Skip to content

Services, Wiki-Artikel und Blog-Beiträge durchsuchen

↑↓NavigierenEnterÖffnenESCSchließen

Network & Infrastructure Security

Network Penetration Testing. Simulate attackers. Eliminate vulnerabilities.

Active Directory. Lateral Movement. Privilege Escalation. Firewall Bypass. We test your network infrastructure from inside and outside - mapping every exploitable path and privilege chain.

OSCP-Certified ISO 27001 Pentest Box 100% in-house testers

Organizations that trust AWARE7 to protect their network infrastructure

500+
Pentests completed
8+
Years of experience
Avg 8
critical findings per test
100%
in-house testers

Two Perspectives

External or internal network pentest?

Both tests simulate different attacker perspectives and deliver complementary findings. For a complete picture we recommend combining both.

01

Test type

Attacker from the internet

External Pentest

Simulates an attacker with no prior access to your infrastructure. The starting point is the public internet - exactly like a real attack.

Check points

  • Exposed services: web servers, mail servers, FTP, RDP, SSH
  • VPN gateways for known CVEs and misconfigurations
  • DNS configuration: zone transfers, subdomain enumeration, DNSSEC
  • Firewall rules and port filtering for bypass opportunities
  • Mail security: SPF, DKIM, DMARC, open relay, SMTP enumeration
  • Port scanning, service enumeration and vulnerability assessment
Request quote

Duration / Price

Duration: 5-10 business days

from EUR 5,400

02

Test type

Insider or compromised endpoint

Internal Pentest

Simulates an attacker with internal network access - whether a malicious insider, a device compromised via phishing, or an attacker after initial breach.

Check points

  • Active Directory: full analysis of all attack paths
  • Network segmentation: VLAN hopping, broadcast attacks
  • Lateral movement: pivoting through the network after initial access
  • Privilege escalation: local and domain-wide elevation of privilege
  • NTLM relay, Kerberoasting, Pass-the-Hash, DCSync
  • Executable remotely via AWARE7 Pentest Box - no travel required
Request quote

Duration / Price

Duration: 8-15 business days

from EUR 8,000

Our recommendation: Combine both tests for a complete picture. External perimeter and internal network are two sides of the same attack surface - viewed separately, blind spots emerge.

Active Directory Pentest

Active Directory: The Keys to the Kingdom

In 9 out of 10 internal pentests, the path to full domain compromise runs through Active Directory misconfigurations. We systematically check all known attack paths - from Kerberoasting to DCSync.

KRB

Kerberoasting

Service accounts with SPNs allow Kerberos tickets to be requested without admin rights. Weak passwords can be cracked offline - often within seconds.

ASR

AS-REP Roasting

Accounts without Kerberos pre-authentication yield AS-REP hashes without valid credentials. Hashcat and John the Ripper crack weak passwords offline.

PTH

Pass-the-Hash / Ticket

Stolen NTLM hashes or Kerberos tickets enable lateral movement without a plaintext password. Impacket and Mimikatz are the standard tools.

NTR

NTLM Relay

LLMNR/NBT-NS poisoning with Responder captures authentication attempts. Ntlmrelayx forwards them onward - often directly to the domain controller.

DCS

DCSync

With sufficient replication rights, all password hashes in the domain can be extracted - without local access to the domain controller.

GT

Golden / Silver Ticket

With the KRBTGT hash, arbitrary Kerberos tickets can be forged (Golden Ticket) - unlimited, persistent domain access without knowing any password.

GPO

GPO & ACL Abuse

Misconfigured Group Policy Objects and ACL entries allow privilege escalation. BloodHound automatically visualizes all attack paths.

ADCS

ADCS - Certificate Services

Active Directory Certificate Services (ESC1-ESC8): misconfigured certificate templates allow privilege escalation and persistent domain access.

BloodHound-powered attack path analysis

We use BloodHound to collect all AD objects, permissions and delegations and visualize them in a directed graph. This reveals attack paths that remain hidden in manual analysis - including chained privilege escalation across multiple hops.

Request AD assessment

Scope

Full attack surface coverage

From the external perimeter to the domain controller - we cover all attack vectors in your network infrastructure.

Network Protocols & Services

SMBv1/v2, RPC, LDAP, Kerberos, NTP, SNMP, IPMI/BMC. Legacy protocols, default credentials and insecure service configurations are identified and verified.

Network Segmentation

VLAN hopping, 802.1Q double tagging, ARP spoofing, DHCP starvation and spoofing, misconfigured trunking ports. We verify whether segments are actually isolated.

Wireless / Wi-Fi

WPA2/WPA3 weaknesses, rogue access points, evil-twin attacks, guest network isolation, client isolation, RADIUS configuration and captive portal bypasses.

VPN & Firewall

VPN gateways (IPSec, SSL/TLS, WireGuard) for known CVEs, weak cipher suites and misconfigurations. Firewall rules for excessive permissions and bypass opportunities.

IDS/IPS Evasion

Testing whether attacks are detected by deployed intrusion detection and prevention systems. Fragmentation, obfuscation and low-and-slow techniques against signature-based systems.

Lateral Movement

Simulation of network spread after initial access: pivoting through compromised systems, command-and-control paths, persistence mechanisms and data exfiltration scenarios.

AWARE7 Pentest Box

Internal pentest - without travel.

The AWARE7 Pentest Box eliminates the need for on-site visits: the hardware device is connected to your network once. Our OSCP-certified experts then conduct the full internal penetration test entirely remotely - at the same quality level as an on-site engagement.

Setup
Device connected to your network once - by post or a brief on-site visit
Connection
Encrypted mobile back-channel: no VPN, no firewall changes required on your side
After completion
After completion: return the device - no permanent remote access remains

Pentest Box advantages

No travel costs

No day rate for travel and accommodation - typical saving of EUR 500-1,500

Highly secure

End-to-end encryption, no permanent access, hardware-secured mobile channel

Same quality

Identical depth as an on-site engagement - the same experts, the same tools

Pricing

Transparent fixed prices

No hourly rate risk. No surprise costs. Binding fixed-price quote within 24 business hours.

Scroll horizontally

Test type Price (net) Duration Scope
External Pentest Request quote from 5,400 EUR 5-10 business days Perimeter analysis (all public IPs) · VPN / Firewall / DNS / Mail · CVSS report + management summary
Internal Pentest Request quote from 8,000 EUR 8-15 business days Active Directory analysis · Lateral movement / privilege escalation · Pentest Box optional (no extra charge)
Combined - internal & external Recommended Request combined package from 12,000 EUR 12-20 business days External + internal pentest · Full AD assessment · Consolidated report + roadmap · NIS-2 / ISO 27001 compliance evidence
Custom Scope as needed Schedule consultation On request Individual Large or complex network · Multi-site / group structures · Red team / adversary simulation · Free initial consultation

Security Retainer - plan ahead, not react

Quarterly or semi-annual network pentests at reduced rates, a fixed slot in the project schedule, and a familiar team. Ideal for NIS-2-affected organizations and critical infrastructure operators.

Enquire about retainer

Compliance

Meet regulatory requirements

Network penetration tests are explicitly required or recognized as an accepted verification measure in several regulatory frameworks.

NIS2

NIS-2 Directive

Article 21 of the NIS-2 Directive requires essential and important entities to implement technical security measures, including vulnerability testing and penetration testing as recognized risk-management practices.

ISO27k

ISO 27001:2022

Control A.8.8 (Vulnerability Management) requires the active identification and treatment of technical vulnerabilities. Network pentests are the recognized means of demonstrating compliance.

TISAX

TISAX

The ENX/VDA standard for the automotive industry (TISAX assessment level 2+) requires regular security reviews of IT infrastructure as a supplier requirement.

DORA

DORA

The EU Digital Operational Resilience Act (DORA, Articles 26-27) mandates threat-led penetration testing (TLPT) for financial entities. Our network pentests provide the technical foundation and documented evidence.

Why AWARE7 for your network pentest

What sets us apart from other providers

Pure awareness platforms don't test systems. Pure consulting firms are too far removed. AWARE7 combines both: we hack your infrastructure and train your employees: tailored to mid-sized companies, personal, without enterprise overhead.

01

Research and teaching as our foundation

20 %

Around 20% of our revenue comes from research projects for the BSI and the BMBF. Our studies, published at ACM and Springer conferences, analyse millions of websites and tens of thousands of phishing emails. Three of our executives are professors at German universities at the same time.

02

Digital sovereignty: no compromises

100 %

From first contact to final report, your data is stored on our own servers in Germany - no US cloud providers, no third-country transfers. Our AI also runs on our own hardware in Germany - with locally operated open-source models. Client and project data never reach external AI services. All staff are permanently employed, covered by social insurance and bound by uniform legal obligations.

More on digital sovereignty
03

Fixed price within 24h: predictable project timelines

Within 24 hours you receive a binding fixed-price quote without hourly rate risk. A well-practised team and standardised processes ensure a clear schedule with a defined start and end date.

04

Your dedicated contact

A personal project manager accompanies you from the first meeting to the retest. You book appointments directly with your contact person and keep the same contact throughout the project.

Peer-reviewed publications

First page of the paper: Different Seas, Different Phishes - Large-Scale Analysis of Phishing Simulations

Different Seas, Different Phishes - Large-Scale Analysis of Phishing Simulations

ACM AsiaCCS 2025

Oskar Braun, Jan Hörnemann, Norbert Pohlmann, Matteo Große-Kampmann

First page of the paper: A Platform for Physiological and Behavioral Security

A Platform for Physiological and Behavioral Security

NSPW 2025

Jan Hörnemann

First page of the paper: Privacy from 5 PM to 6 AM: Tracking and Transparency in the HbbTV Ecosystem

Privacy from 5 PM to 6 AM: Tracking and Transparency in the HbbTV Ecosystem

IEEE/IFIP DSN 2025

Jan Hörnemann, Norbert Pohlmann, Matteo Große-Kampmann

First page of the paper: Understanding Regional Filter Lists: Efficacy and Impact

Understanding Regional Filter Lists: Efficacy and Impact

PoPETS 2025

Jan Hörnemann, Norbert Pohlmann, Matteo Große-Kampmann

Who is AWARE7 the right partner for?

Mid-sized companies with 50-2,000 employees

Companies that need real security, without paying for a DAX-corporation provider. Fixed price, clear scope, one point of contact.

IT managers & CISOs

Who have to argue convincingly in-house and need a report in boardroom language for that, not just technical findings.

Regulated industries

Critical infrastructure, healthcare, financial services: NIS-2, ISO 27001, DORA. We know the requirements and deliver evidence that auditors accept.

How we start

Three steps to your network pentest

From first contact to a running pentest typically takes 5-10 business days.

01

Initial consultation

A free 30-minute call with one of our security experts. We clarify scope, objectives and open questions - no commitment, no sales pressure.

02

Fixed-price quote

Within 24 business hours you receive a binding fixed-price quote with a clearly defined scope, timeline and deliverables. No hourly rate, no hidden costs.

03

Pentest starts

After contract signing we coordinate all details with your IT team. Kick-off meeting, Rules of Engagement, emergency contacts - then the pentest begins at the agreed date.

FAQ

Frequently asked questions about network pentests

Everything you need to know before your initial consultation.

An external network pentest simulates an attacker from the internet with no prior access. It covers publicly reachable services, VPN gateways, mail servers, DNS configuration and firewall rules. An internal pentest simulates a compromised employee or insider who already has access to the internal network. The focus is on Active Directory, network segmentation, lateral movement and privilege escalation. Our recommendation: combine both tests, as most real-world attacks traverse both phases.
A focused external network pentest typically takes 5-10 business days. An internal pentest with Active Directory analysis requires 8-15 business days depending on complexity. The combined package (external + internal + AD) is designed for 12-20 business days. In the free initial consultation we clarify the exact scope, and you receive a binding fixed-price quote within 24 business hours.
The AWARE7 Pentest Box is a physical hardware device that we send you by post or briefly connect on-site. The device connects exclusively via an encrypted mobile back-channel to our security team - without VPN access, without firewall changes, and without leaving any permanent remote access on your side. Our OSCP-certified experts then carry out the full internal penetration test entirely remotely. The result is qualitatively equivalent to an on-site engagement - without travel and accommodation costs.
An Active Directory assessment systematically examines all known AD attack paths: Kerberoasting (offline cracking of weak service account passwords), AS-REP Roasting (accounts without Kerberos pre-auth), Pass-the-Hash and Pass-the-Ticket (lateral movement with stolen credentials), DCSync (extraction of all password hashes), BloodHound analysis of all delegation paths, GPO misconfigurations, and attacks on Certificate Services (ADCS, ESC1-ESC8). The goal is to uncover every possible path to Domain Admin compromise.
We rely on a combined toolkit: Nmap and Masscan for port scanning and service enumeration, Metasploit Framework for exploitation, BloodHound and SharpHound for Active Directory analysis, Impacket for NTLM relay and Kerberos attacks, Responder for LLMNR/NBT-NS poisoning, CrackMapExec for lateral movement, and Burp Suite for services with web interfaces. What matters most, however, is the manual judgment of our experts - tools provide data, humans find attack paths.
No. We work exclusively according to recognized standards (PTES, OSSTMM) and agree on all tests in writing upfront. We only conduct destructive tests such as denial-of-service in isolated test environments. Before testing in production environments we recommend current backups - this is stipulated contractually. All testers are ISO 27001 Lead Auditors and operate within contractually fixed Rules of Engagement.
Preparation is minimal: you designate a technical contact person who can be reached in an emergency. For internal tests we ask for a network connection and a standard domain user account (no admin). For external tests a written test authorization is sufficient. We handle the rest: scope definition, Rules of Engagement, and coordination with your IT team. Typical lead time from contract signing: 5-10 business days.
Our network pentest report contains: a management summary (2-3 pages) for executive and supervisory audiences with risk assessment and investment recommendations; a complete finding list with CVSS scores (v3.1), technical details, screenshots, reproducible proof-of-concepts, and concrete remediation guidance; an attack path documentation showing how individual findings can be chained into a full compromise; and a prioritized remediation roadmap. On request you receive an anonymized sample report in advance.
At minimum annually; for critical infrastructure or after major network changes, more frequently. After mergers, acquisitions or major IT projects we recommend a timely pentest of the new environment. NIS-2-affected organizations and critical infrastructure operators should test at least semi-annually. Many of our clients use our retainer model: planned, regular tests at reduced rates with a fixed slot in the project schedule.
Yes - for all three. The NIS-2 Directive requires essential and important entities to implement technical security measures; penetration testing is explicitly recognized as a risk-management measure under Article 21. ISO 27001:2022 Control A.8.8 requires active management of technical vulnerabilities. For critical infrastructure sectors, regular network pentests are expected as part of cybersecurity obligations under sector-specific regulations. Our reports are designed as compliance evidence for auditors and certification bodies.

Fixed-price quote in 24 hours

Tell us briefly about your infrastructure - we'll prepare a binding quote for your network penetration test. No hourly rate, no hidden costs.

Free · 30 minutes · No obligation

Certifications & Standards

OSCP
Offensive Security
ISO 27001
Lead Auditor
PTES
Pentest Standard
OSSTMM
Open Source Security
Pentest Box
Remote Solution
T.I.S.P.
Certified Training Provider

Rufen Sie uns an

Mo-Fr, 8:00-17:00 Uhr - persönlich und unverbindlich.

0209 8830 6764
Jetzt anrufen