Infrastructure
Internal penetration testing
Internal penetration testing answers a blunt question: if an attacker, rogue device or compromised laptop lands inside the network, how far can they get and what business systems can they reach?
Common internal attack paths
Internal compromise often comes from identity and configuration gaps rather than exotic exploits. Active Directory, local admin reuse, weak segmentation and credential exposure usually drive the highest impact.
- Active Directory privilege paths and certificate abuse
- LLMNR, NBT-NS and NTLM relay opportunities
- Weak or reused local administrator credentials
- File shares, secrets and sensitive internal services
Assumed breach testing
An assumed-breach start begins from a realistic internal foothold, such as network access or a low-privileged account. This shows containment and blast radius more clearly than perimeter-only testing.
Safe rules of engagement
Internal testing needs clear safety limits, escalation contacts and windows for sensitive actions. Production-impacting techniques should be controlled and explicitly approved.
FAQ
Common questions
Is internal testing only for large companies?
No. Smaller teams with Active Directory, VPN users, cloud networks or office networks can still have high-impact internal attack paths.
Can testing start without domain credentials?
Yes. A no-credentials or low-privileged start can show what a real intruder could do from an initial foothold.
Can internal testing include Active Directory?
Yes. Active Directory is usually central to internal network risk and should be included where present.