// Network Pentesting — External · Internal · Active Directory · Wi-Fi

Your Network Has
Hidden Attack Paths

Network penetration testing simulates a real attacker who has breached your perimeter. We map your entire network, exploit vulnerabilities, move laterally, escalate privileges — and show you the blast radius before a real attacker does.

68%
Breaches involve network-level access
AD
Active Directory Attack Testing
PTES
PTES & NIST Framework
5-Day
Standard Engagement

Two Types of Network Threats

External testing simulates an attacker on the internet — scanning your public IPs, probing exposed services, attempting to breach your perimeter. Internal testing simulates a threat actor who is already inside your network — via phishing, a rogue employee, or a compromised vendor.

Both scenarios are equally dangerous. 34% of breaches are caused by insiders, and once an attacker is inside a flat network, they can reach every server, workstation, and database within hours.

External: Full recon, port scanning, service exploitation, VPN/RDP attacks

Internal: Active Directory attacks, Kerberoasting, Pass-the-Hash, lateral movement

Wi-Fi: WPA2 cracking, evil twin AP, PMKID attack

Full kill-chain simulation from initial access to domain compromise

cyberhq@netpentest:~$ ./network_audit.sh 192.168.1.0/24

[*] Phase 1: Network discovery & port scan...

[+] Discovered 47 live hosts, 312 open ports

[!] SMBv1 enabled on 8 hosts (EternalBlue risk)

[*] Phase 2: Active Directory enumeration...

[+] Domain: CORP.LOCAL | DCs: 2 | Users: 423

[CRITICAL] AS-REP Roasting: 3 users w/no preauth

[CRITICAL] Kerberoasting: 7 SPNs crackable

[HIGH] LLMNR/NBT-NS poisoning successful

[CRITICAL] Domain Admin hash captured via NTLM relay

[*] Simulating full domain compromise...

[✓] Domain compromised in 4h 12m from initial access

Network Attack Reality

93%

of company networks can be penetrated by an external attacker in the first attempt

Positive Technologies 2024

4.5hrs

average time for an attacker to reach domain admin once inside the network

CrowdStrike 2024 Report

60%

of internal network tests result in complete domain compromise by CyberHQ

CyberHQ Engagement Stats

// Attack Techniques We Simulate

KerberoastingAS-REP RoastingPass-the-HashPass-the-TicketLLMNR PoisoningNTLM RelayBloodHound AD MappingDCSync AttackSMB RelayEternalBlue (MS17-010)Golden TicketSilver TicketMITMWi-Fi PMKID Attack

What We Test

External Network

  • ›Public IP & port enumeration
  • ›Exposed RDP, SSH, FTP exploitation
  • ›VPN & firewall bypass attempts
  • ›SSL/TLS configuration review
  • ›DNS zone transfer attempts

Active Directory

  • ›Kerberoasting & AS-REP Roasting
  • ›BloodHound attack path analysis
  • ›Pass-the-Hash / Pass-the-Ticket
  • ›DCSync & Golden Ticket attacks
  • ›ACL abuse & GPO misconfiguration

Lateral Movement

  • ›SMB relay & NTLM relay attacks
  • ›LLMNR/NBT-NS poisoning
  • ›Network segmentation bypass
  • ›Pivot through compromised hosts
  • ›Credential reuse across systems

Wi-Fi Security

  • ›WPA2/WPA3 password cracking
  • ›Evil twin access point attack
  • ›PMKID capture attack
  • ›Guest network isolation testing
  • ›Rogue AP detection

Services & Protocols

  • ›SMB, RDP, SSH, FTP, Telnet
  • ›MSSQL, MySQL, Oracle DB attacks
  • ›SNMP community string abuse
  • ›Printer & IoT device attacks
  • ›VLAN hopping techniques

Privilege Escalation

  • ›Local privilege escalation (Windows/Linux)
  • ›Sudo misconfigurations
  • ›Token impersonation (Windows)
  • ›Unquoted service path attacks
  • ›SUID/SGID binary exploitation
// Execution Lifecycle

Network Penetration Testing Methodology

PTES & NIST SP 800-115 5-Phase Attack Simulation

PHASE 01 STAGE 1/5
Reconnaissance & Surface Mapping

Reconnaissance & Surface Mapping

Passive OSINT and active port scanning discover all alive subnets, DMZ hosts, open services, and listening ports across your IP range.

NmapMasscanAmassShodan
PHASE 02 STAGE 2/5
Vulnerability & Service Enumeration

Vulnerability & Service Enumeration

Banner grabbing, SMB/RPC probing, and deep service fingerprinting detect unpatched CVEs, weak ciphers, and misconfigurations.

NessusCrackMapExecResponder
PHASE 03 STAGE 3/5
Exploitation & Initial Access

Exploitation & Initial Access

Weaponizing confirmed exploits and default credentials to bypass perimeter firewalls and establish internal footholds.

MetasploitCustom ExploitsHydra
PHASE 04 STAGE 4/5
Lateral Movement & AD Compromise

Lateral Movement & AD Compromise

Simulating internal threat actor pivots: Kerberoasting, AS-REP Roasting, Pass-the-Hash, and BloodHound attack path execution to Domain Admin.

BloodHoundMimikatzImpacket
PHASE 05 STAGE 5/5
Remediation Roadmap & Free Retest

Remediation Roadmap & Free Retest

Delivering prioritized GPO hardening guides, network segmentation blueprints, and CVSS scores, verified with a 30-day free re-test.

Executive SummaryTechnical PoCFree Retest

Comprehensive Security Deliverables Included

Every engagement includes executive briefings, technical PoCs, code-level fix guidance, and a complimentary 30-day verification re-test.

Case Study: Manufacturing Company Internal Network

How we achieved domain admin in 4 hours from a standard employee workstation — without any special tools.

// THE SITUATION

Client Background

A 200-employee manufacturing company in Gujarat with a flat Windows domain network. No internal firewall segments, all servers on the same VLAN as user workstations. IT team believed they were secure because no external attacks had succeeded.

Scope: Internal network pentest
Starting position: Standard user workstation
Duration: 3 days

// ATTACK PATH

How We Did It

  • [T+0h]LLMNR poisoning captured domain user's NTLMv2 hash
  • [T+1h]Cracked hash offline — password: "Company@123"
  • [T+2h]Kerberoasting yielded 12 service account hashes — 4 cracked
  • [T+3h]One cracked service account had DCSync rights — full AD dump
  • [T+4h]Domain Admin via Golden Ticket — persistent access to entire network
// OUTCOME

After Our Report

The client implemented network segmentation, disabled LLMNR, enforced strong password policies, and removed unnecessary Kerberos SPNs. CyberHQ re-tested — zero critical findings remained.

Network segmented into 6 VLANs
Domain admin attack path eliminated
ISO 27001 certification achieved

Get Your Network Assessed

Tell us your network size and we'll scope a full external + internal assessment. Every engagement starts with a signed NDA and a clear scope of work.

NDA Before Engagement
External + Internal Options
Free Re-Test Included