Offensive Security · Network Penetration Testing Service dossier · 01/13

Network Penetration Testing

Your network is the terrain an attacker actually fights on. We test it the way an intruder would — across your external perimeter and your internal estate — going far beyond port scanning to prove how a single foothold becomes full compromise.

Veteran researchers. CERT-In empaneled. Manual exploitation, not just a scan report.

Discipline
Offensive
Standards
NIST SP 800-115 · PTES · MITRE ATT&CK
Models
Black-box · grey-box
Retest
Remediation retest included
Credential
CERT-In Empaneled
02

Beyond the scan, into the network

A network assessment that stops at open ports and a list of CVEs tells you where the doors are — not whether anyone can walk through them.

Real intrusions rarely turn on a single dramatic exploit. They begin with a modest foothold, then escalate: harvested credentials, a misconfigured service, a trust relationship abused, a path traced quietly from one host to the next until an attacker holds the domain. The risk that matters is not the vulnerability in isolation. It is the chain.

We test that chain. Across your external perimeter and your internal corporate network — and, where Wi-Fi is in scope, your wireless environment — our researchers combine automated discovery for breadth with manual, hands-on exploitation for the depth and judgment a scanner cannot reach. We confirm what is genuinely exploitable, demonstrate how far it reaches, and measure the business impact — then report it with the evidence and the remediation your team needs.

"A scanner finds the open door. An attacker walks through it, then finds the next one. We test the whole walk."
03

External and internal

Different vantage points reveal different risks. We assess both your perimeter and your internal estate — together they describe how exposed you really are — and can extend the engagement to your wireless edge where Wi-Fi is in scope.

External — perimeter

The view from the internet

We assess your internet-facing infrastructure exactly as an anonymous, unauthenticated attacker would encounter it — enumerating exposed hosts, services and entry points, then attempting to gain an initial foothold from the outside. This is the truest test of your perimeter and the gateway most real intrusions pass through.

Internal — assumed breach

What happens once they're inside

Starting from a position inside your network — a compromised workstation, a contractor's access, a single set of stolen credentials — we model the assumed-breach scenario that defines modern attacks. From there we pursue privilege escalation, credential access, lateral movement and the Active Directory paths (Kerberoasting, relay attacks, trust abuse) that lead to domain dominance.

Add-on

Wireless

Where Wi-Fi is part of the in-scope environment, we can extend the engagement to your wireless edge — testing for weak or crackable WPA2/WPA3 pre-shared keys, captured handshakes and PMKID, rogue access points and evil-twin attacks against enterprise wireless, and the segmentation failures that let a wireless or guest client reach the corporate network it should never touch.

04

What an attacker is really after

Every finding we report ladders up to a real adversarial goal. We test for the outcomes an intruder pursues, not just the vulnerabilities in isolation.

01

Gaining a foothold

Turning an exposed service or weak credential into the first authenticated step inside.

02

Escalating privileges

Moving from a low-privilege account to local admin, then toward domain control.

03

Harvesting credentials

Extracting passwords, hashes and Kerberos tickets to unlock the next host.

04

Moving laterally

Pivoting host to host and segment to segment, following trust the network already grants.

05

Reaching critical assets

Reaching the data stores, domain controllers and management planes that run the business.

06

Maintaining access

Establishing the persistence and evasion a real intruder would use to stay unnoticed.

05

A disciplined, attacker-led methodology

We follow a structured methodology aligned with recognized standards — NIST SP 800-115 and the Penetration Testing Execution Standard (PTES) — so coverage is repeatable and defensible, while the exploitation itself stays creative and adversarial. Within the engagement, the offensive actions we take are mapped to the MITRE ATT&CK framework, so every step is named in the same language your defenders use. Each phase opens into the specific attacker tactics beneath it.

INFORMATIONGATHERING VULNERABILITYANALYSIS EXPLOITATION POST-EXPLOITATION REPORTING 02 03 04 05 Pre-engagement Interactions Intelligence Gathering Discovery Fingerprinting Initial Access Execution Privilege Escalation Persistence Defense Evasion Credential Access Domain Trust Discovery Lateral Movement Preparing Reports Presentation Remediation Testing
FIG. 01Network methodology — five phases; each opens into the attacker tactics beneath it
PHASE 01 Information Gathering Pre-engagement interactions · Intelligence gathering · Discovery · Fingerprinting. We agree the rules of engagement, then map the in-scope estate: live hosts, open ports, the services and versions behind them, and the full reachable attack surface.
PHASE 02 Vulnerability Analysis Combine automated discovery with manual review to identify candidate weaknesses across the surface — and, critically, eliminate the false positives a scanner alone would leave behind.
PHASE 03 Exploitation Initial access · Execution · Privilege escalation · Persistence. Safely prove impact. We confirm each finding by demonstrating what an attacker could actually do — gaining a foothold, running code, and elevating privilege on the host.
PHASE 04 Post-Exploitation Defense evasion · Credential access · Domain trust discovery · Lateral movement. Measure how far that foothold reaches: harvesting credentials, mapping domain trusts, and moving laterally toward the assets and the domain that matter.
PHASE 05 Reporting Preparing reports · Presentation · Remediation testing. Deliver clear, prioritized, reproducible findings with evidence and concrete fixes — and re-verify the fixes once your team has applied them.
06

Tools find the obvious. People find the dangerous.

Both have a role. We use each for what it does best — and we never let a scan stand in for an assessment.

Automated — breadth

Breadth, at speed

Automated tooling rapidly discovers in-scope hosts, sweeps for open ports and services, and flags known, signature-based weaknesses across a wide surface. We treat its output as a starting point — every result is triaged by an analyst and false positives are eliminated before anything reaches your report. Suited to establishing baseline exposure across non-critical assets at scale.

Manual — depth

Depth, with judgment

The findings that decide a breach — chained exploits, privilege escalation, credential reuse, trust abuse and the Active Directory attack paths that turn one host into a domain — require a researcher who understands how an attacker reasons. Our analysts examine each open port and service by hand, exploit and chain real weaknesses, and pursue the lateral paths no automated tool is built to follow.

07

Choose the depth of visibility

We tailor the engagement to how much we know going in. More context means deeper coverage in the same window.

Less context More context
Black-box

We test with no internal knowledge of the target — exactly as an outside attacker would encounter it. A black-box engagement determines what is exploitable from beyond the network, with no credentials or documentation provided. Best for validating your true external exposure.

Grey-box
Most common model

We test with partial knowledge: network design and architecture documentation, and a measure of internal access to in-scope assets. This is the most common and cost-effective model for internal engagements — it lets us reach deeper, role-specific and post-authentication weaknesses far more efficiently.

Full-knowledge reviews of firewall rules, device configurations and network architecture are delivered under our Network Configuration & Firewall Rules Review service.

08

What we test against

Across an engagement we systematically probe the control areas that determine whether a foothold stays contained or becomes a compromise:

01 Authentication How identities are verified across the estate, including the protocols (such as Kerberos) that underpin enterprise authentication and the attacks that target them.
Access Control
02 Authorization Whether the right entities are granted the right access, and how authentication data is protected as it moves between systems.
Access Control
03 Data at Rest Protection of data stored on system drives, external media, storage-area networks (SANs) and backups.
Data Security
04 Data in Transit Protection of data moving across wired, wireless, internal and public networks against interception and downgrade.
Data Security
05 User Input Handling Injection and input-handling flaws exposed on network services — SQL injection, OS command injection, cross-site scripting, insecure file upload, HTTP response splitting and related classes.
Data Security
06 Updates & Upgrades Firmware versions, operating-system patch levels and hotfixes across in-scope assets.
Risk Management
07 Logging & Monitoring Whether activity is logged and observable enough to detect an intrusion — and what those logs may inadvertently expose.
Risk Management
08 Misconfiguration Default, weak or unsafe configurations that disclose internal or sensitive information, or that hand an attacker an unintended advantage.
Configuration Management
09 Password Management Credential strength, storage and management across the network, and resistance to spraying, brute force and offline cracking.
System Security
09

How an engagement works

A clear path from kickoff to remediation — built to give your team findings they can act on immediately, in the language their defenders already use.

01
Intelligence Gathering
We agree scope and rules of engagement, then gather the open-source and infrastructure intelligence that frames the assessment.
02
Discovery
We identify the live hosts and reachable systems that make up the real, in-scope attack surface.
03
Fingerprinting
We determine the operating systems, platforms and technologies in play, so testing is precise rather than generic.
04
Open Ports & Services Enumeration
We enumerate every open port and the services and versions running behind it — by hand, not just by signature.
05
Vulnerability Analysis
We combine automated discovery with manual analysis to surface candidate weaknesses, and discard the false positives a scanner leaves behind.
06
Verification
We confirm each candidate weakness is genuine before any exploitation is attempted — no theoretical findings, no noise.
07
Exploitation
We safely prove impact: gaining a foothold, escalating privilege and establishing the persistence a real intruder would.
08
Post-Exploitation
We measure how far the foothold reaches — credential access, domain-trust discovery and lateral movement — then report, present and re-test the fixes.
10

What we can test

If it's reachable on your network, it's in scope. The same attacker mindset extends across the whole estate.

Servers Application, database, file and domain servers across on-premises and hosted environments.
Network Devices Routers, switches and the management planes that run them.
Firewalls Perimeter and internal firewalls, and the rule sets that are meant to contain an attacker. → Network Config & Firewall Review
Load Balancers The traffic-distribution layer and its exposure.
Proxies Forward and reverse proxies and their handling of trusted traffic.
IDS / IPS Detection and prevention systems — including how well they actually see and stop an active intruder.
Cloud & Virtualization Cloud-hosted infrastructure and virtualized environments that extend the network beyond your walls. → Cloud Security Assessment
Custom Deployments Bespoke or environment-specific systems tested against the way they're really built.
11

What you receive

Every engagement ends in a report your team can act on — written for both the engineers who will fix the issues and the leaders who must understand the risk.

01

Executive summary

Risk posture and business impact in plain language for leadership.

02

Detailed findings

Each issue with severity, affected hosts and services, reproducible proof-of-concept and clear evidence.

03

Attack-path narrative

How individual findings chain into real compromise — the story a vulnerability list can't tell.

04

Remediation guidance

Specific, prioritized fixes mapped to each finding — not generic advice.

05

Standards mapping

Offensive actions mapped to MITRE ATT&CK; methodology aligned to NIST SP 800-115 and PTES.

06

Remediation retest

We re-verify fixes so you can confirm the risk is genuinely closed.

07

Direct researcher access

A debrief with the people who did the testing, not a handoff to a call centre.

CERT-In Empaneled NIST SP 800-115 PTES MITRE ATT&CK

Supports ISO 27001, SOC 2, PCI-DSS and RBI/SEBI assessment requirements

12

Frequently asked questions

How is this different from a vulnerability scan?

A scan produces a list of potential issues from known signatures. A penetration test confirms what is actually exploitable, chains weaknesses the way an attacker would — foothold to privilege escalation to lateral movement — and measures how far an intrusion really reaches. We use scanning as one input, never as the assessment itself.

Should we test externally, internally, or both?

External testing reflects an anonymous internet attacker and validates your perimeter. Internal testing assumes that perimeter is eventually crossed — by phishing, a stolen credential or an insider — and measures the damage from there. Most organizations need both, because the two answer different questions. Wireless is assessed where Wi-Fi is part of the in-scope environment.

What is "assumed breach," and why test that way?

Modern attackers almost always get inside eventually. Assumed breach starts the internal engagement from a realistic foothold and asks the question that matters most: once they're in, how far can they get? It is the fastest route to the privilege-escalation and Active Directory findings that decide a real incident.

Will testing disrupt our production network?

We scope and pace engagements to avoid operational impact, coordinate windows with your team, and treat any potentially intrusive testing — including wireless deauthentication or denial-of-service demonstrations — with explicit, written agreement.

How often should we test?

At minimum annually, and after any significant change to your network, infrastructure or Active Directory — as well as when compliance requires it. Frequently changing environments benefit from a recurring cadence.

Do you retest after we fix the issues?

Yes. Remediation retesting is included so you can confirm each finding is genuinely resolved.

Offensive Security · Network Penetration Testing

Find the path before they do.

Tell us what your environment looks like and we'll scope an assessment that fits — or connect you directly with a researcher.