An assumed breach, not a theatre piece
We start from a realistic foothold, the phished laptop or the standard account, because that is where real incidents begin. No artificial head start, no unrealistic constraints.
A phishing email will land eventually, and that is why serious testing starts after it does. Our internal penetration testing begins from an assumed breach, a single compromised laptop or a standard domain account, and proves how far an attacker reaches.
How an internal pentest worksProtected by reCAPTCHA. The Google Privacy Policy and Terms of Service apply.
Request received.
We’ll be in touch within one business day with next steps.
No se ha podido enviar. Inténtalo otra vez o escríbenos.















We do not argue about whether an attacker gets in. We assume they already have, from the most realistic starting point you can give us, and measure the damage from there.
Getting from one ordinary login to full control of your network is rarely a single dramatic exploit. It is a chain of small, well-understood steps: capturing a password as it crosses the network, reusing it to log in elsewhere, cracking a weak service password offline, abusing the system Windows uses to prove identity, and finally copying the master key that unlocks every account.
An internal pentest asks how far an attacker gets once inside. An external pentest asks whether someone on the internet can break in.
Not sure where to start?
If one laptop is compromised tomorrow, how bad does it get? A ransomware near-miss, an audit clause, an insurer, or a new CISO baselining the estate forces the answer.
If you claim your cardholder data environment is segmented, PCI DSS requires you to prove it holds under attack, not on a diagram. We test the boundary from the outside of the segment inward.
When the ask is for assurance, you need an external, expert-led engagement and a deliverable that turns how far an attacker reaches into business impact, in language a non-technical stakeholder can read.
The cheapest moment to validate is right after the change. We test from inside, prove which privilege paths still exist, and retest after the fix to confirm the work did what it was meant to do.
The question is not ‘do we have findings’ but ‘is that route closed and which others are open’. We start from the account that was involved, test whether the path still works, and map every adjacent privilege route.
We start from an assumed breach inside that network and prove how far a single foothold gets, so what you are taking on is a measured path rather than an assurance.
Real attackers do not start from zero: they start from a foothold. So do we. Your Active Directory and your segmentation decide the path we take through it.
Most internal tests hand back a list of missing patches. Here is where we go further.
We start from a realistic foothold, the phished laptop or the standard account, because that is where real incidents begin. No artificial head start, no unrealistic constraints.
The real routes from one foothold to full network control, ranked by how directly each reaches your crown jewels. Break one link and the path closes: fix the route, not the noise.
We test whether your boundaries hold under attack and document exactly what crosses them, the evidence PCI DSS, NIS2 and your auditor actually require.
Optional purple-team mode: every step logged and timed, so you learn whether your SOC and EDR catch the lateral movement, not just whether the path exists.
We at Etnia highly value our collaboration with Asperis Security.
We at Etnia highly value our collaboration with Asperis Security. Their professionalism, approachability, quick response and ability to adapt to our needs have been key in every project. The quality of service and continuous support always give us peace of mind. Without a doubt, it is a pleasure to have them as technology partners.
ASPERIS has worked alongside us to define and implement our cybersecurity roadmap in Microsoft 365 with a structured approach aligned to business objectives. Thanks to their advice, we took the strategic step of completing our Microsoft ecosystem and reinforcing it with CrowdStrike for advanced mobile device protection, significantly raising our security level.
At NPAW we have collaborated with Asperis on various security initiatives and the experience has been very positive. We especially value their ability to adapt to our needs and the depth with which they approach each project. Results are clear, structured and useful for decision-making and continuous security improvement. We like working with Asperis for the judgment and value they bring to every collaboration. Their work has helped us strengthen our security level.
With Asperis you don’t hire a service. You hire a partner. They don’t look to bill a project. They look to establish a relationship of trust, caring about the key points that affect your organisation’s security. Professionalism, know-how and diligence.
Tell us your starting assumption and the assets you most need to protect. An experienced consultant will reply.
An internal penetration test is a controlled, hands-on attack that begins from inside your network, from an assumed breach such as a phished laptop or a standard employee login, to prove how far an attacker could reach. It focuses on your login system (Active Directory), on turning ordinary accounts into administrators, on moving between machines, and on reaching backups and sensitive data. The deliverable is a set of proven attack routes ranked by how directly each one reaches full network control and your crown jewels, each with evidence your team can reproduce.
An assumed breach means we start the test from a position an attacker would realistically already hold, a standard domain account or a compromised workstation, rather than spending the engagement getting in. We start there because phishing, a stolen laptop or a reused password will eventually succeed, so the question that matters is not whether someone gets a foothold but how much damage that foothold allows. It is the fastest way to measure your real blast radius.
An external pentest tests what an attacker on the internet can reach; an internal pentest tests what they reach once inside. External answers ‘can they break in’. Internal answers ‘how far do they get, and how fast’. Most regulated companies run both on different cycles, because reducing your exposed surface and limiting your internal blast radius are two separate problems.
A typical internal pentest runs one to three weeks of active testing, depending on the size of your Active Directory estate and the number of segments in scope, plus scoping beforehand and the retest afterwards. A single-domain environment is usually one to two weeks; multi-domain forests, multiple sites or heavy segmentation scale from there. We confirm the timeline in the proposal within 48 hours of the first call.
No, not without your explicit consent. Every engagement runs under documented Rules of Engagement: agreed test windows, protected assets, forbidden actions and a kill-switch contact. Techniques that could affect stability are only used with prior approval, and we never run destructive tests against the servers that run your login system. Sensitive steps, such as proving we could copy the master key to every account (DCSync), are demonstrated as a controlled, one-off proof, not a disruptive operation.
Price follows the size of your estate, the number of segments in scope and the test type, and we quote a fixed price with no hidden fees and no obligation to renew. A single-domain internal assessment sits at the bottom of the range; larger forests and multi-site networks scale from there. The retest that confirms your fixes is always included.
The senior specialist you meet on the first call runs it end to end. Our team holds OSCP, OSEP, CRTO and CRTP credentials, the certifications built specifically around Active Directory and red-team tradecraft, most have worked inside enterprise security teams, and we are NASA Bug Bounty verified contributors. The same person scopes, executes and retests. You deal with them directly throughout.
At least once a year as a compliance floor for ISO 27001, ENS, PCI DSS, SOC 2, NIS2 and DORA. In practice, a fresh test is warranted by any material change to your identity or network: an Active Directory or GPO refactor, an IAM or SSO migration, a re-segmentation project, a new site, or an acquisition you are integrating. A ransomware near-miss in your sector is also a strong trigger.
Start with a no-obligation introductory meeting. We will agree the starting assumption, the assets to protect and the segments in scope, and define the right internal pentest before the project begins.
Protected by reCAPTCHA. The Google Privacy Policy and Terms of Service apply.
Request received.
Request received. A senior specialist will reply within one business day with scope, a fixed quote and a timeline.
No se ha podido enviar. Inténtalo otra vez o escríbenos.
Or email [email protected] directly.
OUR CLIENTS HAVE ALREADY DONE IT
We at Etnia highly value our collaboration with Asperis Security.
ASPERIS has worked alongside us to define and implement our cybersecurity roadmap in Microsoft 365 with a structured approach aligned to business objectives.
At NPAW we have collaborated with Asperis on various security initiatives and the experience has been very positive.
With Asperis you don’t hire a service. You hire a partner.
Pick a time that suits you. You tell us what you need and where you are, and we explain how we work and how we can help.