subnets, agreed starting access (standard user, workstation, VPN), and crown-jewel targets. Establish a remote access channel mirroring the assumed breach vector — no privileged starting position unless specifically requested.

02
Low-Noise Discovery & Enumeration

Sweep in-scope segments for live hosts, open ports, and service versions using traffic patterns calibrated to avoid IDS threshold alerts — replicating how a real attacker avoids detection during reconnaissance.

03
Credential Capture & Relay

Deploy LLMNR/NBT-NS poisoning, SMB relay, and IPv6 misconfiguration attacks to capture and relay NTLM credentials — demonstrating how quickly a network-layer foothold becomes domain access.

04
Vulnerability Exploitation

Exploit confirmed vulnerabilities across all in-scope services — unpatched CVEs, default credentials on management interfaces, misconfigured network devices — chaining each to extend reach across segments.

05
Privilege Escalation to Domain Admin

Escalate from standard user through local administrator to domain administrator using misconfigured services, Kerberos attacks, credential harvesting, and Active Directory exploitation — documenting every step.

06
Impact Demonstration & Cleanup

Demonstrate access to crown-jewel targets (domain controllers, database servers, backup infrastructure) through documented evidence. Remove all tooling, persistence mechanisms, and artefacts before disengaging.

Attack Techniques

Network-Layer Weapons We Test Against You

LLMNR / NBT-NS PoisoningSMB Relay Attacks IPv6 Misconfiguration (mitm6)WPAD Abuse Pass-the-HashPass-the-Ticket KerberoastingAS-REP Roasting VLAN HoppingSNMP Community String Abuse Network Device Default CredentialsUnauthenticated NFS/SMB Shares NetBIOS SpoofingPrinter Exploitation Legacy Protocol Abuse (Telnet/FTP/rsh)Unencrypted Management Protocols
Capabilities

What Separates Our Internal Testing

🗺️
Attack Path Visualisation

BloodHound-generated graphs showing every path from your starting position to domain admin — not a list of vulnerabilities, but a map of what an attacker actually does with them.

📡
Network Device Testing

Routers, switches, and firewalls get assessed for management interface exposure, weak credentials, and firmware-level vulnerabilities — not just servers and workstations.

🔕
IDS/IPS Evasion Measurement

We record which attacks generated alerts and which didn't — giving your SOC a prioritised list of detection gaps that reflect actual attacker behaviour in your environment.

🏗️
Segmentation Validation

We test whether your VLANs actually contain lateral movement — or whether a workstation on the guest network can reach your production databases.

Deliverables

Evidence You Can Act On

Attack Chain Narrative

Step-by-step walkthrough of the highest-impact attack path executed, from initial access to domain compromise — written for executive and technical audiences.

BloodHound Attack Path Export

Exported attack path graphs with annotated screenshots showing every pivot point from workstation to crown-jewel target.

Technical Findings Report

Per-finding documentation with CVSS scores, reproduction steps, and network-topology-aware remediation recommendations.

Network Segmentation Diagram

Annotated network map highlighting exploited pivot paths and recommended firewall rule and VLAN configuration changes.

Remediation Workshop

Optional 2-hour workshop with your IT security team to walk through findings and prioritise remediation effort.

Assess Your Internal Exposure

Know Your Blast Radius Before an Attacker Does

We scope from a single assumed-breach starting position and deliver full chain documentation within 10 business days.

Request Internal Network PT Discuss Scope