All methodologies
Network & infrastructure

Network Penetration Testing Methodology

External and internal network assessment — from host discovery through service exploitation and, where authorized, Active Directory post-exploitation. Internal testing is VPN-gated: you provide the config, we test as an attacker who phished a workstation would.

Phase 1

Host Discovery

Find what is live

Identify live hosts across the in-scope ranges, even behind drop-all firewalls, before deeper probing.

Nmap (host discovery)
Masscan
RustScan
Phase 2

Port & Service Scanning

Find the doors

Enumerate open ports and fingerprint the service + version behind each, capturing CPEs for accurate CVE correlation.

Nmap -sV + NSE
Service/banner detection
CPE capture
Phase 3

Vulnerability & CVE Analysis

Find the weaknesses

Correlate discovered services against the live CVE catalogue and test for misconfigurations, weak protocols, and default credentials.

CVE enrichment (NVD)
Nuclei
default-creds
SMB / SNMP / NFS checks
Phase 4

Exploitation

Prove the impact

Validate exploitable services within your authorization scope, with safe controls and credential brute-force only against accounts you authorize.

Metasploit (detection)
Hydra
NetExec
Exploit-DB matching
Phase 5

Post-Exploitation & Active Directory

Measure the blast radius

Where authorized, measure what an attacker could reach — with deep Active Directory attack-path analysis most platforms skip.

BloodHound-Python
Impacket suite
Kerbrute
LDAPdomaindump
Phase 6

Reporting

Make it actionable

Findings prioritised by real-world impact, mapped to MITRE ATT&CK and compliance frameworks, with remediation guidance.

MITRE ATT&CK mapping
Risk-scored findings
PDF / web / DOCX reports

Standards we map to

Every finding is tagged against the frameworks your compliance team actually uses.

MITRE ATT&CK
PCI-DSS v4.0 (11.4)
ISO/IEC 27001:2022 (A.12.6)
NIST SP 800-115

A note on authorization

Every active test requires either attested ownership of the target during signup or an explicit written authorization on file. We log every test request against this authorization so there's never any ambiguity about scope — we are bound by the same Computer Misuse legislation our customers are.

Explore other methodologies

Ready to run a Network & Infrastructure assessment?

Run your first scan in minutes. No credit card required for the free tier.