Network Penetration Testing Report — Sample
NorthStar Financial Services, Inc. — External and Internal Network Penetration Test. A fictional external and internal network penetration testing assessment of NorthStar Financial Services, Inc., covering external attack surface, internal network security, Active Directory, network segmentation, network devices, wireless security, cloud/hybrid connectivity, attack-path analysis, findings, and remediation guidance.
FICTIONAL SAMPLE — NOT AN ACTUAL CLIENT NETWORK PENETRATION TEST. NorthStar Financial Services, Inc. is fictional. All domains (including northstar-example.com), IP addresses, hostnames, credentials, configurations, findings, and evidence shown are fictional or synthetic. No real client network, system, or infrastructure was tested, and no real customer data or credentials were used. TMG Security is not affiliated with, endorsed by, reviewed by, or certified by PTES, NIST, or any standards body.
Overview
This is a fictional, illustrative sample of a network penetration testing report. It demonstrates how TMG Security structures and documents a professional external and internal network security assessment — from scope and PTES/NIST SP 800-115-informed methodology through network segmentation testing, Active Directory security review, network device assessment, wireless and cloud/hybrid testing, findings, and remediation guidance. The full sample report contains 46 illustrative findings drawn from 152 fictional test cases, executed against a fictional enterprise environment spanning 13 internal network zones. NorthStar Financial Services, Inc. does not exist; every finding, test case, host, and figure in this sample is fictional and constructed to show TMG's reporting standard, not to describe any real organization's security posture.
What this sample report covers
NorthStar Financial Services, Inc. does not exist. Every finding, test case, host, zone, and figure in this sample is fictional and constructed to show TMG's methodology and reporting standard for a PTES/NIST SP 800-115-informed network penetration test — not to describe any real organization's security posture.
- How TMG defines scope, rules of engagement, and testing objectives for combined external and internal network testing
- How the external perimeter is enumerated and tested — VPN, remote access portal, mail gateway, DNS, load balancer, and bastion host
- How the internal network is assessed under an assumed-breach model, starting from a standard user-tier foothold
- How network segmentation is validated against the documented zone-to-zone policy matrix
- How Active Directory domain architecture, privileged groups, service accounts, and credential hygiene are reviewed
- How network devices — firewalls, switches, wireless controllers, and management platforms — are assessed
- How wireless networks and cloud/hybrid connectivity are tested
- How attack-path analysis chains individual findings into realistic, fictional compromise scenarios
- How findings are rated using CVSS v3.1-inspired scoring and mapped to CWE, then evidenced and remediated
- How a remediation roadmap and retest methodology are structured for security engineering follow-through
Assessment overview
This fictional assessment was performed against NorthStar Financial Services, Inc., a fictional financial services / fintech organization, combining an external black-box/grey-box assessment of the internet-facing perimeter with an internal assumed-breach assessment starting from a standard user-tier foothold.
Scope
Scope for this fictional assessment covered the full external perimeter and eight internal network zones, plus wireless and cloud/hybrid connectivity, exercised over the assessment period against 152 fictional test cases.
- External perimeter: internet-facing VPN gateway, remote access portal, public web application gateway/WAF, external DNS, email security gateway, external perimeter firewall, external load balancer, bastion/jump host, and externally reachable remote administration surface
- Internal network zones: User Workstation, Server, Application, Database, Identity/AD, Management, Security Tooling, and Backup VLANs
- Network security devices: next-generation firewalls (external and internal), core switch, distribution switches, wireless LAN controller, and network management platform
- Windows / enterprise infrastructure: Active Directory domain controllers, Windows file server, application server, management server, internal PKI/certificate services, internal DNS, and internal monitoring server
- Linux / application infrastructure: Linux application server, internal API server, monitoring server, logging/SIEM collector, and backup server
- Cloud / hybrid connectivity: fictional site-to-site VPN, hybrid identity synchronization server, and cloud management interface
- Wireless networks: corporate SSID (NSF-CORP), guest SSID (NSF-GUEST), and management SSID (NSF-WLAN-MGMT)
Out of scope: any production system, network, or data belonging to a real organization; denial-of-service testing of any kind; physical security testing; social engineering campaigns; destructive exploitation; third-party vendor infrastructure; and cloud provider infrastructure below the fictional tenant/management layer.
Testing methodology
TMG Security's network testing approach is conceptually informed by PTES (the Penetration Testing Execution Standard) and NIST SP 800-115. Testing proceeded through the following phases:
- Pre-Engagement: scope confirmation, rules of engagement sign-off, target and credential provisioning, and emergency-contact exchange
- Rules of Engagement: formal agreement on testing windows, authorized techniques, prohibited activities, and stop conditions
- Reconnaissance: passive and active information gathering against the external attack surface — DNS, WHOIS, certificate transparency, and public-source review
- Attack Surface Discovery: enumeration of all in-scope external and internal hosts, culminating in the asset register
- Service Enumeration: port and service discovery across all in-scope hosts, producing the service/port register
- Vulnerability Analysis: correlation of enumerated services and configurations against known weakness classes
- Configuration Review: manual review of firewall, network device, Active Directory, and wireless configuration
- Authentication Testing: assessment of authentication mechanisms across VPN, remote administration, and directory services
- Network Segmentation Testing: validation of the segmentation matrix against observed live traffic flows
- Active Directory Assessment: domain architecture, trust, privileged group, service account, and credential-exposure review
- Lateral Movement Assessment: controlled, non-destructive demonstration of lateral movement paths made possible by chained findings
- Privilege Escalation Assessment: controlled, non-destructive demonstration of privilege-escalation paths from standard to privileged access
- Exposure Validation: confirmation that identified weaknesses represent genuine, reproducible exposure
- Controlled Exploitation: safe, non-destructive proof-of-concept execution for Critical and High findings only
- Post-Exploitation Validation: confirmation of the practical impact of a successful technique without further action
- Evidence Collection: capture of illustrative evidence for every finding, mapped to the evidence register
- Risk Rating: assignment of a CVSS-style illustrative score and severity rating to every finding
- Remediation: development of finding-specific and program-level remediation guidance
- Retest: post-remediation validation methodology, described in the retest section below
TMG Security is not affiliated with, endorsed by, reviewed by, or certified by PTES, NIST, or any standards body. References to PTES and NIST SP 800-115 describe the testing methodology used and do not imply any official certification of NorthStar Financial Services or TMG Security.
Network architecture
The fictional NorthStar environment is organized into 13 internal network zones, spanning user, server, application, database, identity, backup, management, security tooling, wireless, and cloud/hybrid segments. This sample report shows how TMG documents network architecture as the baseline for segmentation and lateral-movement testing.
| Zone | Fictional Range | Description |
|---|---|---|
| User Workstation VLAN | 10.40.10.0/24 | Standard end-user Windows workstations, laptops, VDI clients |
| Server VLAN | 10.40.20.0/24 | Windows infrastructure servers — file, application, management, monitoring, PKI, internal DNS |
| Application VLAN | 10.40.30.0/24 | Linux application, internal API, logging/SIEM, and monitoring servers |
| Database VLAN | 10.40.40.0/24 | Primary transactional and reporting database instances |
| Identity / AD VLAN | 10.40.50.0/24 | Active Directory domain controllers and identity infrastructure |
| Backup VLAN | 10.40.60.0/24 | Backup repository and backup-management infrastructure |
| Management VLAN | 172.20.10.0/24 | Out-of-band management interfaces for network devices |
| Security Tooling VLAN | 172.20.20.0/24 | Vulnerability scanning and EDR management infrastructure |
| Wireless — Corporate SSID | 10.50.10.0/24 | Corporate-issued and BYOD endpoints (NSF-CORP) |
| Wireless — Guest SSID | 10.50.20.0/24 | Guest and visitor wireless clients (NSF-GUEST) |
| Wireless — Management SSID | 10.50.30.0/24 | Wireless infrastructure management (NSF-WLAN-MGMT) |
| Cloud / Hybrid Connectivity | 10.50.0.0/24 | Site-to-site VPN termination and hybrid identity/cloud management |
| External Perimeter / DMZ | 10.40.0.0/24 | Internet-facing gateways, VPN, portal, mail, DNS |
External attack surface
TMG Security enumerated and tested nine fictional internet-facing systems comprising NorthStar's external attack surface.
| Asset | Hostname | Purpose |
|---|---|---|
| NS-A01 | NS-FW-EXT01 | External perimeter firewall / primary internet edge |
| NS-A02 | NS-VPNGW01 | Remote-access VPN gateway — vpn.northstar-example.com |
| NS-A03 | NS-PORTAL01 | Employee/partner remote access portal — portal.northstar-example.com |
| NS-A04 | NS-WAF01 | Fronts public-facing web applications |
| NS-A05 | NS-MAILGW01 | Inbound/outbound mail filtering — mail.northstar-example.com |
| NS-A06 | NS-DNSEXT01 | Authoritative DNS for northstar-example.com |
| NS-A07 | NS-LBEXT01 | TLS termination and load distribution for public services |
| NS-A08 | NS-BASTION01 | Administrative jump host for external vendor and remote admin access |
| NS-A09 | NS-RADMIN01 | Externally reachable WinRM/RDP administration surface for on-call engineers |
Internal network architecture
Internally, NorthStar's fictional environment separates user, server, application, database, identity, backup, management, and security-tooling traffic across dedicated VLANs, with three wireless SSIDs — Corporate (NSF-CORP), Guest (NSF-GUEST), and Management (NSF-WLAN-MGMT) — and a dedicated Security Tooling VLAN hosting vulnerability scanning and EDR management infrastructure. A Cloud/Hybrid Connectivity segment terminates a fictional site-to-site VPN and hosts the hybrid identity synchronization server and cloud management interface bridging the on-premises domain to the fictional cloud tenant.
Network segmentation assessment
TMG Security tested documented zone-to-zone pairs from the segmentation matrix against the traffic actually permitted on the live network, comparing expected policy against observed reachability. A representative selection of results is shown below; the complete segmentation matrix is included in the full sample PDF.
| Source | Destination | Expected | Observed | Risk |
|---|---|---|---|---|
| User Workstation VLAN | Database VLAN | Denied by default — no direct reachability | Permitted — unrestricted TCP/1433 reachability via overly broad rule | Critical |
| User Workstation VLAN | Backup VLAN | Denied — backup infrastructure isolated | Permitted — SMB share reachable with broad read permission | High |
| Guest Wireless SSID | Corporate network (all zones) | Denied — full isolation | Denied, as expected | None |
Active Directory security
TMG Security assessed NorthStar's fictional single-domain, single-forest Active Directory design — two domain controllers (NS-DC01, NS-DC02) — covering privileged group membership, service account hygiene, password policy, LDAP, Kerberos, SMB signing, SYSVOL, Group Policy security, administrative pathways, and monitoring. Domain Admins membership was found to exceed the minimum required for genuine Tier-0 activity, including several accounts used for routine application support. The Default Domain Policy enforces only an 8-character minimum password length with no banned-password-list screening. Several SPN-registered service accounts use stale, non-rotated passwords vulnerable to Kerberoasting, and a Domain Admin-equivalent service account credential was recoverable from a legacy Group Policy Preferences (SYSVOL) artifact.
Privileged Active Directory Service Account Credential Exposed Through Insecure Group Policy Preferences Configuration
A legacy Group Policy Preferences artifact stored in SYSVOL contains an encrypted credential using Microsoft's publicly-documented GPP encryption key. Any authenticated domain user — including a standard, non-privileged account — can decrypt it and recover the plaintext credential for svc-backupsync, a service account holding Domain Admin-equivalent rights. Recommendation: remove all legacy GPP-based credential storage from SYSVOL, rotate the exposed account's credential, and reduce the account's privileges to the minimum required for its backup function.
Weak Service Account Security Enables Lateral Movement via Kerberoasting
Multiple SPN-registered service accounts use stale, non-rotated passwords recoverable through offline Kerberos ticket cracking (Kerberoasting), allowing an attacker with any authenticated domain access to request service tickets and crack them offline without triggering account lockout. Recommendation: rotate all service account passwords to high-entropy values, adopt Group Managed Service Accounts (gMSA) where supported, and monitor for abnormal service-ticket request volume.
Network device security
TMG Security assessed NorthStar's fictional firewalls (external and internal), core switch, distribution switches, wireless LAN controller, and network management platform, covering management protocols, SNMP configuration, administrator access, ACLs, management-plane segmentation, configuration backups, logging, and firmware lifecycle. HTTPS/SSH were observed for device management with no Telnet exposure. Default vendor administrative credentials were not rotated on the core switch and internal firewall, and management-plane ACLs are missing on the core switch and internal firewall and overly broad on distribution switches. Automated configuration backups are stored unencrypted on a broadly-accessible general IT share, and the wireless LAN controller was running outdated firmware.
Exposed Management Plane Enables Administrative Access to Core Network Devices from User VLAN
An attacker with User VLAN access can reach the administrative web console of the core switch and internal firewall and authenticate using an unrotated default credential, since management-plane ACLs are missing on these devices and the management interface is reachable from the general user network rather than being restricted to the dedicated Management VLAN. Recommendation: restrict all device management interfaces to the Management VLAN only, rotate every default vendor administrative credential, and apply management-plane ACLs denying all source zones except authorized administrative hosts.
SNMP Community String Configuration Exposes Network Device Information
SNMPv1/v2c remains enabled alongside SNMPv3 on the core and distribution switches, using guessable community strings that disclose network topology and device configuration to anyone able to reach the management interface. Recommendation: disable SNMPv1/v2c fleet-wide, migrate fully to SNMPv3 with authentication and encryption, and restrict SNMP access to the Security Tooling VLAN.
Wireless security
TMG Security assessed NorthStar's three fictional wireless SSIDs. The Corporate SSID (NSF-CORP) uses WPA2-Enterprise with 802.1X/PEAP-MSCHAPv2, but retains a legacy shared-PSK fallback for IoT-style devices that has not been rotated in over two years. The Guest SSID (NSF-GUEST) uses WPA2-Personal with correctly configured client isolation from the corporate network. The Management SSID (NSF-WLAN-MGMT) uses WPA2-Personal for wireless LAN controller control-plane traffic; an overly broad firewall rule permits Corporate SSID clients to reach the Management VLAN.
Insecure Firewall Rule Permits Management-Plane Access From Corporate Wireless Segment
An overly broad firewall source object allows corporate wireless clients on NSF-CORP to reach management VLAN interfaces that are intended to be reachable only by infrastructure personnel on wired administrative segments. Recommendation: scope the firewall source object to wired administrative hosts only, and remove wireless segments from any rule permitting management-plane reachability.
Weak Corporate Wireless Configuration — Shared PSK Fallback Available Alongside 802.1X
A legacy shared pre-shared key fallback remains available on the Corporate SSID for IoT-style devices and has not been rotated in over two years, providing a lower-assurance authentication path alongside the primary 802.1X/PEAP-MSCHAPv2 configuration. Recommendation: migrate IoT-style devices to a dedicated, isolated SSID with MAC-based or certificate-based authentication, and retire the shared PSK fallback on the corporate SSID.
Cloud / hybrid security
TMG Security reviewed NorthStar's fictional site-to-site VPN connectivity and hybrid identity synchronization server bridging the on-premises Active Directory domain to a fictional cloud tenant and cloud management interface.
Overly Permissive VPN Trust Allows Split-Tunnel Access to Sensitive On-Prem Resources
The fictional site-to-site VPN configuration permits split-tunnel routing that grants a broader set of on-premises resources than the cloud connectivity's documented purpose requires. Recommendation: scope the VPN's routed prefixes to only the resources the cloud connectivity genuinely needs, and disable split-tunnel access to sensitive internal zones.
Weak Hybrid Segmentation Between On-Prem Identity Sync Server and Cloud Management Path
The hybrid identity synchronization server sits on a segment with broader reachability to the cloud management path than its synchronization function requires, widening the practical blast radius if the sync server is ever compromised. Recommendation: isolate the hybrid identity sync server on a dedicated segment with only the specific connectivity its synchronization role requires.
Findings summary
This fictional assessment identified 46 illustrative findings across NorthStar's external perimeter, internal network, Active Directory, network devices, wireless, and cloud/hybrid connectivity, drawn from 152 fictional test cases. Every finding, severity rating, and evidence reference is fictional and specific to this network penetration test.
Example Critical findings
All four Critical findings from this fictional assessment are shown in full below.
External VPN Authentication Can Be Bypassed Through Legacy Authentication Workflow
A legacy authentication workflow remains active on NorthStar's fictional remote-access VPN gateway alongside the primary multi-factor login path. Any attacker in possession of a single valid domain credential — obtained through any means, such as password reuse or phishing — can establish a full VPN session without satisfying the second authentication factor, by directing the connection through the legacy endpoint. Recommendation: decommission the legacy authentication workflow entirely, or if a legacy client population still requires it, enforce the same multi-factor requirement on that path as the primary login flow.
Insufficient Internal Network Segmentation Enables Unauthenticated Reachability from User VLAN to Database VLAN
Hosts on the User Workstation VLAN can establish direct TCP/1433 (SQL Server) connections to hosts on the Database VLAN, with no intermediate application tier and no authentication boundary enforced at the network layer, due to an overly broad firewall rule between the two zones. Recommendation: restrict Database VLAN reachability to only the specific application-tier hosts that require it, and remove direct User VLAN to Database VLAN connectivity entirely.
Privileged Active Directory Service Account Credential Exposed Through Insecure Group Policy Preferences Configuration
A legacy Group Policy Preferences artifact stored in SYSVOL contains an encrypted credential using Microsoft's publicly-documented GPP encryption key. Any authenticated domain user can decrypt it and recover the plaintext credential for svc-backupsync, a service account holding Domain Admin-equivalent rights. Recommendation: remove all legacy GPP-based credential storage from SYSVOL and rotate the exposed account's credential immediately.
Exposed Management Plane Enables Administrative Access to Core Network Devices from User VLAN
An attacker with User VLAN access can reach the administrative web console of the core switch and internal firewall and authenticate using an unrotated default credential. Recommendation: restrict all device management interfaces to the Management VLAN only and rotate every default vendor administrative credential.
High-severity findings
All nine High findings from this fictional assessment are shown below.
SMB Signing Not Enforced on Critical Internal Windows Servers
SMB signing is not enforced on critical internal Windows servers, so an attacker positioned on the Server VLAN who can capture NTLM authentication traffic can relay it to these servers and obtain an authenticated SMB session without knowing the underlying credential. Recommendation: enforce SMB signing on all Windows servers, prioritizing Tier-0 and Tier-1 systems.
Insecure LDAP Configuration Permits Credential Exposure via Unsigned, Unencrypted Bind
NorthStar's domain controllers accept unsigned, unencrypted LDAP binds, exposing credentials transmitted during authentication to interception or relay attacks by anyone positioned on the same network segment. Recommendation: enforce LDAP signing and channel binding, and disable unsigned LDAP binds domain-wide.
Excessive Administrative Access Across User Network Segment via Helpdesk Group Policy
Tier-1 helpdesk accounts hold standing local administrator rights fleet-wide across the User Workstation VLAN through a Restricted Groups Group Policy misconfiguration, enabling lateral movement from any user workstation to any other, and increasing the impact of a single helpdesk account compromise. Recommendation: replace standing local administrator rights with a just-in-time privileged access solution scoped to specific support tickets.
Weak VPN Security Configuration Permits Legacy Cryptographic Negotiation
NorthStar's fictional VPN gateway allows deprecated cipher suites and key-exchange algorithms to be negotiated, weakening the confidentiality of remote-access traffic for any client that does not enforce modern cryptography on its own. Recommendation: disable deprecated cipher suites and key-exchange algorithms on the VPN gateway, permitting only current, strong cryptographic configurations.
SNMP Community String Configuration Exposes Network Device Information
SNMPv1/v2c remains enabled alongside SNMPv3 on the core and distribution switches, using guessable community strings that disclose network topology and device configuration. Recommendation: disable SNMPv1/v2c fleet-wide and migrate fully to SNMPv3 with authentication and encryption.
RDP Accessible Across Improperly Segmented Network Boundaries
Remote Desktop Protocol reachability unintentionally crosses segmentation boundaries, allowing direct administrative access from user-tier zones to privileged administrative servers rather than being restricted to a dedicated jump-host path. Recommendation: restrict RDP reachability to a dedicated privileged access workstation / jump-host path, and deny direct RDP from user-tier zones to administrative servers.
Insecure Firewall Rule Permits Management-Plane Access From Corporate Wireless Segment
An overly broad firewall source object allows corporate wireless clients to reach management VLAN interfaces intended only for infrastructure personnel on wired administrative segments. Recommendation: scope the firewall source object to wired administrative hosts only.
Sensitive Backup Repository Reachable From User VLAN Without Authentication Segmentation
Backup infrastructure on the Backup VLAN is directly reachable from user workstations with broad read permissions, exposing encrypted backups containing database snapshots to anyone on the User Workstation VLAN. Recommendation: restrict Backup VLAN reachability to backup-management hosts only, and remove broad read access to backup shares.
Weak Service Account Security Enables Lateral Movement via Kerberoasting
SPN-registered service accounts use stale, non-rotated passwords recoverable through offline Kerberos ticket cracking, allowing any authenticated domain user to request service tickets and crack them offline. Recommendation: rotate all service account passwords to high-entropy values and adopt Group Managed Service Accounts (gMSA) where supported.
Attack path analysis
The full sample report walks through two illustrative, fictional attack chains showing how individually-rated findings combine into realistic compromise scenarios.
Attack Path 1 — External to domain-level impact: starting from the internet, an attacker exploits the legacy VPN authentication bypass (NET-001) to obtain network access using only a single valid credential. From the User Workstation VLAN, the insufficient segmentation gap (NET-002) provides direct reachability to the Database VLAN. Independently, the SYSVOL credential exposure (NET-003) provides a Domain Admin-equivalent credential to any authenticated user, completing a path to full domain-level impact.
Attack Path 2 — Assumed-breach lateral movement: starting from a compromised User VLAN workstation (the internal assumed-breach starting point), internal enumeration discovers SMB and LDAP configuration weaknesses (NET-005, NET-006) that expose credential material via Kerberoasting (NET-013). The recovered credential is used for lateral movement to a privileged administrative server reachable via improperly segmented RDP (NET-010), from which the exposed management plane (NET-004) provides a path to network device compromise.
These attack-chain narratives are illustrative of TMG's reporting approach and do not describe any real exploitation — no real network, device, or credential was involved.
Remediation roadmap
Every finding in the full sample report carries an owning fictional role, a target remediation date, and a status, grouped into a phased roadmap: immediate action on the four Critical findings, a 31–60 day phase for the nine High findings, a 90-day phase for the fourteen Medium findings, and an ongoing hardening and governance program tracking the nine Low and ten Informational items.
- Immediate (0–30 days): all four Critical findings — NET-001, NET-002, NET-003, NET-004
- 31–60 days: all nine High findings — NET-005 through NET-013
- 90 days: all fourteen Medium findings — NET-014 through NET-027
- Ongoing hardening and governance program: the nine Low and ten Informational findings — NET-028 through NET-046
Retest methodology
The full sample report's retest methodology follows a structured approach: each remediation claim is validated against the original finding's proof of concept, retesting occurs only after confirmation that remediation is complete, and a final retest report documents closure status for every finding.
Limitations
This fictional assessment was scoped to the systems and network segments explicitly listed in the scope section above; testing did not extend to physical security, third-party infrastructure, or denial-of-service techniques. Findings reflect point-in-time observations only, and this sample does not represent a complete or exhaustive test of every possible network attack surface.
Conclusion
NorthStar's fictional network demonstrates foundational security controls but requires prioritized remediation of four Critical and nine High findings, concentrated in network segmentation, Active Directory credential hygiene, and management-plane access control, before a stronger trust posture is achieved.
What's included in the full report
Beyond the sections summarized on this page, the complete sample PDF includes a full set of supporting appendices, and the complete finding register is reproduced below:
- Scope Register
- Asset Register
- Service / Port Register
- Network Architecture Register
- Network Segmentation Matrix
- Active Directory Assessment Matrix
- Test Case Register — all 152 fictional test cases executed
- Finding Register (all 46 findings, with ID, title, severity, and mapping)
- Evidence Register
- Remediation Priority Matrix
- Test Accounts / Fictional Identities
- Technology / Software Inventory
- Methodology Traceability
- Attack Path Register
| ID | Title | Severity |
|---|---|---|
| NET-001 | External VPN Authentication Can Be Bypassed Through Legacy Authentication Workflow | Critical |
| NET-002 | Insufficient Internal Network Segmentation Enables Unauthenticated Reachability from User VLAN to Database VLAN | Critical |
| NET-003 | Privileged Active Directory Service Account Credential Exposed Through Insecure Group Policy Preferences Configuration | Critical |
| NET-004 | Exposed Management Plane Enables Administrative Access to Core Network Devices from User VLAN | Critical |
| NET-005 | SMB Signing Not Enforced on Critical Internal Windows Servers | High |
| NET-006 | Insecure LDAP Configuration Permits Credential Exposure via Unsigned, Unencrypted Bind | High |
| NET-007 | Excessive Administrative Access Across User Network Segment via Helpdesk Group Policy | High |
| NET-008 | Weak VPN Security Configuration Permits Legacy Cryptographic Negotiation | High |
| NET-009 | SNMP Community String Configuration Exposes Network Device Information | High |
| NET-010 | RDP Accessible Across Improperly Segmented Network Boundaries | High |
| NET-011 | Insecure Firewall Rule Permits Management-Plane Access From Corporate Wireless Segment | High |
| NET-012 | Sensitive Backup Repository Reachable From User VLAN Without Authentication Segmentation | High |
| NET-013 | Weak Service Account Security Enables Lateral Movement via Kerberoasting | High |
| NET-014 | Outdated TLS Configuration on External Remote Access Portal | Medium |
| NET-015 | Certificate Configuration Issue on External VPN Gateway | Medium |
| NET-016 | DNS Configuration Weakness Permits Zone Transfer from External DNS Server | Medium |
| NET-017 | Exposed Service With Unnecessary Functionality on External Load Balancer | Medium |
| NET-018 | Information Disclosure Through Verbose Error Messages on Public Web Application Gateway | Medium |
| NET-019 | Legacy/Insecure Protocol Exposure — SMBv1 Still Enabled on Internal File Server | Medium |
| NET-020 | Unnecessary East-West Connectivity Between Application VLAN and Database VLAN Beyond Required Ports | Medium |
| NET-021 | Insecure Monitoring Interface Exposes Sensitive Telemetry Without Authentication | Medium |
| NET-022 | Weak Internal TLS Configuration on Internal API Server | Medium |
| NET-023 | Kerberos Configuration Weakness — Unconstrained Delegation Enabled on Legacy Application Server | Medium |
| NET-024 | Excessive Privilege Assignment — Standard Support Accounts Present in Domain Admins Group | Medium |
| NET-025 | Weak Password Policy Permits Short, Non-Complex Domain Passwords | Medium |
| NET-026 | Insecure Administrative Pathway — Helpdesk Staff Granted Direct RDP to Domain Controllers | Medium |
| NET-027 | Weak Corporate Wireless Configuration — Shared PSK Fallback Available Alongside 802.1X | Medium |
| NET-028 | Guest Wireless Network Isolation Weakness Permits Limited Reachability to Printer VLAN | Low |
| NET-029 | Insecure SNMP Configuration — SNMPv2c Enabled Alongside SNMPv3 on Distribution Switches | Low |
| NET-030 | Outdated Device Firmware on Wireless LAN Controller | Low |
| NET-031 | Configuration Backup Exposure — Unencrypted Device Configurations Stored on Shared Drive | Low |
| NET-032 | Weak Network-Device ACL Permits Broader Source Range Than Required for SSH Management | Low |
| NET-033 | Excessive Domain Information Disclosure via Unauthenticated LDAP Enumeration | Low |
| NET-034 | SYSVOL-Related Sensitive Configuration Reference in Legacy Logon Script | Low |
| NET-035 | Overly Permissive VPN Trust Allows Split-Tunnel Access to Sensitive On-Prem Resources | Low |
| NET-036 | Weak Hybrid Segmentation Between On-Prem Identity Sync Server and Cloud Management Path | Low |
| NET-037 | Positive Observation — Next-Generation Firewall Enforces Application-Aware Policy at External Perimeter | Informational |
| NET-038 | Positive Observation — Centralized Logging and SIEM Collection Implemented Across Core Infrastructure | Informational |
| NET-039 | Positive Observation — Multi-Factor Authentication Enforced on Primary VPN Login Path | Informational |
| NET-040 | Recommendation — Adopt Privileged Access Workstations for Tier-0 Administrative Activity | Informational |
| NET-041 | Recommendation — Formalize Network Segmentation Review Cadence | Informational |
| NET-042 | Recommendation — Expand SIEM Detection Coverage for Lateral Movement Techniques | Informational |
| NET-043 | Informational — Management VLAN Naming Convention Inconsistent Across Network Documentation | Informational |
| NET-044 | Informational — Legacy DNS Records Identified for Decommissioned Hosts | Informational |
| NET-045 | Recommendation — Implement Network Access Control (802.1X) on Wired User Ports | Informational |
| NET-046 | Recommendation — Establish Formal Firewall Rule Review and Recertification Process | Informational |
Frequently asked questions
Is this an actual client penetration testing report?+
No. NorthStar Financial Services, Inc. and the assessed network environment are fictional. This is a sample/demonstration report and does not represent a real client engagement or real network security assessment.
What is a network penetration test?+
A network penetration test is an authorized, simulated attack against an organization's network infrastructure — external and/or internal — designed to identify exploitable weaknesses in configuration, segmentation, authentication, and privileged access before a real attacker does.
What does a network penetration test cover?+
A TMG Security network penetration test covers the external attack surface, internal network segmentation, Active Directory security, network device configuration, wireless networks, and cloud/hybrid connectivity, combining automated enumeration with manual testing and controlled, non-destructive exploitation.
Does network penetration testing include Active Directory?+
Yes. Active Directory domain architecture, privileged group membership, service account hygiene, password policy, LDAP, Kerberos, SMB signing, SYSVOL, and Group Policy security are core parts of every TMG internal network assessment.
Does network penetration testing include network segmentation?+
Yes. TMG validates the documented zone-to-zone segmentation policy against actual observed network reachability, testing whether traffic that should be denied between zones is genuinely blocked.
Does network penetration testing include wireless networks?+
Yes. TMG assesses corporate, guest, and management wireless SSIDs for authentication strength, client isolation, and inappropriate reachability into wired network segments.
Does network penetration testing include external and internal testing?+
Yes. TMG combines an external black-box/grey-box assessment of the internet-facing perimeter with an internal assumed-breach assessment starting from a standard user-tier foothold, since real-world compromise can originate from either direction.
What is an assumed-breach network penetration test?+
An assumed-breach test starts from the position of an attacker who already has a foothold inside the network — such as a compromised standard user workstation — rather than requiring the tester to first breach the perimeter, focusing effort on lateral movement, privilege escalation, and segmentation testing.
What is included in a professional network penetration testing report?+
A complete report includes scope and methodology, a network architecture overview, detailed findings with severity ratings, evidence, and remediation guidance, attack-path analysis chaining findings into realistic scenarios, a remediation roadmap, and a retest methodology — all illustrated in this sample.
How does TMG Security report network vulnerabilities?+
Every finding is written up with a unique ID, a CVSS v3.1-inspired severity score, a CWE mapping where applicable, a clear description, evidence, and a specific remediation recommendation, then tracked through a remediation roadmap with an owner, target date, and status until retest.
View the full sample PDF
The complete illustrative report, including the full methodology, network architecture and segmentation registers, all 46 detailed findings with evidence panels, attack-path analysis, the remediation roadmap, and every appendix — scope register, asset register, service/port register, network architecture register, network segmentation matrix, Active Directory assessment matrix, test case register, finding register, evidence register, remediation priority matrix, test accounts/fictional identities, technology/software inventory, methodology traceability, and attack path register.
Request a similar assessment
This sample shows how TMG Security structures an external and internal network penetration test. TMG also provides Offensive Security & Penetration Testing, API Security Testing, Web Application Security Testing, and Mobile Application Security Testing for organizations that need an actual assessment of a real environment.
