A security assessment that simulates an attacker already inside your network, to find how far they could escalate privileges, move laterally, and reach critical systems.
Testing that starts from a compromised position (a workstation or a standard domain user), focusing on what an attacker does after initial access, rather than spending the engagement getting in.
Yes. Active Directory and Kerberos are the primary internal attack surface, and the focus of most engagements, including Kerberoasting, delegation abuse, and paths to Domain Admin.
Yes. We validate whether segmentation actually separates sensitive environments such as a PCI Cardholder Data Environment from the rest of the network.
Network access from an in-scope internal segment, or a standard domain user account for grey-box testing to simulate a compromised employee.
No. Testing is rate-limited, destructive techniques are excluded by default, and anything potentially disruptive requires explicit approval and a scheduled window.
It depends on the number of hosts, Active Directory complexity, and objectives. Most engagements run one to two weeks. Request a scoped quote.