◆ Next live training: Red Blue Purple AI · Sep 1 & 3, 2026 · Attacking AI · Sep 22 & 24, 2026
HomeConsultingAssumed Breach Penetration Testing
Offensive Security Services

Assumed Breach Penetration Testing

Simulating real-world internal threats

Our Internal Assumed Breach Penetration Testing service represents a significant evolution beyond standard internal tests. Traditional methodologies often rely on established checklists targeting common Microsoft ecosystem misconfigurations and classic pivoting techniques toward high-value assets like Domain Controllers. While still valuable, this only addresses part of the modern internal threat landscape.

Acknowledging that initial access is often inevitable, our service operates from an Assumed Breach perspective, simulating attackers already active inside your network. This provides a realistic assessment of your internal resilience, detection capabilities, and the true impact of a breach.

Assumed breach investigation
Our Approach

Our unique tri-methodology approach

To deliver the most comprehensive evaluation, we run three distinct yet complementary methodologies in parallel during every engagement: spanning classic Active Directory tradecraft, compromise through your DevOps fabric, and the newest frontier: your own AI tooling turned insider threat.

The Evolved Traditional Methodology

// established playbooks
  • Foundation: Builds upon tried-and-true internal penetration testing techniques refined over the last decade by leading security experts.
  • Techniques: Actively identifies and exploits common internal misconfigurations within Active Directory, network protocols, and the broader Microsoft stack. Uses credential capture (MitM, Kerberoasting, pass-the-hash, NTLM relays, token impersonation), privilege escalation, and lateral movement to map pathways through the environment.
  • Modern Integration: Incorporates modern vectors targeting technologies like Azure Active Directory, Microsoft Graph API, and hybrid cloud infrastructure misconfigurations.
  • Goal: Assess pathways to critical infrastructure, including Domain Controllers and other sensitive resources, using established adversary playbooks.

Compromise via DevOps

// low and slow
  • Philosophy: Mimics the behavior of patient, sophisticated adversaries (like APTs) who prioritize stealth ("low and slow") and operate post-access to avoid immediate detection by Security Operations Centers (SOCs).
  • Tactics: Employs methodical reconnaissance to identify non-traditional, high-value internal targets often overlooked by standard tests: internal DevOps tooling (CI/CD pipelines, Kubernetes dashboards, artifact repositories); documentation portals, wikis, and collaboration platforms (Confluence, SharePoint); internal AI/ML management systems and open-source platforms; ChatOps interfaces (Slack, Teams integrations); and other critical internal web applications and APIs controlling valuable assets.
  • Attack Vectors: Focuses on sophisticated web application and authentication-based attacks (SSRF, API abuse, chained misconfigurations, authentication bypass) against these targets.
  • Stealth: Operates primarily over standard protocols like HTTPS, blending in with legitimate network traffic and challenging conventional monitoring solutions.
  • Goal: Gradually amass credentials, sensitive data, and internal intelligence from diverse sources to map complex attack paths and potentially execute a coordinated, widespread compromise, demonstrating the potential for deep system access before triggering alarms.

AI as an Insider

// AI as a pivot point
  • The scenario: One developer or technical user gets popped: a phish, an infostealer, a poisoned dependency. In a modern engineering org, that single workstation isn't just an endpoint. It's a launchpad, because it's wired into the same AI tooling the entire company just rolled out.
  • The new pivot: Agentic assistants like Claude Code, OpenAI Codex, Copilot, and Cursor ship with sweeping reach, source repos, cloud credentials, internal APIs, and MCP connectors, all pre-authorized under the victim's identity. We turn the target's own AI against the enterprise, inheriting every token, permission, and connector it's already trusted to use.
  • Tradecraft: Hijack agent behavior with prompt injection buried in code, tickets, and docs; weaponize the MCP servers and plugins (GitHub, Jira, Slack, databases, internal APIs) the assistant is trusted to call; and plant instructions in shared repos and CI that detonate the moment a teammate's agent runs, worming operator-to-operator across the engineering org.
  • Why it's brutal: Every move rides sanctioned, trusted tooling over ordinary developer traffic. The AI is supposed to read code, hit APIs, and touch the cloud, so our activity reads as productivity, not intrusion. This is the class of compromise behind real-world incidents like the Mercor breach, where a technical user's AI stack became the adversary's highway into the wider organization.
  • Goal: Prove how one breached technical user cascades, straight through the AI supply chain your org just adopted, into source code, secrets, pipelines, cloud, and production, and hand you the exact map of the permissions, connectors, and agents that made it possible.
// ENTRY ASSUMED BREACH You're already inside // IMPACT CROWN JEWELS DCs · Cloud Source · Prod 01 Evolved Traditional established playbooks AD / Kerberos Relay / PtH Lateral Move 02 Compromise via DevOps CI/CD · repos · apps CI/CD · Repos Web / API Cred Harvest 03 AI as an Insider AI as a pivot point Breached Dev AI Agent + MCP Supply Chain

Three methodologies, run in parallel from a single assumed-breach foothold, converging on your crown jewels.

Why Arcanum

Why our combined approach delivers superior insight

We employ a structured methodology involving a deep dive into your security ecosystem to ensure recommendations are grounded in operational reality and goals.

01

Comprehensive Coverage

Assesses defenses against both known, established attack techniques and the stealthy, evolving TTPs used by modern adversaries.

02

Realistic Simulation

Moves beyond theoretical vulnerabilities to demonstrate how attackers actually operate and persist within a compromised network.

03

Identify Hidden Risks

Uncovers critical attack paths targeting internal web services, APIs, and DevOps infrastructure that standard checklist-based tests often miss.

04

Test Modern Defenses

Challenges your SOC's ability to detect sophisticated, low-and-slow internal attacks disguised as normal user or application traffic.

05

Holistic Assessment

Provides a complete blueprint of how your internal environment holds up against the full spectrum of internal threats.

06

AI Supply-Chain Exposure

Reveals whether your rollout of agentic AI dev tools, and the MCP connectors, plugins, and standing permissions behind them, quietly became your fastest path to full compromise.

Your Outcome

Actionable intelligence to harden your defenses

You don't just get a report; you receive actionable insights based on realistic threat emulation.

What our findings detail

// deliverables
  • Identified vulnerabilities across your internal environment
  • Compromised pathways mapped through the network
  • Potential business impact of the demonstrated attacks
  • SOC evasion potential against low-and-slow activity
  • AI dev-tooling & MCP connector abuse paths (agentic pivots)
  • Prioritized, tailored remediation guidance

What you gain

// visibility
  • Unparalleled visibility into how legacy and emerging attack vectors could jeopardize your critical assets ("crown jewels")
  • A realistic view of your internal resilience and detection capabilities
  • The insight needed to proactively strengthen defenses
  • Guidance to maintain operational resilience against evolving threats

Communication throughout

// just-in-time
  • Every Arcanum penetration testing service includes the option for a shared Slack or Teams channel with our team for the duration of the engagement
  • We report critical findings just in time, the moment we confirm them, instead of making you wait for the final report
  • Direct line to the operators actually testing your environment, so questions get answered by the people with the context
  • We ideate defenses with you in real time, pressure-testing fixes and detections as they go live
  • No surprises at readout: you watch the story unfold and steer priorities as we go

Secure your internal environment against today's threats.

Don't wait for a real breach to discover your internal security gaps. Our tri-methodology Assumed Breach Internal Penetration Test provides the deep insights needed to proactively harden your defenses against the full spectrum of internal threats, including the AI tooling you just handed your developers.