New · Release 2026.04, Multi-tenant audit exports & SLA dashboards now live See changelog →
Network VAPT

Network penetration testing, internal and external

Test the perimeter an attacker reaches first and the lateral movement they would attempt next — firewalls, servers, VPN endpoints and Active Directory, under agreed rules of engagement.

Product illustration · sample data
Security & VAPT
A+ score
EngagementHTTP LabReport PDF
A+
Last scan · 2 hours ago
Critical vulnerabilities0
High severity2
Manual + imported4
Engagement reportReady
Product proof

Already live in the product

Infronest module

This engagement can align with shipped product capabilities in your tenant workspace.

Protected app route: /vapt
Platform

Included in the Infronest workspace

These capabilities ship in the product today—consulting adds human validation and attestation where required.

  • Automated web scanning
  • Scoped engagements
  • HTTP Lab
  • Manual & imported findings
  • Analyst workbench
  • Audit-ready reports
Capabilities

What you get

Delivered with AI-assisted engineering and human review on architecture, security, and production readiness.

External scope: internet-facing IPs, VPN and remote access
Internal scope: lateral movement, privilege escalation, AD weaknesses
Scoped engagements with written rules of engagement
Proof-of-concept evidence for every exploited finding
Retest to confirm remediation held
Workflow

What teams can do here

Step 1
Agree scope and rules
Step 2
Discover and enumerate
Step 3
Exploit and pivot
Step 4
Report and retest
How it works

How it works

01
Agree scope and rules of engagement
We define external and internal targets, testing windows and safety limits in writing before anything runs, aligned to PTES and NIST SP 800-115. Network penetration testing is consulting-led, not a self-serve button.
02
Discover and enumerate
Automated discovery (an nmap-based service/version scan, port scanning, TLS checks and DNS/subdomain enumeration) inventories live hosts and flags commonly risky exposed services such as SMB, RDP, Redis or exposed databases.
03
Exploit and pivot (human-led)
A tester manually validates and, within the agreed rules, attempts exploitation, privilege escalation and lateral movement — including Active Directory weaknesses. This step is performed by people, not the scanner.
04
Report and re-test
Every exploited finding ships with proof-of-concept evidence and CVSS scoring, followed by a re-test to confirm remediation held.
Example

A worked example

Take a mid-size manufacturer with 12 public IPs and a 300-host LAN ahead of a PCI review. After signed rules of engagement, discovery flags exposed RDP and a stale TLS configuration externally, plus an unauthenticated Redis instance and SMB signing disabled inside. The automation stops there. A tester verifies the Redis exposure leaks data and, from a low-privilege foothold, demonstrates lateral movement toward a domain controller — captured as proof-of-concept, not left as theory. The report ranks all five issues by CVSS, and the re-test after hardening confirms the RDP and Redis exposures are closed.

FAQ

Frequently asked questions

What is the difference between external and internal network testing?
External testing targets the internet-facing surface an attacker reaches first — public IPs, VPN and remote-access endpoints. Internal testing assumes a foothold and looks at lateral movement, privilege escalation and Active Directory weaknesses. Most engagements scope both.
How much does a network penetration test cost in India?
Combined network + web VAPT for a mid-size environment typically runs ₹5–15 lakh (USD 6,000–18,000) in the Indian market, while a focused web application test alone is usually ₹1.5–4 lakh (USD 2,000–5,000). Network engagements are consulting-led and quoted on host count, segmentation and depth; Infronest application engagements start at ₹36,750 — scope yours on a demo call.
How long does a network penetration test take?
Typical industry ranges: an external-only test on a small IP range often runs one to two weeks, while combined external + internal engagements for a mid-size network run two to four weeks including reporting. Active-Directory-heavy internal scopes trend longer; a scoped web application test, for comparison, is typically one to three weeks.
How much of the network test is automated versus done by a person?
Discovery and service enumeration are automated (nmap-based scanning, port and TLS checks, risky-service flagging). Exploitation, pivoting and privilege escalation are performed by a human tester under agreed rules — the platform does not autonomously attack your network.
Do you actually exploit and pivot, or only scan?
Within the written rules of engagement, yes — a tester validates findings and attempts controlled exploitation and lateral movement, and every exploited issue is backed by proof-of-concept evidence rather than a scanner guess.
What are the rules of engagement and do you need our approval?
Nothing runs without your signed authorisation. The rules of engagement fix the in-scope IPs, testing windows, off-limits systems and escalation contacts up front, following PTES and NIST SP 800-115.
Could the test disrupt production systems?
We design to avoid it — timing windows, throttled scanning and agreed exclusions. Higher-risk actions are only attempted with explicit sign-off, and fragile production systems can be tested in a maintenance window or against a mirror.

See also: VAPT product hub · Cloud penetration testing · How network pentesting works (blog) · Internal vs external pentesting (blog) · Book a demo

VAPT

All VAPT services

Related

Explore connected offerings

See what an attacker reaches from your perimeter — and after it

Consulting-led external and internal testing under signed rules of engagement, with every exploited path backed by proof-of-concept evidence a reviewer can trust.