Skip to content

Network Penetration Testing: The Complete Guide

What network penetration testing is, how external and internal tests differ, the methodology testers follow, what it costs, and how to buy it well.

Invadel TeamSeptember 2, 20267 min read

Network penetration testing is a controlled, authorized attack on your network infrastructure, performed by security professionals to find and prove the weaknesses a real attacker would exploit. Where a web application test attacks one application, a network test attacks the environment everything runs in: the perimeter that faces the internet, and the internal network behind it, with its servers, workstations, and Active Directory.

It is the oldest and still the most commonly mandated form of penetration testing, and it is also the one where the gap between a real test and a repackaged vulnerability scan is widest. This guide covers what a network penetration test actually involves, the external and internal halves, the methodology, the cost, and how to buy one that is worth the money.

What network penetration testing covers

A network engagement targets infrastructure rather than a single application:

  • Internet-facing systems: public IP ranges, firewalls, VPN gateways, mail servers, remote access portals, exposed management interfaces, and cloud network edges
  • Internal systems: domain controllers and Active Directory, file and application servers, workstations, internal services, and the segmentation between network zones
  • The connective tissue: the trust relationships, credentials, and protocol behavior (SMB, LLMNR, Kerberos, and friends) that let one compromised host become many

The output is not a list of open ports. A proper test delivers proven attack paths: here is the exposed service, here is the exploit, here is the domain admin credential it ultimately yielded, and here is how to close the path.

External vs internal: the two halves

Network penetration testing splits into two engagement types depending on where the attacker starts.

External network penetration testing works from the internet with no access, answering whether an outside attacker can get in. Internal network penetration testing starts from an assumed foothold inside, answering how far that attacker spreads once past the perimeter, and whether Active Directory holds up. They fail independently, which is why frameworks like PCI DSS require both.

We compare them in depth, including which to run first, in external vs internal penetration testing. The short version: if you have never tested, start external; if you run Active Directory and have never tested it, the internal test is the one that will surprise you.

How a network penetration test works, phase by phase

A professional network test follows a recognized methodology, typically PTES or NIST SP 800-115 (our PTES explainer walks through the standard), through six phases:

  1. Scoping and rules of engagement. IP ranges, testing windows, exclusions, and emergency contacts are agreed in writing before anything is touched.
  2. Reconnaissance and discovery. The tester maps the attack surface: live hosts, open ports, running services, and, externally, the footprint you did not know you had (forgotten subdomains, legacy hosts, shadow IT).
  3. Enumeration and vulnerability identification. Services get interrogated for versions, misconfigurations, weak protocols, and known vulnerabilities. Automation helps here; judgment decides what matters.
  4. Exploitation. The tester attempts real exploitation of what was found: cracking into the exposed service, spraying the VPN portal, poisoning LLMNR on the internal network, roasting Kerberos tickets. Every claim in the report gets proven, safely, with evidence.
  5. Post-exploitation and lateral movement. From each foothold, the tester pushes further: harvesting credentials, moving host to host, escalating toward domain admin and the systems that hold your crown jewels. This phase is where a flat network or a decade of Active Directory drift gets exposed.
  6. Reporting and retest. Findings arrive with reproduction steps, business impact, and prioritized fixes, followed by a retest to confirm your remediation actually closed the paths. At Invadel the retest is included, not an upsell.

What network tests actually find

The recurring critical findings, engagement after engagement:

  • Exposed services and management interfaces that should never face the internet
  • Unpatched perimeter systems with known, weaponized CVEs
  • Weak or reused credentials on VPNs and portals, often without MFA
  • Flat internal networks where one compromised workstation reaches everything
  • Active Directory escalation paths: Kerberoasting, AS-REP roasting, delegation and ACL abuse, weak group policy
  • Legacy protocols (LLMNR, NBT-NS, SMBv1) quietly handing out credentials
  • Segmentation that exists in the diagram but not in practice

Automated scanners flag some of the first two categories. Nearly everything else on that list is found by a human chaining weaknesses together, which is the difference explained in penetration testing vs vulnerability scanning.

What network penetration testing costs

In the US market, professionally delivered network penetration testing services generally run $4,000 to $15,000 per engagement depending on the size of the environment. We publish fixed prices: external network testing from $4,200 and internal network testing from $6,000, each with a free retest included, and combined engagements quoted as one fixed number. The full market breakdown is in our penetration testing cost guide.

Be suspicious of network “penetration tests” priced in the hundreds of dollars. At that price you are buying a scanner report with a cover page; the economics of senior manual testing do not work any other way.

How often to test

Annually at minimum, and after significant network changes: a firewall or VPN replacement, a cloud migration, an acquisition, a new office, or a domain restructuring. Regulated environments go further: PCI DSS expects internal and external testing at least annually and after significant changes, NYDFS 500 mandates annual testing for covered financial firms, CMMC Level 2 contractors need proof that the CUI enclave boundary holds, and SOC 2 auditors expect testing evidence that is recent, not historical. Between annual tests, validated vulnerability scanning keeps the window of exposure short, and fast-changing environments increasingly move to a continuous testing cadence, delivered as penetration testing as a service, instead of a single yearly event.

Buying it well: what to demand

Four filters remove most of the weak vendors:

  1. Ask what percentage of the work is manual, and who does it. Named senior testers with OSCP-level certifications, not “our platform.”
  2. Ask for a sample report. You are buying the report; read one before you sign anything.
  3. Ask whether the retest is included. Finding issues is half the job; confirming the fixes is the other half.
  4. Demand a fixed price. A vendor who quotes before scoping is guessing; a vendor who bills hourly has no incentive to be efficient.

The longer version of this checklist is in how to choose a penetration testing company. Our full menu of penetration testing services, with a fixed price for each, is one page.

Frequently asked questions

What is the difference between network penetration testing and vulnerability scanning? A scan automatically enumerates known weaknesses and produces a raw list, false positives included. A network penetration test puts a human attacker against your infrastructure to validate, chain, and exploit weaknesses, proving which ones genuinely matter. Scans belong between tests, not instead of them.

Does network penetration testing cause outages? A professionally run test is designed not to. Scope, testing windows, and fragile systems are agreed up front, exploitation is controlled, and anything risky gets coordinated. Disruption on a well-scoped engagement is rare.

Do cloud environments still need network testing? Yes. Cloud moves the perimeter, it does not remove it. Security groups, exposed endpoints, and identity boundaries fail the same ways firewalls do, and hybrid environments add the connection between cloud and on-premise as its own attack surface. Dedicated cloud penetration testing covers the provider-specific layers.

How long does a network penetration test take? Most external engagements run about a week; internal engagements run one to two depending on network size, followed by reporting and the retest cycle.

The short version

Network penetration testing proves whether your infrastructure survives a real attacker, from the internet inward and from a foothold outward. Test externally at least annually, test internal and Active Directory before an attacker does it for you, insist on manual work with an included retest, and never pay penetration test prices for a scanner PDF.

Want the number for your environment? Scope your assessment and we will return a fixed quote for external, internal, or combined network testing within one business day.

Written by

Invadel Team

Senior penetration testers writing from real engagements, the same team that scopes, tests, and reports for our clients. About Invadel →

Find out what an attacker sees.

Tell us what to test and see your fixed price.

Prefer the full scoping questionnaire? 
Start the conversation