Testing · Infrastructure
Network & Infrastructure Testing.
External and internal intrusion testing that proves how far an attacker actually gets — not how many ports are open.
At a glance
- Surface
- Infrastructure
- Execution
- Manual, senior-led
- Retest
- Included, no charge
- Proposal
- Within one business day
Scope
From first foothold to domain compromise.
We start where a real intruder starts and keep going until we hit the objective or run out of runway — then show you every step.
External network testing
Internet-facing estate enumerated, attacked and exploited — VPNs, mail, remote access and forgotten assets.
1–2 weeks
Internal breach simulation
Assume-breach testing from a standard workstation to show the blast radius of one compromised employee.
1–2 weeks
Active Directory attack paths
Kerberoasting, delegation abuse, ACL chains, ADCS and credential relay to domain administrator.
1–2 weeks
Wireless & network segmentation
Rogue access points, WPA-Enterprise abuse and validation that your segmentation actually holds.
3–7 days
Build & configuration review
Gold images, servers, firewalls and hypervisors reviewed against hardened baselines.
1 week
Remediation retest
Every remediated finding re-tested and attested at no additional cost.
Within 90 days
Method
A disciplined intrusion.
Nothing starts before the authorisation letter is signed and the blast radius is agreed.
- 01
Scoping
IP ranges, exclusions, escalation contacts and a signed authorisation letter.
- 02
Enumeration
Asset discovery, service fingerprinting and credential exposure review.
- 03
Exploitation
Foothold, privilege escalation, credential harvesting and lateral movement.
- 04
Objective
Domain, data or crown-jewel objectives pursued and evidenced safely.
- 05
Reporting & retest
Attack-path narrative, prioritised fixes, then verification of remediation.
Deliverables
What lands on your desk.
- Attack-path narrative with diagrams from entry to objective
- Full asset and exposure inventory discovered during testing
- Technical findings with reproduction steps and evidence
- Active Directory hardening recommendations
- Segmentation validation results
- Prioritised remediation roadmap with effort estimates
- Free retest report and attestation letter
Indicative timeline
Kickoff to closure.
- Week 0
- Scoping, rules of engagement, escalation path agreed
- Days 1–3
- Discovery, enumeration and exposure review
- Days 3–10
- Exploitation, escalation and lateral movement
- Days 11–14
- Reporting, walkthrough and executive readout
- Within 90 days
- Free retest and closure letter
Enquire
Start a Network & Infrastructure Testing conversation.
Tell us what you need tested. A senior consultant replies within one business day with scoping questions and indicative timelines — no sales funnel.
PRACTICE 02 OF 07
Start here
See your network the way an intruder does.
Tell us what's exposed and what matters. We'll return a fixed-price proposal and a named lead within one business day.
