Internal network penetration testing

Find out what happens after a workstation, account or internal position is compromised.

Damocles Internal Network Penetration Testing models an attacker with an approved internal foothold and tests lateral movement, privilege escalation, segmentation, administrative paths and access to sensitive systems.

Assumed internal footholdLateral movement and privilegeSegmentation validationSensitive-system access
Why customers buy this test

Understand how far an attacker could move inside your network.

An internal attacker or compromised endpoint often has access to services, names, identities and trust relationships that are invisible from the internet. Internal testing evaluates how much attacker capability that foothold provides and which controls prevent or accelerate movement toward sensitive systems.

The engagement is commonly used to test segmentation, administrative design, workstation and server trust, identity exposure and the practical consequence of a compromised user or device.

01

Measure blast radius

Understand how far an attacker can move from the agreed starting position.

02

Test segmentation

Validate whether business, server, management and restricted zones enforce the intended access.

03

Find privilege paths

Identify credentials, services and administrative relationships that allow escalation or control of higher-value systems.

What we test

Internal hosts, services, trust zones and administrative paths in the agreed environment.

Testing can begin from a standard user workstation, an agreed network segment, a supplied virtual foothold or another authorised starting position.

NW

Internal networks

Approved user, server, management, data-centre and other internal network ranges.

SG

Segmentation controls

Access between trust zones, restricted networks and management paths.

SV

Internal services

File, database, management, middleware and other services that can be abused or chained.

CR

Credential exposure

Credentials, secrets, cached access and unsafe authentication behaviour encountered during authorised testing.

AD

Administrative paths

Remote administration, management protocols, privileged interfaces and control-plane access.

DA

Data and sensitive systems

Authorised validation of paths to systems, shares, databases and services identified as high value.

Technical assurance

See how far an attacker could move inside your network.

Test representative internal access to expose weak trust boundaries, credentials, services and privilege paths that could turn one compromised device into broader control.

Internal exposure

Reachable systems, services and administrative interfaces.

Identity and credentials

Weak authentication, reusable credentials and credential material.

Privilege escalation

Paths from ordinary access to local or domain privilege.

Lateral movement

Trust relationships and services that enable movement between systems.

Segmentation

Whether sensitive environments resist access from lower-trust locations.

Legacy protocols

Insecure or relayable protocols that increase compromise impact.

Operational visibility

Security events available to trace representative activity.

13governed test areas
3authorised testing perspectives
6controlled evidence outputs
10framework / control evidence mappings
What we actually test

Representative technical coverage with the evidence produced.

These are governed procedures from the service assurance profile—not generic marketing categories. The complete matrix below records applicability, access requirements and limitations for every coverage area.

Jump to full coverage matrix ↓
Coverage area

Assumed internal foothold

Damocles records the supplied network position, host context, identity and expected trust zone, then establishes the discovery and reachability available from that foothold.

Evidence producedEvidence records the host, service, connection, credential, permission or attack-path evidence relevant to assumed internal foothold.
Framework references
Technical Guide to Information Security Testing and Assessment SP 800-115
Coverage area

Internal service discovery

Damocles enumerates reachable hosts, listening ports, service indicators and administrative protocols within the approved internal ranges.

Evidence producedA discovered-item register with address, service, version or location and reconciliation status.
Framework references
Technical Guide to Information Security Testing and Assessment SP 800-115
Coverage area

Network trust zones

Damocles maps intended trust zones to routing, firewall and ACL evidence and identifies representative boundary paths for validation.

Evidence producedEvidence records the host, service, connection, credential, permission or attack-path evidence relevant to network trust zones.
Framework references
Technical Guide to Information Security Testing and Assessment SP 800-115
Coverage area

Segmentation enforcement

Damocles attempts approved allowed and denied connections between actual source and destination test points and records the enforcement result.

Evidence producedEvidence records the host, service, connection, credential, permission or attack-path evidence relevant to segmentation enforcement.
Framework references
Technical Guide to Information Security Testing and Assessment SP 800-115
Coverage area

Credential exposure

Damocles inspects authorised endpoints, shares, service configuration and protocol behaviour for reusable credentials or credential material without bulk harvesting.

Evidence producedEvidence records the host, service, connection, credential, permission or attack-path evidence relevant to credential exposure.
Framework references
Technical Guide to Information Security Testing and Assessment SP 800-115
Coverage area

Lateral movement

Damocles validates representative remote-management, service, trust or credential paths between approved systems and stops after minimum evidence of additional access.

Evidence producedEvidence records the host, service, connection, credential, permission or attack-path evidence relevant to lateral movement.
Framework references
Technical Guide to Information Security Testing and Assessment SP 800-115

Showing 6 representative areas. The full governed matrix contains 13 coverage areas.

Standards and assurance coverage

See how this engagement is structured, classified and mapped before opening the full evidence matrix.

References are shown according to the role they play in the engagement. Methodologies guide testing, taxonomies classify findings, severity methods support consistent scoring, and control mappings connect scoped evidence to broader assurance work.

01 · Test method

How testing is structured

Approved methodology, verification and testing guidance used to select and structure relevant procedures within the authorised scope.

Technical Guide to Information Security Testing and Assessment SP 800-115
02 · Finding language

How weaknesses and severity are classified

Approved risk, weakness and severity references provide a consistent language for confirmed findings without replacing customer-specific business impact.

Common Weakness Enumeration 4.20Common Vulnerability Scoring System 4.0
03 · Control evidence

What maps into compliance and assurance work

10governed evidence mappings across 7 approved frameworks and 6 referenced controls.
3 directly assessed3 supporting evidence4 contextual
Security and Privacy Controls for Information Systems and Organizations Release 5.2.0Directly assessed
AC-4

Tests representative allowed and denied information flows between approved internal source and destination points and correlates results with enforcement evidence where supplied.

Security and Privacy Controls for Information Systems and Organizations Release 5.2.0Directly assessed
AC-6

Tests representative least-privilege boundaries by validating safe local, lateral and privileged paths from the agreed internal foothold and supplied identities.

Security and Privacy Controls for Information Systems and Organizations Release 5.2.0Supporting evidence
CA-8

Performs an authorised internal penetration test from the agreed foothold and records discovery, lateral movement, privilege paths and sensitive-system reachability.

+ 7 additional governed mappings in the full control matrix.

Jump to full control mapping ↓
04 · Evidence package

What the customer can use after the engagement

A prioritised technical report showing validated compromise paths, affected systems, remediation actions and retest results.

  • Authorised scope and rules of engagement
  • Coverage matrix
  • Retest and residual-risk record
  • + 3 additional controlled outputs

What this means: technical evidence may support risk, compliance and audit activity where the mapping is applicable. It does not by itself certify the organisation, establish complete compliance or assess controls outside the authorised scope.

How we test

Manual validation backed by controlled evidence.

Damocles begins from the agreed internal foothold, maps reachable services and identity relationships, and safely validates representative lateral and privilege paths. Configuration review supports but does not replace observed host and network results; protected systems and disruptive actions remain excluded.

How to read the mapping

Evidence is mapped to the part of a control we can actually assess.

Directly assessed means the engagement tests the relevant behaviour. Supporting evidence means the result can contribute to a broader control assessment. Contextual references explain relevance without claiming that the control was tested.

All relevant frameworks
Technical Guide to Information Security Testing and Assessment SP 800-115Information Security Manual June 2026Common Weakness Enumeration 4.20Common Vulnerability Scoring System 4.0Security and Privacy Controls for Information Systems and Organizations Release 5.2.0Prudential Standard CPS 234 Information Security effective 1 July 2019Prudential Practice Guide CPG 234 Information Security published June 2019ISO/IEC 27001 2022 with Amendment 1:2024ISO/IEC 27002 2022Payment Card Industry Data Security Standard 4.0.1
Testing perspectives3 authorised viewpoints and access models

Assumed internal foothold

Operates from the supplied internal network position without assuming credentials beyond those authorised.

Included when
Used to establish discovery and reachability available after an initial internal compromise.
Access required
A test host or connection, source subnet, expected trust zone, approved ranges and exclusions.
Limitations
Represents one foothold and cannot establish access from every internal segment.

Supplied standard user or workstation

Uses a controlled standard identity and workstation to inspect credential, service, lateral-movement and local privilege conditions.

Included when
Used where user or endpoint context materially changes reachable services or permissions.
Access required
A dedicated domain or local identity, representative workstation and expected user rights.
Limitations
Does not represent other builds, groups, cached sessions or privileged identities.

Privileged-path and configuration reviewer

Analyses network, host and directory evidence to connect permissions, management paths and trust relationships.

Included when
Used to substantiate attack paths or compare observed behaviour with intended controls.
Access required
Relevant ACLs, firewall and routing exports, directory evidence, system inventories and access models.
Limitations
Evidence review cannot prove every live path and validation stops at the minimum safe proof.
Exact test coverage and evidence13 governed coverage areas
What Damocles tests, the evidence produced and the scope boundary for each controlled coverage area.
Coverage areaWhat Damocles testsPerspective and accessEvidence producedReferences and limits
Assumed internal footholdDamocles records the supplied network position, host context, identity and expected trust zone, then establishes the discovery and reachability available from that foothold.Assumed internal foothold
Assessment requires approved ranges, supplied footholds, test hosts, identities, flow expectations and relevant network, host or directory evidence, selected specifically for assumed internal foothold.
Evidence records the host, service, connection, credential, permission or attack-path evidence relevant to assumed internal foothold.
Technical Guide to Information Security Testing and Assessment SP 800-115

Applicability: Applies to Assumed internal foothold when the relevant internal system, identity or trust boundary is included.

Limit: The conclusion is limited to the sampled assumed internal foothold; results cover supplied footholds and test points; protected systems and disruptive actions remain excluded.

Internal service discoveryDamocles enumerates reachable hosts, listening ports, service indicators and administrative protocols within the approved internal ranges.Assumed internal foothold
Approved ranges, names, locations and the expected asset or interface inventory.
A discovered-item register with address, service, version or location and reconciliation status.
Technical Guide to Information Security Testing and Assessment SP 800-115

Applicability: Performed for customer-owned ranges, names, locations or interfaces listed in the authorised inventory.

Limit: Discovery is point-in-time and cannot establish ownership or absence outside the approved inventory; intrusive enumeration stops at the agreed boundary.

Network trust zonesDamocles maps intended trust zones to routing, firewall and ACL evidence and identifies representative boundary paths for validation.Privileged-path and configuration reviewer
Assessment requires approved ranges, supplied footholds, test hosts, identities, flow expectations and relevant network, host or directory evidence, selected specifically for network trust zones.
Evidence records the host, service, connection, credential, permission or attack-path evidence relevant to network trust zones.
Technical Guide to Information Security Testing and Assessment SP 800-115

Applicability: Applies to Network trust zones when the relevant internal system, identity or trust boundary is included.

Limit: The conclusion is limited to the sampled network trust zones; results cover supplied footholds and test points; protected systems and disruptive actions remain excluded.

Segmentation enforcementDamocles attempts approved allowed and denied connections between actual source and destination test points and records the enforcement result.Assumed internal foothold
Assessment requires approved ranges, supplied footholds, test hosts, identities, flow expectations and relevant network, host or directory evidence, selected specifically for segmentation enforcement.
Evidence records the host, service, connection, credential, permission or attack-path evidence relevant to segmentation enforcement.
Technical Guide to Information Security Testing and Assessment SP 800-115

Applicability: Applies to Segmentation enforcement when the relevant internal system, identity or trust boundary is included.

Limit: The conclusion is limited to the sampled segmentation enforcement; results cover supplied footholds and test points; protected systems and disruptive actions remain excluded.

Credential exposureDamocles inspects authorised endpoints, shares, service configuration and protocol behaviour for reusable credentials or credential material without bulk harvesting.Assumed internal foothold
Assessment requires approved ranges, supplied footholds, test hosts, identities, flow expectations and relevant network, host or directory evidence, selected specifically for credential exposure.
Evidence records the host, service, connection, credential, permission or attack-path evidence relevant to credential exposure.
Technical Guide to Information Security Testing and Assessment SP 800-115

Applicability: Applies to Credential exposure when the relevant internal system, identity or trust boundary is included.

Limit: The conclusion is limited to the sampled credential exposure; results cover supplied footholds and test points; protected systems and disruptive actions remain excluded.

Lateral movementDamocles validates representative remote-management, service, trust or credential paths between approved systems and stops after minimum evidence of additional access.Supplied standard user or workstation
Assessment requires approved ranges, supplied footholds, test hosts, identities, flow expectations and relevant network, host or directory evidence, selected specifically for lateral movement.
Evidence records the host, service, connection, credential, permission or attack-path evidence relevant to lateral movement.
Technical Guide to Information Security Testing and Assessment SP 800-115

Applicability: Applies to Lateral movement when the relevant internal system, identity or trust boundary is included.

Limit: The conclusion is limited to the sampled lateral movement; results cover supplied footholds and test points; protected systems and disruptive actions remain excluded.

Local privilege escalationDamocles examines local groups, rights, services, scheduled tasks, stored credentials, installed software and host configuration for a safe path to local administrative access.Supplied standard user or workstation
Assessment requires approved ranges, supplied footholds, test hosts, identities, flow expectations and relevant network, host or directory evidence, selected specifically for local privilege escalation.
Evidence records the host, service, connection, credential, permission or attack-path evidence relevant to local privilege escalation.
Technical Guide to Information Security Testing and Assessment SP 800-115

Applicability: Applies to Local privilege escalation when the relevant internal system, identity or trust boundary is included.

Limit: The conclusion is limited to the sampled local privilege escalation; results cover supplied footholds and test points; protected systems and disruptive actions remain excluded.

Domain privilege escalationDamocles analyses directory groups, ACLs, delegation, service accounts and identity relationships for a safe path to increased domain privilege.Supplied standard user or workstation
Assessment requires approved ranges, supplied footholds, test hosts, identities, flow expectations and relevant network, host or directory evidence, selected specifically for domain privilege escalation.
Evidence records the host, service, connection, credential, permission or attack-path evidence relevant to domain privilege escalation.
Technical Guide to Information Security Testing and Assessment SP 800-115

Applicability: Applies to Domain privilege escalation when the relevant internal system, identity or trust boundary is included.

Limit: The conclusion is limited to the sampled domain privilege escalation; results cover supplied footholds and test points; protected systems and disruptive actions remain excluded.

Administrative protocolsDamocles tests approved administrative protocols for authentication, signing, encryption and access restrictions from the supplied foothold.Assumed internal foothold
Current configuration export or read-only access, diagrams, owners and representative validation endpoints.
Configuration excerpts, object or rule identifiers and observed validation results.
Technical Guide to Information Security Testing and Assessment SP 800-115

Applicability: Performed when current configuration evidence and a representative endpoint or device are included in the review.

Limit: A configuration snapshot cannot prove continuous enforcement across excluded nodes; validation avoids changes unless implementation work is authorised.

Management-plane exposureDamocles determines whether standard footholds can reach network, security, hypervisor, backup or infrastructure management interfaces contrary to the intended model.Privileged-path and configuration reviewer
Current configuration export or read-only access, diagrams, owners and representative validation endpoints.
Configuration excerpts, object or rule identifiers and observed validation results.
Technical Guide to Information Security Testing and Assessment SP 800-115

Applicability: Performed when current configuration evidence and a representative endpoint or device are included in the review.

Limit: A configuration snapshot cannot prove continuous enforcement across excluded nodes; validation avoids changes unless implementation work is authorised.

Sensitive-system reachabilityDamocles attempts named required and forbidden protocols to approved high-value destinations from representative footholds.Assumed internal foothold
Named source and destination test points, expected flow matrix and a safe test window.
Source-to-destination results linked to rule, route or boundary evidence; the record names the tested sensitive-system reachability object, path or control and its observed result.
Technical Guide to Information Security Testing and Assessment SP 800-115

Applicability: Performed when both ends of the network path and the enforcing device are owned or expressly authorised for testing.

Limit: Results cover the tested source, destination, protocol and route; testing stops on instability and does not authorise third-party or denial-of-service activity.

Attack-path chainingDamocles joins observed foothold, credential, privilege, lateral-movement and sensitive-system reachability evidence into a reproducible attack chain.Assumed internal foothold
Named source and destination test points, expected flow matrix and a safe test window.
Source-to-destination results linked to rule, route or boundary evidence; the record names the tested attack-path chaining object, path or control and its observed result.
Technical Guide to Information Security Testing and Assessment SP 800-115

Applicability: Performed when both ends of the network path and the enforcing device are owned or expressly authorised for testing.

Limit: Results cover the tested source, destination, protocol and route; testing stops on instability and does not authorise third-party or denial-of-service activity.

Protected and excluded systemsDamocles marks protected and excluded systems in the test inventory, prevents active interaction with them and records how each exclusion constrains discovery or path conclusions.Assumed internal foothold
Assessment requires approved ranges, supplied footholds, test hosts, identities, flow expectations and relevant network, host or directory evidence, selected specifically for protected and excluded systems.
Evidence records the host, service, connection, credential, permission or attack-path evidence relevant to protected and excluded systems.
Technical Guide to Information Security Testing and Assessment SP 800-115

Applicability: Applies to Protected and excluded systems when the relevant internal system, identity or trust boundary is included.

Limit: The conclusion is limited to the sampled protected and excluded systems; results cover supplied footholds and test points; protected systems and disruptive actions remain excluded.

Framework and control mappings10 governed evidence mappings
Where scoped technical evidence maps to approved security frameworks and control objectives.
Framework and controlsMapping typeWhat Damocles assessesEvidence producedApplicability and limits
Security and Privacy Controls for Information Systems and Organizations Release 5.2.0
AC-4
Directly assessedTests representative allowed and denied information flows between approved internal source and destination points and correlates results with enforcement evidence where supplied.Source-to-destination results, enforcing rule or route evidence and observed bypass or unexpected reachability findings.

Applies: Applies where representative trust zones, source hosts, destinations and expected flows are included.

Limit: Only sampled paths are established; alternate paths, excluded zones and continuous enforcement remain outside the conclusion.

Security and Privacy Controls for Information Systems and Organizations Release 5.2.0
AC-6
Directly assessedTests representative least-privilege boundaries by validating safe local, lateral and privileged paths from the agreed internal foothold and supplied identities.Credential, permission, service and privilege-path evidence showing the minimum validated transition.

Applies: Applies to authorised systems and identities where privilege or lateral-movement testing is included.

Limit: Does not establish least privilege for every user, service, host or permission and validation stops at the minimum safe proof.

Security and Privacy Controls for Information Systems and Organizations Release 5.2.0
CA-8
Supporting evidencePerforms an authorised internal penetration test from the agreed foothold and records discovery, lateral movement, privilege paths and sensitive-system reachability.Rules of engagement, internal service inventory, lateral-movement records, privilege-path evidence, findings and retest records where included.

Applies: Relevant where the customer uses internal penetration testing within a broader assessment program.

Limit: Does not establish testing frequency, enterprise coverage, assessor governance or completeness of the broader program.

Information Security Manual June 2026
ISM-1181
Directly assessedTests representative network-zone segregation by exercising approved allowed and denied paths between selected internal trust zones.Source and destination records, expected flow matrix, observed connectivity outcome and enforcement evidence.

Applies: Applies where the customer supplies defined network zones, test points and expected flows.

Limit: Testing proves only sampled paths and does not establish that every network segment, route or enforcement point satisfies ISM-1181.

Information Security Manual June 2026
ISM-2118
Supporting evidenceProvides scoped internal penetration-test evidence that can support an organisation's security-assurance testing program.Authorised scope, discovered services, validated compromise paths, remediation guidance and retest results where included.

Applies: Relevant where the organisation uses the engagement within its vulnerability-assessment and penetration-testing program.

Limit: A single engagement does not establish required testing cadence, full asset coverage or compliance with ISM-2118.

Prudential Standard CPS 234 Information Security effective 1 July 2019
CPS 234 paragraph 27
Supporting evidenceProduces scoped internal network penetration-testing evidence that may support an APRA-regulated entity's systematic testing of information-security control effectiveness.Governed scope, internal reachability and compromise-path evidence, findings, remediation guidance and retest results where included.

Applies: Relevant only where the customer determines that the assessed internal systems and evidence are applicable to its assurance or compliance scope. For APRA-regulated entities, the customer determines how the engagement contributes to its broader systematic control-testing program.

Limit: A scoped engagement does not by itself establish the customer's systematic testing program, testing frequency, full control population, specialist independence, governance, reporting or compliance with other CPS 234 requirements.

Prudential Practice Guide CPG 234 Information Security published June 2019
Framework-level context
ContextualProduces scoped internal network penetration-testing evidence consistent with CPG 234 guidance that testing techniques should be selected for the control and risk being assessed.Governed scope, internal reachability and compromise-path evidence, findings, remediation guidance and retest results where included.

Applies: Relevant only where the customer determines that the assessed internal systems and evidence are applicable to its assurance or compliance scope. APRA-regulated customers determine how this evidence contributes to their broader assurance program.

Limit: CPG 234 is prudential guidance rather than a standalone certification target; this mapping does not claim assessment of the complete guidance or customer compliance.

ISO/IEC 27001 2022 with Amendment 1:2024
Framework-level context
ContextualProduces scoped internal network penetration-testing evidence that may support customer assurance activities organised around ISO/IEC 27001 where the assessed systems and behaviours are relevant.Governed scope, internal reachability and compromise-path evidence, findings, remediation guidance and retest results where included.

Applies: Relevant only where the customer determines that the assessed internal systems and evidence are applicable to its assurance or compliance scope.

Limit: Licensed ISO/IEC 27001 control or requirement identifiers and text are intentionally withheld. The engagement does not establish ISO/IEC 27001 certification, attestation or whole-framework conformity.

ISO/IEC 27002 2022
Framework-level context
ContextualProduces scoped internal network penetration-testing evidence that may support customer assurance activities organised around ISO/IEC 27002 where the assessed systems and behaviours are relevant.Governed scope, internal reachability and compromise-path evidence, findings, remediation guidance and retest results where included.

Applies: Relevant only where the customer determines that the assessed internal systems and evidence are applicable to its assurance or compliance scope.

Limit: Licensed ISO/IEC 27002 control or requirement identifiers and text are intentionally withheld. The engagement does not establish ISO/IEC 27002 certification, attestation or whole-framework conformity.

Payment Card Industry Data Security Standard 4.0.1
Framework-level context
ContextualProduces scoped internal network penetration-testing evidence that may support customer assurance activities organised around PCI DSS where the assessed systems and behaviours are relevant.Governed scope, internal reachability and compromise-path evidence, findings, remediation guidance and retest results where included.

Applies: Relevant only where the customer determines that the assessed internal systems and evidence are applicable to its assurance or compliance scope.

Limit: Licensed PCI DSS control or requirement identifiers and text are intentionally withheld. The engagement does not establish PCI DSS certification, attestation or whole-framework conformity.

Assurance boundary: Damocles maps assessed coverage and findings to agreed security frameworks and control objectives. This provides traceable technical evidence that may support risk, assurance and audit activities. A penetration test does not by itself certify an organisation, establish complete compliance with a framework or confirm the effectiveness of controls outside the authorised scope.

Report and evidence outputs6 controlled output types

Authorised scope and rules of engagement

Records authorised scope and rules of engagement produced from the authorised Internal network penetration testing work.

Included when
Included in the final deliverable when the relevant procedure is performed.
Limitations
Contains only evidence gathered from authorised systems, identities and review material.

Coverage matrix

Records coverage matrix produced from the authorised Internal network penetration testing work.

Included when
Included in the final deliverable when the relevant procedure is performed.
Limitations
Contains only evidence gathered from authorised systems, identities and review material.

Retest and residual-risk record

Records retest and residual-risk record produced from the authorised Internal network penetration testing work.

Included when
Included in the final deliverable when the relevant procedure is performed.
Limitations
Contains only evidence gathered from authorised systems, identities and review material.

Internal service inventory

Records internal service inventory produced from the authorised Internal network penetration testing work.

Included when
Included in the final deliverable when the relevant procedure is performed.
Limitations
Contains only evidence gathered from authorised systems, identities and review material.

Lateral-movement path record

Records lateral-movement path record produced from the authorised Internal network penetration testing work.

Included when
Included in the final deliverable when the relevant procedure is performed.
Limitations
Contains only evidence gathered from authorised systems, identities and review material.

Privilege-path evidence

Records privilege-path evidence produced from the authorised Internal network penetration testing work.

Included when
Included in the final deliverable when the relevant procedure is performed.
Limitations
Contains only evidence gathered from authorised systems, identities and review material.
What you receive

A prioritised technical report showing validated compromise paths, affected systems, remediation actions and retest results.

Attack paths we look for

Post-compromise paths that increase attacker privilege and reach.

The test focuses on practical movement and impact rather than attempting every possible host exploit.

LM

Lateral movement

Movement between hosts and services using available trust, credentials and management paths.

PE

Privilege escalation

Paths from standard access to local, service, administrative or broader privileged control.

SG

Segmentation bypass

Unintended paths between user, server, management or restricted networks.

CR

Credential reuse

Reusable, exposed or over-privileged credentials that expand attacker access.

MS

Management-service abuse

Administrative interfaces and protocols that provide control beyond the intended user role.

CH

Chained internal compromise

Multiple weaknesses combined to reach a sensitive host, system or administrative boundary.

Engagement options

Choose the starting position and breadth of the assumed-compromise scenario.

The statement of work identifies the supplied foothold, accounts, networks, prohibited systems and intended target outcomes.

User compromise
UW

Compromised user workstation

Start from a standard workstation or equivalent position and assess movement and privilege.

Credential compromise
AC

Compromised user account

Start with approved user credentials and test accessible services, privilege and trust relationships.

Segmentation
SG

Network segmentation test

Focus on whether approved source zones can reach systems and management paths they should not.

Estate
EN

Broader internal estate test

Assess multiple internal ranges and trust zones under a wider assumed-breach scenario.

What you receive

Evidence showing how far an internal foothold can travel and which controls should stop it.

Findings are linked to the starting position, attack path and affected control boundary.

BR

Blast-radius summary

Clear explanation of what the initial foothold could reach and why that matters.

MP

Movement path

Step-by-step lateral movement and privilege path where issues can be chained.

SG

Segmentation findings

Evidence of unintended access between trust zones and the affected policy or architecture.

TF

Technical findings

Affected host or service, exploit condition, evidence, impact and remediation guidance.

RP

Prioritised remediation

Fix order focused on breaking high-value movement and privilege paths.

RR

Retest evidence

Validation of agreed fixes and segmentation changes where retesting is included.

Remediation and retesting

Retesting confirms whether the movement or privilege path was actually broken.

A meaningful internal retest reproduces the original path from the agreed starting position and checks the changed control, segmentation or privilege condition.

Where remediation changes the architecture substantially, Damocles records the new scope required rather than pretending the original limited retest covers the redesigned environment.

Testing delivery

A controlled technical engagement without turning the service page into a methodology manual.

The commercial scope comes first. Delivery is then controlled through written authority, agreed safety boundaries and a clear retest path.

01

Scope and authorise

Confirm targets, ownership, attacker perspective, accounts, exclusions, timing, contacts and prohibited activity.

02

Test and validate

Perform the authorised manual and technical testing required to prove or disprove the attack paths in scope.

03

Report and brief

Provide evidence, impact, affected scope, remediation priorities and a technical walkthrough with the people responsible for the fix.

04

Retest

Reproduce agreed findings after remediation and record whether they are resolved, reduced or still exploitable.

Scope boundaries

Internal testing uses the agreed foothold and excludes systems or techniques that are not explicitly authorised.

High-risk production actions, destructive testing, uncontrolled credential attacks and access to specially protected systems require explicit written approval.

Active Directory and identity abuse can be included within an internal test, but a dedicated identity engagement provides deeper coverage when directory and privilege architecture are the primary concern.

Scope the right test

Tell us the foothold you want modelled and the sensitive systems you need protected.

We will define the internal ranges, accounts, segmentation boundaries, prohibited systems, evidence and retest scope required.