Infrastructure Penetration Tests

An agent on the network. An AI operator running the playbook.

Drop a small agent onto a workstation or jump host inside the network you want tested. An AI operator picks it up, walks the full internal pentest methodology, and writes everything it sees back to the platform in real time. Discovery, Active Directory recon, BloodHound attack paths, ADCS abuse, safe credential attacks, lateral movement, all on a structured workflow that you can audit phase by phase.

Start an internal pentest View all features

From an agent install to confirmed attack paths

No tunnel, no jump server hand-offs, no operator-of-the-day building tooling from scratch. The agent connects out, the AI operator connects in, and the engagement runs end to end.

1
Deploy the agent
Install the agent on a Windows or Linux host inside the target network. It enrols with a one-time token, calls home over HTTPS, and shows up in your workspace as soon as the first heartbeat lands.
2
Define the engagement
Pick a depth (Shallow audit, Medium pentest, Deep red team), set the scope CIDRs, and optionally provide test credentials. The platform allocates the agent and hands control to the AI operator.
3
Watch the methodology run
The operator walks every required checkpoint for the chosen depth: IP sweep, service enum, DC discovery, AD baseline audit, ADCS recon, SharpHound, attack-path computation, kerberoast, AS-REP roast, password spray, nuclei, and depth-specific exploitation.
4
Get a finding pack you can use
Every host, service, finding, attack path and event lands in one workspace. The phase gate refuses to close the engagement until every required check has been addressed, so you never get a half-finished assessment dressed up as a clean report.

What an engagement actually looks like

Two views from a sample Medium-depth engagement: events recorded per methodology phase, and the network topology the operator built up while walking the playbook.

Events recorded per phase

Each bar shows how many timeline events the AI operator wrote during that phase, broken down by outcome. Skipped checkpoints stay visible so you can see where the operator chose to stand down and why.

Completed Failed (attempted) Skipped (with reason) Findings logged

Network topology built from recon

A live graph of what the operator discovered. Hover any node to see what was found there. Red edges are attack paths the operator computed from BloodHound data after SharpHound ingest finished.

Domain Controller Workstation Server / fileserver ADCS / vulnerable target Agent host

Sample timeline excerpt

00:01:14 recon IP sweep across 10.10.30.0/24, 27 alive hosts completed
00:08:40 discovery Service enum (top-100), 3 DCs identified via SRV records completed
00:42:11 ad SharpHound CollectionMethod=All ingested, 5 attack paths to Domain Admins completed
01:14:55 ad ADCS template ESC1 abusable by Domain Users discovered finding
02:03:22 credential Kerberoast: 4 SPN-bearing accounts, 1 hash cracked offline finding
02:39:08 credential Password spray, 1 attempt per account, no lockouts triggered completed
03:55:46 exploitation Nuclei (medium+critical) against discovered web services completed
05:21:30 lateral PTH against FS01 with cracked service hash, whoami /priv captured finding

Built for Active Directory, not just port scanning

Phase-gated methodology
Every depth has a fixed checklist of mandatory checkpoints. The operator records each one as completed, attempted-and-failed, or skipped with a reason. The engagement cannot close until all required phases have been honestly addressed. No skipped-only Phase 4 sneaking past as success.
BloodHound attack-path computation
SharpHound CollectionMethod=All runs from inside the network, results get ingested per kind (users, computers, groups, sessions), and the operator computes shortest paths to Domain Admins and Enterprise Admins. The result lands in an Attack Paths tab you can browse before any exploitation kicks off.
ADCS abuse coverage (ESC1 to ESC15)
certipy find -vulnerable runs against every CA the operator can reach. Each vulnerable template gets a finding documenting the ESC class, the principal that can abuse it, and the prerequisites. At Deep depth the operator attempts the matching exploitation and proves the captured identity.
Safe credential attacks by default
Kerberoasting and AS-REP roasting always crack hashes offline, never online. Password spray is throttled hard: one attempt per account per engagement at Medium, three at Deep, against a curated list of common passwords. Lockout policy is honored, never tested.
Real-time timeline by track
Every command the operator runs writes a timeline event tagged with its track: recon, discovery, AD, credential, exploitation, lateral. You can filter the timeline live as the engagement runs and see which workstation the agent is hitting right now.
Three depths for three jobs
Shallow runs a 90-minute read-only configuration audit, no exploitation. Medium runs a 6-hour pentest with safe AD attacks plus light service exploitation. Deep runs a 12-hour red-team simulation including delegation abuse, DCSync, lateral movement, and a domain-dominance attempt.

Pick the engagement that matches your authorization

Same agent, same methodology, different aggressiveness. The depth you pick is the depth the operator will execute, no scope creep.

Shallow
90minutes
A read-only configuration audit. Discovery, DC identification, full AD baseline audit, ADCS recon, configuration findings. No credential attacks, no exploitation.
  • IP sweep + DC discovery
  • AD baseline configuration audit
  • ADCS template recon (read-only)
Medium
6hours
A pentest. Adds SharpHound + attack-path computation, vulnerable ADCS template assessment, safe credential attacks, default-credential checks, and a curated nuclei pass against discovered web services.
  • SharpHound + BloodHound paths
  • Kerberoast + AS-REP roast (offline only)
  • Throttled password spray
  • Default-creds + nuclei web pass
Deep
12hours
A full red-team simulation. Adds delegation abuse, ADCS exploitation, DCSync where replication rights are obtained, lateral movement proof, and a domain-dominance attempt with a written breakdown of every viable path.
  • ADCS exploitation (ESC1, ESC4, ESC8)
  • Unconstrained / RBCD delegation abuse
  • DCSync against krbtgt + administrator
  • Lateral movement + domain dominance

Internal pentests should not be a once-a-year event

Test continuously, not annually
Internal infrastructure changes constantly: new servers come online, GPOs get edited, ADCS templates get tweaked, service accounts get added. A yearly engagement misses all of it. With an agentic workflow you can run a Shallow audit every week and a Medium pentest every month without paying for a consultancy each time.
Catch the AD misconfigurations that always burn organizations
krbtgt password not rotated, NTLMv1 still allowed, ESC1 templates abusable by Domain Users, anonymous SID enumeration, ProtectedUsers empty. These are the issues that show up in every breach report. The Shallow audit alone surfaces all of them in 90 minutes.
Validate detections without scheduling a red team
Run a Medium or Deep engagement, watch your SOC pick up SharpHound traffic, kerberoast hash requests, password spray patterns, and nuclei probes. A full audit trail of what was attempted and when, ready to compare against your detection alerts.
Give vendors and acquisitions a real security baseline
When you onboard a new subsidiary or vendor network, an agent install and a Medium engagement give you a real picture of what they have inside, what is exploitable, and what needs fixing first. Cheaper and faster than a third-party pentest, with the same coverage.

What the operator actually looks at

Pulled directly from the methodology checklist. Every Medium engagement covers all of these. Deep adds the post-exploitation tier on top.

IP sweep Service enumeration Full TCP port scan Domain Controller discovery AD baseline audit krbtgt password age SMB / LDAP signing NTLMv1 status Anonymous SID enumeration Password policy Stale account detection AdminSDHolder ADCS recon (certipy) SharpHound collection BloodHound attack paths Kerberoasting AS-REP roasting Password spray Default credential checks SMB null session Web service fingerprinting Nuclei web scan ADCS ESC1 to ESC15 abuse Unconstrained delegation RBCD abuse DCSync Pass-the-hash / Pass-the-ticket Lateral movement proof Domain dominance

Run an internal pentest from your own infrastructure

Install the agent on a host you control, pick a depth, and let the AI operator walk the playbook end to end. The phase gate makes sure nothing important gets skipped.

Have questions? Get in touch →