Infrastructure & AD pentest
Infrastructure and Active Directory penetration testing
We test the external perimeter, internal network, and domain environment for realistic paths from initial access to critical assets.
The priority is safe proof of attack chains, excessive privilege, and weak segmentation boundaries.
01 / Coverage
What we test
We confirm boundaries and critical journeys before testing so the work reflects your business risk.
External perimeter
Public services, remote access, VPN, mail infrastructure, and exposure mistakes.
Internal network
Segmentation, trust, network protocols, shared resources, and lateral movement resistance.
Active Directory
Kerberos and NTLM, delegation, ACLs, GPOs, service accounts, and privilege paths.
Operations and visibility
Passwords, local admin, patching, logging, and the ability to detect activity.
02 / Method
An assessment you can defend to engineers and auditors
We combine manual investigation, tooling, and evidence control. A specialist validates every reported finding.
- 01
Set the rules
Define starting position, address space, critical systems, restrictions, and stop procedure.
- 02
Map the surface
Assess reachable services, configuration, trust relationships, and plausible entry points.
- 03
Build attack paths
Safely combine weaknesses and determine which critical assets are actually reachable.
- 04
Plan risk reduction
Separate quick controls from structural work, then validate remediation.
03 / Outputs
Material built for decisions and remediation
The report explains risk to leaders and gives engineers reproducible steps without scanner noise.
PENTEST.RED / INFRA / 04
Attack-path map
Clear chains from entry point to critical asset with the required conditions.
Technical report
Validated findings, evidence, affected hosts, and prioritized controls.
Hardening plan
Sequenced improvements to segmentation, identity, configuration, and monitoring.
Readout and retest
A working session with IT and security teams followed by path validation.
How is an internal pentest different from a configuration audit?
A pentest shows how weaknesses combine into a working attack path. An audit compares settings to a baseline in greater breadth; the two can be combined.
Is Active Directory testing safe?
Yes, with clear rules. We exclude destructive actions, control load, and agree sensitive techniques in advance.
Do you start without an account?
Both scenarios are possible: a guest or connected-device position, or a standard user account that models a compromised employee.
Can you test only the external perimeter?
Yes. External testing can be a standalone engagement or the first phase of a combined assessment.
Next step
Get a scoped assessment plan
Tell us about the system, timing, and reason for testing. We will clarify scope and recommend an engagement with no obligation.