Measure blast radius
Understand how far an attacker can move from the agreed starting position.
Damocles Internal Network Penetration Testing models an attacker with an approved internal foothold and tests lateral movement, privilege escalation, segmentation, administrative paths and access to sensitive systems.
An internal attacker or compromised endpoint often has access to services, names, identities and trust relationships that are invisible from the internet. Internal testing evaluates how much attacker capability that foothold provides and which controls prevent or accelerate movement toward sensitive systems.
The engagement is commonly used to test segmentation, administrative design, workstation and server trust, identity exposure and the practical consequence of a compromised user or device.
Understand how far an attacker can move from the agreed starting position.
Validate whether business, server, management and restricted zones enforce the intended access.
Identify credentials, services and administrative relationships that allow escalation or control of higher-value systems.
Testing can begin from a standard user workstation, an agreed network segment, a supplied virtual foothold or another authorised starting position.
Approved user, server, management, data-centre and other internal network ranges.
Access between trust zones, restricted networks and management paths.
File, database, management, middleware and other services that can be abused or chained.
Credentials, secrets, cached access and unsafe authentication behaviour encountered during authorised testing.
Remote administration, management protocols, privileged interfaces and control-plane access.
Authorised validation of paths to systems, shares, databases and services identified as high value.
Test representative internal access to expose weak trust boundaries, credentials, services and privilege paths that could turn one compromised device into broader control.
Reachable systems, services and administrative interfaces.
Weak authentication, reusable credentials and credential material.
Paths from ordinary access to local or domain privilege.
Trust relationships and services that enable movement between systems.
Whether sensitive environments resist access from lower-trust locations.
Insecure or relayable protocols that increase compromise impact.
Security events available to trace representative activity.
These are governed procedures from the service assurance profile—not generic marketing categories. The complete matrix below records applicability, access requirements and limitations for every coverage area.
Damocles records the supplied network position, host context, identity and expected trust zone, then establishes the discovery and reachability available from that foothold.
Damocles enumerates reachable hosts, listening ports, service indicators and administrative protocols within the approved internal ranges.
Damocles maps intended trust zones to routing, firewall and ACL evidence and identifies representative boundary paths for validation.
Damocles attempts approved allowed and denied connections between actual source and destination test points and records the enforcement result.
Damocles inspects authorised endpoints, shares, service configuration and protocol behaviour for reusable credentials or credential material without bulk harvesting.
Damocles validates representative remote-management, service, trust or credential paths between approved systems and stops after minimum evidence of additional access.
Showing 6 representative areas. The full governed matrix contains 13 coverage areas.
References are shown according to the role they play in the engagement. Methodologies guide testing, taxonomies classify findings, severity methods support consistent scoring, and control mappings connect scoped evidence to broader assurance work.
Approved methodology, verification and testing guidance used to select and structure relevant procedures within the authorised scope.
Approved risk, weakness and severity references provide a consistent language for confirmed findings without replacing customer-specific business impact.
Tests representative allowed and denied information flows between approved internal source and destination points and correlates results with enforcement evidence where supplied.
Tests representative least-privilege boundaries by validating safe local, lateral and privileged paths from the agreed internal foothold and supplied identities.
Performs an authorised internal penetration test from the agreed foothold and records discovery, lateral movement, privilege paths and sensitive-system reachability.
+ 7 additional governed mappings in the full control matrix.
Jump to full control mapping ↓A prioritised technical report showing validated compromise paths, affected systems, remediation actions and retest results.
What this means: technical evidence may support risk, compliance and audit activity where the mapping is applicable. It does not by itself certify the organisation, establish complete compliance or assess controls outside the authorised scope.
Damocles begins from the agreed internal foothold, maps reachable services and identity relationships, and safely validates representative lateral and privilege paths. Configuration review supports but does not replace observed host and network results; protected systems and disruptive actions remain excluded.
Directly assessed means the engagement tests the relevant behaviour. Supporting evidence means the result can contribute to a broader control assessment. Contextual references explain relevance without claiming that the control was tested.
Operates from the supplied internal network position without assuming credentials beyond those authorised.
Uses a controlled standard identity and workstation to inspect credential, service, lateral-movement and local privilege conditions.
Analyses network, host and directory evidence to connect permissions, management paths and trust relationships.
| Coverage area | What Damocles tests | Perspective and access | Evidence produced | References and limits |
|---|---|---|---|---|
| Assumed internal foothold | Damocles records the supplied network position, host context, identity and expected trust zone, then establishes the discovery and reachability available from that foothold. | Assumed internal foothold Assessment requires approved ranges, supplied footholds, test hosts, identities, flow expectations and relevant network, host or directory evidence, selected specifically for assumed internal foothold. | Evidence records the host, service, connection, credential, permission or attack-path evidence relevant to assumed internal foothold. | Technical Guide to Information Security Testing and Assessment SP 800-115 Applicability: Applies to Assumed internal foothold when the relevant internal system, identity or trust boundary is included. Limit: The conclusion is limited to the sampled assumed internal foothold; results cover supplied footholds and test points; protected systems and disruptive actions remain excluded. |
| Internal service discovery | Damocles enumerates reachable hosts, listening ports, service indicators and administrative protocols within the approved internal ranges. | Assumed internal foothold Approved ranges, names, locations and the expected asset or interface inventory. | A discovered-item register with address, service, version or location and reconciliation status. | Technical Guide to Information Security Testing and Assessment SP 800-115 Applicability: Performed for customer-owned ranges, names, locations or interfaces listed in the authorised inventory. Limit: Discovery is point-in-time and cannot establish ownership or absence outside the approved inventory; intrusive enumeration stops at the agreed boundary. |
| Network trust zones | Damocles maps intended trust zones to routing, firewall and ACL evidence and identifies representative boundary paths for validation. | Privileged-path and configuration reviewer Assessment requires approved ranges, supplied footholds, test hosts, identities, flow expectations and relevant network, host or directory evidence, selected specifically for network trust zones. | Evidence records the host, service, connection, credential, permission or attack-path evidence relevant to network trust zones. | Technical Guide to Information Security Testing and Assessment SP 800-115 Applicability: Applies to Network trust zones when the relevant internal system, identity or trust boundary is included. Limit: The conclusion is limited to the sampled network trust zones; results cover supplied footholds and test points; protected systems and disruptive actions remain excluded. |
| Segmentation enforcement | Damocles attempts approved allowed and denied connections between actual source and destination test points and records the enforcement result. | Assumed internal foothold Assessment requires approved ranges, supplied footholds, test hosts, identities, flow expectations and relevant network, host or directory evidence, selected specifically for segmentation enforcement. | Evidence records the host, service, connection, credential, permission or attack-path evidence relevant to segmentation enforcement. | Technical Guide to Information Security Testing and Assessment SP 800-115 Applicability: Applies to Segmentation enforcement when the relevant internal system, identity or trust boundary is included. Limit: The conclusion is limited to the sampled segmentation enforcement; results cover supplied footholds and test points; protected systems and disruptive actions remain excluded. |
| Credential exposure | Damocles inspects authorised endpoints, shares, service configuration and protocol behaviour for reusable credentials or credential material without bulk harvesting. | Assumed internal foothold Assessment requires approved ranges, supplied footholds, test hosts, identities, flow expectations and relevant network, host or directory evidence, selected specifically for credential exposure. | Evidence records the host, service, connection, credential, permission or attack-path evidence relevant to credential exposure. | Technical Guide to Information Security Testing and Assessment SP 800-115 Applicability: Applies to Credential exposure when the relevant internal system, identity or trust boundary is included. Limit: The conclusion is limited to the sampled credential exposure; results cover supplied footholds and test points; protected systems and disruptive actions remain excluded. |
| Lateral movement | Damocles validates representative remote-management, service, trust or credential paths between approved systems and stops after minimum evidence of additional access. | Supplied standard user or workstation Assessment requires approved ranges, supplied footholds, test hosts, identities, flow expectations and relevant network, host or directory evidence, selected specifically for lateral movement. | Evidence records the host, service, connection, credential, permission or attack-path evidence relevant to lateral movement. | Technical Guide to Information Security Testing and Assessment SP 800-115 Applicability: Applies to Lateral movement when the relevant internal system, identity or trust boundary is included. Limit: The conclusion is limited to the sampled lateral movement; results cover supplied footholds and test points; protected systems and disruptive actions remain excluded. |
| Local privilege escalation | Damocles examines local groups, rights, services, scheduled tasks, stored credentials, installed software and host configuration for a safe path to local administrative access. | Supplied standard user or workstation Assessment requires approved ranges, supplied footholds, test hosts, identities, flow expectations and relevant network, host or directory evidence, selected specifically for local privilege escalation. | Evidence records the host, service, connection, credential, permission or attack-path evidence relevant to local privilege escalation. | Technical Guide to Information Security Testing and Assessment SP 800-115 Applicability: Applies to Local privilege escalation when the relevant internal system, identity or trust boundary is included. Limit: The conclusion is limited to the sampled local privilege escalation; results cover supplied footholds and test points; protected systems and disruptive actions remain excluded. |
| Domain privilege escalation | Damocles analyses directory groups, ACLs, delegation, service accounts and identity relationships for a safe path to increased domain privilege. | Supplied standard user or workstation Assessment requires approved ranges, supplied footholds, test hosts, identities, flow expectations and relevant network, host or directory evidence, selected specifically for domain privilege escalation. | Evidence records the host, service, connection, credential, permission or attack-path evidence relevant to domain privilege escalation. | Technical Guide to Information Security Testing and Assessment SP 800-115 Applicability: Applies to Domain privilege escalation when the relevant internal system, identity or trust boundary is included. Limit: The conclusion is limited to the sampled domain privilege escalation; results cover supplied footholds and test points; protected systems and disruptive actions remain excluded. |
| Administrative protocols | Damocles tests approved administrative protocols for authentication, signing, encryption and access restrictions from the supplied foothold. | Assumed internal foothold Current configuration export or read-only access, diagrams, owners and representative validation endpoints. | Configuration excerpts, object or rule identifiers and observed validation results. | Technical Guide to Information Security Testing and Assessment SP 800-115 Applicability: Performed when current configuration evidence and a representative endpoint or device are included in the review. Limit: A configuration snapshot cannot prove continuous enforcement across excluded nodes; validation avoids changes unless implementation work is authorised. |
| Management-plane exposure | Damocles determines whether standard footholds can reach network, security, hypervisor, backup or infrastructure management interfaces contrary to the intended model. | Privileged-path and configuration reviewer Current configuration export or read-only access, diagrams, owners and representative validation endpoints. | Configuration excerpts, object or rule identifiers and observed validation results. | Technical Guide to Information Security Testing and Assessment SP 800-115 Applicability: Performed when current configuration evidence and a representative endpoint or device are included in the review. Limit: A configuration snapshot cannot prove continuous enforcement across excluded nodes; validation avoids changes unless implementation work is authorised. |
| Sensitive-system reachability | Damocles attempts named required and forbidden protocols to approved high-value destinations from representative footholds. | Assumed internal foothold Named source and destination test points, expected flow matrix and a safe test window. | Source-to-destination results linked to rule, route or boundary evidence; the record names the tested sensitive-system reachability object, path or control and its observed result. | Technical Guide to Information Security Testing and Assessment SP 800-115 Applicability: Performed when both ends of the network path and the enforcing device are owned or expressly authorised for testing. Limit: Results cover the tested source, destination, protocol and route; testing stops on instability and does not authorise third-party or denial-of-service activity. |
| Attack-path chaining | Damocles joins observed foothold, credential, privilege, lateral-movement and sensitive-system reachability evidence into a reproducible attack chain. | Assumed internal foothold Named source and destination test points, expected flow matrix and a safe test window. | Source-to-destination results linked to rule, route or boundary evidence; the record names the tested attack-path chaining object, path or control and its observed result. | Technical Guide to Information Security Testing and Assessment SP 800-115 Applicability: Performed when both ends of the network path and the enforcing device are owned or expressly authorised for testing. Limit: Results cover the tested source, destination, protocol and route; testing stops on instability and does not authorise third-party or denial-of-service activity. |
| Protected and excluded systems | Damocles marks protected and excluded systems in the test inventory, prevents active interaction with them and records how each exclusion constrains discovery or path conclusions. | Assumed internal foothold Assessment requires approved ranges, supplied footholds, test hosts, identities, flow expectations and relevant network, host or directory evidence, selected specifically for protected and excluded systems. | Evidence records the host, service, connection, credential, permission or attack-path evidence relevant to protected and excluded systems. | Technical Guide to Information Security Testing and Assessment SP 800-115 Applicability: Applies to Protected and excluded systems when the relevant internal system, identity or trust boundary is included. Limit: The conclusion is limited to the sampled protected and excluded systems; results cover supplied footholds and test points; protected systems and disruptive actions remain excluded. |
| Framework and controls | Mapping type | What Damocles assesses | Evidence produced | Applicability and limits |
|---|---|---|---|---|
| Security and Privacy Controls for Information Systems and Organizations Release 5.2.0 AC-4 | Directly assessed | Tests representative allowed and denied information flows between approved internal source and destination points and correlates results with enforcement evidence where supplied. | Source-to-destination results, enforcing rule or route evidence and observed bypass or unexpected reachability findings. | Applies: Applies where representative trust zones, source hosts, destinations and expected flows are included. Limit: Only sampled paths are established; alternate paths, excluded zones and continuous enforcement remain outside the conclusion. |
| Security and Privacy Controls for Information Systems and Organizations Release 5.2.0 AC-6 | Directly assessed | Tests representative least-privilege boundaries by validating safe local, lateral and privileged paths from the agreed internal foothold and supplied identities. | Credential, permission, service and privilege-path evidence showing the minimum validated transition. | Applies: Applies to authorised systems and identities where privilege or lateral-movement testing is included. Limit: Does not establish least privilege for every user, service, host or permission and validation stops at the minimum safe proof. |
| Security and Privacy Controls for Information Systems and Organizations Release 5.2.0 CA-8 | Supporting evidence | Performs an authorised internal penetration test from the agreed foothold and records discovery, lateral movement, privilege paths and sensitive-system reachability. | Rules of engagement, internal service inventory, lateral-movement records, privilege-path evidence, findings and retest records where included. | Applies: Relevant where the customer uses internal penetration testing within a broader assessment program. Limit: Does not establish testing frequency, enterprise coverage, assessor governance or completeness of the broader program. |
| Information Security Manual June 2026 ISM-1181 | Directly assessed | Tests representative network-zone segregation by exercising approved allowed and denied paths between selected internal trust zones. | Source and destination records, expected flow matrix, observed connectivity outcome and enforcement evidence. | Applies: Applies where the customer supplies defined network zones, test points and expected flows. Limit: Testing proves only sampled paths and does not establish that every network segment, route or enforcement point satisfies ISM-1181. |
| Information Security Manual June 2026 ISM-2118 | Supporting evidence | Provides scoped internal penetration-test evidence that can support an organisation's security-assurance testing program. | Authorised scope, discovered services, validated compromise paths, remediation guidance and retest results where included. | Applies: Relevant where the organisation uses the engagement within its vulnerability-assessment and penetration-testing program. Limit: A single engagement does not establish required testing cadence, full asset coverage or compliance with ISM-2118. |
| Prudential Standard CPS 234 Information Security effective 1 July 2019 CPS 234 paragraph 27 | Supporting evidence | Produces scoped internal network penetration-testing evidence that may support an APRA-regulated entity's systematic testing of information-security control effectiveness. | Governed scope, internal reachability and compromise-path evidence, findings, remediation guidance and retest results where included. | Applies: Relevant only where the customer determines that the assessed internal systems and evidence are applicable to its assurance or compliance scope. For APRA-regulated entities, the customer determines how the engagement contributes to its broader systematic control-testing program. Limit: A scoped engagement does not by itself establish the customer's systematic testing program, testing frequency, full control population, specialist independence, governance, reporting or compliance with other CPS 234 requirements. |
| Prudential Practice Guide CPG 234 Information Security published June 2019 Framework-level context | Contextual | Produces scoped internal network penetration-testing evidence consistent with CPG 234 guidance that testing techniques should be selected for the control and risk being assessed. | Governed scope, internal reachability and compromise-path evidence, findings, remediation guidance and retest results where included. | Applies: Relevant only where the customer determines that the assessed internal systems and evidence are applicable to its assurance or compliance scope. APRA-regulated customers determine how this evidence contributes to their broader assurance program. Limit: CPG 234 is prudential guidance rather than a standalone certification target; this mapping does not claim assessment of the complete guidance or customer compliance. |
| ISO/IEC 27001 2022 with Amendment 1:2024 Framework-level context | Contextual | Produces scoped internal network penetration-testing evidence that may support customer assurance activities organised around ISO/IEC 27001 where the assessed systems and behaviours are relevant. | Governed scope, internal reachability and compromise-path evidence, findings, remediation guidance and retest results where included. | Applies: Relevant only where the customer determines that the assessed internal systems and evidence are applicable to its assurance or compliance scope. Limit: Licensed ISO/IEC 27001 control or requirement identifiers and text are intentionally withheld. The engagement does not establish ISO/IEC 27001 certification, attestation or whole-framework conformity. |
| ISO/IEC 27002 2022 Framework-level context | Contextual | Produces scoped internal network penetration-testing evidence that may support customer assurance activities organised around ISO/IEC 27002 where the assessed systems and behaviours are relevant. | Governed scope, internal reachability and compromise-path evidence, findings, remediation guidance and retest results where included. | Applies: Relevant only where the customer determines that the assessed internal systems and evidence are applicable to its assurance or compliance scope. Limit: Licensed ISO/IEC 27002 control or requirement identifiers and text are intentionally withheld. The engagement does not establish ISO/IEC 27002 certification, attestation or whole-framework conformity. |
| Payment Card Industry Data Security Standard 4.0.1 Framework-level context | Contextual | Produces scoped internal network penetration-testing evidence that may support customer assurance activities organised around PCI DSS where the assessed systems and behaviours are relevant. | Governed scope, internal reachability and compromise-path evidence, findings, remediation guidance and retest results where included. | Applies: Relevant only where the customer determines that the assessed internal systems and evidence are applicable to its assurance or compliance scope. Limit: Licensed PCI DSS control or requirement identifiers and text are intentionally withheld. The engagement does not establish PCI DSS certification, attestation or whole-framework conformity. |
Assurance boundary: Damocles maps assessed coverage and findings to agreed security frameworks and control objectives. This provides traceable technical evidence that may support risk, assurance and audit activities. A penetration test does not by itself certify an organisation, establish complete compliance with a framework or confirm the effectiveness of controls outside the authorised scope.
Records authorised scope and rules of engagement produced from the authorised Internal network penetration testing work.
Records coverage matrix produced from the authorised Internal network penetration testing work.
Records retest and residual-risk record produced from the authorised Internal network penetration testing work.
Records internal service inventory produced from the authorised Internal network penetration testing work.
Records lateral-movement path record produced from the authorised Internal network penetration testing work.
Records privilege-path evidence produced from the authorised Internal network penetration testing work.
A prioritised technical report showing validated compromise paths, affected systems, remediation actions and retest results.
The test focuses on practical movement and impact rather than attempting every possible host exploit.
Movement between hosts and services using available trust, credentials and management paths.
Paths from standard access to local, service, administrative or broader privileged control.
Unintended paths between user, server, management or restricted networks.
Reusable, exposed or over-privileged credentials that expand attacker access.
Administrative interfaces and protocols that provide control beyond the intended user role.
Multiple weaknesses combined to reach a sensitive host, system or administrative boundary.
The statement of work identifies the supplied foothold, accounts, networks, prohibited systems and intended target outcomes.
Start from a standard workstation or equivalent position and assess movement and privilege.
Start with approved user credentials and test accessible services, privilege and trust relationships.
Focus on whether approved source zones can reach systems and management paths they should not.
Assess multiple internal ranges and trust zones under a wider assumed-breach scenario.
Findings are linked to the starting position, attack path and affected control boundary.
Clear explanation of what the initial foothold could reach and why that matters.
Step-by-step lateral movement and privilege path where issues can be chained.
Evidence of unintended access between trust zones and the affected policy or architecture.
Affected host or service, exploit condition, evidence, impact and remediation guidance.
Fix order focused on breaking high-value movement and privilege paths.
Validation of agreed fixes and segmentation changes where retesting is included.
A meaningful internal retest reproduces the original path from the agreed starting position and checks the changed control, segmentation or privilege condition.
Where remediation changes the architecture substantially, Damocles records the new scope required rather than pretending the original limited retest covers the redesigned environment.
The commercial scope comes first. Delivery is then controlled through written authority, agreed safety boundaries and a clear retest path.
Confirm targets, ownership, attacker perspective, accounts, exclusions, timing, contacts and prohibited activity.
Perform the authorised manual and technical testing required to prove or disprove the attack paths in scope.
Provide evidence, impact, affected scope, remediation priorities and a technical walkthrough with the people responsible for the fix.
Reproduce agreed findings after remediation and record whether they are resolved, reduced or still exploitable.
High-risk production actions, destructive testing, uncontrolled credential attacks and access to specially protected systems require explicit written approval.
Active Directory and identity abuse can be included within an internal test, but a dedicated identity engagement provides deeper coverage when directory and privilege architecture are the primary concern.
We will define the internal ranges, accounts, segmentation boundaries, prohibited systems, evidence and retest scope required.