Infrastructure & AD pentest

Infrastructure and Active Directory penetration testing

We test the external perimeter, internal network, and domain environment for realistic paths from initial access to critical assets.

The priority is safe proof of attack chains, excessive privilege, and weak segmentation boundaries.

↓See our method
Testing is limited to the agreed scope and requires written authorization
01External + internal
02Active Directory
03Privilege attack paths

01 / Coverage

What we test

We confirm boundaries and critical journeys before testing so the work reflects your business risk.

01

External perimeter

Public services, remote access, VPN, mail infrastructure, and exposure mistakes.

02

Internal network

Segmentation, trust, network protocols, shared resources, and lateral movement resistance.

03

Active Directory

Kerberos and NTLM, delegation, ACLs, GPOs, service accounts, and privilege paths.

04

Operations and visibility

Passwords, local admin, patching, logging, and the ability to detect activity.

02 / Method

An assessment you can defend to engineers and auditors

We combine manual investigation, tooling, and evidence control. A specialist validates every reported finding.

  1. 01

    Set the rules

    Define starting position, address space, critical systems, restrictions, and stop procedure.

  2. 02

    Map the surface

    Assess reachable services, configuration, trust relationships, and plausible entry points.

  3. 03

    Build attack paths

    Safely combine weaknesses and determine which critical assets are actually reachable.

  4. 04

    Plan risk reduction

    Separate quick controls from structural work, then validate remediation.

03 / Outputs

Material built for decisions and remediation

The report explains risk to leaders and gives engineers reproducible steps without scanner noise.

Included in the engagement04

PENTEST.RED / INFRA / 04

01

Attack-path map

Clear chains from entry point to critical asset with the required conditions.

02

Technical report

Validated findings, evidence, affected hosts, and prioritized controls.

03

Hardening plan

Sequenced improvements to segmentation, identity, configuration, and monitoring.

04

Readout and retest

A working session with IT and security teams followed by path validation.

04 / FAQ

Common questions

sales@pentest.red
How is an internal pentest different from a configuration audit?

A pentest shows how weaknesses combine into a working attack path. An audit compares settings to a baseline in greater breadth; the two can be combined.

Is Active Directory testing safe?

Yes, with clear rules. We exclude destructive actions, control load, and agree sensitive techniques in advance.

Do you start without an account?

Both scenarios are possible: a guest or connected-device position, or a standard user account that models a compromised employee.

Can you test only the external perimeter?

Yes. External testing can be a standalone engagement or the first phase of a combined assessment.

Next step

Get a scoped assessment plan

Tell us about the system, timing, and reason for testing. We will clarify scope and recommend an engagement with no obligation.

PENTEST.RED

Start with your attack surface.

Leave your details. We’ll discuss your goals and show you the platform.

We use these details to contact you about this request.