Network Penetration Testing in India & UAE.
Goal-oriented network penetration testing across your external attack surface, internal segments, Active Directory and cloud-to-on-prem boundaries. We chain misconfigurations, exposed services and credential weaknesses the way a real attacker would — and report so your network team can fix, not just acknowledge.
What is network penetration testing?
Network penetration testing attacks your internal and external network infrastructure — servers, firewalls, VPNs, and Active Directory — to find and exploit the weaknesses an intruder would use to move laterally. Macksofy delivers CERT-In-format network pentests with segmentation validation for enterprises across India and the UAE.
Four scopes. Quote them separately or as one.
Most Indian regulators want the external test annually and the internal test on a risk basis. Most breaches need the internal one. We price each independently so you can stage the programme.
Everything an attacker can reach without a single credential.
- ▸ASN, DNS and certificate-transparency footprint mapping
- ▸Exposed VPN, mail, RDP, file-share and admin interfaces
- ▸Cloud-edge surface: public endpoints, buckets, load balancers
- ▸Shadow assets nobody put in the CMDB
Assume a laptop is already compromised. How far does that go?
- ▸Segment discovery and host enumeration from a user-VLAN foothold
- ▸NTLM relay, LLMNR/NBT-NS poisoning, SMB signing gaps
- ▸Lateral movement via WMI, PsExec, WinRM and SSH
- ▸Local-admin reuse across the estate
The directory is the network. Most compromises end here.
- ▸BloodHound / SharpHound attack-path graphing
- ▸Kerberoasting, AS-REP roasting, delegation abuse
- ▸ADCS certificate-template escalation (ESC1–ESC16)
- ▸Tiering-model validation and privileged-group sprawl
Prove the boundary your network diagram claims exists.
- ▸Source-to-destination reachability testing per zone pair
- ▸DMZ → internal and cloud → on-prem trust-path discovery
- ▸PCI-DSS and OT/IT boundary validation
- ▸Matrix deliverable your network team can action directly
Six hours from the internet to domain admin.
Not a list of CVEs — a chain. This is the narrative your network team receives at debrief, with every hop reproducible and every fix pinned to the hop it closes.
- Quantify real network-side risk vs. theoretical CVSS scores
- Satisfy CERT-In annual VAPT, RBI System Audit, SEBI CSCRF and ISO 27001 network testing requirements
- Validate that segmentation actually segments — not just on paper
- De-risk M&A integrations and datacenter migrations
- External reconT+0hT1595Attack-surface mapping
ASN + certificate-transparency sweep surfaces a Citrix StoreFront portal outside the documented asset inventory.
- Perimeter footholdT+1hT1190Exposed service exploitation
Unpatched gateway plus a reused local credential yields a session on a DMZ host. No phishing required.
- Domain enumerationT+2hT1087BloodHound / SharpHound
Any authenticated domain user can read the directory. The graph exposes every delegation edge and nested admin group.
- Credential accessT+3hT1558.003Kerberoasting
A service account with an SPN and a weak, never-rotated password cracks offline in under an hour.
- Delegation abuseT+5hT1550.003Constrained delegation (S4U2Self)
That same service account is trusted for delegation to a host it never needed — impersonate any user to it, including a domain admin.
- Domain compromiseT+6hT1078.002Demonstrated, not exercised
Domain-admin access proven against a Macksofy-planted canary account. Client credentials are never dumped or used.
Composite of one anonymised engagement against a listed Indian manufacturer. Elapsed times are what that path actually took, not an average — yours depends on patch level, delegation hygiene and tiering.
Your diagram says segmented. Does the packet agree?
Segmentation is the control auditors accept on paper and attackers disprove in practice. We test every zone pair in both directions and hand back a matrix, not a paragraph.
| DMZ | User VLAN | Server VLAN | DB tier | OT / plant | Cloud VPC | |
|---|---|---|---|---|---|---|
| DMZ | ||||||
| User VLAN | ||||||
| Server VLAN | ||||||
| Cloud VPC |
DMZ → Server VLAN — Legacy jump-host permits SMB from the DMZ
User VLAN → DB tier — Any workstation reaches TCP/1433 directly
Server VLAN → OT / plant — Historian bridges IT and the Purdue L3 boundary
Cloud VPC → Server VLAN — Site-to-site tunnel has no return-path ACL
Six phases, every one documented.
- ▸ASN, subdomain, certificate transparency, OSINT recon
- ▸Exposed service enumeration (VPN, mail, web, API, file-share, RDP)
- ▸Cloud-edge attack surface (S3, ALB, exposed buckets, public endpoints)
- ▸Authenticated + unauthenticated scanning (Nessus, Nuclei) with manual triage
- ▸Manual exploitation of misconfigurations, default credentials, exposed admin
- ▸Phishing as a controlled initial-access vector (RoE-permitting)
- ▸Network reconnaissance and segment mapping
- ▸Active Directory enumeration (BloodHound, AdRecon)
- ▸Kerberoasting, AS-REP roasting, NTLM relay, ADCS abuse
- ▸Lateral movement via WMI, PSExec, WinRM, SSH
- ▸Local-admin to domain-admin path discovery
- ▸Constrained / unconstrained delegation abuse
- ▸Kerberos delegation attacks (Resource-Based, S4U2Self)
- ▸Demonstrated DA compromise (read-only by RoE default)
- ▸User VLAN → server VLAN reachability testing
- ▸DMZ → internal trust path discovery
- ▸Cloud → on-prem hybrid trust validation
- ▸EDR / IDS bypass attempts within agreed scope
- ▸Executive summary with attack-path diagram
- ▸Per-finding writeup (CVSS, PoC, remediation snippet)
- ▸MITRE ATT&CK TTP mapping
- ▸Free retest within 30 days of fix submission
Anonymised, but not sanitised.
Scope · External + internal + AD, 8 sites + DR datacenter
Finding · External Citrix → kerberoast → DA in 6 hours via misconfigured constrained delegation
Critical — fixed before next IT-audit cycle, no incident occurred
Scope · Internal pentest of segmented citizen-data network
Finding · User VLAN → database VLAN reachable via unfiltered SMB on a forgotten jump-host
High — segmentation gap remediated, MeitY data-localisation control restored
A chain you can reproduce. Not a scanner PDF.
Every operator on your network is a full-time Macksofy employee. No subcontractors and no offshore handoff of your topology.
Nessus and Nuclei give us coverage. Everything we report is then hand-verified, so you get exploitable findings rather than a CVSS spreadsheet to argue with.
Reports land in the format RBI System Audit, SEBI CSCRF, ISO 27001 and CERT-In annual VAPT reviewers expect — no rework cycle before submission.
Entra ↔ on-prem AD, site-to-site tunnels and cloud return paths are tested as one estate, because that is how an attacker crosses them.
Coverage from tools. Findings from people.
Scanners set the baseline and save you money on breadth. The exploitable findings — delegation paths, trust abuse, segmentation gaps — come from an operator reading the output.
Transparent tiers. No surprises at quote time.
Indicative price ranges based on typical Indian engagements. Final fixed-price quote within 72 hours of the discovery call.
Focused
- Manual + tooled testing
- CERT-In format report
- Free 30-day retest
Stack
- Everything in Focused
- Web + API + mobile coverage
- Executive + technical briefings
Programme
- Everything in Stack
- Quarterly cycles + post-release retests
- Same consultants throughout
Note · Indicative pricing in INR. Final quote depends on scope, asset count and engagement window. Fixed-price proposal within 72 hours.
What you get when the test ends
- Executive summary (board-ready, 2–3 pages)
- Technical report with CVSS 3.1 scoring and PoC per finding
- Attack-path diagram (perimeter → domain compromise)
- Segmentation validation matrix
- MITRE ATT&CK TTP mapping
- Remediation guidance per finding (network-team friendly)
- Free retest within 30 days of fix submission
- CERT-In / ISO 27001 / SOC 2 compliance letter
Sectors we operate in
Empanelled by CERT-In. Accredited by EC-Council.
“We've worked with three Big 4 firms before Macksofy. None found what their team did in our payments stack. The most actionable report we've received in a decade.”
“The CHFI training Macksofy delivered for our cyber cell raised investigation quality measurably. Practical, India-context-aware, and respectful of our operational realities.”
“Came in with zero security background. 5 weeks later I was running Burp Suite and Metasploit confidently. Cleared CEH on the first attempt.”
Things people ask before signing.
Where Macksofy delivers Network Pentest.
On-site engagements across India's BFSI, fintech, government and SaaS metros plus the UAE. Senior consultants fly from Mumbai BKC for kickoff, key reviews and exit briefings; remote weeks run through the rest of the engagement.
Macksofy delivers this work to the following standards and regulator requirements. Definitions and controls are sourced from the issuing bodies below.
Get a fixed-price proposal in 48 hours.
Tell us about your security need — pentest, audit, training or a wider engagement. A senior consultant will reply within a few business hours.
- CERT-In Empanelled
- EC-Council ATC · CompTIA Authorized
- Thousands of professionals trained
- India + UAE engagements
