Network penetration testing
From the addresses you publish to the domain you trust. External testing shows what the internet can reach. Internal testing shows how far an attacker gets once they are in.
What this engagement is
Network testing is still how you find the forgotten VPN concentrator, the file server with SMBv1, the service account that is Domain Admin, and the segmentation that exists in a Visio and not in the VLAN.
We run external tests against agreed IP ranges and hostnames, and internal tests from a assumed-breach position on the LAN or via a drop box you place. Active Directory environments get the attention they deserve: Kerberos, unconstrained delegation, ACL paths, the usual greatest hits, proven, not scanned-and-prayed.
Denial of service is off the table unless you schedule it. Production change windows are written down. Critical findings get a phone call the same day.
What we actually look for
External perimeter
Exposed services, weak crypto, default creds, VPN and mail edge, the marketing CMS nobody patched.
Internal network
Segmentation, living-off-the-land, credential reuse, printer-to-DC paths.
Active Directory
Kerberoasting, AS-REP, delegation, ACL abuse, LAPS gaps, tiering that is not.
Remote access
Citrix, VPN, RDP gateways, MFA bypasses that are really MFA adjacent.
Wireless (optional)
Agreed SSIDs, evil twin only if written into scope, no surprise guests on the corp SSID.
Questions buyers ask before they sign
External, internal, or both?
If you have never tested, start external plus a short internal assumed-breach. If you are APRA-regulated or running AD, internal is not optional.
Do you need a domain account?
For internal AD work, an unprivileged domain user is the honest starting point. We can also start from the network with no account if that matches your threat model.
Will you crash production?
We exclude DoS. We avoid known-dangerous exploits against fragile OT or medical devices, which should be scoped out or tested in a window. Tell us what is brittle before we start.
Often scoped alongside
Web application penetration testing
Your web app is the front door to customer data, payments and admin. We test it logged in, role-aware, reading the JavaScript and probing th…
Learn more > [api]API penetration testing
Your SPA is a skin. The API is the product. We test REST, GraphQL and internal service APIs for the authorisation bugs that turn one user's …
Learn more > [mob]Mobile app penetration testing
The store listing is not the threat model. We assess the iOS and Android clients and the APIs they call, on-device and on the wire, mapped t…
Learn more >Scope this test
Send the target, the roles and the deadline. You will get a fixed quote in AUD, usually within two business days.