Skip to content
Penetration testing
  • External network penetration testing
  • Internal network penetration testing
  • Web application penetration testing
  • API penetration testing
  • Mobile application penetration testing
  • Wireless penetration testing
  • Cloud security assessment
  • Social engineering and phishing simulation
Security assurance
  • Essential Eight assessment
  • Configuration review and benchmarking
  • Remediation support and retesting
Managed security
  • Vulnerability management
  • Continuous application scanning
  • SIEM monitoring
  • EDR monitoring
All services on one page
Industries How we work About Blog
1300 AURIAN Contact
Menu
Penetration testing
  • Penetration testing services
  • External network penetration testing
  • Internal network penetration testing
  • Web application penetration testing
  • API penetration testing
  • Mobile application penetration testing
  • Wireless penetration testing
  • Cloud security assessment
  • Social engineering and phishing simulation
Security assurance
  • Security assurance and compliance services
  • Essential Eight assessment
  • Configuration review and benchmarking
  • Remediation support and retesting
Managed security
  • Managed security services
  • Vulnerability management
  • Continuous application scanning
  • SIEM monitoring
  • EDR monitoring
  • All services
  • Industries
  • How we work
  • About
  • Blog
Call 1300 AURIAN Contact
  1. Services
  2. Penetration testing
  3. Internal network penetration testing

Penetration testing

Internal network penetration testing

We start where an attacker with a foothold would, on a workstation with no credentials, and work towards the assets that matter.

Scope a test Call 1300 AURIAN

Who this is for

  • You assume the perimeter will eventually be breached

    Phishing, a stolen laptop or a supplier's access can put an attacker inside. You want to know how far they would get from there.

  • Your environment is Windows and Active Directory heavy

    Estates that run Active Directory on-premises alongside Microsoft 365 are where the paths to domain admin usually live, and they are the estates we test most.

  • An audit or insurer has asked about internal controls

    You need evidence that segmentation, privileged access and credential hygiene hold up against someone already inside the network.

What our internal network penetration test covers

Internet Web application API Perimeter Cloud tenancy Email Office network Workstation Identity Wireless Crown jewels Servers INTERNET: NOT IN SCOPE HERE Covered by external network penetration testing. Click to open that service. WEB APPLICATION: NOT IN SCOPE HERE Covered by web application penetration testing. Click to open that service. API: NOT IN SCOPE HERE Covered by API penetration testing. Click to open that service. PERIMETER: NOT IN SCOPE HERE Covered by external network penetration testing. Click to open that service. CLOUD TENANCY: NOT IN SCOPE HERE Covered by cloud security assessment. Click to open that service. EMAIL: NOT IN SCOPE HERE Covered by external network penetration testing. Click to open that service. OFFICE NETWORK: CHECKS INCLUDE Segmentation between user, server and management networks LLMNR, NBT-NS and mDNS poisoning SMB signing and relay exposure Rogue device and unmanaged host discovery WORKSTATION: CHECKS INCLUDE Local administrator password reuse across hosts Endpoint control bypass from a standard user Credential material left on hosts and in scripts Lateral movement between workstations IDENTITY: CHECKS INCLUDE Active Directory attack paths to domain administrator AD CS template and enrolment misconfiguration Kerberos abuse: Kerberoasting and AS-REP roasting Group, delegation and trust misuse WIRELESS: NOT IN SCOPE HERE Covered by wireless penetration testing. Click to open that service. CROWN JEWELS: CHECKS INCLUDE The path from a workstation to customer data, end to end What a domain administrator can reach, and how quickly SERVERS: CHECKS INCLUDE Shares readable by every user Credential reuse against servers and databases Domain controller and backup reachability Unpatched and legacy services on the server segment Internet Web application Perimeter API Email Cloud tenancy Office network Workstation Wireless Identity Crown jewels Servers INTERNET: NOT IN SCOPE HERE Covered by external network penetration testing. Click to open that service. WEB APPLICATION: NOT IN SCOPE HERE Covered by web application penetration testing. Click to open that service. PERIMETER: NOT IN SCOPE HERE Covered by external network penetration testing. Click to open that service. API: NOT IN SCOPE HERE Covered by API penetration testing. Click to open that service. EMAIL: NOT IN SCOPE HERE Covered by external network penetration testing. Click to open that service. CLOUD TENANCY: NOT IN SCOPE HERE Covered by cloud security assessment. Click to open that service. OFFICE NETWORK: CHECKS INCLUDE Segmentation between user, server and management networks LLMNR, NBT-NS and mDNS poisoning SMB signing and relay exposure Rogue device and unmanaged host discovery WORKSTATION: CHECKS INCLUDE Local administrator password reuse across hosts Endpoint control bypass from a standard user Credential material left on hosts and in scripts Lateral movement between workstations WIRELESS: NOT IN SCOPE HERE Covered by wireless penetration testing. Click to open that service. IDENTITY: CHECKS INCLUDE Active Directory attack paths to domain administrator AD CS template and enrolment misconfiguration Kerberos abuse: Kerberoasting and AS-REP roasting Group, delegation and trust misuse CROWN JEWELS: CHECKS INCLUDE The path from a workstation to customer data, end to end What a domain administrator can reach, and how quickly SERVERS: CHECKS INCLUDE Shares readable by every user Credential reuse against servers and databases Domain controller and backup reachability Unpatched and legacy services on the server segment

We test the internal network as an assumed-breach exercise, first with no credentials and then with those of a standard user, following the paths a real intruder would take.

  • Active Directory enumeration and attack paths to domain administrator
  • Active Directory Certificate Services misconfigurations, including the ESC escalation paths
  • Kerberos abuse, covering Kerberoasting and AS-REP roasting of weak service accounts
  • Legacy protocol abuse such as LLMNR, NBT-NS and mDNS poisoning
  • Password policy, spraying against internal services, and credential reuse
  • Local administrator sprawl and the reuse of local accounts across machines
  • Network segmentation between user, server, guest and management networks
  • Endpoint controls, including application control and privilege management, tested from a user's seat
  • The path from a foothold to the crown jewels: file shares, databases and line-of-business systems

How we test it

An internal network penetration test is an assumed-breach exercise. Rather than debate whether an attacker can get in, we assume they already have a foothold, a workstation on the office LAN, and measure how far that foothold reaches. Every test is run by a senior Aurian consultant against the Penetration Testing Execution Standard, NIST SP 800-115 and the MITRE ATT&CK framework, so the techniques and the report map to a language your team and your auditors already use.

We begin with no credentials, because that is where an intruder begins after plugging in a rogue device or landing malware on a machine. Within the first hour a consultant is usually capturing credentials from legacy name-resolution protocols and enumerating Active Directory. We then move to an authenticated phase with a standard user account, which mirrors the position an attacker reaches the moment one person is phished, and which surfaces the certificate services, Kerberos and privilege weaknesses that lead upward.

The goal is a demonstrated path, not a list of theoretical issues. We chain each weakness to the next, by hand, until we reach domain administrator and a crown-jewel asset you nominate at scoping, such as the finance file share or the student information system. The report draws that path out step by step, shows the evidence at each one, and explains what single change would have broken the chain, so remediation starts with the fixes that matter most.

Standards PTES, NIST SP 800-115, MITRE ATT&CK

  1. 01 Foothold

    We reach your LAN through a small testing device we ship to you, or a VPN you provide, with no credentials, exactly as an intruder starts.

  2. 02 Enumeration

    We map Active Directory, the trust relationships between systems, and the accounts and services that offer a way up.

  3. 03 Escalation

    We chain the weaknesses we find, from a poisoned response to a captured hash to a privileged account, testing each step by hand.

  4. 04 Objective and reporting

    We show how far the chain reaches, usually to domain admin and a nominated crown-jewel asset, then report every step and how to break it.

What you receive

Every finding in an Aurian report looks like this: what we found, the evidence, what it means for you, and what to change.

Extreme AUR-2026-014 Sample finding, fictional environment

AD CS misconfiguration allows privilege escalation to domain admin

Affected asset
Certificate template CorpComputer on CA01.corp.example.local
Rating
Extreme Likely 4 × Critical 6 = 24

Description

A published certificate template allows a standard domain user to request a certificate that authenticates as any account, including a domain administrator. This is the ESC1 misconfiguration: the template permits requesters to supply the subject name and enables client authentication.

Evidence

PS> Certify.exe find /vulnerable
[!] Vulnerable Certificate Template : CorpComputer
    Enrollment Rights   : CORP\Domain Users
    msPKI-Certificate-Name-Flag : ENROLLEE_SUPPLIES_SUBJECT
    pkiExtendedKeyUsage : Client Authentication
PS> Certify.exe request /template:CorpComputer /altname:CORP\Administrator
[*] Certificate issued for CORP\Administrator

A standard user account was able to request a certificate that authenticates as the domain Administrator.

Impact

Any user who can log in, including one an attacker has just phished, can become a domain administrator in minutes. From there the attacker controls every account, server and file share in the domain. There is no exploit code or missing patch here, only a misconfigured template, which is why it is so often missed.

Remediation

Remove the ENROLLEE_SUPPLIES_SUBJECT flag from the template, or restrict enrolment to a small, trusted group and require manager approval. Audit every template for the same pattern, and enable the certificate authority logging that records these requests so future abuse is visible.

References

  • MITRE ATT&CK, T1649 steal or forge authentication certificates
  • ASD, securing Active Directory
  • Executive summary written for the board and the insurer, in plain language
  • Technical findings ranked by severity, each with evidence and a fix
  • The attack path drawn out, from foothold to domain admin, step by step
  • Remediation guidance your own engineers can apply without calling us

Common findings

What this kind of engagement typically surfaces, so you can recognise your own environment.

  • Legacy protocol abuse

    LLMNR and NBT-NS left enabled, letting a consultant capture and relay credentials within minutes of connecting.

  • Active Directory Certificate Services misconfigurations

    Templates that let ordinary users mint certificates for privileged accounts, a fast and quiet path to domain admin.

  • Kerberoastable service accounts

    Service accounts with weak passwords and high privilege whose credentials can be requested by any user and cracked offline.

  • Local administrator reuse

    The same local administrator password across many machines, so one compromised host opens the rest.

  • Flat networks

    User, server and management systems sharing one segment, so a foothold on a workstation reaches the domain controllers directly.

  • Over-privileged users and stale accounts

    Everyday accounts in privileged groups, and long-forgotten accounts that still work, both widening the attack surface.

Frequently asked questions

How do you reach our network?

We ship a small testing device that you plug into a network port and that connects back to us, or we test through a VPN you provide. The device suits a single site with a spare port; a VPN suits distributed estates. We agree the approach at scoping.

Do you need credentials?

We start with none, to show what an intruder reaches from a bare foothold. We then run an authenticated phase with a standard user account, because that reflects the position an attacker reaches after phishing one person, and it finds far more.

Is it safe to run against production?

Yes, with care. We avoid techniques that risk availability, we agree fragile systems in advance, and we keep a contact open throughout. Password spraying is rate-limited to avoid lockouts. Anything higher risk is only run with your explicit agreement.

How long does it take?

It depends on the size of the environment and the number of sites: typically six to twelve days of testing, with the report following. We confirm the timeframe after scoping.

What do you need from us to prepare?

A network port for the testing device or a VPN account, a standard user account for the authenticated phase, and a technical contact for the kick-off. We send a short checklist so nothing holds up the start.

Related services

External network penetration testing

External penetration testing of your internet-facing perimeter: exposed services, VPN, mail and DNS, tested by hand by a senior consultant.

Essential Eight assessment

Essential Eight assessment against the ASD maturity model: every strategy tested with evidence, rated ML0 to ML3, with a prioritised uplift roadmap.

Social engineering and phishing simulation

Phishing simulation and social engineering assessment: measured, consented email and voice campaigns that show your awareness baseline and process gaps.

Penetration testing services

Scope a test with a senior consultant

Tell us what you need to know about your environment. We reply within one business day.

Scope a test Call 1300 AURIAN

Aurian Security is an Australian penetration testing and security assurance firm. Senior consultants perform every engagement, for clients across the country.

Penetration testing

  • External network penetration testing
  • Internal network penetration testing
  • Web application penetration testing
  • API penetration testing
  • Mobile application penetration testing
  • Wireless penetration testing
  • Cloud security assessment
  • Social engineering and phishing simulation

Assurance and managed

  • Security assurance
  • Essential Eight assessment
  • Configuration review and benchmarking
  • Remediation support and retesting
  • Managed security
  • Vulnerability management
  • Continuous application scanning
  • SIEM monitoring
  • EDR monitoring

Company

  • About Aurian
  • How we work
  • Industries
  • Blog
  • Contact
  • Privacy policy
526/368 Sussex St, Sydney NSW 2000 1300 AURIAN (1300 287 426) sales@aurian.com.au

© 2026 Aurian Security Pty Ltd. ACN 639 930 528.

This site is static, loads no third-party trackers, and publishes a security.txt.