Offer

Free security assessment — you only subscribe if we find a P0 or P1 vulnerability.

Claim free assessment
CyVigilant
All articles
VAPT

Internal vs External Network Penetration Testing: Goals, Methodology, and What Each Finds

April 21, 2026·CyVigilant Security Team
VAPTCyVigilant

Network penetration testing is often requested as a single line item — "pentest the network" — but the discipline splits cleanly into two distinct exercises with different threat models, methodologies, and findings profiles. An external network pentest simulates an attacker on the internet with no prior access. An internal network pentest simulates an attacker who has already cleared the perimeter — a compromised employee workstation, a phished contractor, an exploited internet-facing system, or a malicious insider. Both are necessary components of a mature security programme; doing only one gives you an incomplete picture of your exposure.

External network penetration testing: the internet-facing attack surface

External pentest scope is defined by the organisation's publicly reachable IP space and DNS records — the attack surface that any internet adversary can probe without any special access. Reconnaissance starts before a single probe: passive enumeration via Shodan, Censys, SecurityTrails, Certificate Transparency logs, and BGP route data surfaces IP ranges, certificate CNAMEs, open ports, and service banners before the tester sends a single packet to the target. This passive phase often reveals forgotten assets — legacy VPN gateways, development environments with outdated software, acquired subsidiary IP ranges — that internal teams are unaware of.

Active testing then enumerates live hosts, services, and versions. Common external findings include: exposed management interfaces (RDP, SSH, WinRM, Kubernetes API server, database admin ports) accessible from the internet; web application vulnerabilities (injection, authentication bypass, broken access control); SSL/TLS weaknesses (expired certificates, weak cipher suites, HSTS not enforced); email infrastructure misconfigurations (SPF, DKIM, DMARC gaps that enable domain spoofing); and VPN or remote access solutions running end-of-life software with known CVEs.

Internal network penetration testing: the post-breach perspective

Internal pentest simulates the attacker who is already inside the perimeter — operating with the access of a standard employee workstation or a compromised server. The questions being answered are: how far can this foothold go, how quickly, and with what impact? Common starting positions are a standard domain user account (testing the assumed-breach scenario) or no credentials at all (testing whether an attacker can go from unauthenticated on the internal LAN to domain administrator through exploitation alone).

The internal attack surface is almost always larger than organisations expect. Active Directory misconfigurations drive the majority of internal pentest findings in Windows environments: Kerberoastable service accounts (weak passwords on SPNs), AS-REP roastable users (pre-authentication disabled), unconstrained delegation (allows impersonation of any user), pass-the-hash and pass-the-ticket attacks against NTLM authentication, and BloodHound/SharpHound-identified attack paths to Domain Admin. In mixed environments, legacy protocols — LLMNR, NBT-NS, NTLMv1 — enable responder-based credential capture on the internal LAN. Our penetration testing service covers these internal paths in detail.

Network segmentation: testing whether it actually holds

One of the most valuable outputs of an internal pentest is segmentation validation. Organisations invest in VLANs, firewall rules, and network access control to contain breach impact. In theory, the corporate LAN should not reach the production database VLAN; the payment processing network should be segregated from general corporate systems. In practice, firewall rules accumulate, legacy inter-VLAN routes are never cleaned up, and IT shortcuts create paths that security architects never intended. An internal pentest actively tests whether an attacker in the corporate VLAN can reach the production database, the backup infrastructure, or the out-of-band management network. For PCI-DSS compliance, segmentation testing is a hard requirement — penetration testing must validate that the Cardholder Data Environment (CDE) is effectively isolated.

What a combined internal and external pentest looks like

A full-scope network pentest typically chains the two exercises: the external phase attempts to breach the perimeter, and if successful, the internal phase uses that foothold. If the external phase does not achieve a perimeter breach (a good outcome), the internal phase begins from a defined starting position. This chained model is the most realistic simulation of how sophisticated attackers actually operate — they do not stop at the firewall. For regulated environments (RBI-regulated banks, SEBI MIIs, IRDAI-regulated insurers), the chain model is closer to what regulators expect when they mandate penetration testing as distinct from vulnerability assessment.

CyVigilant conducts both internal and external network penetration tests as standalone engagements or as part of a comprehensive security programme. To discuss scope and approach, explore our VAPT services or talk to an expert.

Get started

Put this into action.

Book a 30-minute scoping call with a CERT-In empanelled security expert.

Talk to an Expert