main logo icon

Published on

October 1, 2026

|

29 min read

Best Internal Network and Active Directory Penetration Testing Companies (2026): Ranked for AD, Entra ID and Assumed-Breach Testing

Ranked guide to the best internal network and Active Directory penetration testing companies in 2026, with what PCI DSS 11.4.2 and 11.4.5, NYDFS 500.5 and OSFI B-13 require, Entra ID scope and assumed-breach starts, verified 1 and 2 October 2026.

Arafat Afzalzada

Arafat Afzalzada

Founder

Network Security

Summarize with AI

ChatGPTPerplexityGeminiGrokClaude

TL;DR

Microsoft says more than 78 percent of the human-operated attacks it has seen breached a domain controller, and in more than 35 percent of cases a domain controller was the device spreading ransomware at scale. In hybrid estates the directory is also the road into Microsoft Entra ID, which is why Microsoft says the Entra Connect server must be treated as a Tier 0 component. PCI DSS v4.0.1 names the test: Requirement 11.4.2 requires internal penetration testing at least once every 12 months and after significant change, and 11.4.5 requires segmentation testing on the same clock, every six months for service providers under 11.4.6. NYDFS 500.5 requires annual testing from inside and outside the information systems' boundaries, and OSFI Guideline B-13 says federally regulated financial institutions should regularly perform tests and exercises, such as penetration testing and red teaming, using an intelligence-led approach. The best internal network and Active Directory penetration testing companies in 2026 are Stingrai, SpecterOps, TrustedSec, Mandiant (Google Cloud), CrowdStrike, NetSPI, Kroll, Praetorian, GuidePoint Security, NCC Group, Rapid7 and ISA Cybersecurity. Every vendor entry links to a page on the vendor's own site, read on 1 and 2 October 2026 or, where a site blocked automated reads, from its newest archived capture.

Microsoft says that in more than 78 percent of the human-operated cyberattacks it has seen, the attackers breached a domain controller, and that in more than 35 percent of cases the device distributing ransomware at scale was a domain controller (Microsoft Security blog, 9 April 2025). Microsoft does not publish the sample size or period behind either figure. The joint guidance Detecting and Mitigating Active Directory Compromises, developed by Australia's ASD ACSC in cooperation with CISA, the NSA, the Canadian Centre for Cyber Security, NCSC-UK and NCSC-NZ, was first published on 25 September 2024 with 17 common Active Directory compromise techniques; the September 2026 revision, which CISA lists with a revision date of 15 September 2026, adds an eighteenth section, on Shadow Credentials. In hybrid estates the directory is also the road into the cloud: in its August 2025 report on Storm-0501, Microsoft Threat Intelligence described an intrusion that moved from on-premises Active Directory to an Entra Connect Sync server and then to a synced account holding the Global Administrator role in Microsoft Entra ID (Microsoft Threat Intelligence, 27 August 2025).

Where Stingrai fits: Stingrai is a CREST-accredited penetration testing service provider at firm level, headquartered in Toronto with a London office and founded in 2021. Internal network and Active Directory engagements are human-led: two named penetration testers from a team holding OSCE³, OSWE, OSEP, CREST CRT and CISSP, a team that also holds the CRTE, CRTP, CRTO and CRTL red team certifications, start from an ordinary domain account and report every path they prove, with the object and attribute behind each hop. Entra ID is tested as part of the same identity plane: app registrations, service principals, consent grants, Conditional Access gaps and hybrid-join trust back to on-premises AD. Work is delivered as a one-time annual engagement or a continuous program through the PTaaS portal, with retesting and an attestation letter included. Active Directory and network scopes are quoted, with pricing returned within 24 hours; published package prices cover one web application and its APIs (pricing).

Quick answer: who are the best internal network and Active Directory penetration testing companies in 2026?

The best internal network and Active Directory penetration testing companies in 2026 are Stingrai, SpecterOps, TrustedSec, Mandiant (Google Cloud), CrowdStrike, NetSPI, Kroll, Praetorian, GuidePoint Security, NCC Group, Rapid7 and ISA Cybersecurity. Stingrai ranks first for named, certified penetration testers who prove AD and Entra ID attack paths hop by hop from an assumed-breach start, with retesting and an attestation letter, one-time or continuous. SpecterOps, TrustedSec and Mandiant follow for identity attack path depth across AD and Entra ID, an AD assessment led by Microsoft Certified Masters, and AD hardening shaped by incident response.

Two-column chart of what PCI DSS v4.0.1, NYDFS, OSFI B-13 and the proposed HIPAA rule ask of internal and segmentation testing in 2026

Why internal network and Active Directory testing matters in 2026

A perimeter test answers whether an attacker gets in. An internal test answers how far one foothold goes, and in most Windows estates the answer runs through the directory.

Ransomware runs through the domain controller

Microsoft's April 2025 analysis explains why the domain controller sits in the middle of so many intrusions: "Domain controllers are the backbone of any on-premises environment, managing identity and access through Active Directory (AD)." They hold the directory database, including the most privileged accounts, and they have to be accessible to many endpoints, which is what an operator who wants to encrypt hundreds or thousands of machines at once needs. That is why the two Microsoft figures above matter for scoping: the test that matters is the one that measures every route from an ordinary account to the directory, not a sweep for missing patches.

What testers look for, in defender terms: the shortest proven paths from a standard user to Tier 0, service accounts whose passwords can be recovered offline, permissions that let a low-privileged principal change a privileged object, certificate templates that issue authentication certificates to the wrong population, and administrator passwords reused across a fleet. Our Active Directory penetration testing guide breaks the directory into nine scope layers, and the internal network penetration testing guide covers the network-layer findings that lead into it.

Hybrid identity: the directory is also the way into Entra ID

Microsoft's own deployment guidance is blunt about the sync server: "The Microsoft Entra Connect server must be treated as a Tier 0 component as documented in the Active Directory administrative tier model" (Microsoft Learn, last updated 16 January 2026). The Storm-0501 report shows why. Microsoft describes an enterprise whose subsidiaries ran separate domains joined by trusts and synced to several Entra ID tenants, an Entra Connect Sync server that was not onboarded to endpoint protection, and "a non-human synced identity that was assigned with the Global Administrator role in Microsoft Entra ID," an account that "lacked any registered MFA method." Microsoft also records that some privileged sign-in attempts were "blocked by Conditional Access policies and multifactor authentication (MFA) requirements," which is the control working.

Each of those is a finding a hybrid-aware internal test can produce before an attacker does: a sync server outside the Tier 0 boundary or outside monitoring, trusts that let one domain's compromise reach another, privileged cloud roles held by synced accounts, privileged identities without MFA, and gaps in Conditional Access coverage. The Azure and Entra ID scoping guide lists the cloud-side checks; the point of this ranking is to find firms that test both directories as one plane.

The joint guidance as a coverage checklist

The joint guidance is the most useful document to put in front of a vendor, because it names the most common Active Directory compromise techniques (17 in the 2024 edition, 18 in the September 2026 revision) and recommends strategies to mitigate each. Ask every shortlisted firm which of the 18 it tests for by name, and which it would only report as configuration observations.

What the rules actually require for internal testing

PCI DSS names internal and segmentation testing outright. NYDFS names a test from inside the boundary. OSFI B-13 expects testing without setting a cadence, and HIPAA's testing requirement is still a proposal. Here is the operative text.

PCI DSS v4.0.1, Requirements 11.4.1 and 11.4.2: internal penetration testing

The PCI Data Security Standard v4.0.1, published by the PCI Security Standards Council in June 2024, requires a documented methodology under 11.4.1 that includes "Testing from both inside and outside the network," "Testing to validate any segmentation and scope-reduction controls," and "Network-layer penetration tests that encompass all components that support network functions as well as operating systems." The applicability notes define the internal half: "Testing from inside the network (or 'internal penetration testing') means testing from both inside the CDE and into the CDE from trusted and untrusted internal networks."

Requirement 11.4.2 then states that internal penetration testing is performed:

  • Per the entity's defined methodology.

  • At least once every 12 months.

  • After any significant infrastructure or application upgrade or change.

  • By a qualified internal resource or qualified external third party.

  • With organizational independence of the tester (not required to be a QSA or ASV).

Requirement 11.4.4 closes the loop: exploitable vulnerabilities and security weaknesses are corrected according to the entity's risk assessment, and "Penetration testing is repeated to verify the corrections." Where the cardholder data environment is domain-joined, the directory paths that reach it are part of that internal test. The PCI DSS penetration testing guide covers merchant and service provider evidence in more depth.

PCI DSS Requirements 11.4.5 and 11.4.6: segmentation testing

If segmentation is used to isolate the cardholder data environment from other networks, 11.4.5 requires penetration tests on the segmentation controls:

  • At least once every 12 months and after any changes to segmentation controls or methods.

  • Covering all segmentation controls and methods in use.

  • According to the entity's defined penetration testing methodology.

  • Confirming that the segmentation controls and methods are operational and effective, and isolate the CDE from all out-of-scope systems.

  • Confirming the effectiveness of any use of isolation to separate systems with differing security levels.

  • Performed by a qualified internal resource or qualified external third party, with organizational independence of the tester.

Requirement 11.4.6 applies the same test to service providers "At least once every six months and after any changes to segmentation controls/methods." The standard's guidance explains the stakes, "Many attacks have involved the attacker moving laterally from what an entity deemed an isolated network into the CDE," and notes that "Techniques such as host discovery and port scanning can be used to verify out-of-scope segments have no access to the CDE."

In practice a segmentation report should name every out-of-scope segment tested, the method used from each, the result against the written policy, the date and the tester's independence. Bring a source-to-destination matrix to the scoping call; the internal network guide includes one you can adapt.

NYDFS 23 NYCRR 500.5

New York's cybersecurity regulation, as amended effective 1 November 2023, requires covered entities to conduct "penetration testing of their information systems from both inside and outside the information systems' boundaries by a qualified internal or external party at least annually" (23 NYCRR 500.5(a)(1)). Section 500.19 exempts some covered entities from 500.5, including smaller ones that fall under its employee, revenue or asset thresholds; for every other covered bank, insurer or licensed financial services company, an internal test is an annual obligation.

OSFI Guideline B-13 (Canada)

OSFI's Guideline B-13, dated July 31, 2022, is written as expectations. Section 3.1.2 says federally regulated financial institutions "should also regularly perform tests and exercises, to identify vulnerabilities or control gaps in its cyber security programs (e.g., penetration testing and red teaming) using an intelligence-led approach." Section 3.2.7 adds identity expectations that read like an Active Directory scope, including privileged access management and "Ensuring system and service accounts are securely authenticated, managed and monitored to detect unauthorized usage." The OSFI B-13 guide covers cadence and third-party expectations.

HIPAA: a proposal, not yet a rule

The HIPAA Security Rule in force today does not name penetration testing. The proposed rule published on 6 January 2025 at 90 FR 898 would add 45 CFR 164.312(h)(2)(iii), under which "Penetration testing must be performed at least once every 12 months" or more often if the risk analysis requires. As of 1 October 2026 the Federal Register lists only the proposal under RIN 0945-AA22.

Rule

Internal test named?

Cadence

What the evidence has to show

PCI DSS v4.0.1, 11.4.1 and 11.4.2

Yes

At least every 12 months and after significant change

Testing inside the CDE and into it from trusted and untrusted internal networks, by an independent qualified tester, with retesting of corrections under 11.4.4

PCI DSS v4.0.1, 11.4.5

Yes, segmentation

At least every 12 months and after changes to segmentation

Every segmentation control tested; the CDE isolated from all out-of-scope systems

PCI DSS v4.0.1, 11.4.6

Yes, service providers

At least every six months and after changes

The same segmentation evidence, twice as often

NYDFS 23 NYCRR 500.5(a)(1)

Yes

At least annually

Testing from inside and outside the information systems' boundaries by a qualified party

OSFI Guideline B-13, 3.1.2

Named as an example ("should")

Set by the institution

Intelligence-led tests and exercises such as penetration testing and red teaming

HIPAA Security Rule

Not today; proposed at 90 FR 898

Proposed: at least every 12 months

Proposed: testing of relevant electronic information systems by a qualified person

Assumed-breach starting points: what each one proves

Every internal test starts somewhere, and each starting position is a separate run of the methodology with its own price. The assumed breach explainer covers when to start inside rather than run a full red team. The table below maps the common starts to the evidence each one produces.

Starting point

What it proves

Evidence it supports

Standard domain account on the user network

How far a phished employee's identity reaches, and every proven path to Tier 0

PCI DSS 11.4.2 testing from trusted internal networks; NYDFS 500.5 testing inside the boundary

Device on an untrusted segment (guest Wi-Fi, vendor or plant network), no credentials

Whether segmentation holds, and whether a device alone yields credentials

PCI DSS 11.4.5 segmentation results, pair by pair

Compromised server in a DMZ or application tier

Whether an internet-facing compromise can reach the core

Internal testing after significant change under 11.4.2

Synced user account in Entra ID

Whether a cloud foothold crosses the hybrid seam to on-premises AD, or the reverse

Proof that Entra ID and on-premises controls hold together

Tier 1 administrator account

Whether the Tier 0 boundary holds under pressure

Privileged access evidence, including OSFI B-13 section 3.2.7

For a first Active Directory engagement, one or two ordinary domain accounts are the usual start, because they direct the budget at the escalation surface rather than at getting in. Add an untrusted-segment start wherever PCI DSS segmentation applies.

The internal network and Active Directory attack surface: what a good scope covers

A scope written as a list of IP ranges gets a host sweep. A scope written as the areas below gets an identity test.

Scope map of eight areas an internal network and Active Directory penetration test should cover, from Tier 0 assets to segmentation and management planes
  • Tier 0 assets. Domain controllers, the Entra Connect server, certificate authorities, backup and virtualization management, and anything that can push code or policy to them. Testers trace every lower-tier account or system these depend on.

  • Privileged groups and service accounts. Nested group membership, service accounts whose passwords can be recovered offline, accounts with Kerberos pre-authentication disabled, and stale privileged accounts.

  • Permissions, delegation and Group Policy. Who can reset passwords, add group members, write to privileged objects, edit or link Group Policy, or act on behalf of other users through delegation settings.

  • Active Directory Certificate Services. Template permissions, requester-supplied subjects, enrollment endpoints and authority settings that could issue authentication certificates to the wrong population.

  • Trusts and multi-domain forests. Trust direction and filtering, and whether a compromise in one domain or acquired forest reaches another. Kroll's research talk on forests puts it plainly: "Domain trust boundaries are not security boundaries."

  • The hybrid identity seam. The sync server and its accounts, synced accounts holding privileged Entra roles, MFA registration on privileged identities, Conditional Access coverage and federation settings.

  • Network-layer exposure. Name-resolution fallback, services that accept unsigned or relayed authentication, legacy protocols, local administrator password reuse and file shares holding credentials.

  • Segmentation and management planes. Whether user, guest, vendor and server segments can reach the cardholder data environment, backup, hypervisor and out-of-band management, tested pair by pair.

What a good Active Directory finding report contains

The report is what an auditor files and what an engineer fixes from, so judge vendors by a redacted sample before you sign. Every finding should read like a reproducible path, not a scanner line.

Checklist chart of the nine fields a good Active Directory finding should contain, from starting position and proven path to the dated retest result

At the report level, look for:

  • An executive summary that states the starting positions, the number of independent paths proven and the fastest one.

  • Configuration observations kept separate from proven exploitation, so a list of weak settings is never presented as a demonstrated compromise.

  • Tier 0 dependencies written as systemic findings rather than dozens of host tickets.

  • Hybrid seam findings covering the sync server, its accounts and synced privileged identities.

  • Segmentation results pair by pair wherever PCI DSS 11.4.5 applies.

  • A remediation roadmap ordered by how many paths each fix removes, with owners.

  • A data handling note on how directory exports and any recovered credentials were stored and destroyed.

  • A dated retest record, plus a letter an auditor, insurer or customer can file.

The Active Directory guide sets out the full report and roadmap structure.

How we ranked them

Twelve vendors were scored against ten criteria. Every accreditation was checked on the CREST Marketplace, and every vendor entry links to a page on the vendor's own site, read on 1 and 2 October 2026. Kroll's site blocked automated reads, so its entries use the newest archived captures of its pages: 18 August 2026 for the Active Directory page, which has moved to a new address, November 2025 for its penetration testing page, September 2025 for its forest research and September 2026 for its office pages.

  1. Published internal network or Active Directory testing work on the vendor's own site: a service page, methodology or program.

  2. Identity depth: attack paths, certificate services, delegation and trusts, plus Entra ID or hybrid identity where stated.

  3. Assumed-breach starting positions offered.

  4. Firm-level accreditation on the CREST Marketplace.

  5. Named testers, identified with their certifications before signing.

  6. Retest policy stated in writing.

  7. Delivery: a portal for findings, and both one-time and continuous options.

  8. Evidence for PCI DSS 11.4, NYDFS 500.5 and auditors, including segmentation results and a letter a third party will accept.

  9. Pricing transparency.

  10. North American delivery in the United States, Canada or both.

The 12 companies at a glance

#

Company

HQ

CREST Marketplace

Internal and AD evidence

Entra ID or Azure stated

Assumed-breach start

Retest stated

Published pricing

Best for

1

Stingrai

Toronto, ON (London, UK office)

Penetration Testing

AD assessment page; internal and external network testing

Yes

Yes, ordinary domain account

Included

Web app tiers only; AD and network quoted

Named testers across AD, Entra ID and the network

2

SpecterOps

Alexandria, VA (Seattle office)

Penetration Testing; ISO 27001

Attack path assessments; penetration testing

Yes

Not stated

Not stated

No

Large AD and Entra ID estates

3

TrustedSec

Fairlawn, OH

Penetration Testing

Active Directory Security Assessment

Separate Microsoft cloud reviews

Not stated

Yes

No

Directory breadth from AD specialists

4

Mandiant (Google Cloud)

Part of Google Cloud

Penetration Testing, Threat Led Penetration Testing (Irish entity)

AD Security Assessment; internal penetration test

Yes, Azure and Microsoft 365 integration

Simulated malicious insider

Not stated

No

AD hardening from an incident response team

5

CrowdStrike

Austin, TX

Not listed

AD Security Assessment; internal penetration test

Not stated

Insider threat penetration test

Not stated

No

A configuration review and internal test together

6

NetSPI

Minneapolis, MN (Toronto office)

Penetration Testing, Threat Led Penetration Testing

Internal network testing incl. AD and PCI segmentation

Separate Azure cloud pentest

Not stated

Not stated

No

Recurring PCI internal and segmentation testing

7

Kroll

New York, NY (Toronto office)

Penetration Testing, Incident Response, Security Operations Centre

AD Security Assessment; internal network testing

Separate Microsoft 365 and Azure reviews

Not stated

Not stated

No

AD testing beside incident response

8

Praetorian

Austin, TX

Penetration Testing

Assumed breach exercise; AD path analysis

Not stated

Yes, dedicated exercise

Not stated

No

Objective-driven assumed breach

9

GuidePoint Security

Reston, VA

Penetration Testing; SOC 2 Type 2

Active Directory Security Assessment

Not stated

Not stated

Not stated

No

A baseline AD audit

10

NCC Group

Manchester, UK (Chicago regional HQ; Waterloo, ON office)

Broadest set, incl. Penetration Testing and Threat Led Penetration Testing

Internal network testing; AD defence research

Not stated

Not stated

Not stated

No

Testing, threat-led work and incident response together

11

Rapid7

Boston, MA

Not listed

Internal and segmentation testing in a managed red team tier

Not stated

Testing after initial access

Not stated

No

Annual internal test inside continuous red teaming

12

ISA Cybersecurity

Toronto, ON (Calgary and Ottawa offices)

Not listed

Internal penetration testing

Not stated

Rogue employee or compromised account

Not stated

No

A Canadian-headquartered provider

"Not stated" means the vendor's own pages we reviewed do not say. Ask for it in writing.


1. Stingrai

Stingrai is a global CREST-accredited penetration testing services company founded in Toronto, Canada in 2021, trusted by companies from startups to enterprises to meet audit requirements for SOC 2, ISO 27001, CMMC, PCI DSS and HIPAA. OSCE³, OSWE, OSEP, CREST CRT certified pentesters, who are also world-class security researchers and bug bounty hunters. Choose from fully human-led or hybrid (AI agents plus human penetration testers) engagements across web, API, mobile, AI and LLM, cloud, network, Active Directory and social engineering penetration tests and red team engagements.

What an IT security lead can check. The firm-level accreditation is on the CREST Marketplace supplier page for Stingrai Inc, separate from the CREST CRT certifications individual testers hold. Ratings are 5.0 out of 5 from 20 reviews on Clutch and 4.9 out of 5 from 11 reviews on G2. Stingrai's researchers have published 18 CVEs, a figure stated on the Snipe page, and the team page names each tester, including a team lead with 16 years in penetration testing, red teaming and exploit development. Two named penetration testers from a team holding OSCE³, OSWE, OSEP, CREST CRT and CISSP run each human-led engagement, reviewed by the team lead and an engagement partner, and the team also holds the CRTE, CRTP, CRTO and CRTL red team certifications.

How internal and AD engagements are tested. The Active Directory assessment starts from the position of an ordinary domain user and reports every path proved, with the object and attribute behind each hop, across Kerberos service accounts, permissions and delegation, coerced authentication, Active Directory Certificate Services, Group Policy, domain and forest trusts, credential exposure and the Tier 0 boundary; collector data is validated by hand. Internal network testing starts inside the LAN, on-site or remote, and covers credential relay, privilege escalation, Active Directory attack paths and lateral movement, with segmentation testing added for PCI DSS scopes. Azure and Entra ID testing covers app registrations, service principals and consent grants, Conditional Access gaps and hybrid-join and on-premises trust relationships, so the seam between the two directories is tested as one plane. StingAD, the team's open-source Active Directory assessment toolkit under the Apache 2.0 license, supports the work, and red team engagements can run in an assumed-breach mode when detection is the question.

Evidence and delivery. Stingrai runs both one-time annual engagements timed to a PCI DSS or audit cycle and continuous programs. In either model, findings post to the PTaaS portal as they are confirmed, each with a working proof of concept and remediation guidance, with live chat to the assigned testers during the test and Jira and Slack integration. The AD report orders the remediation roadmap by how many paths each fix removes. Retesting is included, and human-led and hybrid engagements include an attestation letter for auditors, insurers and customers.

Where Snipe fits. Snipe, Stingrai's autonomous AI penetration testing agent, tests web applications and their APIs only. Active Directory, internal network, segmentation and Entra ID work is done by penetration testers. Where an internal web application is in scope, the Hybrid tier has Snipe and penetration testers testing together throughout, with the testers directing its focus.

Pricing: Active Directory, internal network and Entra ID scopes are quoted through get a quote, with pricing returned within 24 hours and the retest included. Published prices cover one web application and its APIs: US$3,000 for an Autonomous Pentest and US$6,800 for a Hybrid Pentest per assessment, or US$650 and US$1,275 per month on 12-month continuous plans.

Strength: proven paths across AD, Entra ID and the network from named, certified testers, with the accreditation, ratings and tester credentials checkable in public sources. Limitation: a small team, so multi-site on-site work needs scheduling lead time, and the fixed-price packages cover one web application and its APIs only. Best for: mid-market and enterprise organizations in the US and Canada that need AD, Entra ID and internal network testing with evidence for PCI DSS, NYDFS or audit programs, one-time or continuous.

2. SpecterOps

SpecterOps lists offices in Alexandria, Virginia and Seattle and presents itself as the creator of BloodHound, its attack path mapping platform. Its services page offers penetration testing "focusing on viable attack paths to your most sensitive data and management systems across network, application, AI, and specialty environments," and attack path assessments that, powered by its BloodHound Enterprise product, map "chains of abusable privileges across critical assets to identify choke points in your identity attack surface" across AD, Entra ID, GitHub, Okta and JAMF. Purple team assessments are offered alongside. SpecterOps reports more than 200 enterprise and government customers. CREST lists Specter Ops Inc with Penetration Testing, two years of membership and an ISO 27001 company certification. Named testers, retest terms and pricing are not stated.

Strength: identity attack path specialists across AD and Entra ID, with choke-point remediation built into the method. Limitation: the attack path assessment runs on its own BloodHound Enterprise product, so separate product-led analysis from manual testing in the statement of work. Best for: large AD and Entra ID estates that want attack paths mapped at scale and choke points fixed first.

3. TrustedSec

TrustedSec operates from 3485 Southwestern Boulevard in Fairlawn, Ohio. Its Active Directory Security Assessment evaluates "domains, forests, group policies, and privileged accounts," with Microsoft Certified Masters who "identify critical misconfigurations and privilege escalation paths, mapping them to real-world attacker techniques documented in the MITRE ATT&CK framework." The page says the service was "Recently enhanced through TrustedSec's acquisition of Trimarc Security, led by Microsoft Certified Master Sean Metcalf," and its listed coverage includes Kerberos service account weaknesses, unconstrained and constrained delegation, AdminSDHolder and ACL misconfigurations, and domain controller security posture. Its penetration testing page states, "we retest to confirm they've been successfully mitigated." CREST lists Penetration Testing with two years of membership and 51 to 100 technical people. Named testers and pricing are not stated.

Strength: an AD-specific assessment led by Microsoft Certified Masters and mapped to ATT&CK, with retesting stated. Limitation: TrustedSec's own FAQ contrasts the assessment with penetration tests that "often demonstrate single exploit chains," so specify whether you are buying breadth, proven exploitation or both. Best for: organizations facing an acquisition, migration or audit that want breadth across the directory from one US firm.

4. Mandiant (Google Cloud)

Mandiant, part of Google Cloud, lists an Active Directory Security Assessment among its technical assurance services. Its AD assessment datasheet describes onsite workshops and data collection used to "evaluate the architecture (including both on-premise and cloud-based environments) and identify possible attack paths within the Active Directory infrastructure," across forest architecture and trusts, privileged accounts, Group Policy, permission delegation, service accounts and SPNs, and integration with Microsoft Azure and Microsoft Office 365. The lifecycle runs one week each for documentation review, onsite workshops and data analysis, then two weeks of reporting, and the method was "developed based on extensive incident response experience." Its penetration testing service includes internal tests that use a "simulated malicious insider." CREST lists Mandiant (part of Google Cloud) under Ireland, serving Europe and the Middle East, with Penetration Testing, Threat Led Penetration Testing and Incident Response. Named testers, retest terms and pricing are not stated.

Strength: AD hardening built from incident response, with the Azure and Microsoft 365 integration named in scope. Limitation: the assessment is a workshop and data-collection review rather than an exploitation test, so pair it with the internal penetration test, and the CREST listing belongs to the Irish entity. Best for: enterprises that want AD hardening guidance from an incident response team alongside a separate internal test.

5. CrowdStrike

CrowdStrike's press releases carry an Austin, Texas dateline. Its Active Directory Security Assessment is "designed to review Active Directory configuration and policy settings to assess security configuration issues attackers can leverage," through documentation review, staff discussions, proprietary tools and manual review, with tools and processes "developed by Microsoft Certified Masters in Active Directory." Its penetration testing services include internal penetration testing that covers "system identification, enumeration, vulnerability discovery, exploitation, privilege escalation and lateral movement." CrowdStrike is not on the CREST Marketplace, and named testers, retest terms and pricing are not stated.

Strength: an AD configuration review and an internal penetration test available from one large security provider. Limitation: the AD service is a configuration review, and if you also run CrowdStrike's own products, agree in writing how the test stays independent of the tools it is testing. Best for: enterprises that want a configuration review and an internal test bought together.

6. NetSPI

NetSPI lists its headquarters in Minneapolis, Minnesota and an office in Toronto, Ontario. Its internal network penetration testing page scopes workstations, servers and intranet applications and lists segmentation testing for PCI DSS compliance, offline password auditing of AD accounts, system and domain-level privilege escalation and Active Directory vulnerabilities, built on NIST SP 800-53, PCI DSS, OWASP Top 10 and MITRE ATT&CK. A continuous internal testing option covers "privilege escalation, lateral movement, Active Directory vulnerabilities, and network segmentation," with findings delivered through a centralized platform. CREST lists Penetration Testing and Threat Led Penetration Testing with ten years of membership. Named testers, retest terms and pricing are not stated.

Strength: an internal testing page that names PCI segmentation testing and AD password auditing, one-time or continuous, with a Toronto office. Limitation: AD coverage sits inside a broader internal network test, so ask how many testing days go to the identity layer. Best for: PCI-scoped organizations that want internal and segmentation testing as a recurring program.

7. Kroll

Kroll states that it is headquartered in New York and lists a Toronto office at 333 Bay Street. Its Active Directory Security Assessment combines "automated and manual testing methods" to find vulnerabilities "that could be exploited by both unauthenticated and authenticated threat actors on your networks," across trust configuration, privileged accounts, Active Directory Certificate Services and Kerberos services, including the "Identification of hidden Active Directory escalation paths." Its penetration testing services list external and internal network testing, and a Kroll research talk on Active Directory forests set out a methodology for testing trusts across domains and forests. CREST lists Penetration Testing, Incident Response and Security Operations Centre accreditations with eight years of membership. Named testers, retest terms and pricing are not stated.

Strength: an AD assessment that looks for weaknesses open to both unauthenticated and authenticated attackers, beside an incident response practice, with a Toronto office. Limitation: testing is one line in a large risk advisory firm and the forest research dates from 2019, so ask who on today's team will test; Kroll also describes the assessment as a review of directory configuration and settings, so ask whether paths are proven or only listed. Best for: organizations that want AD testing next to incident response, in the US or Canada.

8. Praetorian

Praetorian's press releases carry an Austin, Texas dateline. Its assumed breach exercise works toward a predetermined business objective, with examples that include emulating a ransomware attack and demonstrating access to a VIP mailbox, data or workstations, through stages that include lateral movement and privilege escalation. Its advanced offensive security page adds attack path mapping with Active Directory path analysis, privilege escalation mapping and cross-environment path discovery, mapped to MITRE ATT&CK. CREST lists Penetration Testing with two years of membership. Named testers, retest terms and pricing are not stated.

Strength: assumed-breach exercises built around business objectives rather than host counts. Limitation: the exercise sits with its red team services, so decide whether you are buying coverage of the directory or a measure of detection. Best for: organizations that want an objective-driven assumed-breach engagement with AD path analysis.

9. GuidePoint Security

GuidePoint Security lists its headquarters at 1900 Reston Metro Plaza in Reston, Virginia. Its Active Directory Security Assessment audits the directory's services, settings and accounts, with focus areas including Service Principal Name configuration, Kerberos authentication, domain functional levels, password policy and reuse, share, user, group and computer permissions, null sessions, domain trust configuration and SMB configuration, and recommends "what configurations to harden that would be specifically targeted by an adversary." Its penetration testing services add red and purple team assessments and a PTaaS platform. CREST lists Penetration Testing with three years of membership and a US SOC 2 Type 2 certification. Named testers, retest terms and pricing are not stated.

Strength: a published AD focus list next to penetration, red and purple team testing. Limitation: GuidePoint describes the AD service as a "baseline security audit," so buy the internal penetration test separately to prove which weaknesses chain. Best for: organizations that want a baseline AD audit before or beside an internal test.

10. NCC Group

NCC Group lists its global headquarters in Manchester, England, a North American regional headquarters at 11 E Adams Street in Chicago and an office in Waterloo, Ontario. Its network penetration testing services address "external or internal vulnerabilities" in manual, hybrid and autonomous tiers, with the autonomous and hybrid tiers built on its partner Horizon3.ai's NodeZero platform. Its research team publishes a "Defending Your Directory" series of defensive guides on Kerberos service account abuse, certificate services, replication abuse and pass-the-hash, and a CISO's guide to preventing Active Directory threats from November 2024. CREST lists the broadest set of accreditations in this ranking, including Penetration Testing, Threat Led Penetration Testing, Incident Response and Security Operations Centre, with 19 years of membership. Named testers, retest terms and pricing are not stated.

Strength: the widest CREST accreditation set here plus defender-oriented AD research, with a Waterloo office. Limitation: the network testing page we reviewed does not describe Active Directory scope, so write the identity layer and the manual tier into the statement of work. Best for: organizations that want testing, threat-led work and incident response from one provider with a Canadian office.

11. Rapid7

Rapid7 lists its global headquarters at 120 Causeway Street in Boston. Its Vector Command Advanced tier, described in an August 2025 Rapid7 post last updated in September 2026, lets organizations "incorporate internal network penetration and segmentation testing directly into their ongoing offensive security program" inside its managed red team service, identifying "Lateral movement paths through Active Directory or flat networks," privilege escalation, sensitive data exposure across file shares and gaps in detection and response. Rapid7 is not on the CREST Marketplace, and named testers, retest terms and pricing are not stated. Rapid7's service page lists the internal penetration and segmentation test as an annual component of the otherwise continuous service.

Strength: an annual internal penetration and segmentation test built into a continuous managed red team program. Limitation: the internal and segmentation test runs once a year inside a red team subscription, so check that its date and report format meet your PCI DSS or audit deadline. Best for: organizations that want an annual internal and segmentation test bundled with continuous external red teaming.

12. ISA Cybersecurity

ISA Cybersecurity lists its head office at 3280 Bloor Street West in Toronto, with offices in Calgary, Ottawa and London. Its penetration testing services include internal penetration testing that identifies "exploitable vulnerabilities and security capabilities inside your environment, simulating a rogue employee or a compromised account," and a June 2025 article by its senior director of offensive security gives breaching an Active Directory environment as an example penetration test objective. ISA is not on the CREST Marketplace, and named testers, retest terms and pricing are not stated.

Strength: a Canadian-headquartered provider with offices in Toronto, Ottawa and Calgary. Limitation: AD scope is described in a sentence rather than a published methodology, so ask for the AD test plan and a redacted sample report. Best for: Canadian organizations that want a domestic provider for internal testing.


Firms considered and not ranked

Optiv's Active Directory Assessment, published in April 2022, is aimed at organizations that have "lost control and visibility" of directory support, security and access governance and is run by strategic consultants with the client's operations and governance team, and the penetration testing page we read does not describe internal or Active Directory scope; its targeted network penetration test brief, which mentions the internal network, dates from 2020. Horizon3.ai's NodeZero runs autonomous internal pentests that a customer's own team launches "with or without credentials," which makes it a tool to run between engagements rather than a testing firm; NCC Group pairs it with consultants. Finally, the managed IT or security provider that administers your directory should not be the one testing it.

How much does internal network and Active Directory penetration testing cost in 2026?

Internal and Active Directory engagements are quoted per scope, because domains, forests, trusts, certificate services, hybrid identity, sites, segmentation pairs and the number of starting positions all change the effort. Stingrai quotes Active Directory and network engagements as a fixed price with the retest included, returned within 24 hours of a quote request. Its published package prices are for web application testing only: US$3,000 for an Autonomous Pentest, which is Snipe alone with no penetration testers, and US$6,800 for a Hybrid Pentest, where penetration testers and Snipe test together, each per assessment of one web application and its APIs, or US$650 and US$1,275 per month on 12-month continuous plans. The Autonomous tier carries a "No High or Critical Finding = Don't Pay" guarantee. Current figures are on the pricing page.

The bands below are indicative. The US figures come from Stingrai's network testing page and our penetration testing cost guide; the Canadian figures come from the Canadian cost guide.

Scope

Indicative US band

Indicative Canadian band

Internal network test

US$5,000 to US$40,000 and above (network, external or internal)

CA$12,000 to CA$20,000 (small), CA$20,000 to CA$35,000 (standard), CA$35,000 to CA$50,000+ (large)

Active Directory assessment

Quoted per scope

CA$15,000 to CA$25,000 (small), CA$25,000 to CA$35,000 (standard), CA$35,000 to CA$50,000+ (large)

PCI DSS bundle: internal, external and segmentation

US$12,000 to US$25,000 commonly

Quoted per scope

Annual program

US$20,000 to US$50,000 (mid-market budget), US$50,000 to US$150,000+ (enterprise program)

CA$40,000 to CA$120,000+ (continuous PTaaS subscription)

Field time is not calendar time. Stingrai's published timelines put external plus internal testing of a single site and domain at one to two tester weeks across two to four weeks, a PCI DSS scope with segmentation at three to six weeks, and multi-site, multi-domain internal testing at four to eight weeks. Book ahead of any audit or board date the report has to meet.

Buyer checklist: questions to put to every vendor

Send these in writing with the request for proposal, and compare the answers side by side.

  1. Who exactly will test, can we see their names and certifications before we sign, and will the same people run the retest?

  2. Where will the test start? Price an ordinary domain account, an untrusted segment and a synced Entra ID account as separate starts.

  3. Which of the 18 techniques in the September 2026 revision of the joint Active Directory compromise guidance do you test by name?

  4. How do you prove a path, and what will you decline to execute in a production directory?

  5. Do you treat the Entra Connect server, its accounts and synced privileged identities as Tier 0 and test them?

  6. How will you test our segmentation for PCI DSS 11.4.5, from which segments, and how is each result recorded?

  7. What does one finding look like? Ask for a redacted AD finding with the hop-by-hop path, ATT&CK mapping and detection notes.

  8. How are directory exports and any recovered credentials stored, and when and how are they destroyed?

  9. Is retesting included, and does it re-walk each proven path?

  10. How is your organizational independence documented, which PCI DSS 11.4.2 and 11.4.5 require, and are you independent of our managed service provider, the identity and endpoint tools we run, and whoever designed our segmentation?

Frequently Asked Questions

Who are the best internal network and Active Directory penetration testing companies in 2026?

The best internal network and Active Directory penetration testing companies in 2026 are Stingrai, SpecterOps, TrustedSec, Mandiant (Google Cloud), CrowdStrike, NetSPI, Kroll, Praetorian, GuidePoint Security, NCC Group, Rapid7 and ISA Cybersecurity. Stingrai ranks first: a CREST-accredited penetration testing service provider at firm level whose AD and internal engagements are human-led by two named penetration testers from a team holding OSCE³, OSWE, OSEP, CREST CRT and CISSP, starting from an ordinary domain account, covering Entra ID and the hybrid seam, with retesting and an attestation letter, one-time or continuous. SpecterOps, TrustedSec and Mandiant follow.

Does PCI DSS v4.0.1 require internal penetration testing?

Yes. Requirement 11.4.2 requires internal penetration testing per the entity's defined methodology, at least once every 12 months and after any significant infrastructure or application upgrade or change, by a qualified internal resource or qualified external third party with organizational independence. The applicability notes to 11.4.1 define internal testing as testing from inside the CDE and into the CDE from trusted and untrusted internal networks, and 11.4.4 requires exploitable findings to be corrected and the testing repeated to verify the corrections.

What does PCI DSS 11.4.5 require for segmentation testing?

If segmentation is used to isolate the cardholder data environment, 11.4.5 requires penetration tests on the segmentation controls at least once every 12 months and after any change to them, covering all segmentation controls and methods in use, confirming they are operational and effective and isolate the CDE from all out-of-scope systems, by a qualified and organizationally independent tester. Requirement 11.4.6 shortens the interval to at least once every six months for service providers.

What is the difference between an internal network penetration test and an Active Directory assessment?

An internal network penetration test measures what an attacker can reach and exploit from a foothold inside the network: hosts, services, file shares, protocols and segmentation. An Active Directory test concentrates on the identity plane: privileged groups, service accounts, permissions, delegation, certificate services, Group Policy and trusts, and the paths from an ordinary account to control of the directory. Many vendors sell configuration reviews under the assessment name, so ask whether paths are proven or only listed.

Where should an internal or Active Directory penetration test start?

Most engagements start from an assumed-breach position, usually one or two ordinary domain accounts on a standard user network, because that is what a phished employee hands an attacker. Add a start on an untrusted segment such as guest Wi-Fi or a vendor network to prove segmentation, and a synced cloud identity if you run Entra ID. Each start is a separate run of the methodology, so price each one.

How does Microsoft Entra ID change an Active Directory penetration test?

In a hybrid estate the on-premises directory and Entra ID share identities, so a compromise on one side can reach the other. Microsoft says the Entra Connect server must be treated as a Tier 0 component. A test should cover the sync server and its accounts, privileged cloud roles held by synced accounts, MFA registration on those accounts and Conditional Access coverage, the same areas Microsoft Threat Intelligence examined in its August 2025 Storm-0501 report.

What should an Active Directory penetration test report contain?

Every finding should name the starting position, list the path hop by hop with the object and the right or attribute behind each step, include redacted evidence, state the Tier 0 impact, map to a MITRE ATT&CK technique, note where detection could have fired, and give a fix at configuration level with its owner and side effects. The report should also count proven paths, keep configuration observations separate from proven exploitation, include segmentation results where PCI DSS applies, and record dated retest outcomes.

How much does internal network and Active Directory penetration testing cost in 2026?

Stingrai quotes Active Directory and internal network scopes as a fixed price with the retest included, because domains, forests, trusts, certificate services, hybrid identity and the number of starting positions drive the effort; its published prices of US$3,000 (Autonomous) and US$6,800 (Hybrid) per assessment cover one web application and its APIs only. Indicative bands put a US network test at US$5,000 to US$40,000 and above and a standard Canadian Active Directory assessment at CA$25,000 to CA$35,000.

Do NYDFS Part 500 and OSFI B-13 require internal penetration testing?

NYDFS does, for covered entities that are not exempt under section 500.19. 23 NYCRR 500.5(a)(1) requires covered entities to conduct penetration testing of their information systems from both inside and outside the information systems' boundaries by a qualified internal or external party at least annually. OSFI Guideline B-13 is phrased as an expectation: federally regulated financial institutions should regularly perform tests and exercises such as penetration testing and red teaming using an intelligence-led approach, and section 3.2.7 adds identity controls including privileged access management.


Ready to scope an internal network and Active Directory penetration test?

The intrusion that ends in a ransom note rarely starts at a domain controller. It starts with an ordinary account, a sync server nobody tiered, a template that issues the wrong certificate or a segment that was never as isolated as the diagram claimed. Stingrai is a CREST-accredited penetration testing service provider whose testing supports the evidence PCI DSS, NYDFS, OSFI B-13, SOC 2 and ISO 27001 programs ask for, delivered as a one-time annual engagement or as continuous coverage, with named penetration testers, retesting and an attestation letter. Explore Active Directory testing and internal and external network testing, book a free scoping call, get a quote for your domains and segments, or see the published package prices on the pricing page.

0 views

0

X

Related reading

Best Penetration Testing Companies for Construction and Engineering Firms (2026)
Network SecuritySocial Engineering

Best Penetration Testing Companies for Construction and Engineering Firms (2026)

The best penetration testing companies for construction and engineering firms in 2026, ranked, with what CMMC, CPCSC, owners and insurers actually require.

30 min read

Best Enterprise Penetration Testing Companies (2026): Ranked for Global Programs, Procurement and Continuous Coverage
Network SecurityWeb App Security

Best Enterprise Penetration Testing Companies (2026): Ranked for Global Programs, Procurement and Continuous Coverage

The best enterprise penetration testing companies in 2026, ranked on capacity, CREST and threat-led schemes, vendor security, MSA terms and board reporting.

31 min read

Best Penetration Testing Companies for Hotels and Hospitality (2026): Ranked for PCI DSS, Guest Data and Franchise Networks
Network SecurityWeb App Security

Best Penetration Testing Companies for Hotels and Hospitality (2026): Ranked for PCI DSS, Guest Data and Franchise Networks

The best penetration testing companies for hotels and hospitality groups in 2026, ranked, with what PCI DSS 11.4, the FTC Marriott order and PIPEDA require.

31 min read

Contents

X