Internal penetration testing
Secure your internal network and your Active Directory.
What is an internal pentest?
Internal penetration tests, also called "internal pentests" or "network pentests", simulate an attacker who already has access to your network, for example through the compromise of an employee. These tests identify the vulnerabilities that could be exploited to take control of your information system, and validate how well your detection tools perform.
Objectives
Our audits highlight realistic risk scenarios, including:
Theft of sensitive data
Business interruption
Ransom demands
Data loss
Damage to your brand
The HELX approach
During an internal pentest, we analyze all the resources available on your network (services, internal applications, file shares and more) to spot sensitive data accessible to everyone as well as vulnerabilities. At the end of the audit, we present the results and deliver a report with a prioritized, actionable list of every fix needed to close the vulnerabilities we found. And if you lack the internal resources to apply the fixes, we offer hands-on support and hardening services.
Audit types
An internal penetration test can start from different initial conditions. During our first conversation, we decide together which scenario best fits your needs.
Black box
Simulates a realistic attack by a hacker with access to your internal network but no account.
Gray box
Simulates an attack by a hacker who has compromised an account or a server on your internal network.
White box
A complete analysis of the information system with administrator access.
Methodology
Our internal penetration tests follow a rigorous, proven methodology that lets us audit your entire internal network as exhaustively as possible. During a network pentest, we pay particular attention to poor administration practices and vulnerable services (Active Directory, business applications, printers, telephony, file shares and more).
- 01
Information gathering
Mapping of your internal network, identification of exposed services, collection of information about domain users and servers, and passive analysis of the traffic on the reachable subnet.
- 02
Vulnerability research
Analysis of the collected information to find vulnerable services, broken access controls or dangerous configurations that could lead to the compromise of servers or the Active Directory domain.
- 03
Vulnerability exploitation
Execution of the attacks to validate the exploitability of the detected vulnerabilities, assess their severity and obtain additional access.
- 04
Post-exploitation
Use of the access obtained to extract sensitive information, repeat the previous steps on new networks and expand across the entire information system.
- 05
Compromise paths
All the vulnerabilities discovered are chained into one or more attack paths to build realistic compromise scenarios.
- 06
Risk assessment
Classification of the flaws by severity and estimation of the impact on the internal network and the business.
A bit of technical detail
We identify vulnerabilities that could affect your internal network, your servers and your data:
- Network configuration flaws
- Public vulnerabilities (CVE)
- Analysis of file shares
- Broken access controls (ACL)
- Web vulnerabilities in internal applications
- Dangerous ADCS configuration
- System and application privilege escalation
- Credential harvesting on machines
- Lateral movement through credential replay
- Active Directory domain compromise
Our other penetration tests
Frequently asked questions
How much does an internal penetration test cost?
Between €5,100 and €12,750 excl. VAT depending on the size of your estate (Windows and Linux servers, workstations). Small businesses, SMBs and non-profits get a 15% discount; the online quote simulator gives you an immediate estimate.
Do you need to come on site?
Your choice: on-site work or remote access through an appliance we ship to you or a dedicated VPN. The result is the same either way: a foothold on the internal network, just like an attacker or a compromised provider would have.
Is Active Directory covered?
It is the very core of the test: privilege escalation, attack paths to privileged accounts, weak passwords, dangerous delegations. Our consultants hold CRTP/CRTO certifications on these topics.
Can the test disrupt the network?
The techniques we use are proven and non-destructive; the most sensitive actions (relaying, poisoning) are validated with you and run outside critical hours if needed.
What do we need to prepare?
Almost nothing: network access (a jack or VPN), and optionally a standard workstation and an unprivileged user account for the "compromised employee" scenario. We take care of the rest.
Tell us about your project.
Let us talk through your needs and expectations and build the right service for you.
