Home / Services

Infrastructure Pentest

Technical diagram of a segmented corporate network, showing the perimeter, an exposed service and the attack path identified between segments

Infrastructure Pentest

IT infrastructure supports the applications, services, systems and communications that are essential to how an organisation operates. Servers, firewalls, network devices, wireless networks, Internet-facing services and other assets may contain vulnerabilities that allow partial or total compromise of the environment.

The goal of an Infrastructure Pentest is to identify those vulnerabilities before they can be exploited by criminals, allowing fixes to be applied proactively and significantly reducing the risk of security incidents.

Depending on the agreed scope, the assessment can cover both internal infrastructure and Internet-facing assets.

Internal Network Pentest

An Internal Network Pentest simulates the scenario in which an attacker has already gained access to the corporate environment, whether through a compromised device, valid credentials, physical access, third parties or any other attack vector.

The goal is to assess which vulnerabilities can be exploited, which systems can be compromised and how far an intruder could move through the internal environment and reach sensitive information.

This type of assessment helps the company understand the impact of a possible compromise of the internal network and identify opportunities to strengthen security controls.

What is assessed in an Internal Network Pentest

Depending on the agreed scope, the assessment may include:

  • Network segmentation;
  • Wireless networks (Wi-Fi);
  • Windows and Linux servers;
  • Active Directory;
  • Firewalls;
  • Switches and routers;
  • Infrastructure devices;
  • File shares;
  • Insecure configurations;
  • Privilege management;
  • Authentication controls;
  • Lateral movement;
  • Privilege escalation;
  • Exposed internal services;
  • Other vulnerabilities present in the infrastructure.

External Network Pentest

An External Network Pentest simulates an attack carried out by an intruder with no prior access to the company environment, assessing only the authorised assets exposed to the Internet.

The goal is to identify vulnerabilities that could allow unauthorised access, exposure of sensitive information, compromise of systems or use of the infrastructure as an entry point for broader attacks.

This assessment makes it possible to identify existing risks before they can be exploited by criminals.

What is assessed in an External Network Pentest

Depending on the agreed scope, the assessment may include:

  • Internet-facing servers;
  • Firewalls;
  • VPNs;
  • Gateways;
  • Remote access services;
  • Edge devices;
  • Administrative Web portals;
  • Email services;
  • DNS servers;
  • Digital certificates;
  • TLS/SSL configuration;
  • Exposed services and ports;
  • Outdated components;
  • Insecure configurations;
  • Other vulnerabilities present in Internet-facing assets.

Methodology

The assessment is carried out using internationally recognised methodologies, adapted to the agreed scope and to the characteristics of the environment.

Most of the tests are executed manually by specialists, with automated tools used only to support reconnaissance, enumeration and initial validation.

During the assessment we analyse vulnerabilities related to asset configuration, service exposure, authentication, access control, privilege management, network segmentation and the other security controls present in the infrastructure.

All tests are carried out in a controlled manner and previously authorised by the company, seeking to minimise impact on normal operation of the environment.

Professional Report with Results

At the end of the assessment we deliver a technical report and an executive report containing everything needed to support the remediation of the vulnerabilities identified.

The report includes:

  • All vulnerabilities identified;
  • Severity rating (Critical, High, Medium, Low or Informational);
  • Technical evidence of the exploitation of each vulnerability found;
  • Description of the business impact;
  • Clear remediation recommendations;
  • References to security best practices.

Alongside the technical report we also provide a Penetration Test Attestation Letter, a document that certifies the tests were carried out and can be used as evidence in audits, compliance processes, vendor approval and with clients and business partners.