If one laptop gets compromised, how far could an attacker actually get?

Starting from the access level of a typical employee device, we test how far lateral movement, privilege escalation, and Active Directory abuse can take an attacker.

What we test

Methodology

Foothold simulation

Starting from an assumed-compromised internal host, matching a realistic breach scenario.

Internal recon

Mapping the domain, trust relationships, and shared resources an attacker would target.

Privilege escalation

Chaining misconfigurations toward domain admin, the way real intrusions unfold.

Lateral movement

Testing how far the compromise spreads across hosts and network segments.

What you get

Typical duration

5–8 business days

Scope

Internal network segment

Delivery

Report + readout call

Retest

Included

Testers

CEH · OSCP

Ready to scope this engagement?

Tell us about your environment and we’ll come back with a fixed-scope quote within one business day.