Skip to main content
Home/Services/Internal Network Penetration Testing
Active Directory & Internal Network

Internal Network Penetration Testing

Simulate an assumed-breach adversary inside your network - attacking Active Directory, escalating privileges, and moving laterally to your crown-jewel assets.

SOC 2 Type II ISO 27001 OSFI B-13 PCI-DSS v4.0 PIPEDA Bill C-27 NIST CSF CIS Controls
engagement log Internal Network Penetration Testing testing
day 01 scope internal subnets confirmed · rules of engagement signed agreed
day 01 recon Active Directory topology & forest trusts enumerated complete
day 02 finding LLMNR & NBT-NS poisoning - captured NTLMv2 hashes critical
day 03 finding Kerberoasting vulnerable service account (svc_backup) high
day 03 finding SMB signing disabled - relayed admin session to DC critical
day 04 triage reviewed and countersigned by a Lorikeet pentester published
day 04 deliver tickets opened in tracker with BloodHound attack graph 201
after retest remediation verified · included in scope at no charge retested
retest included human countersigned report your auditor accepts
1-2 weekstypical duration $9,500fixed scope, from 8deliverables 8methodology stages
Scope

What This Engagement Covers

The Service

The most damaging enterprise breaches do not stop at the firewall. Once an adversary secures initial access through a spear-phishing payload, compromised VPN credential, or rogue workstation, their primary objective is your Active Directory forest. Our internal network penetration test simulates a determined threat actor operating from within your corporate perimeter. We map your internal subnets, identify Kerberoasting and AS-REP roasting targets, exploit SMB signing and LLMNR/NBT-NS broadcast flaws, abuse unconstrained delegation, and chain misconfigured ACLs to reach domain compromise and demonstrate real-world impact.

What We Test

We assess your complete internal network and directory infrastructure: Active Directory domains and trusts, domain controllers, Kerberos authentication policies, Group Policy Objects (GPOs), network segmentation and VLAN isolation, internal firewalls, routers, switches, VPN gateways, internal DNS, database clusters, virtualization hosts, and exposed management protocols (RDP, SSH, WMI, WinRM). We evaluate credential hygiene, token impersonation, delegation rights (unconstrained, constrained, RBCD), and path-to-compromise chains across physical, virtual, and hybrid environments.

Targets

Components Evaluated in Scope

Our testers systematically inspect the following architectural layers and attack vectors during the assessment.

Active Directory domain and forest architecture
Kerberoasting and AS-REP roasting attack paths
Pass-the-Hash, Pass-the-Ticket, and overpass-the-hash
SMB signing validation and NTLM relay targets
LLMNR, NBT-NS, and mDNS broadcast poisoning
Active Directory Certificate Services (AD CS) misconfigurations
Network segmentation and VLAN hopping validation
Internal service exposure and vulnerability scanning
Credential harvesting from file shares, scripts, and memory
Domain privilege escalation paths and delegation abuse
Method

How We Run It

We execute an assumed-breach methodology starting from an unprivileged domain user or network port. After initial network discovery and Active Directory mapping using non-destructive tooling, we identify lateral movement vectors, capture and analyze hashes, test credential reuse across endpoints, and pursue escalation paths toward high-privilege groups. Every attack path is meticulously documented with reproduction proofs, timestamped command logs, and risk impact analysis without disrupting production operations.

01

Host Discovery & Network Enumeration

Subnet scanning, port mapping, and identification of live hosts, routing topologies, and unsegmented network enclaves across all corporate VLANs.

02

Active Directory Architecture Mapping

Detailed enumeration of domain trusts, forest structures, Domain Controllers, GPOs, and LDAP directory objects via BloodHound and Adalanche.

03

Network Protocol Exploitation

Testing for broadcast name resolution abuse (LLMNR, NBT-NS, mDNS), IPv6 DNS takeover (mitm6), and SMB relay vectors on unsigned endpoints.

04

Credential Harvesting & Roasting

Identifying Kerberoasting targets with service principal names (SPNs), AS-REP roastable pre-auth accounts, and searching network shares for cleartext configuration secrets.

05

Privilege Escalation Analysis

Evaluating misconfigured Active Directory ACLs, Group Policy permissions, vulnerable certificate templates (AD CS / ESC1-ESC8), and local privilege escalation vectors.

06

Lateral Movement & Pivoting

Assessing pass-the-hash, pass-the-ticket, overpass-the-hash, and remote management execution (WMI, WinRM, SSH) between tier boundaries.

07

Network Segmentation & VLAN Bypass

Testing isolation between corporate workstations, production servers, PCI cardholder data environments (CDE), and guest networks.

08

Post-Exploitation & Data Impact Validation

Demonstrating achievable business impact (such as proof-of-access to sensitive databases or backups) with strict non-destructive safeguards.

Deliverables

What You Receive

Findings land in your tracker as you go, not only in a PDF at the end. Free retesting is included in scope, not billed as a change order.

  • Attack path narrative with kill chain mapping and visual timelines
  • Technical findings report with CVSS v3.1 scoring and reproduction steps
  • Network topology and Active Directory BloodHound attack path diagrams
  • Credential exposure and password policy analysis report
  • Lateral movement and privilege escalation evidence documentation
  • Network segmentation bypass and firewall validation summary
  • Prioritised remediation roadmap with practical hardening guidance
  • Free retest validation within 48 hours and formal Letter of Attestation
Typical Results

What We Usually Find

The issues this engagement surfaces most often. Your environment will differ, but this reflects typical exposure patterns.

LLMNR / NBT-NS Broadcast Poisoning SMB Signing Disabled on Critical Servers Kerberoastable Accounts with Weak Passwords Active Directory Certificate Services (AD CS) Misconfigurations Excessive Domain User ACLs & Unconstrained Delegation Insufficient Network Segmentation Between Workstations & Servers Unpatched CVEs on Internal Appliances & Hypervisors Cleartext Credentials in Network Shares & Scripts
Fit

Who This Is For

Enterprise IT Environments with On-Prem or Hybrid Active Directory
Canadian Financial Institutions Subject to OSFI Guideline B-13
Organizations Preparing for SOC 2 Type II or ISO 27001 Audits
Businesses After a Corporate Merger or Acquisition
Healthcare & Energy Organizations Subject to PIPEDA / Law 25 / PIPA
Companies Validating EDR / XDR Detection & SOC Response Capabilities
Standards this assessment supports

Findings are mapped directly to SOC 2 Type II, ISO 27001, OSFI B-13, PCI-DSS v4.0, PIPEDA, Bill C-27, NIST CSF, CIS Controls, allowing your team to drop the report into an audit package without manual translation.

Canadian Operations

Calgary & Toronto Security Specialists

Canadian enterprises face increasing scrutiny from regulators including OSFI (Guideline B-13 on technology and cyber risk management), provincial privacy authorities under Alberta PIPA and Quebec Law 25, and federal oversight under PIPEDA. Lorikeet Security Canada maintains senior offensive security specialists in Calgary and Toronto, supporting on-site testing across Alberta and Ontario as well as secure remote appliance deployments across all provinces.

Calgary OfficeAlberta Operations
Toronto OfficeOntario Operations
FAQ

Common Questions

What starting position do you assume for an internal pentest? +

The standard starting position is an assumed-breach scenario with an unprivileged domain user account connected to an internal network port or corporate workstation. This accurately models a modern attacker who has established initial access via phishing or credential stuffing. We can also begin from an unauthenticated network jack if your objective is to evaluate rogue device access controls.

Will you attempt full domain compromise? +

Yes, pursuing domain administrator privileges through realistic attack chains is a primary technical goal. We document every step taken and establish safety stop points. If your security team requests that we hold off on Domain Controller exploitation, we customize the rules of engagement during the scoping phase.

Can you test without disrupting users and production operations? +

All testing is conducted using non-destructive methods designed to prevent business disruption. We avoid brute-force attacks that could trigger account lockouts and schedule intensive vulnerability validation during agreed maintenance windows. Our testers coordinate directly with your internal security operations team.

How does an internal penetration test support Canadian compliance audits? +

Our reports provide direct cross-references to OSFI Guideline B-13, SOC 2 Trust Services Criteria (CC6.1, CC6.6), ISO 27001:2022 Control A.8.8, and PCI-DSS v4.0 Requirement 11.4. You receive an executive summary, detailed technical remediation guidance, and a formal letter of attestation countersigned by a senior consultant.

Client Stories

Trusted by Fast-Growing Companies

JBWeb

Digital Agency

“From Pentest to malware analysis these guys know what they're doing.”

We came to Lorikeet Security with not so small task of tracking down the source of a cyber incident. Lorikeet Security looked at attack vectors and they set up a full test environment and really showed they knew what they were doing. With amazing analytics reports on down to the minute of login attempts. The level of detail that Cyber Insurance Companies wish they had in house - Those reports are an invaluable tool and give confidence and value add to the executive level for pre or post ransomware attacks.

SOCaaS Incident Response
Flowtriq

SaaS Platform

“Streamlined Security Testing with White Glove Service”

We used Lorikeet Security for a PTaaS pentest and briefly tried their ASM tool - both were amazing. Fast tests, accurate findings, and everything handled through a modern interface. The report summary, live chat, asset management, and live quoting features of the portal really stand out. Their 'white glove' touch contributed to a 10/10 experience. They're truly changing the pentest game with the new portal clients can use.

Penetration Testing Continuous Assessments
Next

Scope It in One Call

Tell us what is in scope and we come back with a fixed flat-rate price and a verified start date. No discovery-call maze, no hourly estimates that move.