Internal pentesting
What can an attacker do inside your network?
In an internal pentest, the NodeZero platform takes the perspective of an attacker or malicious insider who has already gained access to your internal network. Assess on-premises infrastructure, cloud infrastructure, identity and access management infrastructure, data infrastructure, and virtual infrastructure.
Autonomous exploits
NodeZero autonomously discovers and exploits weaknesses in your network just as an attacker would. It moves laterally in your environment by compromising credentials through credential attacks, mining exposed data, bypassing security controls, and exploiting key vulnerabilities and misconfigurations.

Reveal critical impacts
NodeZero orchestrates hundreds of offensive security tools and chains weaknesses together to demonstrate the types of impacts attackers seek: domain compromise, business email compromise, access to sensitive data exposure, ransomware, and the ability to pivot to the cloud.

Test from different perspectives
Unlike manual pentests, where less than one per cent of a network is typically tested, NodeZero scales to support your largest networks. Your internal pentest options let you configure which IP ranges should be included and excluded in a test. You can test the whole private IP space (RFC 1918) if you want. You can also run multiple tests at the same time in different network segments for maximum efficiency.

Add OSINT to your testing
NodeZero can make use of open-source intelligence (OSINT) to inform certain attacks, just like a real-world attacker might. If you configure NodeZero with basic seed information such as your company name or domains, NodeZero will gather publicly available information related to your company and incorporate it into the pentest.
Insider Threat Testing: the reach of a compromised or malicious user
Insider Threat Testing configures NodeZero to start from the perspective of an authenticated user — with the credentials, network position, and access a genuine employee or compromised account would have — and then asks what an attacker with that foothold could actually reach. It proves the real-world impact of over-provisioned access, stale privileges, weak segmentation between user and server tiers, and credential reuse. Use it to validate zero-trust boundaries, verify least-privilege enforcement, and generate evidence for the personnel-security expectations of the PSPF and Defence Security Principles Framework (DSPF) and for ISM access-review and privileged-access controls.

Segmentation testing: validate zone boundaries actually hold
Segmentation testing runs scoped NodeZero pentests across the logical and physical boundaries your architecture relies on — user VLANs to server VLANs, supplier interconnects to production, OT to IT, cloud to on-premises. NodeZero enumerates IPs, ports, services, and applications reachable from each starting point and attempts lateral movement across the boundary. You see whether segmentation actually contains a breach where it is designed to — direct evidence that zone controls, firewalls, and ACLs enforce what the architecture says they enforce. For SOCI-regulated operators that is direct evidence for the zone-isolation hazards a CIRMP must address under Part 2B, and for any organisation it evidences the ISM network-segmentation controls an assessor will ask you to demonstrate rather than assert.

Full transparency: proof of every exploit
You see precisely what NodeZero runs and which hosts or users it compromises — every action carries a timestamp. After the test, you get a prioritised summary of impact and complete visibility into each proven attack path: step-by-step summaries showing where credentials were compromised or remote access tools were used midstream. For every weakness, NodeZero shows the proof that it was exploited, the downstream impacts that followed, and the fix actions to close it. That timestamped, per-weakness exploit evidence is exactly the audit artefact a DISP, Essential Eight Maturity Level 2–3, or ISM control review asks for — proof the weakness existed, was reachable, and was remediated.

Four reports your team and your auditor can both use
Every pentest produces a set of reports written for different audiences: an Executive Summary for the board, a detailed Pentest report carrying the proof and fix actions your technical team works from, a Segmentation report that evidences whether your zone boundaries held, and a Fix Actions Report that prioritises remediation. Reports are easily customised and co-branded, so a Drochaid-delivered engagement reaches your stakeholders under your own banner. The Segmentation report is especially useful as zone-control evidence for a SOCI CIRMP. Reports are written for the people who have to act on them, not just filed away.
Continuous validation: replace the annual pentest
Do not rely on a point-in-time pentest. Schedule NodeZero to run automatically on a recurring basis — once a week is the recommended cadence, or whatever interval suits you — and it delivers continuous autonomous pentesting with no user intervention: no one has to launch the tests or even sign in to start them. Each run verifies your fixes and surfaces new weaknesses, and you can compare results across runs to see exactly what changed. That turns penetration testing from an annual project your auditor ticks off once into a continuous programme that proves your posture is holding — or shows you the moment it stops.

What NodeZero uncovers in your network
Asset discovery and network enumeration
NodeZero finds assets including hosts, devices, cloud services, and running applications. It fingerprints network assets such as routers, domain controllers, VMware vCenter servers, and databases. It scans for open TCP and UDP ports and fingerprints the services running on those ports, as well as the operating systems, web servers, and applications behind them. You can see how the attack modules align to the MITRE ATT&CK framework.
Goes far beyond CVEs
NodeZero identifies and exploits critical weaknesses that go far beyond common vulnerabilities and exposures (CVEs). Unlike other automated tools, it autonomously chains weaknesses together without a predefined script. Many of the attack paths NodeZero executes don't involve exploiting any CVEs. The scoring reflects what NodeZero was actually able to accomplish — significantly different from the static CVE scoring that vulnerability scanners use.
Vulnerable services
Vulnerable services running on network hosts that have known CVEs. NodeZero exploits these vulnerabilities to perform activities such as executing remote commands, dumping credentials, or accessing sensitive data. New N-day tests are continually added.
Misconfigured network devices, servers, and applications
Weak passwords, default configurations, open ports, and insecure network settings on routers, servers, and applications. Misconfigurations — not unpatched CVEs — are the dominant finding in most environments, and NodeZero exploits them to prove the path they open.
Gaps in your security controls
NodeZero tests your defences, not just your assets — for example, attempting endpoint detection and response (EDR) evasion through techniques like OS credential dumping. It shows where controls fail to detect or block a real attack, giving you evidence to validate Essential Eight Maturity Level 2–3 control effectiveness rather than assume it.
Weak network segmentation
Misconfigured firewall rules and improper network zoning that let an attacker cross boundaries that are meant to contain a breach. NodeZero proves where segmentation does and does not hold — the weakness behind many of the lateral-movement paths it uncovers.
Weak authentication
Default or easily guessable passwords and weak authentication mechanisms. NodeZero attempts to exploit them to gain unauthorised access to systems or accounts.
Data leakage and exposure
Misconfigured file shares, insecure data transfer protocols, and weak access controls. Includes payment card information, Tax File Numbers, Medicare numbers, and other personally identifiable information (PII) that increases your risk of ransomware and can jeopardise compliance with the Privacy Act 1988 (Cth) and the NZ Privacy Act 2020.
Exposed credentials
Man-in-the-middle (MiTM) attacks, password cracking, password spraying, and credential phishing — where NodeZero harvests credentials entered into internal phishing-campaign assets and reuses them in further exploitation attempts. NodeZero executes these techniques to obtain login credentials from within the target network during an internal pentest. You can also run regular password audits with the NodeZero AD Password Audit (/nodezero/product/ad-password-audit) to get ahead of weak and reused credentials.
Learn more →Cloud pivoting
During your internal pentest, NodeZero will try to pivot into your cloud environments, identifying attack paths leading to the compromise of cloud assets and data. This includes Amazon S3 storage buckets, Amazon EC2 instances, Microsoft 365 cloud-based services, and Microsoft Azure virtual machines.
Advanced post-exploitation with NodeZero RAT
NodeZero orchestrates a purpose-built internal remote access tool that offers many of the same capabilities as adversary emulation tools like Cobalt Strike, Meterpreter, and Sliver — chosen to simulate what a real intruder could do after initial access. Once deployed, it continues the attack path: credential dumping, system information gathering, and impact assessment. Tuned for production safety, not evasion; cleans up after itself when the pentest completes.
Fast, low-maintenance, and safe by default
Validate and improve your security posture, proactively protect against ransomware, and streamline your compliance initiatives.
High speed
Kick off your NodeZero pentest in minutes instead of the weeks a manual pentest could take.
Low maintenance
With a SaaS architecture, there is no hardware or software to maintain and no required agents to install.
Safe by default
NodeZero is built to run in production, not just a lab. It operates within production-safe defaults, the NodeZero RAT cleans up after itself when the pentest completes, and you can configure IP ranges to include or exclude so sensitive hosts stay out of scope — autonomous testing without the risk of an autonomous incident.
See what an attacker could access in your network
Run an internal pentest with NodeZero and get proof of exploitable weaknesses, prioritised fix guidance, and 1-click verification.