---
title: Internal IT Infrastructure Penetration Test
url: https://www.vidrasec.com/services/internal-it-infrastructure-penetration-test/
description: Internal IT infrastructure penetration test: can an attacker reach Domain Admin after one wrong click? Active Directory and network. From 8,000 euros.
---


**An Internal IT Infrastructure Penetration Test simulates an attacker who already has a foothold inside your network (for example after a phishing click) and tests whether they can move laterally and reach Domain Admin.**

Someone on your team **clicks the wrong email attachment**, and an attacker is inside your network. What happens next depends on what they find there: does the attack stop at one machine, or do they move laterally and **take over every system you run**? This test answers that question before a real attacker does.

External infrastructure is usually well secured these days. The internal network is a different story: **no encryption**, **security mechanisms turned off** (legacy software does not support them), **completely outdated software**. In the worst case, these vulnerabilities lead to a **complete compromise of company data**. Regular internal infrastructure penetration testing finds these weaknesses before an attacker does.

## Scope

This penetration test can be tailored to focus on specific systems, such as a particular server or the configuration of Windows clients, as determined during the scoping call. Moreover, this test can assess your detection capabilities, although it's important to note that detection is not the primary focus of a penetration test. These are the main focus points of the test:

* **Penetration test of Active Directory**, including credential attacks such as dumping local hashes (see [Dumping Hashes in Windows 11 24H2](/blog/dump-hashes-in-windows-11-24h2/)) and mapping attack paths to Domain Admin with [BloodHound](/blog/bloodhound-intro/)
* Check whether all **recommended countermeasures** are in place
* **Identification of vulnerabilities** in the network
* **Identification of outdated software** in the network
* **Misconfigurations**, e.g., Active Directory Certificate Services or [AD Tiering gaps](/blog/active-directory-tiering/)
* Test for open file shares with confidential data
* And overall: **can an attacker gain Domain Admin rights** in your network?

*Looking for the external test instead? This one covers your internal network and Active Directory. To test your internet-facing systems (servers, VPNs, mail, remote access) from an attacker's perspective outside your network, see the [External IT Infrastructure Penetration Test](/services/external-it-infrastructure-penetration-test/).*

## Why

* A single phishing click gives a real attacker exactly the starting position this test simulates: **a normal user account inside your network**
* **Active Directory misconfigurations, legacy protocols, and weak segmentation** regularly open a path from that account all the way to Domain Admin
* Ransomware groups automate exactly these attack paths. Closing them decides whether one infected client stays an incident or becomes a company-wide outage
* Your infrastructure changes constantly; only regular testing catches the misconfigurations that creep in over time

## Why VidraSec 🦦

{{< trust >}}

I have, many times, gained Domain Admin rights, starting just as a normal user, in many different types of companies. Small or big makes no difference: there are always vulnerabilities. If I can do it, an attacker can also do it. And I hope that my explaining the vulnerabilities and how to fix them in a report is more pleasant than an attacker explaining where to send the Bitcoins. If you are comparing internal pentest services, the [example reports](/example-reports/) show exactly what you get.

Note: This test includes Active Directory testing from an attacker's perspective (can I reach Domain Admin?). An [Active Directory Audit](/services/active-directory-audit/) is a separate, deeper white-box analysis of AD configuration. Both are complementary and often combined.

## Typical Duration

**3 to 5 days** of testing (up to 2 weeks for large environments). Reporting takes roughly 30 to 50% of the test time on top.

## Typical Price

**from 8,000 €**

The final price depends on the scope and is calculated from the planned effort, which the offer itemizes transparently (person-days times daily rate). The offer total is the final price: if the actual effort ends up a little over or under the estimate, the price stays the same.

{{< mid-cta >}}

## Deliverables

Every engagement includes:
* Written findings report with all vulnerabilities, prioritized by severity, with remediation steps
* Management summary tailored to your audience (technical or executive)
* Live debriefing to walk through findings and answer questions
* Retesting after remediation available on request

See [example reports](/example-reports/) for what a VidraSec report looks like.

## Compliance

Directly relevant for **NIS2** (Article 21, security of network and information systems), **ISO 27001**, and **TISAX** (automotive industry).


## Frequently asked questions

**Why do I need an internal penetration test if my perimeter is secure?**

Perimeters are increasingly well secured, but internal networks often are not. A single wrong click can put an attacker inside, where weak segmentation, legacy software, and Active Directory misconfigurations frequently allow full compromise. The internal test measures that real-world risk.

**Does the internal penetration test require on-site presence?**

Internal pentests are generally performed on-site, but can be done remotely via VPN or a dedicated jump host if your network setup allows it. This is agreed during scoping.

**How long does an internal penetration test take?**

Typically 3 to 5 days of testing, up to 2 weeks for large environments, plus roughly 30 to 50 percent of that time for reporting.

**How much does an internal penetration test cost?**

From 8,000 euros. The final price depends on the size of the environment and is calculated individually based on the required effort.

**How does the fixed price work?**

The offer itemizes the planned effort transparently (person-days times daily rate), so you see exactly how the price is calculated. The offer total is the final price: if the actual effort ends up a little over or under the estimate, the price stays the same, and you always receive the full agreed deliverables.

**What company sizes is an internal penetration test suitable for?**

Internal infrastructure penetration testing makes sense for practically any organization that runs its own network and Active Directory, from small and mid-sized businesses to large enterprises. The effort scales with the size of the environment, so smaller networks need fewer testing days and cost less.


## Related Services

* [**External IT Infrastructure Penetration Test**](/services/external-it-infrastructure-penetration-test/)
* [**Active Directory Audit**](/services/active-directory-audit/)
* [**Cyber Attack Simulation**](/services/cyber-attack-simulation/)

