Network Penetration
Testing in India
Ransomware groups do not breach your network from the front door — they find an unlocked window, then move laterally until they own your domain controller. MDIT Services simulates this exact attack path: from initial foothold to full domain compromise, we expose every lateral movement opportunity, privilege escalation path, and exploitable misconfiguration in your network before attackers do.
The majority of serious cyber incidents in India share a common anatomy: a threat actor gains initial access through a phishing email, an exposed RDP port, or an unpatched VPN gateway — then spends days or weeks moving laterally through the internal network, escalating privileges, and establishing persistence before deploying ransomware or exfiltrating data. The breach itself is often trivial. The damage is done in the lateral movement phase, where an attacker with a foothold in your network systematically compromises everything it touches.
Network penetration testing is the only way to know — with evidence — how far an attacker can move through your environment from a given starting point. It is not a vulnerability scan. It is a controlled attack. Our certified ethical hackers use the same tools and techniques as actual threat actors — Metasploit, BloodHound, Impacket, Responder, CrackMapExec — to demonstrate exactly which systems are reachable, which credentials are reusable, and how quickly a network intrusion can become a domain-wide catastrophe.
Indian organisations face a specific and persistent threat: WannaCry-era vulnerabilities (EternalBlue, MS17-010) are still exploitable in a significant percentage of internal networks we test. Default credentials on network devices remain widespread. Active Directory password policies are routinely weaker than organisations believe. These are not theoretical risks — they are the vulnerabilities ransomware groups are actively exploiting in India today.
What is Network Penetration Testing?
Network penetration testing (also called network VAPT — Vulnerability Assessment and Penetration Testing) is a structured security assessment of your network infrastructure. It combines automated vulnerability scanning with manual exploitation techniques to answer a question that scanning alone cannot: given access to your network from a specific starting point, how far can an attacker go?
A network penetration test assesses the security of physical and logical network components: routers, switches, firewalls, servers, workstations, VPN gateways, wireless access points, Active Directory, and the protocols connecting them. It identifies not just which vulnerabilities exist, but which vulnerabilities are exploitable in your specific environment and what the real-world business impact of exploitation would be.
The output is a technical report that documents exactly what was found and proven — with evidence — along with a remediation roadmap prioritised by risk. Unlike compliance checklists or configuration reviews, penetration testing provides demonstrated proof of exploitability: we show you what an attacker can actually access, not what they theoretically might access.
Internal vs External Network Penetration Testing
Most organisations need both types of assessment — but they answer different questions and require different starting assumptions. Here is how to think about each type and when you need it.
External Network Penetration Testing
Starting assumption: The attacker is on the internet, with no prior access to your network. They know your company name and can look up your IP ranges and domain names.
What it tests:
- Internet-facing IP addresses and DNS records
- Public-facing firewall rules and port exposure
- VPN gateways (Cisco ASA, Fortinet, Palo Alto, OpenVPN)
- Exposed management interfaces (SSH, RDP, admin panels)
- Email server security (SPF, DKIM, DMARC, relay testing)
- SSL/TLS configuration weaknesses
- Information disclosure via DNS, WHOIS, banners
When you need it: Annually, before major infrastructure changes, and as a prerequisite for CERT-In, ISO 27001, and PCI DSS compliance.
Internal Network Penetration Testing
Starting assumption: The attacker has gained initial foothold inside the network — via phishing, a compromised contractor account, or a malicious USB device. The test begins from inside.
What it tests:
- Internal network segmentation effectiveness
- Lateral movement opportunities between network segments
- Active Directory misconfigurations and privilege escalation paths
- Internal server vulnerabilities (SMB, RDP, unpatched CVEs)
- Credential reuse and password spraying across services
- Insider threat simulation — what a disgruntled employee can access
- Data exfiltration pathways from internal network to internet
When you need it: Annually, after ransomware incidents, and whenever significant infrastructure changes are made to the internal network.
For most organisations, we recommend starting with an external VAPT to understand internet-facing exposure, then conducting an internal VAPT to assess the “blast radius” if any of those external exposures are exploited. The combination provides complete visibility into your network’s real security posture.
Our Network VAPT Scope
Our network penetration testing engagements cover a comprehensive range of infrastructure components. The specific scope is agreed with your team before the engagement begins, and we work within your defined testing windows to minimise operational impact.
External Perimeter Testing
Full assessment of internet-facing assets: port scanning, service enumeration, vulnerability identification, exploitation of discovered weaknesses. Covers public IPs, domain perimeter, email infrastructure, CDN configurations, and cloud-hosted assets. We test for open management interfaces, exposed databases, insecure VPN configurations, and weak authentication on public-facing services.
Internal Network Testing
Conducted from inside the network via VPN or on-site access. Covers network enumeration, host discovery, service vulnerability scanning, exploitation of internal vulnerabilities, lateral movement between segments, and privilege escalation. We map the complete attack path from initial compromise to domain administrator — the exact path a ransomware group would take.
Firewall & Router Configuration Review
Analysis of firewall rule sets to identify overly permissive rules, rule shadowing, any-any rules, unnecessary service exposure, and NAT configuration weaknesses. Router and switch configuration review covering default credential checks, management protocol exposure (Telnet, HTTP), and routing protocol security (OSPF, BGP authentication). We review configuration files directly where client access permits.
Active Directory / LDAP Security Audit
Comprehensive AD security assessment using BloodHound to map attack paths to Domain Admin. Kerberoasting and AS-REP roasting to extract crackable service account hashes. Pass-the-Hash and Pass-the-Ticket attack simulation. Group Policy Object misconfiguration review. Trust relationship exploitation. Privileged account enumeration. Assessment of password policy strength, stale account presence, and over-privileged service accounts — the most common AD weaknesses found in Indian enterprise environments.
VPN Security Testing
Security assessment of remote access VPN solutions (Cisco AnyConnect, Fortinet SSL VPN, Palo Alto GlobalProtect, OpenVPN, WireGuard). Tests for authentication bypass, weak cipher suites, split tunnelling misconfigurations, insecure client configurations, and VPN gateway vulnerabilities including known CVEs affecting major VPN products (Fortinet CVE-2024-21762, Ivanti vulnerabilities).
Wireless Network Security Testing
On-site assessment of 802.11 wireless infrastructure. WPA2/WPA3 configuration review, Evil Twin attack simulation, PMKID capture attempts, deauthentication attack testing, rogue access point detection, guest network isolation verification, and captive portal bypass testing. Assessment of whether the wireless network provides a pathway into the internal corporate network.
Network Segmentation Testing
Verification that network segments are effectively isolated — that a compromised device in the guest WiFi cannot reach the corporate LAN, that the OT network cannot be reached from the corporate IT network, and that payment card data environments are properly isolated from general-purpose systems. Network segmentation testing is mandatory for PCI DSS compliance (Requirement 1) and is a core component of most ISO 27001 implementations.
Network Penetration Testing Methodology
Our methodology aligns with PTES (Penetration Testing Execution Standard), NIST SP 800-115, and CERT-In’s empanelment testing guidelines. Every engagement follows a consistent, documented process that produces reproducible, evidence-backed results.
Reconnaissance
Passive and active intelligence gathering. OSINT, DNS enumeration, ASN lookup, certificate transparency, Shodan/Censys analysis.
Scanning
Port and service discovery using Nmap. OS fingerprinting. Service version identification. Network topology mapping.
Enumeration
Deep service enumeration. SMB share discovery. LDAP enumeration. SNMP community strings. Banner grabbing and version correlation to CVEs.
Exploitation
Manual exploitation of confirmed vulnerabilities. Credential attacks, CVE exploitation, misconfiguration abuse. Evidence documented for every exploit.
Post-Exploitation
Privilege escalation from gained access. Persistence simulation (documented, not actually deployed). Data access demonstration.
Pivoting
Lateral movement between network segments. Use of compromised hosts as pivot points. Mapping reach from initial compromise to critical assets.
Reporting
Full technical report with executive summary, CVE-referenced findings, evidence, remediation roadmap, and CERT-In compliance certification.
Rules of Engagement
Before every engagement, we establish a signed Rules of Engagement (RoE) document that defines the exact IP ranges in scope, testing windows (to avoid business-hour disruption), actions that are explicitly prohibited (such as denying service to production systems), escalation contacts for the client’s team, and emergency stop procedures. No penetration test begins without a signed RoE and written client authorisation.
Tools We Use
MDIT Services uses the same tools and frameworks that sophisticated threat actors use — giving you an accurate picture of real-world exploitability, not a theoretical vulnerability assessment.
Nmap / Nessus
Network discovery, port scanning, service version detection, and vulnerability scanning
Metasploit
Exploitation framework for known CVEs. Used for controlled, documented exploitation of confirmed vulnerabilities
BloodHound
Active Directory attack path mapping. Visualises shortest paths to Domain Admin from any user account
Impacket
Python library for Windows protocols. Used for Pass-the-Hash, Kerberoasting, secretsdump, and wmiexec attacks
Responder
LLMNR/NBT-NS poisoning tool for capturing NetNTLM hashes on internal networks for offline cracking
CrackMapExec
Swiss army knife for Windows/Active Directory environments. SMB enumeration, credential spraying, lateral movement
Aircrack-ng
Wireless network security testing suite for WPA2 handshake capture, PMKID attacks, and evil twin simulation
Burp Suite Pro
Web proxy for testing management interfaces, admin panels, and web-based network device UIs
Common Network Vulnerabilities We Find in India
Our experience across hundreds of network penetration tests in Indian enterprises reveals consistent patterns. The following vulnerabilities are found repeatedly — across industries, organisation sizes, and geographies. If your organisation has not recently conducted a network VAPT, there is a high probability that several of these exist in your environment today.
EternalBlue / MS17-010 — WannaCry-era Exploit Still Active
Seven years after WannaCry, we continue to find Windows XP, Windows Server 2003, and Windows 7 systems in Indian enterprise environments — all vulnerable to the NSA-developed EternalBlue exploit. This one vulnerability allows an unauthenticated attacker to gain SYSTEM-level access to any unpatched Windows host on the network, and from there to pivot laterally until they reach a domain controller. We find EternalBlue-exploitable hosts in approximately 30% of internal network assessments.
Default Credentials on Network Devices
Routers, switches, firewalls, NAS devices, IP cameras, and printers deployed with default admin credentials (admin/admin, admin/password, cisco/cisco) are found in the majority of internal network assessments. Default credentials on a managed switch can provide VLAN access to otherwise isolated network segments. On an IP camera system, they often reveal the internal network topology. On a network printer, they can expose stored documents and provide a pivot point.
Open RDP Exposed to the Internet
Remote Desktop Protocol (RDP) on port 3389 exposed directly to the internet is among the most exploited initial access vectors in India. RDP brute-force attacks are automated and continuous — threat actors scan the entire internet every few hours looking for RDP-exposed systems. We find internet-facing RDP in the majority of external perimeter assessments for organisations that have not recently reviewed their firewall rules.
SMBv1 Still Running
SMBv1 — the deprecated Windows file sharing protocol exploited by WannaCry and NotPetya — is still enabled by default in some Windows versions and is left enabled in many Indian enterprise environments for legacy application compatibility. Beyond EternalBlue, SMBv1 enables NTLM relay attacks and Responder-based credential capture. It should be disabled on all systems, with no exceptions unless a compelling application dependency exists and compensating controls are in place.
Weak Active Directory Password Policies
Most organisations believe their AD password policy is strong. Most are wrong. We routinely find domain password policies set to a minimum of 6–8 characters with no complexity requirement, no lockout after failed attempts, and passwords that have not changed in 2+ years. Password spraying with a list of 10–15 common Indian passwords (Welcome@123, Company@2024, Password@1) typically compromises 3–8% of user accounts in environments with weak policies — giving an attacker a foothold from which BloodHound can map the path to Domain Admin.
Unpatched CVEs on Critical Servers
Windows and Linux servers running without current security patches — often due to patch cycle delays, production system risk aversion, or EOL software — present a high proportion of critical findings in network VAPT. Exchange Server, Confluence, Citrix, and F5 BIG-IP vulnerabilities from 2022–2024 are still exploitable in a significant number of Indian enterprise environments because patch deployment has not kept pace with vulnerability disclosure.
Over-Privileged Service Accounts in Active Directory
Service accounts used by backup software, monitoring tools, database connectors, and legacy applications are frequently members of Domain Admins — not because they need that level of access, but because it was the path of least resistance during deployment. BloodHound maps these accounts in minutes, and Kerberoasting can extract crackable hashes for any service account with an SPN. An over-privileged service account with a weak password is a direct path to domain compromise.
Network VAPT for Compliance in India
Network penetration testing is a mandatory or strongly mandated requirement under every major security standard applicable to Indian organisations. Below is how our network VAPT maps to the key compliance frameworks.
| Standard / Regulation | Specific Network VAPT Requirement | How MDIT Supports Compliance |
|---|---|---|
| CERT-In Directive 2022 | Mandatory VAPT for public-facing systems and critical IT infrastructure. CERT-In empanelled vendor required. Annual or post-significant-change cadence mandated. | CERT-In empanelled reports issued with empanelment number. Covers all public-facing assets and internal infrastructure per client request. Includes CERT-In compliance checklist appendix. |
| ISO 27001:2022 | Annex A Control 8.8 (Technical Vulnerability Management) and 8.29 (Security Testing) require regular security testing of network infrastructure. Most certification bodies and enterprise clients interpret this as annual penetration testing. | Our network VAPT report includes ISO 27001 Annex A control mapping. We provide supporting documentation for ISMS evidence requirements. Annual retainer options available for ongoing ISO 27001 compliance. |
| PCI DSS v4.0 — Requirement 11 | Req 11.3: Annual internal and external penetration testing. Req 11.4: Network intrusion detection/prevention. Req 11.3.2: Segmentation testing to verify CDE isolation every 6 months (or after significant changes). | PCI DSS-scoped network VAPT covering CDE segmentation, internal and external testing. Report maps findings to PCI DSS Requirement 11 sub-controls. ASV scanning coordinated as required. |
| RBI IT Governance Framework | Annual Information Security Audit including network VAPT for banks, NBFCs, and payment aggregators. Internet-facing systems and internal critical systems must be assessed by CERT-In empanelled vendor. | RBI-aligned IS audit support including network VAPT. Report format aligned with RBI IS audit reporting requirements. Covers internet banking infrastructure, payment gateways, and internal banking systems. |
| MeitY / NIC Security Policy | Government IT systems hosted on NIC or private cloud must be assessed by CERT-In empanelled vendors before production deployment and annually thereafter. | CERT-In empanelled network VAPT with government-specific scope (data centre network segments, government portal infrastructure, interconnected ministry networks). |
| SEBI Cybersecurity Framework | Mandates annual VAPT of all IT systems for Market Infrastructure Institutions (stock exchanges, depositories, clearing corporations) and Registered Intermediaries (brokers, AMCs). | SEBI-aligned network VAPT covering trading platform infrastructure, order management systems, client portal security, and back-office network security. |
Network VAPT Cost in India
Network penetration testing pricing depends primarily on the number of IP addresses in scope, the complexity of the network architecture, and the additional components tested (Active Directory, wireless, VPN, segmentation). All pricing is fixed-scope and fixed-price — agreed before the engagement begins.
- Up to 20 public IPs
- Port and service enumeration
- VPN gateway testing
- Email security testing
- SSL/TLS review
- CERT-In empanelled report
- Retest included
- Up to 100 internal IPs
- Up to 20 external IPs
- Active Directory audit
- Lateral movement testing
- Firewall rule review
- VPN security testing
- CERT-In + ISO 27001 report
- Retest included
- 100–500+ IPs (internal + external)
- Full AD compromise simulation
- Wireless network testing (on-site)
- Network segmentation testing
- PCI DSS CDE scoping
- Red team elements
- Executive briefing session
- Annual retainer option
All prices are exclusive of GST. On-site engagement for internal network testing includes travel and accommodation for Delhi-based engineers or local partner engineers. A precise quote is provided after a 30-minute scoping call at no charge. Retainer pricing available for organisations requiring quarterly or annual network VAPT cycles.
Frequently Asked Questions
What is network penetration testing?
Network penetration testing is a controlled security assessment where certified ethical hackers simulate real-world attacks against your internal or external network infrastructure. The goal is to identify exploitable vulnerabilities — in firewalls, routers, servers, Active Directory, VPNs, and network protocols — before malicious actors can exploit them. It combines automated vulnerability scanning with manual exploitation and is more comprehensive than a vulnerability scan alone.
What is the difference between internal and external network penetration testing?
External network penetration testing assesses your internet-facing assets from the perspective of an outside attacker with no prior access. Internal network penetration testing is conducted from inside your network and simulates an attacker who has gained initial foothold — testing lateral movement, privilege escalation, and the ability to reach sensitive systems. Most organisations need both. We recommend starting with external VAPT and following with internal VAPT for a complete picture.
How long does a network VAPT take?
A network penetration test covering 50 IPs typically takes 5–8 business days including scanning, enumeration, exploitation, and report writing. Larger environments (200+ IPs) or complex scope including Active Directory, wireless, VPN, and segmentation testing may take 15–25 business days. We provide a precise timeline in the scoping proposal based on your IP count and scope. Testing can be scheduled during off-peak hours to minimise operational impact.
Do you need to be on-site for internal network VAPT?
Not necessarily. Internal network penetration testing can be conducted remotely via a secure VPN connection to your internal network. This is the preferred approach for most engagements as it avoids travel costs and scheduling delays. On-site presence is required for wireless security testing, physical access control review, and certain scenarios where VPN access cannot be arranged. We discuss the optimal approach during the scoping call.
Is network VAPT required for ISO 27001 certification?
Yes. ISO 27001:2022 Annex A Control 8.8 (Management of Technical Vulnerabilities) and Control 8.29 (Security testing in development and acceptance) together require organisations to regularly assess the security of their network infrastructure. Most certification bodies and enterprise client contracts interpret this as annual penetration testing. Our network VAPT report includes ISO 27001 Annex A control mapping to support your certification evidence requirements.
What is Active Directory penetration testing?
Active Directory penetration testing assesses the security of your Windows domain environment using the same techniques ransomware groups use to achieve domain compromise. This includes BloodHound attack path mapping, Kerberoasting, Pass-the-Hash, password spraying, and assessment of GPO misconfigurations, over-privileged service accounts, and stale admin credentials. It is the most impactful component of internal network VAPT and the one most frequently omitted by less experienced vendors.
What does a network VAPT report contain?
Our network VAPT report includes: an executive summary with overall risk rating and key findings; a complete vulnerability register with CVE references, CVSS scores, and severity ratings; technical evidence (Nmap output, Metasploit session captures, BloodHound attack path screenshots) for every finding; specific remediation guidance prioritised by risk; a network attack path diagram; a compliance mapping appendix (CERT-In, ISO 27001, PCI DSS); and a retest certificate issued after remediation confirmation.
How much does network penetration testing cost in India?
Network VAPT costs in India range from ₹50,000 for a small external perimeter assessment (up to 20 public IPs) to ₹5,00,000 or more for large enterprise environments covering 500+ IPs with Active Directory, wireless, VPN, and segmentation testing. All pricing is fixed-scope and fixed-price with no day-rate surprises. Retest of identified vulnerabilities is included in every engagement. We provide a precise quote after a 30-minute scoping call at no charge.
Find Out What’s Inside Your Network Before Attackers Do
Our CERT-In empanelled ethical hackers will test your network the way real attackers would — and give you the evidence and roadmap to close every gap before they get the chance.
