The classic engagement, run two ways. External starts from the public internet with nothing but your domain name: we enumerate what you actually expose, not what the asset inventory claims, and work inward. Internal starts from a position an attacker reaches on day two — a compromised laptop, a guest VLAN, a contractor's VPN account — and answers the question that matters to your insurer: how far does that get them?
Domain escalation paths, credential reuse, unmanaged hosts, flat networks, and stale service accounts are where most internal tests end up. We chain them the way an operator would rather than listing them separately, because the chain is the risk.
- Attack-path narrative from initial foothold to highest privilege reached
- Per-finding evidence: command, output, screenshot, affected assets
- Segmentation test results where PCI or regulatory scope applies
- Prioritized remediation table with owners and effort estimates
- Retest and clean-state attestation letter