Internal penetration testing

Threat emulation schedule with dates, sources, statuses, and a vulnerabilities list with severity and fix status.

An internal penetration test begins where most reports end: the attacker is already inside. A phished user, a contractor laptop, a device someone plugged in. From that position it measures what happens next — which Active Directory paths lead to domain control, whether segmentation actually holds, how large the blast radius is, and what your detection saw while all of it was going on.

For teams who already accept that prevention will fail once

Security teams who have invested heavily in perimeter and endpoint controls and have never measured what a single successful phish is actually worth.

Organizations running Active Directory with delegation, service accounts and trusts accumulated across years of mergers and migrations.

Detection and response teams who want a real adversary to grade their telemetry instead of a tabletop exercise.

User interface with sections titled 'Strikers assigned' showing two profile pictures and their details, and an 'Export' panel with options to include Findings Summary, Assessment Updates, and Compliance Checklist, with a Download button.
[ ASSUME BREACH ]

Same building, three very different questions

Internal testing gets confused with both of its neighbours, and the confusion is expensive. An external test asks what a stranger can reach. A red team asks whether a determined adversary can achieve an objective without being noticed. An internal test grants the starting position deliberately and spends the whole engagement on the part that comes after, which is where trust relationships, segmentation and directory design get graded.

How to tell them apart
External penetration test
Red team
Internal penetration test
Starting position
Nothing. The public internet
Whatever the operator can earn, including phishing your people
Granted on purpose: a standard user account, or a workstation treated as compromised
The question being answered
What can a stranger reach and break?
Can a determined adversary reach the objective without us noticing?
Once someone is inside, how much of the estate do they end up owning?
Stealth
Not a priority
Central. Avoiding detection is part of the test
Deliberately not a priority — coverage is worth more than quiet
Coverage
Everything internet-facing
One or two objectives, pursued deeply
Broad across the internal estate and the directory
What it really grades
Exposure and the accuracy of your inventory
Your detection and response, end to end
Trust relationships, segmentation and how the directory was designed
When to buy it
First, and continuously
Once internal results have stopped being surprising
As soon as your external results stop surprising you

A red team is a valid and different exercise, and it is a poor substitute for internal testing: it optimizes for one path taken quietly, not for a map of every path that exists.

The Active Directory paths that keep working

Kerberoasting
Any authenticated user can request service tickets for accounts that have a service principal name, then attack the resulting material offline. It stays effective wherever service accounts carry human-chosen passwords, and those accounts are frequently over-privileged, which is what turns a low-effort step into a high-value one.
AS-REP roasting
Accounts configured without Kerberos pre-authentication can be attacked without any credentials at all. The setting usually survives from a compatibility decision made years ago for one application, and nobody has revisited which accounts still carry it.
Coercion and NTLM relay
Persuading a machine to authenticate to somewhere the tester controls, then relaying that authentication to a service that will accept it. Microsoft has been steadily deprecating NTLM, and relay chains remain one of the most reliable routes to privilege in real estates because the required signing and channel-binding settings are so often not enforced everywhere.
Certificate services abuse
Active Directory Certificate Services misconfigurations — templates that let a requester specify their own identity, or an enrolment endpoint reachable over an unauthenticated channel — turn into durable domain-level access. This is one of the highest-impact categories on internal engagements and one of the least monitored.
Delegation and ACL abuse
Unconstrained or badly scoped delegation, and object permissions that let one account rewrite another. These are rarely one dramatic mistake; they are the residue of a decade of migrations, and they connect into chains that no single administrator can see from where they sit.
Local admin sprawl and credential reuse
One shared local administrator password, or a privileged account that has logged into an ordinary workstation, collapses the distance between a user laptop and a domain controller. This is the least sophisticated item on the list and the most common reason an engagement finishes early.

Beyond the directory: segmentation, blast radius and what you saw

Segmentation, tested rather than assumed
The question is concrete: from a compromised host on the user VLAN, what can actually be reached? Databases, backup infrastructure, hypervisors, the payment zone, operational technology. Segmentation is the control that decides whether one incident is a bad afternoon or a bad quarter, and it is usually documented rather than verified.
Blast radius, stated as a number
For each starting position, how many systems, accounts and data stores end up reachable. This is the sentence that translates the engagement for a board: one compromised laptop in this office reaches these systems, and here is the single change that shrinks that.
Reachability of the data that matters
Not whether a share is readable in theory, but whether the tester got to regulated or revenue-critical data and what they had to do to get there. Findings phrased in terms of data reached are the ones that survive contact with a prioritization meeting.
Detection and response observations
Because internal testing is not stealth-driven, it produces an honest record of what your tooling logged, what it alerted on, and what nobody noticed. That comparison is worth as much as the vulnerabilities themselves, and it costs nothing extra to collect.

Frequently asked questions

What does assume-breach mean in practice?

It means the engagement does not spend its budget proving that someone can get in, because that is already the industry's working assumption. The tester is given a realistic starting position — a standard user account, or access to a workstation treated as compromised — and the entire engagement is spent on what happens after that. It is the most efficient way to learn what one successful phishing email is worth.

How is internal testing different from external testing?

External testing measures exposure: what a stranger can reach and break with no access. Internal testing measures consequence: given access, how far it goes. They surface different failures. External work tends to find inventory and exposure problems; internal work tends to find trust, segmentation and directory problems, and those are usually the ones that decide how bad a real incident becomes.

What starting access should we provide?

A standard, non-privileged domain user account is the most useful default, because it reproduces the position of a phished employee exactly. Adding a second account at a different privilege level lets the tester verify separation between roles. Some teams start fully unauthenticated on the network first, which is realistic for a rogue device scenario and typically produces credentials within the engagement anyway.

Should we tell the security operations team?

For an internal penetration test, yes. Coverage is the goal, so an uninformed SOC spends the engagement responding to the tester instead of letting the estate be mapped. Tell them the window and the tester's source addresses, and separately record what their tooling detected. If you specifically want to test whether they catch an adversary, that is a red team, and it is a different purchase.

What should the report contain?

Each attack path from starting position to final privilege, with evidence at each step and the earliest point where one change breaks the chain. Then blast radius per starting position, an explicit segmentation result, and the detection observations. A list of individually rated findings without the paths that connect them is the most common weakness in internal reports, because it hides the fact that three mediums are one critical.

How often should internal testing happen?

The compliance floor is annual, and directories drift faster than that: a new service account, a delegation added for one project, a template published to make an application work. Each of those can reopen a path that was closed last year. Retesting after remediation is the minimum, and testing that runs continuously against the internal estate is how the drift stops accumulating unnoticed.

[ RELATED ]

Internal testing is the second half of a network scope, and the natural neighbour of a red team engagement.

Our solution architecture

A centralized platform that combines continuous asset monitoring, autonomous threat emulation, and expert remediation support—powered by AI agents, human validation, and a dedicated governance team.

ALWAYS-ON PLATFORM

More than a test. A strategic layer for real security.

Our AI is powered by a proprietary data layer built from thousands of hours of pentesting and real-world validations. Strike combines autonomous execution and expert human validation to uncover complex risks, reduce noise, and prioritize actionable findings.

In-depth continuous testing

Strikers uncover high-impact vulnerabilities across multi-technology environments (web apps, APIs, mobile, cloud, and more).

AI-led retesting on-demand

Validate fixes instantly, without waiting for the next testing cycle.

Real-time fixing

coming soon

AI agents guide your team step-by-step through remediation to accelerate resolution.

Step-by-step Threat emulation creation

Easily scope, launch, and track your Threat emulation with full transparency.

Human triaging & peer review

Every finding is validated by security experts to ensure accuracy and impact.

Full visibility

Track every finding with complete transparency through security expert work logs and real-time notifications.

Seamless integrations

Connect directly with Slack, Teams and Jira to streamline collaboration with your security and development teams.

Vulnerability Manager

Visualize, manage, and retest vulnerabilities in one platform, with full context on severity, sources, and remediation.

Compliance-ready reporting

Automatically generate up-to-date reports aligned with PCI DSS, HIPAA, ISO 27001, SOC 2, and more.

Ongoing partnership

Weekly check-ins with a dedicated Customer Success Manager, plus personalized onboarding and strategic planning.

More than an offensive security platform, Strike operates as a continuous validation layer for environments that never stop changing.

Boost your experience with Hybrid Testing Booster

Continuous Hybrid Testing

Emulated, deep stealth-based attacks executed by creative, unconventional security experts. Find out how real attackers would breach your systems, and stop them before they do.

Testimonial

Trusted by security teams that lead

"Product was great! The team was exceptional when addressing our sense of urgency with regards to an important timeline, and they were able to deliver effectively and finding important vulnerabilities within our systems."

Gartner 4
Gartner review, Head of Engineering, Banking

"Good option for agile testing, especially if GTM timelines are tight. This is especially important when the release train comes with a lot of new products and releases, making it hard to keep the pace in a traditional ad-hoc business model."

Gartner 3
Gartner review, Product Security Leader Cybersecurity, Hardware

“Strike provides continuous pentesting for our critical web and mobile features. Each month they help us validate new functionalities in production, delivering relevant vulnerabilities and strong value for money. We are very satisfied with their innovative and customer-centric approach.”

Gartner 2
Gartner review, Chief Information Security Officer, Retail

"Strike team was fast and provided the exact solution we needed for our use case. We decided to go for Strike because they provide a pen-testing suite that fits the way we work in terms of speed and communication. Highly recommended!"

Gartner review
Gartner 1
Gartner Review, Chief Technical Officer, Banking

"We greatly value our partnership with Strike. Their exceptional penetration testing services and effective communication have significantly enhanced our cybersecurity, ensuring the safety and trust of our customers' financial information."

Ozan Özgür Özyüksel
Information Security Officer, Plum

"The management of communication channels and the centralization of interactions with the team made the experience much more agile and effective. Having everything in one place was a huge advantage and allowed us to complete the pentest within just a few weeks."

Miguel Langone
CTO at Horizon

“Working with Strike is extremely important to us, especially because they deliver quality work over our products in a continuous way, and provide constant follow-up when it comes to managing the already found vulnerabilities. Moreover, they are constantly making improvements in their SaaS platform so we can have the best experience possible. In case we have a problem, they listen and help us. That’s invaluable.”

Ileana Barrionuevo
Sr AppSec Red Team, NaranjaX

“Working with Strike was an excellent experience for us. We were able to create our own pentests and change their scope each month. The Strikers are world-class professionals who provide us with relevant findings quickly and efficiently. Also, automated tools like Phishing Monitor are really interesting for our company, because they help us spot fake domains trying to impersonate PedidosYa.”

Eduardo Gimenez
CISO, Pedidos Ya

“For us at pier, security is the most important aspect, not only on the surface but throughout our entire product. When we reached out to Strike, we were looking for someone that could test & find vulnerabilities across our entire stack. We are very happy that we have found the right partner to achieve that, and we are looking forward to continuing this important work together.”

Andras Hejj
CEO & CTO, Pier

Human expertise.
AI power.
Superior security.

Whether you’re scaling fast, closing enterprise deals, or just tired of noisy reports, we’ll help you build a security stack that moves faster than your threats.

Book a Demo