Skip to content
Talk to a Security Expert
NETWORK PENETRATION TEST PTES / NIST SP 800-115 SAMPLE REPORT

Network Penetration Testing Report — Sample

NorthStar Financial Services, Inc. — External and Internal Network Penetration Test. A fictional external and internal network penetration testing assessment of NorthStar Financial Services, Inc., covering external attack surface, internal network security, Active Directory, network segmentation, network devices, wireless security, cloud/hybrid connectivity, attack-path analysis, findings, and remediation guidance.

Illustrative Sample Fictional Organization Not an Actual Client Assessment

FICTIONAL SAMPLE — NOT AN ACTUAL CLIENT NETWORK PENETRATION TEST. NorthStar Financial Services, Inc. is fictional. All domains (including northstar-example.com), IP addresses, hostnames, credentials, configurations, findings, and evidence shown are fictional or synthetic. No real client network, system, or infrastructure was tested, and no real customer data or credentials were used. TMG Security is not affiliated with, endorsed by, reviewed by, or certified by PTES, NIST, or any standards body.

01 · OVERVIEW

Overview

This is a fictional, illustrative sample of a network penetration testing report. It demonstrates how TMG Security structures and documents a professional external and internal network security assessment — from scope and PTES/NIST SP 800-115-informed methodology through network segmentation testing, Active Directory security review, network device assessment, wireless and cloud/hybrid testing, findings, and remediation guidance. The full sample report contains 46 illustrative findings drawn from 152 fictional test cases, executed against a fictional enterprise environment spanning 13 internal network zones. NorthStar Financial Services, Inc. does not exist; every finding, test case, host, and figure in this sample is fictional and constructed to show TMG's reporting standard, not to describe any real organization's security posture.

02 · WHAT THIS SAMPLE REPORT COVERS

What this sample report covers

NorthStar Financial Services, Inc. does not exist. Every finding, test case, host, zone, and figure in this sample is fictional and constructed to show TMG's methodology and reporting standard for a PTES/NIST SP 800-115-informed network penetration test — not to describe any real organization's security posture.

  • How TMG defines scope, rules of engagement, and testing objectives for combined external and internal network testing
  • How the external perimeter is enumerated and tested — VPN, remote access portal, mail gateway, DNS, load balancer, and bastion host
  • How the internal network is assessed under an assumed-breach model, starting from a standard user-tier foothold
  • How network segmentation is validated against the documented zone-to-zone policy matrix
  • How Active Directory domain architecture, privileged groups, service accounts, and credential hygiene are reviewed
  • How network devices — firewalls, switches, wireless controllers, and management platforms — are assessed
  • How wireless networks and cloud/hybrid connectivity are tested
  • How attack-path analysis chains individual findings into realistic, fictional compromise scenarios
  • How findings are rated using CVSS v3.1-inspired scoring and mapped to CWE, then evidenced and remediated
  • How a remediation roadmap and retest methodology are structured for security engineering follow-through
03 · ASSESSMENT OVERVIEW

Assessment overview

This fictional assessment was performed against NorthStar Financial Services, Inc., a fictional financial services / fintech organization, combining an external black-box/grey-box assessment of the internet-facing perimeter with an internal assumed-breach assessment starting from a standard user-tier foothold.

OrganizationNorthStar Financial Services, Inc. (Fictional)
IndustryFinancial Services / FinTech
Assessment TypeExternal and Internal Network Penetration Testing
PerspectivesExternal Black-Box/Grey-Box · Internal Assumed-Breach
Assessment Period03 August 2026 – 28 August 2026
Report Date10 September 2026
EnvironmentFictional production-like enterprise environment with isolated test infrastructure
Standards ReferencedPTES concepts · NIST SP 800-115 concepts · CVSS v3.1-inspired scoring · CWE
04 · SCOPE

Scope

Scope for this fictional assessment covered the full external perimeter and eight internal network zones, plus wireless and cloud/hybrid connectivity, exercised over the assessment period against 152 fictional test cases.

  • External perimeter: internet-facing VPN gateway, remote access portal, public web application gateway/WAF, external DNS, email security gateway, external perimeter firewall, external load balancer, bastion/jump host, and externally reachable remote administration surface
  • Internal network zones: User Workstation, Server, Application, Database, Identity/AD, Management, Security Tooling, and Backup VLANs
  • Network security devices: next-generation firewalls (external and internal), core switch, distribution switches, wireless LAN controller, and network management platform
  • Windows / enterprise infrastructure: Active Directory domain controllers, Windows file server, application server, management server, internal PKI/certificate services, internal DNS, and internal monitoring server
  • Linux / application infrastructure: Linux application server, internal API server, monitoring server, logging/SIEM collector, and backup server
  • Cloud / hybrid connectivity: fictional site-to-site VPN, hybrid identity synchronization server, and cloud management interface
  • Wireless networks: corporate SSID (NSF-CORP), guest SSID (NSF-GUEST), and management SSID (NSF-WLAN-MGMT)

Out of scope: any production system, network, or data belonging to a real organization; denial-of-service testing of any kind; physical security testing; social engineering campaigns; destructive exploitation; third-party vendor infrastructure; and cloud provider infrastructure below the fictional tenant/management layer.

05 · TESTING METHODOLOGY

Testing methodology

TMG Security's network testing approach is conceptually informed by PTES (the Penetration Testing Execution Standard) and NIST SP 800-115. Testing proceeded through the following phases:

  • Pre-Engagement: scope confirmation, rules of engagement sign-off, target and credential provisioning, and emergency-contact exchange
  • Rules of Engagement: formal agreement on testing windows, authorized techniques, prohibited activities, and stop conditions
  • Reconnaissance: passive and active information gathering against the external attack surface — DNS, WHOIS, certificate transparency, and public-source review
  • Attack Surface Discovery: enumeration of all in-scope external and internal hosts, culminating in the asset register
  • Service Enumeration: port and service discovery across all in-scope hosts, producing the service/port register
  • Vulnerability Analysis: correlation of enumerated services and configurations against known weakness classes
  • Configuration Review: manual review of firewall, network device, Active Directory, and wireless configuration
  • Authentication Testing: assessment of authentication mechanisms across VPN, remote administration, and directory services
  • Network Segmentation Testing: validation of the segmentation matrix against observed live traffic flows
  • Active Directory Assessment: domain architecture, trust, privileged group, service account, and credential-exposure review
  • Lateral Movement Assessment: controlled, non-destructive demonstration of lateral movement paths made possible by chained findings
  • Privilege Escalation Assessment: controlled, non-destructive demonstration of privilege-escalation paths from standard to privileged access
  • Exposure Validation: confirmation that identified weaknesses represent genuine, reproducible exposure
  • Controlled Exploitation: safe, non-destructive proof-of-concept execution for Critical and High findings only
  • Post-Exploitation Validation: confirmation of the practical impact of a successful technique without further action
  • Evidence Collection: capture of illustrative evidence for every finding, mapped to the evidence register
  • Risk Rating: assignment of a CVSS-style illustrative score and severity rating to every finding
  • Remediation: development of finding-specific and program-level remediation guidance
  • Retest: post-remediation validation methodology, described in the retest section below

TMG Security is not affiliated with, endorsed by, reviewed by, or certified by PTES, NIST, or any standards body. References to PTES and NIST SP 800-115 describe the testing methodology used and do not imply any official certification of NorthStar Financial Services or TMG Security.

06 · NETWORK ARCHITECTURE

Network architecture

The fictional NorthStar environment is organized into 13 internal network zones, spanning user, server, application, database, identity, backup, management, security tooling, wireless, and cloud/hybrid segments. This sample report shows how TMG documents network architecture as the baseline for segmentation and lateral-movement testing.

Fictional network zones — Section 07 of the sample PDF.
ZoneFictional RangeDescription
User Workstation VLAN10.40.10.0/24Standard end-user Windows workstations, laptops, VDI clients
Server VLAN10.40.20.0/24Windows infrastructure servers — file, application, management, monitoring, PKI, internal DNS
Application VLAN10.40.30.0/24Linux application, internal API, logging/SIEM, and monitoring servers
Database VLAN10.40.40.0/24Primary transactional and reporting database instances
Identity / AD VLAN10.40.50.0/24Active Directory domain controllers and identity infrastructure
Backup VLAN10.40.60.0/24Backup repository and backup-management infrastructure
Management VLAN172.20.10.0/24Out-of-band management interfaces for network devices
Security Tooling VLAN172.20.20.0/24Vulnerability scanning and EDR management infrastructure
Wireless — Corporate SSID10.50.10.0/24Corporate-issued and BYOD endpoints (NSF-CORP)
Wireless — Guest SSID10.50.20.0/24Guest and visitor wireless clients (NSF-GUEST)
Wireless — Management SSID10.50.30.0/24Wireless infrastructure management (NSF-WLAN-MGMT)
Cloud / Hybrid Connectivity10.50.0.0/24Site-to-site VPN termination and hybrid identity/cloud management
External Perimeter / DMZ10.40.0.0/24Internet-facing gateways, VPN, portal, mail, DNS
07 · EXTERNAL ATTACK SURFACE

External attack surface

TMG Security enumerated and tested nine fictional internet-facing systems comprising NorthStar's external attack surface.

Fictional external attack-surface assets — Section 08 of the sample PDF.
AssetHostnamePurpose
NS-A01NS-FW-EXT01External perimeter firewall / primary internet edge
NS-A02NS-VPNGW01Remote-access VPN gateway — vpn.northstar-example.com
NS-A03NS-PORTAL01Employee/partner remote access portal — portal.northstar-example.com
NS-A04NS-WAF01Fronts public-facing web applications
NS-A05NS-MAILGW01Inbound/outbound mail filtering — mail.northstar-example.com
NS-A06NS-DNSEXT01Authoritative DNS for northstar-example.com
NS-A07NS-LBEXT01TLS termination and load distribution for public services
NS-A08NS-BASTION01Administrative jump host for external vendor and remote admin access
NS-A09NS-RADMIN01Externally reachable WinRM/RDP administration surface for on-call engineers
08 · INTERNAL NETWORK ARCHITECTURE

Internal network architecture

Internally, NorthStar's fictional environment separates user, server, application, database, identity, backup, management, and security-tooling traffic across dedicated VLANs, with three wireless SSIDs — Corporate (NSF-CORP), Guest (NSF-GUEST), and Management (NSF-WLAN-MGMT) — and a dedicated Security Tooling VLAN hosting vulnerability scanning and EDR management infrastructure. A Cloud/Hybrid Connectivity segment terminates a fictional site-to-site VPN and hosts the hybrid identity synchronization server and cloud management interface bridging the on-premises domain to the fictional cloud tenant.

09 · NETWORK SEGMENTATION ASSESSMENT

Network segmentation assessment

TMG Security tested documented zone-to-zone pairs from the segmentation matrix against the traffic actually permitted on the live network, comparing expected policy against observed reachability. A representative selection of results is shown below; the complete segmentation matrix is included in the full sample PDF.

Representative segmentation test results — Section 10 of the sample PDF.
SourceDestinationExpectedObservedRisk
User Workstation VLANDatabase VLANDenied by default — no direct reachabilityPermitted — unrestricted TCP/1433 reachability via overly broad ruleCritical
User Workstation VLANBackup VLANDenied — backup infrastructure isolatedPermitted — SMB share reachable with broad read permissionHigh
Guest Wireless SSIDCorporate network (all zones)Denied — full isolationDenied, as expectedNone
10 · ACTIVE DIRECTORY SECURITY

Active Directory security

TMG Security assessed NorthStar's fictional single-domain, single-forest Active Directory design — two domain controllers (NS-DC01, NS-DC02) — covering privileged group membership, service account hygiene, password policy, LDAP, Kerberos, SMB signing, SYSVOL, Group Policy security, administrative pathways, and monitoring. Domain Admins membership was found to exceed the minimum required for genuine Tier-0 activity, including several accounts used for routine application support. The Default Domain Policy enforces only an 8-character minimum password length with no banned-password-list screening. Several SPN-registered service accounts use stale, non-rotated passwords vulnerable to Kerberoasting, and a Domain Admin-equivalent service account credential was recoverable from a legacy Group Policy Preferences (SYSVOL) artifact.

NET-003 · CRITICAL · CVSS 9.8

Privileged Active Directory Service Account Credential Exposed Through Insecure Group Policy Preferences Configuration

A legacy Group Policy Preferences artifact stored in SYSVOL contains an encrypted credential using Microsoft's publicly-documented GPP encryption key. Any authenticated domain user — including a standard, non-privileged account — can decrypt it and recover the plaintext credential for svc-backupsync, a service account holding Domain Admin-equivalent rights. Recommendation: remove all legacy GPP-based credential storage from SYSVOL, rotate the exposed account's credential, and reduce the account's privileges to the minimum required for its backup function.

Owner: Identity & Access Management Lead (Fictional Role) · Status: Remediation In Progress

NET-013 · HIGH · CVSS 7.6

Weak Service Account Security Enables Lateral Movement via Kerberoasting

Multiple SPN-registered service accounts use stale, non-rotated passwords recoverable through offline Kerberos ticket cracking (Kerberoasting), allowing an attacker with any authenticated domain access to request service tickets and crack them offline without triggering account lockout. Recommendation: rotate all service account passwords to high-entropy values, adopt Group Managed Service Accounts (gMSA) where supported, and monitor for abnormal service-ticket request volume.

Owner: Identity & Access Management Lead (Fictional Role) · Status: Remediation Planned

11 · NETWORK DEVICE SECURITY

Network device security

TMG Security assessed NorthStar's fictional firewalls (external and internal), core switch, distribution switches, wireless LAN controller, and network management platform, covering management protocols, SNMP configuration, administrator access, ACLs, management-plane segmentation, configuration backups, logging, and firmware lifecycle. HTTPS/SSH were observed for device management with no Telnet exposure. Default vendor administrative credentials were not rotated on the core switch and internal firewall, and management-plane ACLs are missing on the core switch and internal firewall and overly broad on distribution switches. Automated configuration backups are stored unencrypted on a broadly-accessible general IT share, and the wireless LAN controller was running outdated firmware.

NET-004 · CRITICAL · CVSS 9.6

Exposed Management Plane Enables Administrative Access to Core Network Devices from User VLAN

An attacker with User VLAN access can reach the administrative web console of the core switch and internal firewall and authenticate using an unrotated default credential, since management-plane ACLs are missing on these devices and the management interface is reachable from the general user network rather than being restricted to the dedicated Management VLAN. Recommendation: restrict all device management interfaces to the Management VLAN only, rotate every default vendor administrative credential, and apply management-plane ACLs denying all source zones except authorized administrative hosts.

Owner: Network Infrastructure Lead (Fictional Role) · Status: Remediation In Progress

NET-009 · HIGH · CVSS 7.5

SNMP Community String Configuration Exposes Network Device Information

SNMPv1/v2c remains enabled alongside SNMPv3 on the core and distribution switches, using guessable community strings that disclose network topology and device configuration to anyone able to reach the management interface. Recommendation: disable SNMPv1/v2c fleet-wide, migrate fully to SNMPv3 with authentication and encryption, and restrict SNMP access to the Security Tooling VLAN.

Owner: Network Infrastructure Lead (Fictional Role) · Status: Remediation Planned

12 · WIRELESS SECURITY

Wireless security

TMG Security assessed NorthStar's three fictional wireless SSIDs. The Corporate SSID (NSF-CORP) uses WPA2-Enterprise with 802.1X/PEAP-MSCHAPv2, but retains a legacy shared-PSK fallback for IoT-style devices that has not been rotated in over two years. The Guest SSID (NSF-GUEST) uses WPA2-Personal with correctly configured client isolation from the corporate network. The Management SSID (NSF-WLAN-MGMT) uses WPA2-Personal for wireless LAN controller control-plane traffic; an overly broad firewall rule permits Corporate SSID clients to reach the Management VLAN.

NET-011 · HIGH · CVSS 8.2

Insecure Firewall Rule Permits Management-Plane Access From Corporate Wireless Segment

An overly broad firewall source object allows corporate wireless clients on NSF-CORP to reach management VLAN interfaces that are intended to be reachable only by infrastructure personnel on wired administrative segments. Recommendation: scope the firewall source object to wired administrative hosts only, and remove wireless segments from any rule permitting management-plane reachability.

Owner: Network Infrastructure Lead (Fictional Role) · Status: Remediation Planned

NET-027 · MEDIUM · CVSS 6.5

Weak Corporate Wireless Configuration — Shared PSK Fallback Available Alongside 802.1X

A legacy shared pre-shared key fallback remains available on the Corporate SSID for IoT-style devices and has not been rotated in over two years, providing a lower-assurance authentication path alongside the primary 802.1X/PEAP-MSCHAPv2 configuration. Recommendation: migrate IoT-style devices to a dedicated, isolated SSID with MAC-based or certificate-based authentication, and retire the shared PSK fallback on the corporate SSID.

Owner: Network Infrastructure Lead (Fictional Role) · Status: Remediation Planned

13 · CLOUD / HYBRID SECURITY

Cloud / hybrid security

TMG Security reviewed NorthStar's fictional site-to-site VPN connectivity and hybrid identity synchronization server bridging the on-premises Active Directory domain to a fictional cloud tenant and cloud management interface.

NET-035 · MEDIUM · CVSS 6.8

Overly Permissive VPN Trust Allows Split-Tunnel Access to Sensitive On-Prem Resources

The fictional site-to-site VPN configuration permits split-tunnel routing that grants a broader set of on-premises resources than the cloud connectivity's documented purpose requires. Recommendation: scope the VPN's routed prefixes to only the resources the cloud connectivity genuinely needs, and disable split-tunnel access to sensitive internal zones.

Owner: Cloud Infrastructure Lead (Fictional Role) · Status: Remediation Planned

NET-036 · MEDIUM · CVSS 6.4

Weak Hybrid Segmentation Between On-Prem Identity Sync Server and Cloud Management Path

The hybrid identity synchronization server sits on a segment with broader reachability to the cloud management path than its synchronization function requires, widening the practical blast radius if the sync server is ever compromised. Recommendation: isolate the hybrid identity sync server on a dedicated segment with only the specific connectivity its synchronization role requires.

Owner: Cloud Infrastructure Lead (Fictional Role) · Status: Remediation Planned

14 · FINDINGS SUMMARY

Findings summary

This fictional assessment identified 46 illustrative findings across NorthStar's external perimeter, internal network, Active Directory, network devices, wireless, and cloud/hybrid connectivity, drawn from 152 fictional test cases. Every finding, severity rating, and evidence reference is fictional and specific to this network penetration test.

4
Critical
9
High
14
Medium
9
Low
10
Informational
15 · EXAMPLE CRITICAL FINDINGS

Example Critical findings

All four Critical findings from this fictional assessment are shown in full below.

NET-001 · CRITICAL · CVSS 9.4

External VPN Authentication Can Be Bypassed Through Legacy Authentication Workflow

A legacy authentication workflow remains active on NorthStar's fictional remote-access VPN gateway alongside the primary multi-factor login path. Any attacker in possession of a single valid domain credential — obtained through any means, such as password reuse or phishing — can establish a full VPN session without satisfying the second authentication factor, by directing the connection through the legacy endpoint. Recommendation: decommission the legacy authentication workflow entirely, or if a legacy client population still requires it, enforce the same multi-factor requirement on that path as the primary login flow.

Owner: Network Infrastructure Lead (Fictional Role) · Status: Remediation In Progress

NET-002 · CRITICAL · CVSS 9.1

Insufficient Internal Network Segmentation Enables Unauthenticated Reachability from User VLAN to Database VLAN

Hosts on the User Workstation VLAN can establish direct TCP/1433 (SQL Server) connections to hosts on the Database VLAN, with no intermediate application tier and no authentication boundary enforced at the network layer, due to an overly broad firewall rule between the two zones. Recommendation: restrict Database VLAN reachability to only the specific application-tier hosts that require it, and remove direct User VLAN to Database VLAN connectivity entirely.

Owner: Network Infrastructure Lead (Fictional Role) · Status: Remediation In Progress

NET-003 · CRITICAL · CVSS 9.8

Privileged Active Directory Service Account Credential Exposed Through Insecure Group Policy Preferences Configuration

A legacy Group Policy Preferences artifact stored in SYSVOL contains an encrypted credential using Microsoft's publicly-documented GPP encryption key. Any authenticated domain user can decrypt it and recover the plaintext credential for svc-backupsync, a service account holding Domain Admin-equivalent rights. Recommendation: remove all legacy GPP-based credential storage from SYSVOL and rotate the exposed account's credential immediately.

Owner: Identity & Access Management Lead (Fictional Role) · Status: Remediation In Progress

NET-004 · CRITICAL · CVSS 9.6

Exposed Management Plane Enables Administrative Access to Core Network Devices from User VLAN

An attacker with User VLAN access can reach the administrative web console of the core switch and internal firewall and authenticate using an unrotated default credential. Recommendation: restrict all device management interfaces to the Management VLAN only and rotate every default vendor administrative credential.

Owner: Network Infrastructure Lead (Fictional Role) · Status: Remediation In Progress

16 · HIGH-SEVERITY FINDINGS

High-severity findings

All nine High findings from this fictional assessment are shown below.

NET-005 · HIGH · CVSS 8.1

SMB Signing Not Enforced on Critical Internal Windows Servers

SMB signing is not enforced on critical internal Windows servers, so an attacker positioned on the Server VLAN who can capture NTLM authentication traffic can relay it to these servers and obtain an authenticated SMB session without knowing the underlying credential. Recommendation: enforce SMB signing on all Windows servers, prioritizing Tier-0 and Tier-1 systems.

Owner: Network Infrastructure Lead (Fictional Role) · Status: Remediation Planned

NET-006 · HIGH · CVSS 8.3

Insecure LDAP Configuration Permits Credential Exposure via Unsigned, Unencrypted Bind

NorthStar's domain controllers accept unsigned, unencrypted LDAP binds, exposing credentials transmitted during authentication to interception or relay attacks by anyone positioned on the same network segment. Recommendation: enforce LDAP signing and channel binding, and disable unsigned LDAP binds domain-wide.

Owner: Identity & Access Management Lead (Fictional Role) · Status: Remediation Planned

NET-007 · HIGH · CVSS 7.8

Excessive Administrative Access Across User Network Segment via Helpdesk Group Policy

Tier-1 helpdesk accounts hold standing local administrator rights fleet-wide across the User Workstation VLAN through a Restricted Groups Group Policy misconfiguration, enabling lateral movement from any user workstation to any other, and increasing the impact of a single helpdesk account compromise. Recommendation: replace standing local administrator rights with a just-in-time privileged access solution scoped to specific support tickets.

Owner: Identity & Access Management Lead (Fictional Role) · Status: Remediation Planned

NET-008 · HIGH · CVSS 7.4

Weak VPN Security Configuration Permits Legacy Cryptographic Negotiation

NorthStar's fictional VPN gateway allows deprecated cipher suites and key-exchange algorithms to be negotiated, weakening the confidentiality of remote-access traffic for any client that does not enforce modern cryptography on its own. Recommendation: disable deprecated cipher suites and key-exchange algorithms on the VPN gateway, permitting only current, strong cryptographic configurations.

Owner: Network Infrastructure Lead (Fictional Role) · Status: Remediation Planned

NET-009 · HIGH · CVSS 7.5

SNMP Community String Configuration Exposes Network Device Information

SNMPv1/v2c remains enabled alongside SNMPv3 on the core and distribution switches, using guessable community strings that disclose network topology and device configuration. Recommendation: disable SNMPv1/v2c fleet-wide and migrate fully to SNMPv3 with authentication and encryption.

Owner: Network Infrastructure Lead (Fictional Role) · Status: Remediation Planned

NET-010 · HIGH · CVSS 8.0

RDP Accessible Across Improperly Segmented Network Boundaries

Remote Desktop Protocol reachability unintentionally crosses segmentation boundaries, allowing direct administrative access from user-tier zones to privileged administrative servers rather than being restricted to a dedicated jump-host path. Recommendation: restrict RDP reachability to a dedicated privileged access workstation / jump-host path, and deny direct RDP from user-tier zones to administrative servers.

Owner: Network Infrastructure Lead (Fictional Role) · Status: Remediation Planned

NET-011 · HIGH · CVSS 8.2

Insecure Firewall Rule Permits Management-Plane Access From Corporate Wireless Segment

An overly broad firewall source object allows corporate wireless clients to reach management VLAN interfaces intended only for infrastructure personnel on wired administrative segments. Recommendation: scope the firewall source object to wired administrative hosts only.

Owner: Network Infrastructure Lead (Fictional Role) · Status: Remediation Planned

NET-012 · HIGH · CVSS 7.9

Sensitive Backup Repository Reachable From User VLAN Without Authentication Segmentation

Backup infrastructure on the Backup VLAN is directly reachable from user workstations with broad read permissions, exposing encrypted backups containing database snapshots to anyone on the User Workstation VLAN. Recommendation: restrict Backup VLAN reachability to backup-management hosts only, and remove broad read access to backup shares.

Owner: Network Infrastructure Lead (Fictional Role) · Status: Remediation Planned

NET-013 · HIGH · CVSS 7.6

Weak Service Account Security Enables Lateral Movement via Kerberoasting

SPN-registered service accounts use stale, non-rotated passwords recoverable through offline Kerberos ticket cracking, allowing any authenticated domain user to request service tickets and crack them offline. Recommendation: rotate all service account passwords to high-entropy values and adopt Group Managed Service Accounts (gMSA) where supported.

Owner: Identity & Access Management Lead (Fictional Role) · Status: Remediation Planned

17 · ATTACK PATH ANALYSIS

Attack path analysis

The full sample report walks through two illustrative, fictional attack chains showing how individually-rated findings combine into realistic compromise scenarios.

Attack Path 1 — External to domain-level impact: starting from the internet, an attacker exploits the legacy VPN authentication bypass (NET-001) to obtain network access using only a single valid credential. From the User Workstation VLAN, the insufficient segmentation gap (NET-002) provides direct reachability to the Database VLAN. Independently, the SYSVOL credential exposure (NET-003) provides a Domain Admin-equivalent credential to any authenticated user, completing a path to full domain-level impact.

Attack Path 2 — Assumed-breach lateral movement: starting from a compromised User VLAN workstation (the internal assumed-breach starting point), internal enumeration discovers SMB and LDAP configuration weaknesses (NET-005, NET-006) that expose credential material via Kerberoasting (NET-013). The recovered credential is used for lateral movement to a privileged administrative server reachable via improperly segmented RDP (NET-010), from which the exposed management plane (NET-004) provides a path to network device compromise.

These attack-chain narratives are illustrative of TMG's reporting approach and do not describe any real exploitation — no real network, device, or credential was involved.

18 · REMEDIATION ROADMAP

Remediation roadmap

Every finding in the full sample report carries an owning fictional role, a target remediation date, and a status, grouped into a phased roadmap: immediate action on the four Critical findings, a 31–60 day phase for the nine High findings, a 90-day phase for the fourteen Medium findings, and an ongoing hardening and governance program tracking the nine Low and ten Informational items.

  • Immediate (0–30 days): all four Critical findings — NET-001, NET-002, NET-003, NET-004
  • 31–60 days: all nine High findings — NET-005 through NET-013
  • 90 days: all fourteen Medium findings — NET-014 through NET-027
  • Ongoing hardening and governance program: the nine Low and ten Informational findings — NET-028 through NET-046
19 · RETEST METHODOLOGY

Retest methodology

The full sample report's retest methodology follows a structured approach: each remediation claim is validated against the original finding's proof of concept, retesting occurs only after confirmation that remediation is complete, and a final retest report documents closure status for every finding.

20 · LIMITATIONS

Limitations

This fictional assessment was scoped to the systems and network segments explicitly listed in the scope section above; testing did not extend to physical security, third-party infrastructure, or denial-of-service techniques. Findings reflect point-in-time observations only, and this sample does not represent a complete or exhaustive test of every possible network attack surface.

21 · CONCLUSION

Conclusion

NorthStar's fictional network demonstrates foundational security controls but requires prioritized remediation of four Critical and nine High findings, concentrated in network segmentation, Active Directory credential hygiene, and management-plane access control, before a stronger trust posture is achieved.

22 · WHAT'S INCLUDED IN THE FULL REPORT

What's included in the full report

Beyond the sections summarized on this page, the complete sample PDF includes a full set of supporting appendices, and the complete finding register is reproduced below:

  • Scope Register
  • Asset Register
  • Service / Port Register
  • Network Architecture Register
  • Network Segmentation Matrix
  • Active Directory Assessment Matrix
  • Test Case Register — all 152 fictional test cases executed
  • Finding Register (all 46 findings, with ID, title, severity, and mapping)
  • Evidence Register
  • Remediation Priority Matrix
  • Test Accounts / Fictional Identities
  • Technology / Software Inventory
  • Methodology Traceability
  • Attack Path Register
Full illustrative finding register — fictional sample data, finding register appendix of the sample PDF.
IDTitleSeverity
NET-001External VPN Authentication Can Be Bypassed Through Legacy Authentication WorkflowCritical
NET-002Insufficient Internal Network Segmentation Enables Unauthenticated Reachability from User VLAN to Database VLANCritical
NET-003Privileged Active Directory Service Account Credential Exposed Through Insecure Group Policy Preferences ConfigurationCritical
NET-004Exposed Management Plane Enables Administrative Access to Core Network Devices from User VLANCritical
NET-005SMB Signing Not Enforced on Critical Internal Windows ServersHigh
NET-006Insecure LDAP Configuration Permits Credential Exposure via Unsigned, Unencrypted BindHigh
NET-007Excessive Administrative Access Across User Network Segment via Helpdesk Group PolicyHigh
NET-008Weak VPN Security Configuration Permits Legacy Cryptographic NegotiationHigh
NET-009SNMP Community String Configuration Exposes Network Device InformationHigh
NET-010RDP Accessible Across Improperly Segmented Network BoundariesHigh
NET-011Insecure Firewall Rule Permits Management-Plane Access From Corporate Wireless SegmentHigh
NET-012Sensitive Backup Repository Reachable From User VLAN Without Authentication SegmentationHigh
NET-013Weak Service Account Security Enables Lateral Movement via KerberoastingHigh
NET-014Outdated TLS Configuration on External Remote Access PortalMedium
NET-015Certificate Configuration Issue on External VPN GatewayMedium
NET-016DNS Configuration Weakness Permits Zone Transfer from External DNS ServerMedium
NET-017Exposed Service With Unnecessary Functionality on External Load BalancerMedium
NET-018Information Disclosure Through Verbose Error Messages on Public Web Application GatewayMedium
NET-019Legacy/Insecure Protocol Exposure — SMBv1 Still Enabled on Internal File ServerMedium
NET-020Unnecessary East-West Connectivity Between Application VLAN and Database VLAN Beyond Required PortsMedium
NET-021Insecure Monitoring Interface Exposes Sensitive Telemetry Without AuthenticationMedium
NET-022Weak Internal TLS Configuration on Internal API ServerMedium
NET-023Kerberos Configuration Weakness — Unconstrained Delegation Enabled on Legacy Application ServerMedium
NET-024Excessive Privilege Assignment — Standard Support Accounts Present in Domain Admins GroupMedium
NET-025Weak Password Policy Permits Short, Non-Complex Domain PasswordsMedium
NET-026Insecure Administrative Pathway — Helpdesk Staff Granted Direct RDP to Domain ControllersMedium
NET-027Weak Corporate Wireless Configuration — Shared PSK Fallback Available Alongside 802.1XMedium
NET-028Guest Wireless Network Isolation Weakness Permits Limited Reachability to Printer VLANLow
NET-029Insecure SNMP Configuration — SNMPv2c Enabled Alongside SNMPv3 on Distribution SwitchesLow
NET-030Outdated Device Firmware on Wireless LAN ControllerLow
NET-031Configuration Backup Exposure — Unencrypted Device Configurations Stored on Shared DriveLow
NET-032Weak Network-Device ACL Permits Broader Source Range Than Required for SSH ManagementLow
NET-033Excessive Domain Information Disclosure via Unauthenticated LDAP EnumerationLow
NET-034SYSVOL-Related Sensitive Configuration Reference in Legacy Logon ScriptLow
NET-035Overly Permissive VPN Trust Allows Split-Tunnel Access to Sensitive On-Prem ResourcesLow
NET-036Weak Hybrid Segmentation Between On-Prem Identity Sync Server and Cloud Management PathLow
NET-037Positive Observation — Next-Generation Firewall Enforces Application-Aware Policy at External PerimeterInformational
NET-038Positive Observation — Centralized Logging and SIEM Collection Implemented Across Core InfrastructureInformational
NET-039Positive Observation — Multi-Factor Authentication Enforced on Primary VPN Login PathInformational
NET-040Recommendation — Adopt Privileged Access Workstations for Tier-0 Administrative ActivityInformational
NET-041Recommendation — Formalize Network Segmentation Review CadenceInformational
NET-042Recommendation — Expand SIEM Detection Coverage for Lateral Movement TechniquesInformational
NET-043Informational — Management VLAN Naming Convention Inconsistent Across Network DocumentationInformational
NET-044Informational — Legacy DNS Records Identified for Decommissioned HostsInformational
NET-045Recommendation — Implement Network Access Control (802.1X) on Wired User PortsInformational
NET-046Recommendation — Establish Formal Firewall Rule Review and Recertification ProcessInformational
23 · FREQUENTLY ASKED QUESTIONS

Frequently asked questions

Is this an actual client penetration testing report?+

No. NorthStar Financial Services, Inc. and the assessed network environment are fictional. This is a sample/demonstration report and does not represent a real client engagement or real network security assessment.

What is a network penetration test?+

A network penetration test is an authorized, simulated attack against an organization's network infrastructure — external and/or internal — designed to identify exploitable weaknesses in configuration, segmentation, authentication, and privileged access before a real attacker does.

What does a network penetration test cover?+

A TMG Security network penetration test covers the external attack surface, internal network segmentation, Active Directory security, network device configuration, wireless networks, and cloud/hybrid connectivity, combining automated enumeration with manual testing and controlled, non-destructive exploitation.

Does network penetration testing include Active Directory?+

Yes. Active Directory domain architecture, privileged group membership, service account hygiene, password policy, LDAP, Kerberos, SMB signing, SYSVOL, and Group Policy security are core parts of every TMG internal network assessment.

Does network penetration testing include network segmentation?+

Yes. TMG validates the documented zone-to-zone segmentation policy against actual observed network reachability, testing whether traffic that should be denied between zones is genuinely blocked.

Does network penetration testing include wireless networks?+

Yes. TMG assesses corporate, guest, and management wireless SSIDs for authentication strength, client isolation, and inappropriate reachability into wired network segments.

Does network penetration testing include external and internal testing?+

Yes. TMG combines an external black-box/grey-box assessment of the internet-facing perimeter with an internal assumed-breach assessment starting from a standard user-tier foothold, since real-world compromise can originate from either direction.

What is an assumed-breach network penetration test?+

An assumed-breach test starts from the position of an attacker who already has a foothold inside the network — such as a compromised standard user workstation — rather than requiring the tester to first breach the perimeter, focusing effort on lateral movement, privilege escalation, and segmentation testing.

What is included in a professional network penetration testing report?+

A complete report includes scope and methodology, a network architecture overview, detailed findings with severity ratings, evidence, and remediation guidance, attack-path analysis chaining findings into realistic scenarios, a remediation roadmap, and a retest methodology — all illustrated in this sample.

How does TMG Security report network vulnerabilities?+

Every finding is written up with a unique ID, a CVSS v3.1-inspired severity score, a CWE mapping where applicable, a clear description, evidence, and a specific remediation recommendation, then tracked through a remediation roadmap with an owner, target date, and status until retest.

24 · VIEW FULL SAMPLE PDF

View the full sample PDF

The complete illustrative report, including the full methodology, network architecture and segmentation registers, all 46 detailed findings with evidence panels, attack-path analysis, the remediation roadmap, and every appendix — scope register, asset register, service/port register, network architecture register, network segmentation matrix, Active Directory assessment matrix, test case register, finding register, evidence register, remediation priority matrix, test accounts/fictional identities, technology/software inventory, methodology traceability, and attack path register.

NorthStar Financial Services, Inc. Network Penetration Testing Report — Sample.pdf
NETWORK PENETRATION TESTING REPORT · PTES / NIST SP 800-115 · NorthStar Financial Services · Illustrative Sample
25 · REQUEST A SIMILAR ASSESSMENT

Request a similar assessment

This sample shows how TMG Security structures an external and internal network penetration test. TMG also provides Offensive Security & Penetration Testing, API Security Testing, Web Application Security Testing, and Mobile Application Security Testing for organizations that need an actual assessment of a real environment.