Home / Penetration Testing / Infrastructure

Network & Infrastructure
Penetration Testing

External and internal network penetration testing — servers, firewalls, VPN gateways, and Active Directory. We map your real attack paths, from initial foothold through lateral movement to domain compromise.

Overview

From foothold to domain admin.

Your network is where an attacker turns one weakness into total compromise. Infrastructure penetration testing assesses your external perimeter and internal estate to find the paths an intruder would actually take.

We test external-facing services, internal networks, and Active Directory — chaining misconfigurations, weak credentials, and privilege-escalation paths the way a real adversary would, then showing you how to break the chain. CVSS-scored, with a free retest within 60 days.


Coverage

What we test.

External perimeter and internal estate, including Active Directory attack chains.

Methodologies: PTES OSSTMM NIST SP 800-115 MITRE ATT&CK CVSS v3.1

FAQ

Network penetration testing FAQ

The questions we're asked most about scope, cost, and timing.

How much does a network penetration test cost?
Typically €2,500–6,000 depending on whether it is external or internal, the number of live hosts, and Active Directory scope. Use our estimator for a tailored figure.
What is the difference between external and internal penetration testing?
External testing assesses your internet-facing perimeter as a remote attacker. Internal testing simulates an attacker with a foothold — an insider or compromised device — focusing on lateral movement and privilege escalation.
How long does a network penetration test take?
Most take 4 to 10 working days of active testing plus reporting, depending on hosts and the size of the Active Directory environment.
Do you test Active Directory?
Yes — Kerberoasting, delegation abuse, ACL weaknesses, and lateral movement to domain compromise are a core part of internal testing.
What do we receive after the test?
A CVSS-scored report with reproduction steps and prioritised remediation, an executive summary, an attestation letter, and a free retest within 60 days.
What do you need to scope a network test?
IP ranges or hostnames in scope, whether it is external or internal, approximate host counts, and any Active Directory details for internal tests.
How do you run an internal test remotely?
We ship a hardened testing device or deploy a secure virtual jump host on your network, so internal testing does not require us on-site.
Will testing disrupt our network?
We tune intensity to your environment and schedule any potentially disruptive checks; denial-of-service testing is excluded unless explicitly requested.
Do you test wireless networks?
Wireless can be added to an internal or on-site engagement; tell us during scoping and we will include it.
How does this support compliance?
Network testing helps satisfy ISO 27001, SOC 2, and PCI DSS expectations for regular technical testing.

Related services

Explore more.

Ready to test your network?

A 30-minute scoping call costs nothing. A breach costs considerably more.

Book a meeting Send an email