INTERNAL PENETRATION TESTING

Assume they are already inside. Find out how far they get.

A phishing email will land eventually, and that is why serious testing starts after it does. Our internal penetration testing begins from an assumed breach, a single compromised laptop or a standard domain account, and proves how far an attacker reaches.

How an internal pentest works
87%
of our clients renew annually
150+
organisations across multiple European countries
7/10
confirm findings their previous provider did not find
Want to know how far a breach reaches? Share your main concern and your email.

Protected by reCAPTCHA. The Google Privacy Policy and Terms of Service apply.

Trusted by companies in highly regulated environments

Identify exactly how far an attacker gets once they are inside.

ENGAGEMENT · ASSUMED BREACH GOAL · REACH DOMAIN ADMIN
WORKSTATION WS-MKT-04 · phished employee START
Recon · BloodHound + GetUserSPNs
STANDARD USER acme\m.solar · Domain Users
Kerberoast · hashcat -m 13100
SERVICE ACCOUNT svc-backup · SPN exposed
Lateral move · svc-backup is local admin
FILE SERVER FS01.acme.local · admin session in memory
ACL abuse · GenericWrite → group add
PRIVILEGED GROUP Domain Admins · inherited via ACL
DCSync · secretsdump
DOMAIN CONTROLLER DC01.acme.local · KRBTGT reachable GAME OVER
FULL DOMAIN COMPROMISE 5 HOPS · ~38 MIN
footholdWS-MKT-04 (phished, no admin)
escalationsvc-backup → Domain Admins
path_to_DAverified · 5 hops
segmentationoffice → servers · no barrier
crown_jewelsfile shares · backups · KRBTGT

We do not argue about whether an attacker gets in. We assume they already have, from the most realistic starting point you can give us, and measure the damage from there.

Getting from one ordinary login to full control of your network is rarely a single dramatic exploit. It is a chain of small, well-understood steps: capturing a password as it crosses the network, reusing it to log in elsewhere, cracking a weak service password offline, abusing the system Windows uses to prove identity, and finally copying the master key that unlocks every account.

WHAT WE TEST
  • Active Directory: the login your whole network trusts
  • Certificate services that issue Windows identities
  • Passwords captured as they cross the network
  • Passwords left in memory, caches and policy files
  • An ordinary account turned into an administrator
  • Movement from one machine to your core systems
  • Segmentation: the internal walls that contain a breach
  • Backups, file shares and sensitive data stores
INTERNAL VS EXTERNAL PENTEST

Where each one fits.

An internal pentest asks how far an attacker gets once inside. An external pentest asks whether someone on the internet can break in.

YOU ARE HERE

Internal pentesting

External pentesting

Objective
Internal pentesting Prove what an attacker reaches once they are inside.
External pentesting Map the internet-facing surface and prove what leads to a foothold.
Starting point
Internal pentesting A foothold: standard user, VPN, contractor laptop.
External pentesting Internet, no access, no credentials, just your apex domain.
Assets in scope
Internal pentesting Active Directory, ADCS, endpoints, file servers, internal apps.
External pentesting Public portals, exposed APIs, edge appliances, VPN, DNS, mail, cloud perimeter.
Techniques
Internal pentesting Kerberoast, ADCS abuse, ACL chains, NTLM relay, BloodHound paths.
External pentesting OSINT, surface enumeration, CVE chaining, exposed-service exploitation.
Question it answers
Internal pentesting Once inside, how far do they get?
External pentesting Can someone on the internet break in, and how fast?
When it fits
Internal pentesting Ransomware readiness, lateral movement, segmentation audit.
External pentesting Reducing exposure, validating edge changes, meeting external audit clauses.

Why a CTO, CISO or CIO books an internal pentest.

If one laptop is compromised tomorrow, how bad does it get? A ransomware near-miss, an audit clause, an insurer, or a new CISO baselining the estate forces the answer.

TAP A SITUATION
Compliance & audit ISO 27001 audit window

An auditor does not accept an assumption.

If you claim your cardholder data environment is segmented, PCI DSS requires you to prove it holds under attack, not on a diagram. We test the boundary from the outside of the segment inward.

  • Segmentation tested and documented for PCI DSS scope reduction
  • Methodology mapped to PTES, NIST SP 800‑115 and MITRE ATT&CK
  • Execution certificate ready for the auditor folder
  • Retest evidence with timestamps and signoff
Board & customer Board asked for ransomware assurance

Someone with authority asked, and ‘we’re fine’ isn’t an answer.

When the ask is for assurance, you need an external, expert-led engagement and a deliverable that turns how far an attacker reaches into business impact, in language a non-technical stakeholder can read.

  • Executive summary that lands without translation
  • Findings ranked by business impact and audit exposure
  • The path from one laptop to domain control, proven step by step
  • Independence: external and expert-led throughout
Change Active Directory or GPO refactor

You are changing the network. Verify the change landed.

The cheapest moment to validate is right after the change. We test from inside, prove which privilege paths still exist, and retest after the fix to confirm the work did what it was meant to do.

  • Scope tuned to the change being shipped
  • Privileged tiers, delegation and group policy pressure-tested after the change
  • Segmentation checked by attempting the crossing, not by reading the rule set
  • Retest gates closure, not just the report
Incident-driven Ransomware near-miss

Something happened. You need to know what is still reachable.

The question is not ‘do we have findings’ but ‘is that route closed and which others are open’. We start from the account that was involved, test whether the path still works, and map every adjacent privilege route.

  • Targeted scope around the suspected attack path
  • Adjacent privilege routes mapped: directory ACLs, certificates, delegation, hosts
  • Reproducible commands for the incident-response team to replay
  • Live findings to your responders, not the final report
Business event Newly acquired company

A transaction or a handover puts the network under new eyes.

We start from an assumed breach inside that network and prove how far a single foothold gets, so what you are taking on is a measured path rather than an assurance.

  • Scope agreed against the network as it is, the inherited domain included
  • Trust relationships between the old and the new environment tested explicitly
  • Findings ranked by business impact, in language a non-technical reader follows
  • Retest to closure, so the handover ends with the paths closed

Ready to see how far a breach reaches in yours?

Book a call
Thirty minutes with an experienced pentester.

Seven phases, from the first foothold to full control.

Real attackers do not start from zero: they start from a foothold. So do we. Your Active Directory and your segmentation decide the path we take through it.

What you actually get, and why it is different.

Most internal tests hand back a list of missing patches. Here is where we go further.

An assumed breach, not a theatre piece

We start from a realistic foothold, the phished laptop or the standard account, because that is where real incidents begin. No artificial head start, no unrealistic constraints.

Attack paths, not a vulnerability list

The real routes from one foothold to full network control, ranked by how directly each reaches your crown jewels. Break one link and the path closes: fix the route, not the noise.

Segmentation proven, not assumed

We test whether your boundaries hold under attack and document exactly what crosses them, the evidence PCI DSS, NIS2 and your auditor actually require.

Detection-aware, if you want it

Optional purple-team mode: every step logged and timed, so you learn whether your SOC and EDR catch the lateral movement, not just whether the path exists.

Want to see what your next internal pentest with us would look like?

We at Etnia highly value our collaboration with Asperis Security.
Sergi Leno, Systems Manager · ETNIA Barcelona

Loved by engineering and security teams.

We at Etnia highly value our collaboration with Asperis Security. Their professionalism, approachability, quick response and ability to adapt to our needs have been key in every project. The quality of service and continuous support always give us peace of mind. Without a doubt, it is a pleasure to have them as technology partners.
Sergi Leno, Systems Manager
ETNIA Barcelona
ASPERIS has worked alongside us to define and implement our cybersecurity roadmap in Microsoft 365 with a structured approach aligned to business objectives. Thanks to their advice, we took the strategic step of completing our Microsoft ecosystem and reinforcing it with CrowdStrike for advanced mobile device protection, significantly raising our security level.
Jordi Bondia, IT Director
SALVI
At NPAW we have collaborated with Asperis on various security initiatives and the experience has been very positive. We especially value their ability to adapt to our needs and the depth with which they approach each project. Results are clear, structured and useful for decision-making and continuous security improvement. We like working with Asperis for the judgment and value they bring to every collaboration. Their work has helped us strengthen our security level.
Sergi Laencina Verdaguer, CISO
NPAW
With Asperis you don’t hire a service. You hire a partner. They don’t look to bill a project. They look to establish a relationship of trust, caring about the key points that affect your organisation’s security. Professionalism, know-how and diligence.
Juan Valer Tecedor, Software Engineer
GNOSS
READY WHEN YOU ARE

Want a real internal scope for your network?

Tell us your starting assumption and the assets you most need to protect. An experienced consultant will reply.

Questions that come up before signing.

An internal penetration test is a controlled, hands-on attack that begins from inside your network, from an assumed breach such as a phished laptop or a standard employee login, to prove how far an attacker could reach. It focuses on your login system (Active Directory), on turning ordinary accounts into administrators, on moving between machines, and on reaching backups and sensitive data. The deliverable is a set of proven attack routes ranked by how directly each one reaches full network control and your crown jewels, each with evidence your team can reproduce.

An assumed breach means we start the test from a position an attacker would realistically already hold, a standard domain account or a compromised workstation, rather than spending the engagement getting in. We start there because phishing, a stolen laptop or a reused password will eventually succeed, so the question that matters is not whether someone gets a foothold but how much damage that foothold allows. It is the fastest way to measure your real blast radius.

An external pentest tests what an attacker on the internet can reach; an internal pentest tests what they reach once inside. External answers ‘can they break in’. Internal answers ‘how far do they get, and how fast’. Most regulated companies run both on different cycles, because reducing your exposed surface and limiting your internal blast radius are two separate problems.

A typical internal pentest runs one to three weeks of active testing, depending on the size of your Active Directory estate and the number of segments in scope, plus scoping beforehand and the retest afterwards. A single-domain environment is usually one to two weeks; multi-domain forests, multiple sites or heavy segmentation scale from there. We confirm the timeline in the proposal within 48 hours of the first call.

No, not without your explicit consent. Every engagement runs under documented Rules of Engagement: agreed test windows, protected assets, forbidden actions and a kill-switch contact. Techniques that could affect stability are only used with prior approval, and we never run destructive tests against the servers that run your login system. Sensitive steps, such as proving we could copy the master key to every account (DCSync), are demonstrated as a controlled, one-off proof, not a disruptive operation.

Price follows the size of your estate, the number of segments in scope and the test type, and we quote a fixed price with no hidden fees and no obligation to renew. A single-domain internal assessment sits at the bottom of the range; larger forests and multi-site networks scale from there. The retest that confirms your fixes is always included.

The senior specialist you meet on the first call runs it end to end. Our team holds OSCP, OSEP, CRTO and CRTP credentials, the certifications built specifically around Active Directory and red-team tradecraft, most have worked inside enterprise security teams, and we are NASA Bug Bounty verified contributors. The same person scopes, executes and retests. You deal with them directly throughout.

At least once a year as a compliance floor for ISO 27001, ENS, PCI DSS, SOC 2, NIS2 and DORA. In practice, a fresh test is warranted by any material change to your identity or network: an Active Directory or GPO refactor, an IAM or SSO migration, a re-segmentation project, a new site, or an acquisition you are integrating. A ransomware near-miss in your sector is also a strong trigger.

Ready to test your network?

Start with a no-obligation introductory meeting. We will agree the starting assumption, the assets to protect and the segments in scope, and define the right internal pentest before the project begins.

Request an internal pentest proposal.
An experienced pentester replies within one business day. You talk to the person who runs the test.

Protected by reCAPTCHA. The Google Privacy Policy and Terms of Service apply.

Or email [email protected] directly.

OUR CLIENTS HAVE ALREADY DONE IT

We at Etnia highly value our collaboration with Asperis Security.

Sergi Leno, Systems Manager
ETNIA Barcelona

ASPERIS has worked alongside us to define and implement our cybersecurity roadmap in Microsoft 365 with a structured approach aligned to business objectives.

Jordi Bondia, IT Director
SALVI

At NPAW we have collaborated with Asperis on various security initiatives and the experience has been very positive.

Sergi Laencina Verdaguer, CISO
NPAW

With Asperis you don’t hire a service. You hire a partner.