Core service
Internal Infrastructure Penetration Testing
Controlled testing of internal networks, systems and trust relationships to identify realistic paths to compromise.
An internal infrastructure test assesses what could happen after an attacker or compromised device gains a foothold inside the network. The objective is to move beyond isolated missing patches and establish whether segmentation, identity controls, hardening and monitoring prevent meaningful access to sensitive systems.
Founder-led technical delivery
Why Safestorm for this assessment
Felix’s background spans red teaming, enterprise infrastructure and Active Directory. That experience shapes an assume-breach assessment focused on practical movement through the environment: credential access, privilege escalation, tunnelling and pivoting, segmentation and the controls expected to interrupt or expose an attack path.
- More than six years’ offensive-security experience
- OSCP and OSEP certified
- Red teaming, adversary simulation and control validation
- Published IPv6 research presented at BSides London
Felix’s prior experience includes identifying high-impact weaknesses in healthcare environments. Client identities and engagement details remain confidential.
What the assessment covers
Final coverage is agreed during scoping and reflects your technologies, user roles, threat model and operational constraints.
- Network discovery, service enumeration and attack-surface mapping
- Segmentation and filtering between user, server, management and sensitive network zones
- Windows and Linux host configuration, exposed services and patch posture
- SMB, LDAP, Kerberos, NTLM, RDP, SSH and other enterprise protocols
- Credential exposure, password reuse and insecure secrets storage
- Local and domain privilege escalation, lateral movement and trust abuse
- Pivoting and network-path validation where a compromised host could bridge trust zones
- Management interfaces, virtualisation platforms, backup systems and network appliances
- Opportunities to bypass or test the visibility of preventative and detective controls
Common risks identified
Testing is not limited to this list. These examples illustrate the types of material risk the assessment is designed to uncover.
- A standard user or compromised endpoint gaining administrative access
- Weak segmentation allowing movement into sensitive or management networks
- Credentials recovered from shares, configuration files, memory or services
- Legacy protocols and unsafe defaults enabling relay, downgrade or credential attacks
- Critical infrastructure reachable through chained lower-severity weaknesses
A controlled process
How the engagement works
- Step 1
Define network ranges, starting position and critical assets
- Step 2
Agree rules of engagement and operational safety boundaries
- Step 3
Discover hosts, services, identities and accessible network paths
- Step 4
Assess configuration, vulnerabilities and credential exposure
- Step 5
Validate privilege escalation and lateral movement proportionately
- Step 6
Report attack paths, debrief stakeholders and retest remediation
Who this service is suitable for
- Enterprise and hybrid corporate networks
- Environments preparing for accreditation, audit or customer assurance
- Networks following major architecture, office or data-centre changes
- Organisations wanting to validate segmentation and assume-breach resilience
Not sure whether this is the right assessment? Safestorm can help define the assurance question before recommending a scope.
Methodology and industry references
Testing is risk-led and tailored rather than reduced to a checklist. Relevant, recognised guidance helps structure coverage and communicate results.
Referencing a framework does not represent certification against it or guarantee compliance with every control.
Frequently asked questions
What starting access does the tester receive?
This depends on the objective. Testing may begin from an unauthenticated network connection, a representative standard-user account, or both. The assumed foothold is documented clearly in the report.
Will you exploit vulnerabilities on production systems?
Only where controlled validation is authorised and proportionate. Potentially disruptive techniques are excluded or separately approved, and a safer evidence route is used where exploitation would introduce unnecessary risk.
Does this include Active Directory?
Relevant domain attack paths may be examined, but a dedicated Active Directory assessment provides deeper coverage of directory architecture, delegation, certificate services and privilege relationships.
Define the right scope
Tell us what you need to assess, your timescale and the assurance outcome you need. We will propose a proportionate scope and clear rules of engagement.
Discuss your requirements