Internal Network Penetration Testing
Simulate an assumed-breach adversary inside your network - attacking Active Directory, escalating privileges, and moving laterally to your crown-jewel assets.
What This Engagement Covers
The Service
The most damaging enterprise breaches do not stop at the firewall. Once an adversary secures initial access through a spear-phishing payload, compromised VPN credential, or rogue workstation, their primary objective is your Active Directory forest. Our internal network penetration test simulates a determined threat actor operating from within your corporate perimeter. We map your internal subnets, identify Kerberoasting and AS-REP roasting targets, exploit SMB signing and LLMNR/NBT-NS broadcast flaws, abuse unconstrained delegation, and chain misconfigured ACLs to reach domain compromise and demonstrate real-world impact.
What We Test
We assess your complete internal network and directory infrastructure: Active Directory domains and trusts, domain controllers, Kerberos authentication policies, Group Policy Objects (GPOs), network segmentation and VLAN isolation, internal firewalls, routers, switches, VPN gateways, internal DNS, database clusters, virtualization hosts, and exposed management protocols (RDP, SSH, WMI, WinRM). We evaluate credential hygiene, token impersonation, delegation rights (unconstrained, constrained, RBCD), and path-to-compromise chains across physical, virtual, and hybrid environments.
Components Evaluated in Scope
Our testers systematically inspect the following architectural layers and attack vectors during the assessment.
How We Run It
We execute an assumed-breach methodology starting from an unprivileged domain user or network port. After initial network discovery and Active Directory mapping using non-destructive tooling, we identify lateral movement vectors, capture and analyze hashes, test credential reuse across endpoints, and pursue escalation paths toward high-privilege groups. Every attack path is meticulously documented with reproduction proofs, timestamped command logs, and risk impact analysis without disrupting production operations.
Host Discovery & Network Enumeration
Subnet scanning, port mapping, and identification of live hosts, routing topologies, and unsegmented network enclaves across all corporate VLANs.
Active Directory Architecture Mapping
Detailed enumeration of domain trusts, forest structures, Domain Controllers, GPOs, and LDAP directory objects via BloodHound and Adalanche.
Network Protocol Exploitation
Testing for broadcast name resolution abuse (LLMNR, NBT-NS, mDNS), IPv6 DNS takeover (mitm6), and SMB relay vectors on unsigned endpoints.
Credential Harvesting & Roasting
Identifying Kerberoasting targets with service principal names (SPNs), AS-REP roastable pre-auth accounts, and searching network shares for cleartext configuration secrets.
Privilege Escalation Analysis
Evaluating misconfigured Active Directory ACLs, Group Policy permissions, vulnerable certificate templates (AD CS / ESC1-ESC8), and local privilege escalation vectors.
Lateral Movement & Pivoting
Assessing pass-the-hash, pass-the-ticket, overpass-the-hash, and remote management execution (WMI, WinRM, SSH) between tier boundaries.
Network Segmentation & VLAN Bypass
Testing isolation between corporate workstations, production servers, PCI cardholder data environments (CDE), and guest networks.
Post-Exploitation & Data Impact Validation
Demonstrating achievable business impact (such as proof-of-access to sensitive databases or backups) with strict non-destructive safeguards.
What You Receive
Findings land in your tracker as you go, not only in a PDF at the end. Free retesting is included in scope, not billed as a change order.
- Attack path narrative with kill chain mapping and visual timelines
- Technical findings report with CVSS v3.1 scoring and reproduction steps
- Network topology and Active Directory BloodHound attack path diagrams
- Credential exposure and password policy analysis report
- Lateral movement and privilege escalation evidence documentation
- Network segmentation bypass and firewall validation summary
- Prioritised remediation roadmap with practical hardening guidance
- Free retest validation within 48 hours and formal Letter of Attestation
What We Usually Find
The issues this engagement surfaces most often. Your environment will differ, but this reflects typical exposure patterns.
Who This Is For
Findings are mapped directly to SOC 2 Type II, ISO 27001, OSFI B-13, PCI-DSS v4.0, PIPEDA, Bill C-27, NIST CSF, CIS Controls, allowing your team to drop the report into an audit package without manual translation.
Calgary & Toronto Security Specialists
Canadian enterprises face increasing scrutiny from regulators including OSFI (Guideline B-13 on technology and cyber risk management), provincial privacy authorities under Alberta PIPA and Quebec Law 25, and federal oversight under PIPEDA. Lorikeet Security Canada maintains senior offensive security specialists in Calgary and Toronto, supporting on-site testing across Alberta and Ontario as well as secure remote appliance deployments across all provinces.
Common Questions
The standard starting position is an assumed-breach scenario with an unprivileged domain user account connected to an internal network port or corporate workstation. This accurately models a modern attacker who has established initial access via phishing or credential stuffing. We can also begin from an unauthenticated network jack if your objective is to evaluate rogue device access controls.
Yes, pursuing domain administrator privileges through realistic attack chains is a primary technical goal. We document every step taken and establish safety stop points. If your security team requests that we hold off on Domain Controller exploitation, we customize the rules of engagement during the scoping phase.
All testing is conducted using non-destructive methods designed to prevent business disruption. We avoid brute-force attacks that could trigger account lockouts and schedule intensive vulnerability validation during agreed maintenance windows. Our testers coordinate directly with your internal security operations team.
Our reports provide direct cross-references to OSFI Guideline B-13, SOC 2 Trust Services Criteria (CC6.1, CC6.6), ISO 27001:2022 Control A.8.8, and PCI-DSS v4.0 Requirement 11.4. You receive an executive summary, detailed technical remediation guidance, and a formal letter of attestation countersigned by a senior consultant.
Trusted by Fast-Growing Companies
We came to Lorikeet Security with not so small task of tracking down the source of a cyber incident. Lorikeet Security looked at attack vectors and they set up a full test environment and really showed they knew what they were doing. With amazing analytics reports on down to the minute of login attempts. The level of detail that Cyber Insurance Companies wish they had in house - Those reports are an invaluable tool and give confidence and value add to the executive level for pre or post ransomware attacks.
We used Lorikeet Security for a PTaaS pentest and briefly tried their ASM tool - both were amazing. Fast tests, accurate findings, and everything handled through a modern interface. The report summary, live chat, asset management, and live quoting features of the portal really stand out. Their 'white glove' touch contributed to a 10/10 experience. They're truly changing the pentest game with the new portal clients can use.
Scope It in One Call
Tell us what is in scope and we come back with a fixed flat-rate price and a verified start date. No discovery-call maze, no hourly estimates that move.