Skip to content
Macksofy Technologies
Internal · External · AD · Hybrid Cloud

Network Penetration Testing in India & UAE.

Goal-oriented network penetration testing across your external attack surface, internal segments, Active Directory and cloud-to-on-prem boundaries. We chain misconfigurations, exposed services and credential weaknesses the way a real attacker would — and report so your network team can fix, not just acknowledge.

48h
quote turnaround
5–15
working days typical
30 days
free retest window
ATT&CK
mapped reporting
In short

What is network penetration testing?

Network penetration testing attacks your internal and external network infrastructure — servers, firewalls, VPNs, and Active Directory — to find and exploit the weaknesses an intruder would use to move laterally. Macksofy delivers CERT-In-format network pentests with segmentation validation for enterprises across India and the UAE.

Scope options

Four scopes. Quote them separately or as one.

Most Indian regulators want the external test annually and the internal test on a risk basis. Most breaches need the internal one. We price each independently so you can stage the programme.

3–6 days
External network

Everything an attacker can reach without a single credential.

  • ASN, DNS and certificate-transparency footprint mapping
  • Exposed VPN, mail, RDP, file-share and admin interfaces
  • Cloud-edge surface: public endpoints, buckets, load balancers
  • Shadow assets nobody put in the CMDB
5–10 days
Internal network

Assume a laptop is already compromised. How far does that go?

  • Segment discovery and host enumeration from a user-VLAN foothold
  • NTLM relay, LLMNR/NBT-NS poisoning, SMB signing gaps
  • Lateral movement via WMI, PsExec, WinRM and SSH
  • Local-admin reuse across the estate
4–8 days
Active Directory

The directory is the network. Most compromises end here.

  • BloodHound / SharpHound attack-path graphing
  • Kerberoasting, AS-REP roasting, delegation abuse
  • ADCS certificate-template escalation (ESC1–ESC16)
  • Tiering-model validation and privileged-group sprawl
2–5 days
Segmentation validation

Prove the boundary your network diagram claims exists.

  • Source-to-destination reachability testing per zone pair
  • DMZ → internal and cloud → on-prem trust-path discovery
  • PCI-DSS and OT/IT boundary validation
  • Matrix deliverable your network team can action directly
The path that matters

Six hours from the internet to domain admin.

Not a list of CVEs — a chain. This is the narrative your network team receives at debrief, with every hop reproducible and every fix pinned to the hop it closes.

  • Quantify real network-side risk vs. theoretical CVSS scores
  • Satisfy CERT-In annual VAPT, RBI System Audit, SEBI CSCRF and ISO 27001 network testing requirements
  • Validate that segmentation actually segments — not just on paper
  • De-risk M&A integrations and datacenter migrations
Attack path · perimeter to domain admin
InternetDMZUser VLANServer VLANDomain core
  1. External reconT+0hT1595
    Attack-surface mapping

    ASN + certificate-transparency sweep surfaces a Citrix StoreFront portal outside the documented asset inventory.

  2. Perimeter footholdT+1hT1190
    Exposed service exploitation

    Unpatched gateway plus a reused local credential yields a session on a DMZ host. No phishing required.

  3. Domain enumerationT+2hT1087
    BloodHound / SharpHound

    Any authenticated domain user can read the directory. The graph exposes every delegation edge and nested admin group.

  4. Credential accessT+3hT1558.003
    Kerberoasting

    A service account with an SPN and a weak, never-rotated password cracks offline in under an hour.

  5. Delegation abuseT+5hT1550.003
    Constrained delegation (S4U2Self)

    That same service account is trusted for delegation to a host it never needed — impersonate any user to it, including a domain admin.

  6. Domain compromiseT+6hT1078.002
    Demonstrated, not exercised

    Domain-admin access proven against a Macksofy-planted canary account. Client credentials are never dumped or used.

Composite of one anonymised engagement against a listed Indian manufacturer. Elapsed times are what that path actually took, not an average — yours depends on patch level, delegation hygiene and tiering.

Segmentation validation

Your diagram says segmented. Does the packet agree?

Segmentation is the control auditors accept on paper and attackers disprove in practice. We test every zone pair in both directions and hand back a matrix, not a paragraph.

Segmentation validation · source → destination
DMZUser VLANServer VLANDB tierOT / plantCloud VPC
DMZ
User VLAN
Server VLAN
Cloud VPC
Reachable by designCorrectly blockedReachable — should not be
4 segmentation gaps in this sample

DMZServer VLAN Legacy jump-host permits SMB from the DMZ

User VLANDB tier Any workstation reaches TCP/1433 directly

Server VLANOT / plant Historian bridges IT and the Purdue L3 boundary

Cloud VPCServer VLAN Site-to-site tunnel has no return-path ACL

Methodology

Six phases, every one documented.

Phase 1
External attack surface mapping
  • ASN, subdomain, certificate transparency, OSINT recon
  • Exposed service enumeration (VPN, mail, web, API, file-share, RDP)
  • Cloud-edge attack surface (S3, ALB, exposed buckets, public endpoints)
Phase 2
External exploitation
  • Authenticated + unauthenticated scanning (Nessus, Nuclei) with manual triage
  • Manual exploitation of misconfigurations, default credentials, exposed admin
  • Phishing as a controlled initial-access vector (RoE-permitting)
Phase 3
Internal lateral movement
  • Network reconnaissance and segment mapping
  • Active Directory enumeration (BloodHound, AdRecon)
  • Kerberoasting, AS-REP roasting, NTLM relay, ADCS abuse
  • Lateral movement via WMI, PSExec, WinRM, SSH
Phase 4
Privilege escalation + domain compromise
  • Local-admin to domain-admin path discovery
  • Constrained / unconstrained delegation abuse
  • Kerberos delegation attacks (Resource-Based, S4U2Self)
  • Demonstrated DA compromise (read-only by RoE default)
Phase 5
Segmentation validation
  • User VLAN → server VLAN reachability testing
  • DMZ → internal trust path discovery
  • Cloud → on-prem hybrid trust validation
  • EDR / IDS bypass attempts within agreed scope
Phase 6
Reporting & retest
  • Executive summary with attack-path diagram
  • Per-finding writeup (CVSS, PoC, remediation snippet)
  • MITRE ATT&CK TTP mapping
  • Free retest within 30 days of fix submission
Engagement snapshots

Anonymised, but not sanitised.

Listed Manufacturer (Pune)

Scope · External + internal + AD, 8 sites + DR datacenter

Finding · External Citrix → kerberoast → DA in 6 hours via misconfigured constrained delegation

Critical — fixed before next IT-audit cycle, no incident occurred

Risk severity · Critical
LMHC
Government Department (Delhi)

Scope · Internal pentest of segmented citizen-data network

Finding · User VLAN → database VLAN reachable via unfiltered SMB on a forgotten jump-host

High — segmentation gap remediated, MeitY data-localisation control restored

Risk severity · High
LMHC
Why Macksofy for network testing

A chain you can reproduce. Not a scanner PDF.

OSCP / OSEP operators, in-house

Every operator on your network is a full-time Macksofy employee. No subcontractors and no offshore handoff of your topology.

Manual triage, not a scanner dump

Nessus and Nuclei give us coverage. Everything we report is then hand-verified, so you get exploitable findings rather than a CVSS spreadsheet to argue with.

CERT-In empanelled reporting

Reports land in the format RBI System Audit, SEBI CSCRF, ISO 27001 and CERT-In annual VAPT reviewers expect — no rework cycle before submission.

Hybrid, not just on-prem

Entra ↔ on-prem AD, site-to-site tunnels and cloud return paths are tested as one estate, because that is how an attacker crosses them.

Tooling

Coverage from tools. Findings from people.

Scanners set the baseline and save you money on breadth. The exploitable findings — delegation paths, trust abuse, segmentation gaps — come from an operator reading the output.

Tools we operate
NmapNessusNucleiMetasploitBloodHound + SharpHoundCrackMapExec / NetExecImpacketResponder + NTLMRelayXMimikatz / RubeusHashcatCustom Macksofy tooling
Indicative pricing · INR

Transparent tiers. No surprises at quote time.

Indicative price ranges based on typical Indian engagements. Final fixed-price quote within 72 hours of the discovery call.

Free 30-day retest · CERT-In format reports
Tier 01

Focused

₹2.5L–₹5L
Single asset or app
  • Manual + tooled testing
  • CERT-In format report
  • Free 30-day retest
Request a fixed-price quote
Tier 02

Stack

₹6L–₹12L
Multi-asset engagement
  • Everything in Focused
  • Web + API + mobile coverage
  • Executive + technical briefings
Request a fixed-price quote
Tier 03

Programme

Starts at ₹15L
Quarterly retainer · large estate
  • Everything in Stack
  • Quarterly cycles + post-release retests
  • Same consultants throughout
Request a fixed-price quote

Note · Indicative pricing in INR. Final quote depends on scope, asset count and engagement window. Fixed-price proposal within 72 hours.

Deliverables

What you get when the test ends

  • Executive summary (board-ready, 2–3 pages)
  • Technical report with CVSS 3.1 scoring and PoC per finding
  • Attack-path diagram (perimeter → domain compromise)
  • Segmentation validation matrix
  • MITRE ATT&CK TTP mapping
  • Remediation guidance per finding (network-team friendly)
  • Free retest within 30 days of fix submission
  • CERT-In / ISO 27001 / SOC 2 compliance letter
Industries

Sectors we operate in

Banking & Financial ServicesInsurance & InsurTechGovernment & PSUManufacturing & EnergyHealthcare & HealthTechTelecomRetail & E-commerceSaaS & Product Companies
What clients say · Trusted India + UAE

Empanelled by CERT-In. Accredited by EC-Council.

CERT-In Empanelled
Govt of India · MeitY
EC-Council ATC
Authorized Training
ISO 27001 Certified
Info Security Mgmt
CompTIA Authorized Partner
Training Delivery
We've worked with three Big 4 firms before Macksofy. None found what their team did in our payments stack. The most actionable report we've received in a decade.
LF
Information Security Manager
Listed Fintech · BKC, Mumbai
The CHFI training Macksofy delivered for our cyber cell raised investigation quality measurably. Practical, India-context-aware, and respectful of our operational realities.
MP
Cyber Cell
Maharashtra Police · Mumbai
Came in with zero security background. 5 weeks later I was running Burp Suite and Metasploit confidently. Cleared CEH on the first attempt.
HS
DevSecOps Lead
Healthcare SaaS · Hyderabad
FAQ

Things people ask before signing.

Both is the common scope — external proves the perimeter, internal proves what an insider or post-phish attacker can reach. We quote them independently or bundled.
We demonstrate the technique to the point of validated impact, never operationally use it. DA compromise is signalled (e.g., dumping our own canary password hash, not your CFO's) unless explicitly authorised in the RoE.
Network pentesting against modern infrastructure is low-risk if scoped well. We coordinate scan windows with your NOC, avoid known-fragile devices (printers, legacy SCADA), and pause on any operational impact signal.
Delivery footprint

Where Macksofy delivers Network Pentest.

On-site engagements across India's BFSI, fintech, government and SaaS metros plus the UAE. Senior consultants fly from Mumbai BKC for kickoff, key reviews and exit briefings; remote weeks run through the rest of the engagement.

References & standards

Macksofy delivers this work to the following standards and regulator requirements. Definitions and controls are sourced from the issuing bodies below.

Talk to us

Get a fixed-price proposal in 48 hours.

Tell us about your security need — pentest, audit, training or a wider engagement. A senior consultant will reply within a few business hours.

CERT-In Empanelled
Information Security Auditor · India
  • CERT-In Empanelled
  • EC-Council ATC · CompTIA Authorized
  • Thousands of professionals trained
  • India + UAE engagements