Asset discovery
Identify computers, servers, firewalls, switches, VoIP systems, file shares, and other key internal assets, then look for configuration gaps attackers could exploit.
A practical, human-led methodology for mapping your environment, validating weaknesses, demonstrating realistic attack paths, and turning findings into a clear remediation plan.
Internal penetration testing examines how an attacker could move through an environment after gaining a foothold. AP’s methodology combines reconnaissance, technology fingerprinting, controlled exploitation, credential testing, lateral movement analysis, and reporting.
The goal is not simply to produce a vulnerability list. The engagement is designed to show where security controls, permissions, credentials, segmentation, and hardening break down in real attack paths.
AP begins by identifying the systems, identities, services, and trust relationships that shape the internal attack surface.
Identify computers, servers, firewalls, switches, VoIP systems, file shares, and other key internal assets, then look for configuration gaps attackers could exploit.
Map users, groups, privileged accounts, and group policies. BloodHound may be used to visualize attack paths, excessive permissions, and privilege-escalation opportunities.
Map segments, routers, VPNs, wireless networks, communication paths, trust relationships, and potential pivot points between zones.
Review DNS, DHCP, SMB, RDP, FTP, internal web apps, network shares, printers, and management interfaces for exposed or insecure services.
Gather usernames, email addresses, and organizational structure that may inform credential-based testing later in the engagement.
AP develops a more precise picture of exposed software, services, operating systems, patch levels, and cryptographic configuration.
Identify software, languages, frameworks, and applications to understand the technology stack and where configuration weaknesses may exist.
Use network scanning to identify listening ports across in-scope assets and uncover potential entry points.
Probe open ports, identify running services, and use banner information to determine versions that may require deeper validation.
Identify operating systems, service packs, installed patches, and kernel versions to evaluate exposure to known weaknesses.
Review certificates, cipher suites, deprecated protocols, and other cryptographic settings on internal services using SSL/TLS.
Where appropriate within the engagement, identified weaknesses are tested to determine whether they can be chained into meaningful access, privilege escalation, or lateral movement.
Cross-check identified software and dependencies against known CVEs and assess whether relevant vulnerabilities are exploitable in the environment.
Test common AD weaknesses such as Kerberoasting, NetBIOS and LLMNR poisoning, exposed shares, NTLM relay, password spraying, and insecure group-policy permissions.
Use known exploit techniques and proof-of-concept testing to validate security gaps, including relevant application vulnerabilities and exposed-service weaknesses.
Assess whether credentials can be extracted, cracked, reused, or abused, and identify weak password practices or insecure credential storage.
Test whether compromised accounts or systems can cross access boundaries, move laterally, or gain higher privileges through weak permissions and local misconfigurations.
Assess whether access could be maintained and what sensitive data may be reachable, using controlled proof-of-concept techniques within the permitted scope.
The final report connects validated findings to likelihood, impact, evidence, and remediation so technical and business stakeholders can work from the same picture.
The source methodology outlines a seven-step engagement flow. This customer-facing version keeps the operational milestones and omits internal payment notes.
Tell AP what needs testing, what access is available, and what your timeline looks like. The next step is a clear scope and quote.