Network infrastructure security testing
02 — NETWORK / INFRASTRUCTURE PENTEST

Network & Infrastructure Penetration Testing

Firewalls, routers, domains, WiFi, VPNs. Each service targets specific network attack surfaces.

What Is Network Penetration Testing?

Network penetration testing is the simulation of cyberattacks against an organisation's infrastructure — servers, firewalls, network devices, and the services that connect them. The objective is to identify weaknesses that could allow an attacker to gain unauthorised access, move laterally through the environment, or reach sensitive systems and data.

We break network testing into focused sub-services: external infrastructure, internal infrastructure, Active Directory, Wi-Fi, defence in depth validation, and VPN/remote access. Each can be commissioned independently or combined into a full-scope assessment.

Services of a Network Pentest

Every component that connects, routes, or authenticates.

External Infrastructure Pentest

Perimeter devices and services exposed to the internet: firewalls, routers, VPN gateways, public-facing servers, DNS, mail servers. What an attacker sees and probes first.

Internal Infrastructure Pentest

What happens after the perimeter falls. Lateral movement, privilege escalation, domain compromise, internal services, file shares, and the path from a standard user account to domain admin.

Active Directory Pentest

The crown jewel of most enterprise networks. Kerberos weaknesses, NTLM relay, AD trust relationships, Group Policy misconfigurations, delegation issues, ADCS vulnerabilities, and paths to domain admin using BloodHound-style attack path analysis.

Wi-Fi Pentest

Wireless network assessments including rogue access point detection, WPA2/WPA3 enterprise mode flaws, evil twin attacks, guest network isolation testing, and wireless frame injection.

Defence in Depth Pentest

Tests whether layered controls actually work together. Firewall evasion, IDS/IPS bypass, EDR evasion, segmentation validation between trust zones, and verification that a compromise in one layer doesn't cascade into others.

VPN & Remote Access Pentest

VPN concentrators, remote desktop services, SSH gateways, bastion hosts, zero-trust access portals, and MFA implementations. Attackers target remote access relentlessly.

Testing Approaches

Three perspectives. Each reveals a different attack path.

Black Box

Zero knowledge. The tester receives only the target IP range or domain name — no credentials, no network diagrams, no asset inventories. This replicates the perspective of an external attacker with no inside information.

Best for: External perimeter assessments, measuring real-world attack surface exposure.

Grey Box

Partial access. Typically a standard user account on the network, allowing the tester to evaluate internal segmentation, lateral movement potential, and what a compromised employee account could reach.

Best for: Internal assessments, insider threat simulation, network segmentation validation.

White Box

Full transparency. Network architecture diagrams, configuration files, system inventories, and administrative access provided. The tester can evaluate configurations, hardening levels, and identify weaknesses invisible from the network layer.

Includes: Host Configuration Review (HCR), also known as Security Static Analysis Testing (SSAT) — the white box variant that evaluates system hardening against CIS Benchmarks and vendor baselines.

Methodology

Four phases. No shortcuts.

01

Reconnaissance

Network mapping, host discovery, service enumeration, operating system fingerprinting, and attack surface documentation. We identify every reachable service before probing for weaknesses.

02

Identification

Vulnerability discovery through manual probing, service-specific testing, protocol analysis, and configuration review. Every potential weakness is documented and prioritised for exploitation.

03

Exploitation

Controlled exploitation of confirmed vulnerabilities. We chain weaknesses together — initial access, privilege escalation, lateral movement, and persistence — to demonstrate full business impact.

04

Reporting

Comprehensive documentation of attack paths, CVSS-scored findings, business impact analysis, and prioritised remediation steps. Network diagrams showing exploitation paths included.

Our Technical Expertise

What we bring to every network engagement.

Attack Path Mapping

We don't list vulnerabilities. We map attack paths — the chain of steps from initial access to business-critical systems. You see exactly how an attacker would traverse your environment, not just where the gaps are.

Active Directory Specialisation

AD is the most targeted component in enterprise networks. Our consultants specialise in Kerberos attacks, NTLM relay, BloodHound analysis, constrained and unconstrained delegation abuse, and AD CS attack paths.

CIS Benchmark Expertise

In white box engagements, we evaluate every system against CIS Benchmarks — operating systems, cloud platforms, network devices, and application frameworks. Host hardening gaps documented with specific configuration recommendations.

Manual Testing, Always

Tools assist. Humans decide. Every finding is verified by a CREST-certified consultant who can distinguish between a real vulnerability and a false positive that a scanner would flag as critical.

Request a Network Pentest

Tell us about your infrastructure. We'll scope the engagement and send a quote within 48 hours.

Get in Touch