Internal Penetration Testing

Internal Penetration Testing

Expert-led testing that starts inside your network the way a real intrusion does: from a phished laptop, a rogue contractor, or a guest port nobody segmented. We measure how fast an attacker reaches domain administrator, what data sits inside the blast radius, and which controls actually stop them. Delivered by a North Carolina cybersecurity firm that has protected regulated businesses since 2002.

CyberAB RPO #1449 | BBB A+ Since 2003 | NC Licensed Digital Forensics
What It Is

What Is Internal Penetration Testing?

Internal penetration testing is an authorized, simulated cyberattack conducted from inside your network, starting from the position an attacker occupies after a successful phish, a stolen laptop, a compromised vendor connection, or an unsupervised visitor plugging into a conference room port. Security professionals attempt to escalate privilege, harvest credentials, move laterally between systems, and reach the data that matters, exactly as ransomware operators do. The result is documented proof of how far an intruder gets once they are already past the perimeter, how quickly they get there, and which of your existing controls actually slowed them down.

Key Takeaways

  • Internal penetration testing assumes the breach has already happened and measures blast radius: how far an attacker moves, how fast they reach domain administrator, and what data they can take.
  • It is the single most accurate test of ransomware exposure, because ransomware operators do exactly this: land on one endpoint, escalate, spread, then encrypt everything they reached.
  • Petronella Technology Group has delivered offensive security testing since 2002, holds a BBB A+ rating since 2003, and is a CyberAB Registered Provider Organization (RPO #1449) with CMMC Registered Practitioners on staff.
  • Our methodology follows NIST SP 800-115, the Penetration Testing Execution Standard, and MITRE ATT&CK, and satisfies internal testing expectations under PCI DSS, CMMC, NIST 800-171, HIPAA, and SOC 2.
  • Founder Craig Petronella is an MIT-certified cybersecurity professional, NC Licensed Digital Forensics Examiner (License #604180-DFE), and cybersecurity expert witness who investigates real intrusions, so our testing mirrors how breaches actually unfold.

Why It Matters

Why Your Internal Network Needs a Real Test

Perimeter defenses fail. Not often, but often enough that planning around their success is a strategy rather than a control. The question internal penetration testing answers is the one that actually determines whether a security incident becomes a business catastrophe: what happens next?

Almost every organization we test has spent real money on the edge. Firewalls are current, remote access requires multi-factor authentication, email filtering catches most of what arrives. Then a finance clerk approves a login prompt they did not initiate, or a developer runs an installer from a search result, or a laptop leaves a car window, and the attacker is standing inside a network that was never designed to be hostile to them. Inside that network, the picture usually changes fast. File shares are readable by everyone. Service accounts have domain administrator rights because a vendor asked for them in 2019. Local administrator passwords are identical on four hundred workstations. Backups sit on the same domain as the systems they protect.

This is the gap that ransomware exploits, and it is why ransomware remains profitable despite two decades of perimeter investment. Modern operators do not brute-force your firewall. They buy access from a broker who already phished someone, then spend hours or days doing precisely what an internal penetration tester does: enumerate Active Directory, hunt for cached credentials, find a misconfigured certificate template, escalate to domain administrator, locate and delete the backups, and only then deploy the payload. An internal engagement runs the same playbook with your permission and hands you the map before someone else draws it.

The findings are frequently uncomfortable and almost always cheap to fix. A flat network that lets a receptionist workstation talk directly to a database server is a configuration problem, not a budget problem. A service account with unconstrained delegation is a five-minute change once someone knows it exists. The reason these conditions persist is not negligence; it is that nobody has ever looked at the environment from the attacker's seat. Vulnerability scanners do not look for them, because none of them are vulnerabilities in the patching sense. They are the accumulated residue of ordinary decisions made under ordinary pressure, and they are exactly what an intruder monetizes.

Petronella Technology Group brings an investigator's perspective to this work. Because our founder handles digital forensics and expert-witness cases involving real intrusions, we have watched the aftermath of these exact configurations more than once, and we test the paths attackers actually take rather than the ones that produce an impressive slide. Pair a test with our managed cybersecurity services and the findings get remediated, monitored, and retested rather than filed away.

The Attack Surface

What We Attack From the Inside

Once we are on the wire, everything an attacker could reach is in scope. Identity infrastructure comes first, because in a Windows environment identity is the network.

Identity and Active Directory

  • Active Directory enumeration: group nesting, privileged group membership, stale accounts, and delegation misconfiguration
  • Kerberoasting and AS-REP roasting against service accounts with weak or reused passwords
  • Certificate services abuse: vulnerable templates that let any authenticated user request a certificate as a privileged account
  • Credential harvesting from memory, group policy preferences, scripts, share content, and password reuse across local administrator accounts
  • Hybrid identity paths: on-premise compromise that extends into Entra ID, Microsoft 365, and connected cloud tenants

Network, Data, and Recovery

  • Segmentation reality-testing: whether a user VLAN can actually reach servers, management interfaces, and operational technology
  • Protocol-level attacks: LLMNR and NBT-NS poisoning, SMB relay, and unsigned traffic that yields credentials without exploiting anything
  • Sensitive data discovery: open file shares holding patient records, contract documents, controlled unclassified information, or credential spreadsheets
  • Backup and recovery exposure: whether an attacker who owns the domain can also reach, disable, or destroy the backups you would restore from
  • Detection and response validation: which of our actions your monitoring, endpoint detection, and SOC actually noticed, and how long that took

Where internally hosted applications are the primary concern, we recommend pairing this engagement with a dedicated web application penetration test, which examines authenticated workflows, business logic, and API authorization in a depth that a network-focused internal test does not attempt.

Find Out How Far an Intruder Gets

We will scope an internal penetration test against your real environment and show you the path from one compromised laptop to your most sensitive data. Call 919-348-4912 or request a quote.

Scope Choices

Internal vs. External Penetration Testing

The two tests answer different questions, and most mature security programs run both. Understanding the difference is the first step in scoping an engagement that produces useful answers.

Internal Penetration Testing

  • Starting point: inside your network, simulating a compromised workstation, a rogue insider, or an attacker who already phished a user
  • Question answered: once someone is inside, how quickly do they reach domain administrator and your crown-jewel data?
  • Typical findings: flat networks, weak Active Directory configuration, credential harvesting, lateral movement paths, excessive privilege, reachable backups
  • Best for: organizations measuring ransomware blast radius, insider risk, and whether segmentation works in practice rather than on the diagram

External Penetration Testing

  • Starting point: the public internet, with no credentials and no network access
  • Question answered: can an anonymous outsider get in at all, and how far?
  • Typical findings: exposed services, weak remote access, subdomain takeover, credential reuse, perimeter misconfiguration
  • Best for: every organization, as the baseline test and the one auditors ask about first

The honest answer to "which one do we need?" depends on where you are. If you have never had an independent test, start with an external penetration test: it covers the attack surface an opportunistic adversary finds first, and it is what your insurer and your customers ask about. If your perimeter is well managed but a single phished employee would put your entire environment at risk, an internal engagement tells you far more, because it prices the consequence rather than the likelihood. Organizations under CMMC, PCI DSS, or SOC 2 obligations typically run both on an annual cycle.

Both scopes are available from our team, and many clients combine them into a single network penetration testing engagement so that one report covers the full path from the open internet to the data an attacker is actually after. We will help you decide during scoping rather than selling you the larger engagement by default.

Starting Positions

Which Attacker Do You Want Us to Be?

An internal test is defined by where it starts. We choose the starting position with you during scoping, because different assumptions produce genuinely different answers.

Assumed Breach

We begin on a standard corporate workstation with an ordinary domain user account, exactly as an attacker would after a successful phish. This is the most requested scope because it models the most common real-world intrusion and produces the most actionable findings.

Unauthenticated Network Foothold

We start with network access but no credentials, as though someone plugged into a conference room port or joined a poorly isolated wireless network. This tests whether an intruder can obtain their first credential without any help at all.

Malicious Insider

We operate as an employee or contractor who already holds legitimate access and decides to abuse it. This scope answers what a departing engineer, an aggrieved staff member, or a compromised vendor account could quietly take with them.

Compromised Vendor Connection

We start from the access a third party holds through a site-to-site tunnel, remote support tool, or managed device. Supply chain intrusions arrive this way, and the segmentation around vendor access is rarely as tight as anyone assumes.

Segmentation Validation

A targeted scope that tests one question thoroughly: whether the boundaries you rely on actually hold. Common where a cardholder data environment, a CUI enclave, or a clinical network is meant to be isolated from general corporate traffic.

Purple Team Mode

We run the engagement alongside your defenders, announcing each technique so your team can confirm whether their tooling detected it. Less about finding holes and more about tuning detection, and highly effective for organizations with an established SOC.

Methodology

Our Internal Pen Test Process

A structured, standards-aligned engagement built on NIST SP 800-115, the Penetration Testing Execution Standard, and MITRE ATT&CK, with written rules of engagement agreed before any testing begins.

1

Scoping and Rules of Engagement

We agree in writing on the starting position, the subnets and systems in scope, the testing window, escalation contacts, and the systems we will not touch. Fragile legacy hosts, clinical devices, and production control systems are identified up front and handled by agreement rather than by discovery.

2

Access and Reconnaissance

We establish the agreed foothold, usually through a hardened testing device shipped to your site or a controlled virtual machine in your environment, then map the internal landscape: live hosts, services, trust relationships, Active Directory structure, and the shape of your privilege model.

3

Credential Access and Privilege Escalation

We pursue the first meaningful credential and then better ones, using protocol poisoning, service account attacks, share mining, certificate template abuse, and local privilege escalation. Every technique used is logged with a timestamp so your team can correlate it against their own telemetry afterward.

4

Lateral Movement and Objective Pursuit

With elevated access we move toward agreed objectives: domain administrator, a specific data repository, the backup infrastructure, or a segmented enclave. Destructive actions are excluded, exfiltration is simulated rather than performed, and anything with operational risk is coordinated with your team first.

5

Reporting and Executive Debrief

You receive a report written for two audiences: an executive summary that explains business risk in plain language, and a technical section with reproduction steps, evidence, timestamps, and specific remediation guidance. We walk your team through it on a live debrief so questions get answered while the findings are fresh.

6

Remediation Support and Retesting

After you fix the confirmed findings, we retest them to verify the fixes hold and issue an attestation letter suitable for auditors, insurers, and enterprise customers. A finding is only closed once we have proven the fix works in practice.

Deliverables

What You Receive After the Test

Documented Attack Path

A step-by-step narrative from the starting foothold to each objective reached, with the technique, the timestamp, and the evidence at every hop, so leadership understands the actual consequence rather than a severity label.

Time to Domain Administrator

The elapsed time from initial access to full domain control, which is the single most useful number an executive can hold, because it is directly comparable to how long your detection and response actually takes.

Ranked Findings With Evidence

Each finding carries a business-risk rating, technical detail, captured evidence, and clear reproduction steps so your team can confirm and fix it without guesswork or vendor back-and-forth.

Sensitive Data Exposure Report

A record of the regulated or confidential material we were able to reach, including open shares holding health records, contract files, or controlled unclassified information, mapped to the access level required to get there.

Detection Gap Analysis

A timeline of our activity matched against what your monitoring and endpoint tooling recorded, showing which techniques were caught, which were logged but unalerted, and which passed unnoticed entirely.

Retest and Attestation Letter

Validation that your fixes hold, documented in a letter you can hand to auditors, cyber insurers, prime contractors, and enterprise procurement teams.

Comparison

Internal Pen Test vs. the Alternatives

Internal assurance is sold in several forms, and they are not interchangeable. Here is what each one actually delivers.

Capability Internal Pen Test Internal Vulnerability Scan AD Auditing Tool
Measures ransomware blast radius Yes, by reaching the data and the backups No, reports missing patches per host Partially, models paths without proving them
Chains misconfigurations into a real path Yes, core of the engagement No, findings are per-asset Theoretical paths only
Tests whether segmentation actually holds Yes, by attempting to cross it Only where you already point it No, identity scope only
Validates detection and response Yes, with a technique timeline No No
Finds exposed regulated data on shares Yes, from the attacker's access level Rarely, not a scanner function No
Independence for auditors and insurers Yes, third-party attestation Partially, tooling evidence only No, self-assessment

None of this makes scanning worthless. Continuous internal scanning is the right tool for catching a newly published vulnerability on a known host between engagements, and we build it into our vulnerability assessment programs for that reason. If you are weighing the two approaches directly, our guide to vulnerability scanning versus penetration testing walks through where each one earns its cost.

Price the Consequence, Not Just the Risk

A scoping call takes about twenty minutes and costs nothing. We will tell you honestly whether an internal test, an external test, or an application test gives you the most value right now.

Compliance

Internal Testing for Compliance Requirements

Internal testing is written into most of the frameworks our clients operate under, and the evidence an assessor wants is specific.

PCI DSS requires internal penetration testing at least annually and after any significant change, and it separately requires segmentation testing to confirm that the cardholder data environment is genuinely isolated from the rest of the network. That second requirement is the one organizations most often fail, because network diagrams and firewall rules drift apart over time. Our reports are structured to map findings directly to the relevant requirements. See our PCI DSS compliance services for the broader program.

CMMC and NIST 800-171 expect defense contractors to control the flow of controlled unclassified information, enforce least privilege, separate duties, and demonstrate that vulnerability remediation repeats. An internal test is the most direct evidence that those controls function together rather than existing only as policy statements, and it is particularly useful for proving that a CUI enclave is genuinely bounded. As a CyberAB Registered Provider Organization (RPO #1449) with CMMC Registered Practitioners on staff, our team scopes testing to align with your System Security Plan. Explore our CMMC compliance services, or start with our CMMC compliance guide.

HIPAA requires covered entities and business associates to conduct an accurate and thorough risk analysis covering the risks to electronic protected health information, and to implement access controls that limit ePHI to those who need it. Internal testing answers both directly: it demonstrates whether an ordinary user account can read patient records it has no business reading. Craig Petronella is the author of How HIPAA Can Crush Your Medical Practice, and that framing informs how we document findings for healthcare clients pursuing HIPAA compliance.

SOC 2 and cyber insurance both look for evidence of independent testing, and insurers in particular have grown specific about internal controls after paying out on ransomware claims. Carriers now ask whether local administrator passwords are unique, whether privileged accounts are separated, and whether backups are isolated from the production domain. An internal penetration test answers all three with evidence rather than assertion. Our SOC 2 compliance team can align the testing cadence to your audit period.

Why Us

Why Businesses Trust Our Testing

  • Attacker experience, not just tools. Our founder is an NC Licensed Digital Forensics Examiner and cybersecurity expert witness who investigates real intrusions, so we test the lateral movement routes attackers actually take.
  • Manual validation of every finding. Automated tooling gives us coverage, but the exploitation, chaining, and judgment come from experienced testers who confirm each finding by hand before it reaches your report.
  • Safe by design in fragile environments. We routinely test clinical networks, manufacturing floors, and legacy line-of-business systems, and we scope around them deliberately instead of discovering their fragility mid-engagement.
  • Compliance fluency. As a CyberAB Registered Provider Organization (RPO #1449), we know how PCI DSS, CMMC, HIPAA, and SOC 2 expect internal testing and segmentation validation to be scoped, executed, and documented.
  • We can fix what we find. Many testing firms hand over a report and leave. Our managed security and compliance teams can implement the remediation, which means findings close instead of aging.
  • Proven longevity. Founded in April 2002 and BBB A+ rated since 2003, we have defended North Carolina and national clients through more than two decades of evolving threats.

"Petronella Cybersecurity provides outstanding service! Their team is extremely knowledgeable, responsive, and truly cares about protecting their clients. They take the time to explain complex issues in simple terms and deliver real solutions, not just promises."

GB Entraînement, TrustIndex verified review

We are rated 4.7 across 92 verified TrustIndex reviews and 5.0 across 15 Google reviews. You can read them on our reviews page. For a deeper look at how intrusions unfold once an attacker is inside, Craig Petronella's book How Hackers Can Crush Your Business covers the same ground our testers walk, and is listed with his other titles on our books page.

Who We Test For

Industries We Test For

Since 2002 we have tested internal networks for organizations whose exposure carries regulatory as well as financial consequence.

Defense Contractors

Suppliers handling controlled unclassified information who need to prove that a CUI enclave is genuinely bounded and that least privilege is enforced rather than merely documented.

Healthcare Practices

Medical, dental, and behavioral health organizations where clinical devices share a network with administrative workstations and an ordinary user account often reads far more than it should.

Law Firms

Practices holding privileged client material on internal file servers, where a single compromised paralegal account can expose matters across every client the firm serves.

Financial Services

Advisors, lenders, and accounting firms operating under GLBA and FTC Safeguards expectations, where insider risk and segregation of duties carry direct regulatory weight.

Manufacturing and Logistics

Operations where plant systems, vendor connectivity, and corporate IT share more of the network than anyone intends, and where downtime is measured in shifts rather than tickets.

Technology and SaaS

Product companies whose enterprise customers require independent testing evidence before signing, and whose engineering environments hold production credentials by necessity.

FAQ

Internal Penetration Testing Questions

What is internal penetration testing?
Internal penetration testing is an authorized simulated attack that starts inside your network rather than at the perimeter, modeling what happens after an attacker phishes an employee, steals a laptop, or compromises a vendor connection. Testers attempt to escalate privilege, harvest credentials, move laterally between systems, and reach sensitive data, producing documented proof of how far an intruder gets and how quickly. It is the most accurate available measure of ransomware blast radius and insider risk.
How is internal penetration testing different from external penetration testing?
External testing starts from the public internet with no credentials and answers whether an outsider can get in at all. Internal testing assumes that step already succeeded and answers what happens next: how quickly an attacker reaches domain administrator, whether segmentation holds, what regulated data is readable, and whether your backups survive. Most mature programs run both, and organizations under PCI DSS, CMMC, or SOC 2 obligations typically test both scopes annually.
Do you need credentials to perform an internal penetration test?
Not necessarily, and the choice is part of scoping. An unauthenticated scope starts with network access only and tests whether an intruder can obtain their first credential unaided. An assumed breach scope gives us a standard domain user account, which models the most common real intrusion and typically produces more actionable findings in the same amount of time. Many clients run unauthenticated first, then hand over credentials partway through so both questions get answered.
How long does an internal penetration test take?
Most engagements run one to three weeks from kickoff to final report, depending on the size of your environment, the number of sites and domains in scope, and the depth of testing you choose. Active testing is usually the shorter phase; scoping, evidence collection, and reporting take the rest. We agree on the schedule during scoping and coordinate testing windows so there is minimal impact on operations.
Will an internal test disrupt our network or break anything?
We design every engagement to be safe. Denial-of-service techniques and destructive testing are excluded by default, exploitation is controlled and staged, and fragile systems such as clinical devices, manufacturing controllers, and legacy line-of-business servers are identified during scoping and handled by agreement. The written rules of engagement define exactly what is in scope and what is off limits before testing begins, and your escalation contacts can pause the engagement at any point.
Do we need to be onsite, or can testing be done remotely?
Most internal testing is performed remotely. We ship a hardened testing device that your team plugs into the agreed network segment, or we deploy a controlled virtual machine inside your environment, and testing proceeds from there. Onsite work is available where physical access, wireless testing, or an air-gapped environment makes it necessary, and we serve clients across Raleigh, Durham, Chapel Hill, and the wider Triangle directly.
How much does internal penetration testing cost?
Cost depends on scope: the number of internal hosts and sites, how many Active Directory domains are involved, whether segmentation validation or purple team collaboration is included, and the depth of testing you choose. We price each engagement after a short scoping call so the figure reflects your actual environment rather than a generic package. That call is free and carries no obligation.
What compliance frameworks require internal penetration testing?
PCI DSS requires internal penetration testing at least annually and after significant change, plus separate segmentation testing to confirm the cardholder data environment is isolated. CMMC and NIST 800-171 expect defense contractors to enforce least privilege, control the flow of controlled unclassified information, and demonstrate repeating vulnerability remediation. HIPAA requires a thorough risk analysis and access controls limiting ePHI, both of which internal testing evidences directly. SOC 2 auditors and cyber insurance carriers also look for independent testing.
Do you retest after we fix the findings?
Yes. After you remediate, we retest the confirmed findings to verify the fixes hold and provide an attestation letter suitable for auditors, insurers, prime contractors, and enterprise procurement teams. Validation is part of the engagement, because a finding is only truly closed once we have confirmed the fix works in practice rather than on paper.

Last Updated: July 26, 2026

Petronella Technology Group, Inc. · 5540 Centerview Dr., Suite 200, Raleigh, NC 27606 · 919-348-4912 · Serving Raleigh, the Triangle, and clients nationwide