Internal PenEtration Test
This comprehensive infrastructure penetration testing service evaluates the security of your internal network by simulating an attack from an internal threat actor. Our experienced pen-testers use a variety of tools and techniques to identify vulnerabilities from within your network perimeter.
Network Penetration Testing
We start with Network-based vulnerability scans on the internal network. This initial pass aims to discover devices on the network, the services that are accessible and find known vulnerabilities that attackers could exploit on the local network. This helps to judge how “soft” the network’s core is and how easily an attacker could spread across the network to gain additional access if the boundary was compromised or malware deployed to a workstation.
We follow this with further exploration of the discovered services using custom tooling and manual exploration. If you provide login details for Windows or Linux systems, then we will also perform authenticated scans to check for software patch levels and common misconfigurations that cause information leakage.
This testing will include:
- Asset discovery and fingerprinting
- UDP and TCP Port Scan
- Vulnerability assessment
- Penetration testing of any targets based upon the tester’s judgement and output of the Vulnerability assessment.
- Attempts to identify services that may indicate the presence of unauthorised storage services or connections to the network
- Authenticated scan of Windows servers and where accounts have been provided
- Authenticated scan of Linux servers where accounts have been provided
- Before we start any testing, we’ll agree a formal testing Scope document with you. In this, we’ll agree on the IP addresses that are in scope; and any limitations or restrictions on the testing we can perform – for example systems that are in production use; or systems that can be easily rebuilt and thus we can perform more aggressive testing.
We will need you to provide either VPN access, or allow us to deploy a small staging server to undertake our tests.
Once our testing is complete, we’ll provide you with a report with detailed findings, their impact and how to fix them. We can also provide consultancy to help fix these if that is useful to you.