Internal Network Penetration Testing

One password. Whole domain.

Assume one workstation is already lost. A senior U.S. engineer follows the trust from there, by hand, to domain admin. When we reach what matters, we leave a card on the domain controller.

  1. Workstation

    One user. Standard access.

    Patched

  2. Cached Credentials

    A password left on the box.

    Patched

  3. File Share

    Readable by everyone.

    Patched

  4. Service Account

    Ticket cracked offline.

    Patched

  5. Domain Admin

    Every account. Every host.

    Domain owned

  6. Core Banking

    Logged in as a teller. Approved as a manager.

    Approved

  • Patched What a scanner sees
  • Raxis engineer

Nothing replaces skill. Illustrative path, from a real engagement. Not one hop was a CVE.

What We Test

The pentester on your scope call is the one breaking in, and the one retesting your fix. We start from the foothold a real attacker would have, unauthenticated or as one standard user, and see how far it can be taken by hand.

Active Directory Attack Paths

Kerberoasting, delegation abuse, and misconfigured permissions that turn a standard user into domain admin.

Lateral Movement & Escalation

We pivot between systems the way real attackers do, mapping how far one compromised host can reach.

Manual Exploitation

We exploit by hand and chain weaknesses into real impact, not a list of theoretical risk.

Credential Attacks

LLMNR poisoning, hash capture, and offline cracking test your password policy where it matters most.

Network Segmentation

We verify that sensitive segments, including PCI cardholder data environments, are truly isolated.

Host & Service Hardening

Outdated software, default configurations, and exposed internal services that give an attacker an easy next step.

Findings We See in the Wild

None of these is a CVE, and a scanner passes every one. Each is a path to domain admin we walk on real internal networks again and again.

Broadcast Protocol Poisoning

LLMNR and NBT-NS hand us password hashes just for being on the network.

Kerberoast-able Service Accounts

Weak service passwords any domain user can request and crack offline.

Weak Domain Passwords

Policies that look fine on paper and fall to our cracking rigs in minutes.

Excessive Local Admin Rights

Users and service accounts with far more administrator access than their role needs.

Forgotten Systems

Hosts running outdated software with a public exploit already written.

Failed Segmentation

Flat networks where any workstation can reach the domain controllers, databases, and cardholder data.

Two Ways to Test Your Network

Same senior engineers, same manual tradecraft, same live findings in Raxis One. The difference is when you want us on it: once, for a fixed window, or all year, every time it changes.

What You Get

Everything you need to understand, fix, and prove your posture, written by the engineer who did the work. Track status, findings, and delivery in real time with Raxis One.

Executive Summary

A concise readout for leadership and auditors.

Technical Findings

Each with a severity rating, reproduction steps, and clear remediation.

Attack Storyboard

Exactly how we got in, how far we went, and where we left the card.

Included Retest

We verify your fixes and deliver a clean final report, at no extra cost.

Raxis Transporter remote penetration testing devices

No Travel Required: The Raxis Transporter

We ship you a Transporter, a small device that plugs into your network and connects securely back to our engineers. Setup takes minutes, there is nothing to configure, and no one has to fly anywhere. One per site puts us on every office at once.

The Bank Heist

Our stories are based on real events encountered by Raxis engineers. Some details have been altered or omitted to protect customer identities.

Banks tend to have mature perimeters, and their teams are often confident the inside is just as strong. Internal penetration tests exist to check that assumption.

During an internal engagement at a bank, our team recovered previously used credentials from an employee workstation. Testing those credentials carefully across systems led to domain access, and cracked password hashes produced logins that worked on employee workstations and the core banking system itself.

As a controlled proof of concept, we logged in as a teller to initiate a funds transfer, then approved it as a manager. We demonstrated it live for the bank, which used the Raxis report to drive immediate improvements to credential hygiene and access controls.

FAQ: Internal Penetration Testing

What is internal network penetration testing?

It is a test that starts from inside your network, the position an attacker reaches after phishing an employee, stealing a laptop, or plugging into a jack. From there our engineers do what a real intruder would: capture credentials, move between systems, escalate privileges, and see how close they can get to your most sensitive data.

How is an internal pentest different from an external one?

An external test attacks your internet-facing perimeter from the outside. An internal test assumes the perimeter has already been crossed and measures what an attacker can do once inside. Most organizations need both: the external test to check the front door, the internal test to check what happens when someone gets past it.

How is this different from a vulnerability scan?

A scan lists potential issues based on version numbers and known signatures. A Raxis internal pentest exploits them by hand, removes false positives, chains weaknesses together, and shows the real business impact of a breach. A scanner tells you a service is out of date; we show you the domain admin access it leads to.

How often should we run an internal penetration test?

At least once a year, and again after any significant change to your network, such as a merger, a new site, or a major infrastructure project. PCI DSS and most other frameworks expect an annual test. Continuous testing through Raxis Attack keeps you covered between point-in-time engagements.

How long does an internal penetration test take?

Most internal tests run one to two weeks, including reporting. The main drivers are the number of live hosts, the number of physical locations, and whether segmentation testing is included. We give you a firm timeline before the engagement starts.

What do we need to provide?

Your internal IP ranges, a point of contact, and a place to plug in our Transporter device. That is usually all it takes. There is no onsite visit and nothing to install on your workstations.

Do you need domain credentials to run the test?

No. By default we start unauthenticated, with no account, to mirror an attacker who just gained a foothold. Many customers also ask for an assumed-breach test, where we start with a standard user account to see how far a phished employee's access would reach. We can run either or both.

Will testing take our systems down?

It is very unlikely. We avoid disruptive exploits by default, flag fragile or legacy systems during kickoff, and can schedule sensitive testing inside a maintenance window if you prefer. Our goal is to prove risk, not to break production.

Can we include PCI segmentation testing?

Yes. Segmentation validation fits naturally into an internal penetration test, confirming that your cardholder data environment is isolated from out-of-scope networks. PCI DSS requires this for segmented environments, and combining it with your internal test saves time and budget.

Should we notify our SOC or MSSP before testing?

That is your call. Some customers stay quiet to test whether their SOC or MSSP detects and responds to our activity, which is a useful measure on its own. Others notify in advance to avoid alert fatigue. We plan the approach with you during kickoff.

We have multiple offices. Do you test each one?

We can. A Transporter at each site lets us test every location remotely, or we can focus on representative sites if your offices share a common build. We scope this with you based on how your network is segmented between locations.

What do we get at the end?

A full report with an executive summary for leadership and auditors, detailed technical findings with severity ratings and reproduction steps, and an attack storyboard showing exactly how we moved through your network. You also get an attestation letter and a free retest to confirm your fixes. Everything is available in real time through Raxis One.

What drives the cost?

Scope is the main factor: the number of live internal hosts, the number of locations, and whether you add segmentation testing. Contact us for a quote sized to your environment.

Who performs the testing?

Senior US-based Raxis engineers holding certifications such as OSCP and OSCE. No outsourcing, and no junior testers learning on your network.

Request a quote

Tell Us What You Need Tested

We usually respond in one business day.

Please let us know what's on your mind. Include any details about your target environment, timeline, or compliance drivers.