Internal Network Penetration Testing
Internal network penetration testing across Europe. We test what an attacker does after the perimeter falls, from fixed price to free retest.
Internal network penetration testing answers the question your firewall can’t: once an attacker is already inside, on a phished laptop or a rogue device in a meeting room, how far can they get before anyone notices? We simulate that foothold and push it as far as your controls allow, then hand you the exact path and the fixes.
Most breaches don’t stop at the edge. Someone clicks a link, a contractor plugs in an unmanaged machine, a printer with default credentials sits on the same VLAN as your finance server. From that single point, a capable attacker moves laterally, harvests credentials, and reaches the data that actually matters. A perimeter test never sees any of this. That is the gap internal testing is built to close.
What internal network penetration testing actually covers
The engagement starts from an assumed-breach position: we get a network drop, a standard user account, or a connected device, and work outward the way a real intruder would. The point is not to list open ports. It is to prove, with evidence, what an attacker reaches from inside and how to stop them.
Assumed breach, not a lucky guess
We don’t spend your budget trying to pick the front-door lock again. If someone determined wants in, sooner or later they get a foothold. Starting from that assumption is more honest and far more useful, because it tells you what the breach actually costs once it happens. If a single compromised workstation leads to domain admin in an afternoon, you need to know that before an attacker demonstrates it for you.
Scope you control
You decide the boundaries. Some clients want the whole estate in play, others carve out a sensitive production segment or a specific data store as the objective. We agree targets, out-of-scope systems and any fragile hosts in writing before a single packet moves. Everything happens under NDA.
How we run an internal network pen test
Every internal network pen test we run is manual work by a certified engineer, backed by tooling but never replaced by it. A scanner tells you a port is open. It doesn’t chain three medium findings into a full domain takeover. That chaining is the job, and it’s where automated reports fall silent.
Discovery and mapping
We map live hosts, services and trust relationships using nmap, targeted service probing, and passive traffic capture with Responder listening for the noisy broadcast protocols most Windows networks still leak. This phase builds the picture: what talks to what, where the domain controllers sit, which segments are supposed to be isolated and whether they really are.
Credential access
Internal networks leak secrets constantly. Poisoning LLMNR and NBT-NS responses often yields NetNTLM hashes within minutes on a typical Windows estate. We test for SMB signing so we know where relay attacks land, crack what we capture offline, and check for the reused local administrator password that lets one machine’s hash open a hundred others.
Where credentials usually come from
In practice the richest sources are rarely exotic. Cleartext passwords in scripts and scheduled tasks, service accounts with weak passwords and Kerberoastable service principal names, GPP passwords still sitting in SYSVOL, and shares that let any authenticated user read a backup of the last engineer’s notes. None of it needs a zero-day.
Lateral movement and escalation
With a foothold and a set of credentials, we move. Pass-the-hash, pass-the-ticket, and legitimate remote-management protocols let us hop between hosts the way a real intruder does, staying inside normal admin behaviour so we can also gauge whether your monitoring would catch it. On each host we hunt for local privilege escalation: unquoted service paths, writable service binaries, vulnerable drivers, and misconfigured sudo rules on Linux.
Reaching the objective and reporting
The engagement is only worth something if it ends in a clear story. We document the full path from initial foothold to the crown jewels, with screenshots and command output at each step, then write it up so both your board and your engineers can act. Critical findings reach you the same day we confirm them, not weeks later in a PDF.
Vulnerabilities we find inside the perimeter
The internal environment is where years of “we’ll fix it later” accumulate. These are the issues we report most often, and they are almost never the ones a compliance checklist flags.
Broadcast protocol poisoning
LLMNR and NBT-NS remain enabled on a large share of the networks we test. They let us impersonate any host a client fails to resolve, capturing authentication attempts and, on unsigned SMB, relaying them straight into a session on another machine. Disabling these protocols and enforcing SMB signing closes an entire attack class in an afternoon.
Flat networks and failed segmentation
A worrying number of “segmented” networks turn out to be flat where it counts. The guest Wi-Fi reaches the finance VLAN, developer laptops can hit the backup server, a VoIP subnet has an unfiltered route to domain controllers. We test these boundaries directly and tell you which segmentation rules exist on paper only.
Overprivileged accounts and stale access
Service accounts that are also domain admins, personal accounts with rights nobody remembers granting, and shared local administrator passwords across the fleet are the difference between a contained incident and a company-wide one. Weak account hygiene is the single most common escalation path we exploit.
Forgotten and unpatched systems
Every large network hides a few machines no one owns: a legacy application server on an end-of-life operating system, a test box that quietly went to production, a management interface exposed with default credentials. These are the hosts an attacker loves, and the ones your asset inventory rarely lists.
Want this tested on your own systems?
Free 20-minute scoping call, a fixed price with no hourly surprises, and a free retest once you fix what we find.
What you get
You get evidence you can act on, not a wall of severity ratings. Two documents, written for two audiences, plus the working relationship to close the gaps.
Executive summary
A plain-language overview for leadership: what we achieved, what it would mean if a real attacker did the same, and the handful of changes that cut the most risk. No jargon, no scare tactics, a clear read on where you stand.
Technical report
Every finding with an impact statement, a CVSS score, the exact reproduction steps, and a prioritized, specific fix. Where findings chain, we show the chain, because a set of “medium” issues that together yield domain admin is not a set of mediums. Your engineers can reproduce and verify each one.
Attestation and retest
An attestation letter suitable for clients, auditors and insurers confirming the test took place and its scope. After you remediate, we retest the findings at no extra cost to confirm the fixes actually hold under attack, not just in theory.
Compliance and standards
An internal network penetration test maps directly to several frameworks that European organisations answer to. We align the deliverables to whichever ones apply to you.
PCI DSS, ISO 27001 and SOC 2
PCI DSS 4.0 requirement 11.4 calls for internal and external penetration testing, including segmentation testing where you rely on it to reduce scope. ISO 27001 Annex A control 8.8 covers technical vulnerability management, and SOC 2 auditors routinely expect independent testing as evidence. Our reports carry the detail and the attestation these reviews ask for.
DORA, NIS2 and GDPR
For financial entities, DORA’s threat-led testing expectations and NIS2’s risk-management obligations both push regular, evidence-based testing of internal systems. Where personal data sits on the network, GDPR Article 32 expects appropriate technical measures, and a documented internal test is strong evidence you took them seriously.
Methodology
Testing follows recognised methodology drawn from the PTES and the OWASP and NIST guidance, with lateral-movement and escalation techniques mapped to MITRE ATT&CK so your blue team can trace exactly which tactics we used and whether they were detected.
Why manual testing beats a scanner
An automated internal scan will find the missing patch. It will not notice that a low-privilege share exposes a config file, that the config file holds a service-account password, that the service account is Kerberoastable, and that cracking it hands over the domain. That chain is invisible to a scanner and obvious to an experienced engineer. You are paying for the human who connects the dots and, just as importantly, throws out the false positives a scanner would have buried you in.
Fewer findings, better findings
We would rather hand you eight real, exploitable issues ranked by business impact than four hundred “informational” lines you’ll never read. Everything in the report is something we confirmed by hand.
Pricing
Cost depends on scope: the number of live hosts and subnets in play, whether the network is a single site or spread across locations, and how deep you want us to push toward a defined objective. Here is the shape of a typical European engagement.
| Engagement | What’s included | Timeline | Price |
|---|---|---|---|
| Essential | Single site, up to roughly 50 live hosts, assumed-breach foothold, credential and lateral-movement testing, full report and free retest | 4–6 working days | from €3,000 |
| Standard | Mid-size estate, multiple subnets and VLANs, segmentation testing, Active Directory in scope, exec and technical reporting | 6–9 working days | €4,000–€9,000 |
| Advanced | Large or multi-site network, defined crown-jewel objective, detection-evasion testing and blue-team debrief | 9–15 working days | €9,000–€18,000 |
| Compliance add-on | Segmentation attestation and mapping for PCI DSS, ISO 27001, SOC 2 or DORA | with any tier | from €800 |
| Custom / large estate | Multiple sites or a full environment, scoped to your needs after a call | on scoping | custom |
Every engagement is fixed-price, quoted after a free 20-minute scoping call, with no hourly surprises and a retest included. Get a fixed quote
FAQ
How much does internal network penetration testing cost?
How long does an internal network pen test take?
Do you need to be on site, or can you test remotely?
What is the difference between internal and external penetration testing?
Will the test disrupt our network or bring systems down?
Does this satisfy PCI DSS or ISO 27001 requirements?
Who does the actual testing?
What happens after you find something serious?
Related services
Organisations that have hardened the perimeter but never tested what happens once someone gets past it: companies with a Windows domain and shared file storage, businesses facing PCI DSS or ISO 27001 audits, and any team that relies on network segmentation to protect sensitive data and wants proof it actually holds.
Security you can prove
The same standard on every engagement, big or small.
Evidence, not opinions
Every finding ships with a reproduction and proof of concept — no vague "maybe vulnerable".
Humans over scanners
Certified engineers find the logic flaws and chained attacks automated tools walk straight past.
Fixed price, free retest
You know the cost up front, and verifying the fix is part of the deal — not a second invoice.
Ready to lock this down?
Free scoping call, fixed price, free retest. Tell us what you're running and we'll take it from there — usually within one business day.
Tell us what you're running
Scoping is free. We reply within one business day, and under 30 minutes for active incidents.