Deploys in about 5 minutes

A single container connects outbound-only over TLS 443. No VPN, no jump host, and zero inbound firewall rules to open.

Native LAN speed

The agent runs natively on the LAN instead of tunnelling every packet out to a remote scanner, so internal scans finish sooner.

Active Directory and credentials

18+ internal modules cover Windows and AD enumeration, password-policy auditing and credential testing across the domain.

Lateral-movement validation

Phased exploit chains show how one weak credential could become a full pivot, with a strategy engine picking the best technique per finding.

24/7 continuous monitoring

The agent keeps watching: asset drift detection, new and missing-host alerts, and unauthorised-change alerts on a schedule.

Credentials never leave in the clear

Discovered credentials are redacted before findings ship, and the SSH keys used for remediation stay on your own hosts.

What is internal network penetration testing?

Internal network penetration testing is an assumed-breach assessment run from inside your network. Instead of asking whether an attacker can get in, it starts from the position one reaches after a phished credential, a compromised laptop or a rogue device on the LAN, and measures how far that foothold could spread.

The work is enumeration followed by validation. Map internal hosts, services, accounts and trust relationships, find the weak credentials, over-privileged accounts and legacy protocols among them, then safely chain those findings into the lateral-movement and privilege-escalation paths an attacker would realistically take.

On PentestOps it runs through a single outbound-only on-prem agent that deploys in about 5 minutes with 0 inbound firewall rules, follows the same PTES-aligned seven-phase methodology as every other engagement, and stays inside the scope set by your per-tenant Rules of Engagement.

QuestionShort answer
What it testsInternal hosts, services, domain accounts and trust relationships on the LAN.
Attacker positionAlready inside, with a foothold but no special privilege yet.
How PentestOps runs itThrough the on-prem agent, natively on the LAN, across 18+ internal modules.
What you getValidated attack paths with evidence, ranked by CVSS v3.1 and CISA KEV.
How it differs from external testingExternal looks in from the internet. Internal starts from a foothold inside.

Why assumed breach is the right starting point

Perimeter defences fail. A phished credential, a compromised laptop or a rogue device on the LAN can all put an attacker inside your network. Internal network penetration testing takes that assumed-breach view and answers the question that follows: once someone is on the inside, how far can they actually get?

Where external network penetration testing probes what the internet can reach, internal testing works from within the LAN, enumerating hosts, services, users and trust relationships, then safely validating the paths an attacker would take toward domain dominance or sensitive data.

The catch has always been access: reaching an internal network usually means VPNs, jump hosts or shipping hardware. PentestOps removes that friction with a lightweight on-prem agent.

The on-premise agent

Internal testing runs through a single container you deploy inside the network. It connects outbound-only over a reverse tunnel, so it needs no inbound firewall rules, no VPN and no jump host. The platform never initiates a connection to you; the agent always reaches out.

It survives restrictive corporate proxies, auto-reconnects if the link drops, and has zero state to back up. A per-tenant API key is issued at install, and updates roll out through an operator-controlled change window that you can pause indefinitely. Here is the agent at a glance:

PropertyWhat it means
Time to deployAbout 5 minutes from one install command.
Inbound firewall rulesZero. The agent connects outbound-only over TLS 443.
Internal scan speedRuns natively on the LAN, not tunnelled to a remote scanner.
PackagingShips as a Docker container, RPM or DEB package.
Coverage per hostOne host can cover multiple subnets.
Monitoring24/7 asset drift detection and change alerts.

What an internal assessment covers

With 18+ internal modules running natively on the LAN, a single engagement reaches deep into the network:

  • LAN discovery with multi-method host and service detection so nothing on the network hides from the assessment.
  • Active Directory and Windows enumeration, including password-policy auditing via SAM and NTDS hash analysis to find weak and reused secrets.
  • Credential testing against discovered services to find default, weak and reused logins before an attacker does.
  • Known-vulnerability detection with CVE correlation and CISA KEV prioritisation across internal hosts and services.
  • Exploit-chain intelligence that links findings into the routes an attacker would realistically take through the environment.
  • Lateral-movement and privilege-escalation validation, safely proving how a single foothold could expand across the domain.
  • Continuous monitoring with a drift ledger and alerts on new or missing hosts between scheduled scans.

What internal testing does not cover

Scope honesty matters as much as coverage. Internal testing works from inside the network, and these things sit outside it:

  • Your internet-facing perimeter. Public IP ranges, domains and exposed services are assessed by external network penetration testing, which needs no agent at all.
  • Cloud control-plane configuration. IAM, storage and network posture in AWS, Azure, GCP and Microsoft 365 is a credentialed cloud penetration testing audit, not something the agent sees from the LAN.
  • Kubernetes cluster posture. Cluster RBAC and workload security are covered agentlessly through a read-only kubeconfig. See Kubernetes security testing.
  • Traffic monitoring and detection. The agent is not an IDS, IPS or SIEM. It does not watch your network traffic continuously and it is not a backdoor into your environment.
  • Physical and social-engineering testing. Building access, phishing simulations and staff pretexting are separate exercises and are not part of an internal network engagement.
  • Destructive or denial-of-service testing. Exploitation is safe, auditable and scope-enforced. Production systems are not taken down to demonstrate that they could be.
  • Bespoke business-logic research. Automated testing covers the repeatable ground thoroughly and consistently. Novel logic flaws in a custom application still reward human creativity, which is why the platform is built to complement a testing team rather than replace one.

How it works

An internal engagement follows the same repeatable, seven-phase methodology as the rest of the platform, aligned to PTES, NIST SP 800-115 and CREST guidance. See the full testing methodology for the detail.

After the agent is online, discovery and enumeration build a live map of hosts, services, users and trust relationships. Vulnerability analysis correlates findings against the CVE catalogue, strips false positives, and ranks what remains by CVSS v3.1, exploit availability and business impact.

Exploitation and validation then safely confirm the highest-value paths, capturing evidence at each step, before reporting and remediation delivers an executive summary, technical detail and prioritised fixes. On Enterprise, one-click remediation playbooks can be deployed through the agent over SSH, with rollback on validation failure.

Proving the attack path

A vulnerability scan tells you a weakness exists. It cannot tell you whether that weakness leads anywhere. Internal testing closes that gap by chaining findings into a validated attack path: one weak credential, an over-privileged account or a legacy protocol becomes a demonstrated route to sensitive systems.

A strategy engine selects the most appropriate technique per finding, and phased exploit chains turn a small foothold into a full pivot, all under per-tenant Rules of Engagement that stop any activity outside authorised scope. Identity is usually the shortest path, so pair this with Active Directory security testing and read our guide to common Active Directory security issues and attack path validation.

Continuous internal monitoring

Because the agent stays deployed, internal assurance does not stop when a test finishes. It provides 24/7 continuous monitoring: it tracks the internal asset inventory, records every change in a drift ledger, and raises alerts on new hosts, missing hosts and unauthorised changes.

That turns a point-in-time internal test into an always-on coverage layer, catching the rogue device or misconfiguration the day it appears rather than at the next annual assessment.

Why PentestOps for internal testing

PentestOps is an Australian-built platform from Extranet Systems Pty Ltd, an ISO/IEC 27001:2022 certified company. The platform is hosted in Australia and customer data is stored in Australia. Discovered credentials are redacted before findings leave the agent, and remediation keys never leave your hosts.

Internal testing is one lane of a single platform that also covers external, web, API, cloud and identity, so your whole exposure sits in one place. Findings map to 8 compliance reporting frameworks plus CIS Benchmarks, exportable as PDF, CSV or JSON/API. Pricing is asset-wise: an internal subnet target counts as one asset, with scans unlimited within fair use. See pricing to get started.

Frequently Asked Questions

What is an internal network penetration test?

It is an assumed-breach assessment: testing starts from a position inside your network, as if an attacker already has a foothold, and measures how far they could move. It enumerates internal hosts, services, users and trust relationships, then safely validates lateral movement and privilege escalation.

How does the agent connect without any inbound firewall rules?

The agent connects outbound-only over TLS 443 through a reverse tunnel, so the platform never has to reach into your network. That means no inbound firewall rules, no VPN and no jump host. It also works through restrictive corporate proxies and reconnects automatically if the link drops.

How long does the agent take to deploy?

About 5 minutes. You run a single install command from the portal and the agent connects itself. It ships as a Docker container, RPM or DEB package, and one host can cover multiple subnets.

Does the agent read our credentials or leave a backdoor?

No. The agent is not a backdoor and is not always-on traffic monitoring. Credentials it discovers are redacted before any finding ships, so they never leave the agent in plaintext, and the SSH keys used for optional remediation stay on your own hosts. Every action is tied to a signed Rules of Engagement record with a full audit trail.

What does internal testing find that a vulnerability scan misses?

A scan lists weaknesses in isolation. Internal testing chains them into a validated attack path, proving how a single weak credential or misconfiguration could lead to domain compromise. That is the difference between a maybe and demonstrated impact. See attack path validation.

Can one agent cover multiple subnets or sites?

One host can cover multiple subnets. For larger or segmented environments you can deploy additional agents, and fleet management lets you oversee them centrally. The approach scales from a single office to a distributed network.

How is internal network penetration testing priced?

Pricing is asset-wise. An internal subnet target counts as one asset, and scans against your assets are unlimited within fair use. You pay only for the distinct assets in scope. See pricing for current plans.

What compliance frameworks do internal reports map to?

Findings map to 8 compliance reporting frameworks (OWASP Top 10, PCI DSS v4.0, NIST 800-53, SOC 2, HIPAA, GDPR, ISO 27001, SMB1001) plus CIS Benchmarks for AWS, Azure, GCP and Kubernetes. This maps findings in reports and is not a statement of your organisation's certification.

Test your network from the inside out

Deploy the agent in about 5 minutes and run internal network penetration testing with a 7-day free trial. No inbound firewall rules required.