Skip to content
Security incident? Call: +48 732 059 711
Network & infrastructure pentest

From the perimeter to Domain Admin

External and internal network testing, Active Directory takeover paths, segmentation validation — the kind of test that lands in the board report.

Who is it for?

  • Enterprises with on-prem infrastructure
  • Organisations with Active Directory
  • Companies with hybrid environments
  • Manufacturing and OT-adjacent networks
  • NIS2 essential and important entities
What you get

Outcomes

External attack surface map

Every exposed asset, port, service and version — catalogued and prioritised.

Active Directory takeover paths

Kerberoasting, AS-REP, unconstrained delegation, ACL abuse, GPO exploitation — the BloodHound report you need.

Segmentation validation

We verify that VLANs, DMZ and zero-trust zones actually contain an attacker.

Patching & hardening gaps

Missing patches, default credentials, weak protocols (SMBv1, NTLMv1, LLMNR).

Lateral movement story

We chain the findings into a realistic attack story — from one foothold to Domain Admin.

Free retest

One free retest within 30 days — verifies fixes and updates the final report.

How we work

PTES + manual exploitation

  1. 01

    Scoping

    IP ranges, domains, Active Directory forests, exclusions, test windows — documented Rules of Engagement.

  2. 02

    Reconnaissance

    Asset discovery, service fingerprinting, OSINT for external, network mapping for internal.

  3. 03

    Exploitation & post-exploitation

    Privilege escalation, lateral movement, credential dumping, persistence (staged, never destructive).

  4. 04

    Report & retest

    Executive + technical report in 5 business days. Free retest within 30 days.

FAQ

Frequently asked questions

External, internal, or both?
Depends on your risk. External is a good starting point; internal is mandatory if you're NIS2 / DORA regulated.
Do you need an on-site visit for internal testing?
No. We use a hardened Dropbox device or a jump host — whichever fits your policy.
Will this disrupt our network?
We plan test windows, avoid DoS payloads and keep the SOC informed. Production is tested carefully.
How long does it take?
External: 5–8 days. Internal + AD: 10–15 days. Larger environments scale accordingly.
NIS2 / DORA evidence?
Yes. Reports are accepted as evidence of technical testing under NIS2 Art. 21 and DORA.

Scope your network pentest

Share the scope and we will come back with a plan, timeline and price within one business day.