07 / 11

Internal Network Penetration Testing

We test from inside the perimeter, simulating an attacker who already has a foothold. Lateral movement, privilege escalation, Active Directory attack paths, and whether your network segmentation actually holds.

Internal Network Penetration Testing illustration

What is internal network penetration testing?

Internal network penetration testing starts from inside your perimeter and assumes an attacker already has a foothold, from a phished laptop, a rogue contractor or a compromised vendor connection. Where an external test asks whether someone can get in, an internal test asks how far they get once they are in. The work is Active Directory attack paths, lateral movement between hosts, privilege escalation toward Domain Admin, credential relay and replay, internal service and database exposure, and whether your network segmentation actually holds when someone pushes on it. It is a separate engagement from an external network test and evidences a separate compliance obligation.

Testing Checklist

Every engagement covers these critical security areas.

Internal host and port discovery across in-scope ranges
SMB, NFS and file share permission review
Active Directory enumeration and attack path mapping
Kerberoasting and AS-REP roasting
Unconstrained and constrained delegation abuse
NTLM relay and credential replay
Local and domain privilege escalation
Password policy and credential reuse testing
Internal database and management interface exposure
Unpatched internal service identification
Network segmentation and zone isolation testing
Internal certificate and service misconfiguration review

Testing Methodology

A structured, repeatable process that ensures thorough coverage and actionable results.

STEP 01

Access and Scoping

Agree how we reach the internal network and which ranges, domains and systems are in scope. Access method is confirmed during scoping rather than assumed.

STEP 02

Discovery and Enumeration

Map what is actually reachable from the assumed-breach position: live hosts, open services, shares, management interfaces, and trust relationships between systems.

STEP 03

Credential and Privilege Attacks

Test for weak and reused credentials, exposed service accounts, Kerberos attack paths including Kerberoasting and AS-REP roasting, delegation abuse, and relay opportunities.

STEP 04

Lateral Movement

Pivot between hosts using recovered credentials and misconfigurations, chaining findings the way an attacker would rather than reporting them in isolation.

STEP 05

Segmentation Validation

Test whether the network zones that are supposed to be isolated actually are. Where a compliance standard requires segmentation testing as a discrete result, it is reported separately.

STEP 06

Reporting and Retest

Every finding carries reproduction steps, the attack path it enabled, and remediation direction. One free retest within one month of the v1.0 report, delivered as v2.0.

Want to scope your internal network pentest engagement? Both founders take the discovery call.

What you get with Internal Network Pentest at each tier

Tier Includes Price
Startup 1 scope, 5 business days, 6 hours founder-led consulting, 1 free retest within one month of the v1.0 report. INR 74,999
Growth 2 scopes, 10 business days, SOC 2 and ISO 27001 control mapping per finding, a signed Letter of Attestation, 12 hours founder-led consulting, 1 free retest. INR 1,79,999

What counts as one scope: One Active Directory domain, up to 256 live hosts and up to 3 segmentation boundaries. Additional hosts are counted as additional scopes, 256 per scope, and a second Active Directory domain is a second scope. Multi-forest environments, and engagements beyond 4 scopes, are quoted as a custom proposal.

Each additional scope adds 5 business days, so 3 scopes is 15 and 4 is 20. All prices exclude taxes. See every scope definition.

All prices exclude taxes. International engagements invoiced in local currency at snapshot FX.

Framework Alignment

These are the standards that apply to this scope type. Which of them we run on your engagement depends on what you are buying: a checklist-style assessment covers the baseline categories set out in the standards listed here, while audit-evidence work adds systematic test-case coverage and control verification. We scope that with you before the engagement rather than applying every framework by default.

PTESNIST SP 800-115OSSTMM 3MITRE ATT&CKOWASP WSTG v4.2

Compliance Coverage

PCI
PCI DSS v4.0.1
11.4.2: internal penetration testing at least once every 12 months and after significant change, by a qualified internal resource or qualified external third party, with organizational independence of the tester. 11.4.3 covers external penetration testing and is a separate obligation, met by an external network engagement rather than by this one.
ISO
ISO 27001:2022
A.8.8: Management of technical vulnerabilities. A.8.29: Security testing in development and acceptance
SOC
SOC 2
CC4.1: Separate evaluations. CC7.1: Vulnerability detection
RBI
RBI Directions, 2026
Cybersecurity, Technology: Risk, Resilience and Assurance Framework Directions, 2026 (issued 31 July 2026, effective immediately; paragraph 230 repeals the preceding cyber security framework and IT governance directions, and RBI/2023-24/107 is repealed by circular DoS.CO.PPG.66/11.01.005/2026-27, Annex serial 16; issued separately per entity class, Commercial Banks version RBI/DoS/2026-27/410): vulnerability assessment at least once in every six months and penetration testing at least once in 12 months for critical information systems and those in the DMZ having a customer interface (paragraph 151), conducted by appropriately trained and independent information security experts or auditors (paragraph 155). Risk-based approach to requirement and periodicity for non-critical systems.

Deliverables

What you walk away with at the end of every engagement.

01

Technical report with reproduction steps per finding

02

Attack path narrative showing how findings chain together

03

Executive summary for non-technical stakeholders

04

CVSS v3.1 severity scoring per finding

05

Segmentation test results where in scope

06

One free retest within one month of the v1.0 report, delivered as v2.0

07

Letter of Attestation signed by the lead pentester (Growth plan)

Frequently Asked Questions

What counts as one internal network scope?

One scope is one Active Directory domain, up to 256 live hosts and up to 3 segmentation boundaries. Larger estates and multi-forest environments are quoted as a custom scoping proposal rather than squeezed into a fixed scope, because the enumeration and attack-path work grows with the estate rather than staying flat. If you are not sure how many live hosts you actually have, tell us what you know and both founders will size it with you before you buy anything. There is no charge for that conversation.

How much does an internal network pentest cost and how long does it take?

One internal network scope is INR 74,999 plus taxes under the Startup Pentest plan, tested over 5 business days from kickoff to the v1.0 report. Pairing it with an external network test, which is the combination most compliance programmes actually ask for, is two scopes at INR 1,79,999 plus taxes under the Growth Pentest plan over 10 business days, and that plan adds SOC 2 and ISO 27001 control mapping per finding plus a signed Letter of Attestation. Business days are Monday to Friday. Each additional scope adds 5 business days. Both plans include founder-led consulting hours and one full retest within one month of the v1.0 report.

Why does Active Directory decide the outcome of an internal network pentest?

In most Windows estates Active Directory is the control plane, so the interesting question is not whether one host is vulnerable but whether a normal user account can be walked into domain-wide control. That is why the work centres on attack paths rather than a host-by-host vulnerability list: delegation misconfiguration, service account privileges, credential material left in memory or on shares, relay opportunities where signing is not enforced, and nested group membership nobody has audited. A finding that a single workstation is missing a patch is worth far less to you than a documented path from a standard account to Domain Admin.

Does PCI DSS require an internal penetration test?

PCI DSS v4.0.1 requirement 11.4.2 requires internal penetration testing at least once every 12 months and after any significant infrastructure or application change. It is a separate obligation from requirement 11.4.3, which covers external penetration testing, so meeting one does not meet the other. Requirements 11.4.5 and 11.4.6 add segmentation testing on their own cadence where segmentation is used to reduce scope. The tester must be a qualified internal resource or a qualified external third party with organizational independence, and the standard notes the tester is not required to be a QSA or an ASV. Cybersecify is neither a QSA nor an ASV, so we can perform the testing but cannot conduct your assessment or sign your Report on Compliance.

What evidence does an internal network pentest produce for an auditor?

A technical report with reproduction steps for every finding, CVSS severity, business impact in plain language, and remediation guidance, plus a two-page executive summary. On the Growth plan each finding is mapped to the control it evidences: ISO 27001:2022 A.8.8 management of technical vulnerabilities and A.8.29 security testing in development and acceptance, and SOC 2 CC7.1 vulnerability detection and monitoring. A pentest report does not evidence A.8.25 secure development life cycle, which is evidenced by your development process rather than by a test, and we do not claim it. The retest produces a v2.0 report showing which findings were verified fixed, which is what an auditor usually wants to see rather than a list of open items.

Can our own IT team do the internal penetration test?

For your own assurance, yes, and internal testing is useful. For most compliance programmes, no. PCI DSS requires organizational independence of the tester, and SOC 2 CC7.1 evidence is weaker when the people who built and run the network are the same people attesting that it holds. The practical problem is also one of perspective: an internal team tests the network it designed, against the threat model it already has in its head. The independence requirement exists because that blind spot is predictable.

Ready to secure your internal network?

Pentest packages from INR 74,999 (~$790 / ~€680, indicative as at August 2026). Includes consulting hours + 1 free retest within one month. Both founders on every engagement: Rathnakara (OSCP) leads testing, Ashok handles delivery + compliance.