Penetration testing

Assume Breach Assessment

Most testing asks how an attacker gets in. This asks what happens once they are in. We start as a compromised employee on your internal network and show how far a skilled attacker reaches - and exactly what stops them.

Book a scoping call

One machine, already inside

We place a device on your internal network, or take a low-privileged domain-joined account, to model the day after a phishing email works or a laptop is lost. From there we do what a real intruder does: enumerate, escalate, move laterally and go for the assets that matter.

  • Active Directory: credential exposure, privilege escalation and domain takeover paths
  • Lateral movement and what your segmentation actually prevents
  • Access to the data and systems an attacker would monetise or hold to ransom
  • Whether your detection and response notices any of it

Real techniques, scoped to your objectives

The engagement is shaped by the goals we set with you: a specific crown-jewel system, domain admin, a data set. We keep in contact throughout so the test stays useful and nothing disrupts operations. Our team researches the techniques it uses - the WithSecure Elements flaw we found, which let one request isolate an entire fleet of machines, is the kind of thing that only turns up when a human reasons about the system rather than scans it.

A map of the internal risk

  • The attack paths we found, each reproducible, from initial foothold to objective
  • A management summary and a technical report with a clear order to fix in
  • Concrete hardening steps that cut the paths, not a generic checklist
  • A walkthrough with a Q&A round, and a retest once you have remediated

Related reading: the WithSecure Elements flaw that could isolate a whole network.

Find out how far a breach would go

A 30-minute call is enough to scope an assume-breach engagement.

Book a scoping call