EspañolEnglish

Internal network pentest

Assume they are already inside. Find out how far they get.

An internal penetration test starts from a foothold on your network, a phished laptop, a rogue device, a contractor’s access, and works toward Domain Admin and your most sensitive systems. It maps the path a real intruder would take once the perimeter is behind them.

Assumed breach or from a supplied endpoint. Remote or on-site. Scoped on the call.

What an internal pentest answers.

The perimeter will be breached eventually, by a phish, a reused password, a vulnerable VPN. The question that matters is what happens next. An internal test measures how quickly an attacker with a single foothold reaches your crown jewels, and how much your internal controls slow them down. Active Directory is almost always the terrain: this is where a foothold becomes Domain Admin.

Why it matters.

From one host to the whole domain

The value is the chain: a low-privilege user, a misconfigured share, a cached credential, a delegation flaw, and Tier-0 in a handful of hops. We show the exact route, not a list of isolated issues.

Segmentation you can trust

If your network is flat, one foothold owns everything. We test whether your segmentation actually holds, or whether the finance VLAN is one hop from a developer laptop.

Detection where it counts

Internal movement is where most attacks live the longest. Where scope allows, we note which steps your tooling would have caught, so your SOC learns where its blind spots are.

Where it starts.

We agree the starting point that matches your threat model.

Assumed breach

We start from a standard domain user or an unprivileged host, the position an attacker reaches minutes after a successful phish.

Rogue device

A device we connect to your network, on-site or shipped, to model an intruder with physical or network access.

From a specific endpoint

A build you provide, to test what a compromised employee laptop can reach.

How it runs.

One senior operator, yours for the whole engagement, from first host to objective.

  1. 01

    Recon and enumeration

    Mapping the domain: users, groups, hosts, services, shares, trusts. Building the picture an attacker builds before making a move.

  2. 02

    Credential access

    Kerberoasting, AS-REP roasting, LLMNR and NBT-NS poisoning, relay attacks, and hunting cleartext and cached credentials in shares and scripts.

  3. 03

    Privilege escalation

    Local and domain escalation: ACL and GPO abuse, delegation flaws, certificate services (ADCS) abuse, misconfigured service accounts.

  4. 04

    Lateral movement

    Pivoting host to host toward the objective, testing segmentation and internal monitoring as we go.

  5. 05

    Objective and impact

    Domain Admin, Tier-0 assets, or a specific system agreed up front. Demonstrated, evidenced, and always reversible.

What gets tested.

The internal terrain a real intruder crosses.

  • Active Directory: Kerberos, ACLs, GPOs, trusts
  • ADCS (certificate services) abuse paths
  • Credential hygiene: cached, cleartext, service accounts
  • SMB shares and their contents
  • Network segmentation and VLAN isolation
  • Relay and coercion (NTLM, PetitPotam-style)
  • Privileged access and Tier-0 exposure
  • Patch level of internal hosts and services
  • Legacy protocols and misconfigurations
  • Local privilege escalation on workstations and servers

What we usually find.

  • A service account with a weak password and rights over half the domain.
  • A flat network where a developer laptop can reach the backup server.
  • ADCS misconfigured so any user can request a Domain Admin certificate.
  • Cleartext credentials in a login script readable by everyone.

What you get.

  • Attack path documentation with BloodHound graphs
  • Every finding scored, with reproduction steps
  • Prioritized remediation, written for your environment
  • Detection hints for your SOC where scope allows
  • Free retest of Critical findings within 30 days

Internal pentests are scoped on the call, sized to your network. See services and pricing.

Questions.

Is this the same as an Active Directory assessment?

It overlaps. The internal pentest is broader: the whole internal network from a foothold, not only AD. If your concern is specifically AD hardening, the Active Directory Assessment goes deeper on that. The scoping call picks the right one.

Do you need Domain Admin to start?

No. The point is to start with as little as an attacker would have: a standard user, or an unprivileged laptop. If you hand over admin, you learn nothing about the path an attacker actually takes.

On-site or remote?

Either. Remote through a jump host or a shipped device works for most engagements. On-site makes sense when physical access or wireless is in scope.

Will it disrupt the network?

Testing is done carefully, with agreed no-go systems and same-day escalation of anything critical. Noisy or destructive techniques are only used with explicit sign-off.

Internal network

Find out how far a foothold gets.

Thirty minutes, NDA first. You talk to the operator who runs the test, not a salesperson.

Book a free scoping call

Prefer email? engagements@redghostops.com