24/7 SOC monitoring & incident responsesales@bugfoe.com
BestPentestingby BugFoe
Offensive Security

Network & Infrastructure Penetration Testing

External tests show whether attackers can get in. Internal tests show what happens once they do. We deliver both — remotely or on site.

Attack path focus LIVE

  • External perimeter & VPN testing
  • Active Directory attack paths
  • PCI DSS segmentation testing
  • Wireless and VoIP assessments

Overview

Ransomware groups rarely need zero-days. They get in through an unpatched VPN appliance, an exposed remote desktop service or a phished laptop — and then move laterally through flat networks and over-privileged accounts until they reach domain admin and your backups.

Our external tests map and attack everything you expose to the internet. Our internal tests start from an assumed-breach position — a standard user on a corporate device — and show the path an attacker would take to your most critical systems.

For organisations with offices, warehouses or plants, we also assess wireless networks and VoIP systems, which are frequently overlooked entry points.

What's included

External perimeterInternet-facing hosts, VPN and remote access, email gateways and exposed services.
Active DirectoryKerberos attacks, certificate services, delegation, ACL abuse and credential exposure.
SegmentationValidation that sensitive zones (e.g., cardholder data) are isolated as designed.
Internal servicesUnpatched servers, management interfaces, file shares and legacy protocols.
WirelessWPA2/WPA3 configuration, enterprise authentication, guest isolation and rogue access points.
VoIPSIP infrastructure, VLAN hopping, toll fraud exposure and call interception risks.

Our approach

  1. DiscoveryAsset discovery and service enumeration across agreed IP ranges and domains.
  2. Vulnerability analysisCombining scanning with manual validation to remove false positives.
  3. Exploitation & escalationSafe exploitation and privilege escalation toward agreed objectives.
  4. Lateral movementDemonstrating realistic paths to crown-jewel systems and data.
  5. Report & retestAttack narrative, prioritised fixes and verification of remediation.

What you receive

  • External exposure map
  • Internal attack path narrative
  • Segmentation test results (PCI DSS)
  • Active Directory hardening recommendations
  • Retest report and attestation letter

Standards & frameworks

  • PTES
  • NIST SP 800-115
  • PCI DSS 11.4
  • MITRE ATT&CK
  • CIS Controls

Frequently asked questions

Can internal testing be done remotely?

Yes. We provide a pre-configured virtual machine or small device that connects securely back to our testers, avoiding travel costs.

How often should network tests be performed?

At least annually and after significant infrastructure change. PCI DSS requires internal and external testing at least every 12 months and after significant changes.

Will you take down our network?

No. We avoid disruptive techniques unless explicitly agreed and coordinate testing windows for fragile systems.

Engagement timeline

What working with us looks like

Typical timeline for Network & Infrastructure — we confirm exact dates in your proposal.

01Day 0ScopeCall, scope and fixed-price proposal
02Week 1Kick-offAccess, accounts and rules of engagement
03Week 1–2TestingManual testing with real-time critical alerts
04Week 2–3ReportExecutive + technical report and debrief
05+30 daysRetestFix verification and attestation letter
Sample report

Reports engineers can fix from and auditors accept

  • Executive summary in business language
  • Risk-rated findings with reproduction steps
  • Developer-ready remediation guidance
  • Retest results and attestation letter
Request a sample report

Ready to find your risks before attackers do?

Tell us what you need tested or monitored. A senior consultant replies within one business day with a scoped, fixed-price proposal.

  • Fixed-price proposal
  • Reply within 1 business day
  • NDA on request