Skip to content

Network Penetration Testing

 

Learn about external vs internal testing, network segmentation, Active Directory attacks, pass-the-hash, MITM, Kerberoasting, credential dumping, and much more, through the Frequently Asked Questions (FAQs) below. Please schedule a consultation if you are looking for Penetration Testing for compliance or regulatory requirements or to comply with a global security standard.. 

Table of Contents

What is the difference between an external and internal network pen test? 

 

An external network penetration test simulates an attacker who has no prior access to the organization’s network, they attack from the internet, targeting only systems and services that are externally visible. The external test evaluates the strength of the network perimeter: firewalls, VPN gateways, publicly facing web servers, email infrastructure, remote access portals, and cloud-hosted services. An internal network penetration test simulates an attacker who has already gained a foothold inside the network, representing a compromised internal machine, a malicious insider, or a contractor with limited internal access. The internal test evaluates the security of systems, protocols, and configurations that are only accessible from within the network boundary, including Active Directory, internal file shares, database servers, and workstations. Both types of testing are necessary for comprehensive security coverage because perimeter-focused external testing alone assumes attackers will never get inside, an assumption that modern threat realities, including phishing-enabled initial access, do not support. 

 

What does an internal network penetration test actually simulate? 

 

An internal network penetration test simulates the attack scenario in which a threat actor has already achieved initial access to the organization’s internal network, through a compromised employee workstation, an insider threat, a compromised contractor account, or a breach of a third-party vendor with network access. From this inside position, the test simulates the attacker’s next steps: discovering internal systems and services, identifying valuable targets such as domain controllers, financial systems, and databases, attempting privilege escalation, performing lateral movement to reach additional systems, and demonstrating full internal compromise. The most common finding is that organizations with strong external perimeters have extremely weak internal controls, lateral movement to domain administrator often takes minutes rather than hours once inside. 

 

What is network segmentation testing? 

 

Network segmentation testing verifies whether firewall rules, VLANs, DMZs, and access control lists that divide a network into isolated zones are actually preventing unauthorized traffic between those zones. The purpose of segmentation is to contain a breach: if an attacker compromises a guest Wi-Fi device, proper segmentation should prevent access to the corporate data center. Testers attempt to communicate from one network segment to another through various protocols and ports, confirming the boundaries hold as designed. PCI DSS Requirement 11.4.5 mandates segmentation testing at least every six months and after any changes to segmentation controls, making this a regulatory obligation in cardholder data environments. Segmentation failures are among the most impactful findings in a penetration test because they dramatically expand an attacker’s reach after initial compromise. 

 

What is Active Directory (AD) penetration testing? 

 

Active Directory (AD) is the centralized identity and access management system used by most enterprise Windows environments, it controls authentication and authorization for every user, computer, and resource in the domain. Because compromising Active Directory effectively gives an attacker control over an entire organization’s infrastructure, AD penetration testing is one of the highest-impact areas of any internal network assessment. 

Active Directory penetration testing examines domain trust relationships, Group Policy Objects (GPOs) for misconfigurations, Kerberos ticket attack vectors (Kerberoasting, AS-REP Roasting), delegation settings (unconstrained, constrained, and resource-based constrained delegation), ACL (Access Control List) misconfigurations that allow privilege escalation, NTLM relay attack opportunities, password policy weaknesses, and service account security. Tools commonly used include BloodHound (for visualizing attack paths through AD relationships), Impacket, Mimikatz, and CrackMapExec. Active Directory misconfigurations consistently enable rapid progression to full domain compromise in internal penetration tests.

 

What is a pass-the-hash or pass-the-ticket attack and is it tested in a pen test? 

 

Pass-the-Hash (PtH) and Pass-the-Ticket (PtT) are lateral movement techniques used by attackers to authenticate to systems and services using captured credential hashes or Kerberos tickets rather than requiring plaintext passwords. Pass-the-Hash exploits the NTLM authentication protocol, an attacker who has extracted the NTLM hash of a user’s password from memory using tools like Mimikatz can use that hash directly to authenticate to other systems that accept NTLM authentication, without ever cracking the hash to recover the plaintext password. Pass-the-Ticket is the Kerberos equivalent, an attacker captures a Kerberos ticket from memory and uses it to authenticate to services that the legitimate ticket-holder has access to. Both techniques are heavily tested in internal network penetration tests because they are widely used by real-world attackers and ransomware operators to achieve lateral movement after initial compromise. Penetration testers test PtH and PtT within their authorized scope by capturing credentials from compromised systems and demonstrating lateral movement to additional targets. 

 

What is a man-in-the-middle (MITM) attack and how is it tested? 

 

A man-in-the-middle (MITM) attack is a network attack in which an attacker secretly intercepts communication between two parties, such as a user and a web server, or two internal systems, allowing them to eavesdrop on the communication, capture credentials or sensitive data, and potentially modify the data in transit. MITM attacks exploit weaknesses in network protocols, certificate validation, and communication security configurations. Common MITM techniques include ARP spoofing (poisoning a network’s ARP cache to intercept traffic), DNS spoofing (redirecting DNS queries to malicious servers), SSL stripping (downgrading HTTPS connections to HTTP to capture plaintext traffic), and certificate spoofing (using fraudulent certificates to intercept encrypted traffic). Penetration testers test for MITM vulnerabilities by attempting ARP poisoning on internal network segments to verify whether network monitoring tools detect the attack, testing whether SSL/TLS configurations enforce certificate pinning and reject downgrade attacks, evaluating whether internal communication protocols use encryption, and assessing whether HSTS (HTTP Strict Transport Security) is properly implemented to prevent SSL stripping. 

 

What is Kerberoasting and how is it tested in an Active Directory pen test? 

 

Kerberoasting is an Active Directory attack that targets service accounts by exploiting how the Kerberos authentication protocol issues service tickets, allowing any authenticated domain user to request a ticket encrypted with a service account’s password hash, which can then be taken offline and cracked. 

When a domain user requests a Kerberos service ticket for a service registered under a Service Principal Name (SPN), the ticket is encrypted with the service account’s password hash. Because service accounts frequently have weak, static passwords that are rarely rotated, those hashes are highly vulnerable to offline password cracking. Penetration testers identify Kerberoastable accounts using tools such as BloodHound and Impacket’s GetUserSPNs.py, then attempt to crack the extracted hashes using Hashcat or John the Ripper. Kerberoasting is mapped to MITRE ATT&CK technique T1558.003 and is one of the most commonly exploited paths to privilege escalation in enterprise Windows environments. 

 

What is credential dumping and how is it tested in an internal network pen test? 

 

Credential dumping is a post-exploitation technique used to extract authentication credentials, passwords, password hashes, and Kerberos tickets, from a compromised system, enabling lateral movement to additional systems and services. 

The most common credential dumping targets are the Windows Security Account Manager (SAM) database (which stores local user password hashes), the LSASS (Local Security Authority Subsystem Service) process memory (which holds cached credentials for recently authenticated users), the NTDS.dit file on domain controllers (which stores all Active Directory password hashes), and credential stores in browsers, configuration files, and applications. Tools such as Mimikatz, Secretsdump (from Impacket), and ProcDump are used in both real attacks and authorized penetration tests. Penetration testers use credential dumping within their authorized scope to demonstrate how an attacker could achieve lateral movement after initial compromise. Credential dumping is mapped to MITRE ATT&CK Tactic TA0006 (Credential Access), with technique T1003.001 specifically covering OS Credential Dumping via LSASS Memory.

 

Explore Blogs, Webinars and other Resources

Trusted by Reputed Companies

pVerify, Inc.
Electronic Data Solutions
Bernard Robinson & Company
Avance Care
iCliniq
Botsplash
Logically
Mr.Internet Systems
Vision Radiology
Tangible Solutions
Tangible Solutions
WorkSmart
Triyam
Med First Primary and Urgent Care
Arizona State Radiology
DataCaliper
Dose Spot Company Logo
DoseSpot
Forsyte I.T. Solutions
Tego Data

Accreditations and Associations

* Disclaimer: This list of accreditations is held by our team of employees and consultants.

What Our Clients Say

We used databrackets (formerly EHR 2.0) in our small medical practice for our risk analysis assessment to be in compliance with meaningful use. Their response was fast, the final report is detailed but simple and easy to follow. They were always available to answer our questions.
E. Compres
Pulmonary and Sleep Center of the Valley
I never miss the opportunity to learn something new …that’s why I am always registering to all free seminars offered on the web. databrackets (formerly EHR 2.0) happened to be the friendliest, comprehensive and up-to- date source of HIPAA Privacy and Security updates.
Alexandra V.
Community Healthcare Network
Today’s presentation was great! Thank you for sending the slides. My only feedback is that it would be fabulous to have the slides ahead of time so I could print them and take notes on the slides.Thanks for your time and knowledge today!
T.B., PM
Community Health Network
Particularly interesting was the flow chart on Administrative Simplification. I utilize all of the Security subcategories you list under the Security tile and appreciate knowing that I am hitting all of the relevant topics during my employee training.
Jessica B.
JD, CHC
I have re-worked our original risk assessment….We are using databrackets' (formerly EHR 2.0) Meaningful Use Security Risk Analysis Toolkit and it meets our needs. It was easy to use and I believe that it very beneficial to our meeting meaningful use.
Bill Curtis
Neurosurgical Associates Of Texarkana, TX
Information (webinars) presented by databrackets (formerly EHR 2.0) highlights some of today’s most demanding healthcare topics. The webinars help to direct those operating in today’s rapidly changing environment in the right direction.
Candace M.
Privacy and Security Officer, Springhill Medical Center

Our Growing List of Credentials

0 +
Assessments
0 +
Clients
0 +
Assessment Libraries
0 +
Years of Experience
0 +
No. of Staff Trained
0 +
HIPAA
0 +
SOC 2 Readiness
0 +
Pen Testing
0 +
ISO 27001 Certifications
0 +
Dollars Saved in Compliance Penalties