Coverage note
Internal penetration testing: what an intruder could reach once inside
Internal penetration testing starts from a foothold inside your network. So it answers the question a perimeter test cannot: once someone is in, how far can they get, and how quickly would anyone notice?
- Manual exploit chains
- PTES and the OWASP testing guide
- Authorised scope only
What internal penetration testing covers
The scope is your internal estate rather than the internet edge. Therefore the work looks at how systems trust each other, not only at each system alone.
- Segmentation between networks that should stay apart
- Directory services and the privileges they grant
- The lateral paths between workstations, servers and backups
- Sensitive data stores and who can read them
How internal penetration testing starts
Every engagement needs an agreed starting point. So the foothold is chosen with you and written into the rules of engagement before anything begins.
| Starting point | What it simulates | Agreed in writing |
|---|---|---|
| Testing virtual machine | A device already on the network. | Placement and removal date. |
| Standard user account | A compromised employee login. | Privileges and monitoring. |
| Guest network seat | A visitor or contractor. | Which segments are in scope. |
Ready for internal penetration testing?
Tick what you can arrange. Open items become part of the written scope.
Your result appears here as you tick, so you can see what is still open.
Why internal penetration testing finds chains
Inside a network, small weaknesses tend to connect. For example, a stale permission, a reused service account and a flat network are each minor. However, together they can form a route to the systems that matter. Therefore the report shows routes rather than a list, because that is what an attacker would use.
Safety during the engagement
Testing windows, escalation contacts and a stop procedure are agreed first. In addition, every action is logged with a timestamp for your incident team. Then every artefact placed during testing is removed at the end. Our method follows the Penetration Testing Execution Standard and NIST SP 800-115.
Fees and the report
The report is written by the penetration hacker who ran the work, with evidence, business risk and prioritised remediation. Also, the retest is included once you apply the fixes. Full engagements run from $35,000 to $120,000, while the floor is $25,000. Also, the bounded Attack Surface Diagnostic starts at $4,500. Moreover, its fee is credited in full against a full engagement commissioned within ninety days.
Internal penetration testing questions
How long does internal penetration testing take?
It depends on the size of the estate. The fixed fee and timeline are both agreed in the written scope.
Does internal penetration testing need someone on site?
Usually not. A testing virtual machine or an agreed account is often enough.
Will internal penetration testing disrupt users?
Testing windows and a stop procedure keep it controlled, and fragile systems can be excluded.
Is a perimeter test enough on its own?
No. It shows the way in, but not how far someone could go once inside.
Related guides
Scope internal penetration testing
Describe the estate and the foothold you want simulated. The penetration hacker who would lead the work replies with a written scope and one fixed fee.
Send the brief