Internal Network
Penetration Testing
What happens after an attacker breaches your perimeter, or when an insider goes rogue? Canima deploys hundreds of specialized AI agents that systematically map your internal infrastructure, attack Active Directory, execute lateral movement, and escalate privileges to domain admin. Every credential, every pivot, every escalation step is documented with proof.
$ canima agent deploy --scope internal
[*] Deploying 47 agents to 10.0.0.0/16
[*] AD Enumeration: 2,847 objects indexed
[+] Kerberoastable SPN: [email protected]
[+] TGS hash captured → Hashcat mode 13100
[+] Cracked: svc_backup:Summer2024!
[*] Lateral movement → DC01 via PSRemoting
[+] DCSync: krbtgt hash extracted
[!] DOMAIN ADMIN achieved in 4 pivots
From Initial Foothold to Domain Compromise
Real attackers do not stop at one exploited host. Neither do we. Canima chains together credential attacks, service exploitation, and privilege escalation paths to show you exactly how far an adversary can reach inside your network.
Active Directory Attack Surface
Full AD enumeration including users, groups, trusts, GPOs, delegation configurations, and ACL-based privilege escalation paths. Identifies Kerberoastable SPNs, AS-REP roastable accounts, unconstrained delegation, and resource-based constrained delegation misconfigurations that real attackers chain together for domain compromise.
Credential Attacks & Hash Cracking
Lockout-aware password spraying across LDAP, SMB, RDP, and Kerberos. LLMNR/NBT-NS poisoning for NTLMv2 capture. Offline hash cracking with Hashcat against captured Kerberos TGS tickets and NTLM hashes. Every cracked credential feeds back into the knowledge graph for downstream agents to leverage.
Lateral Movement & Pivoting
Pass-the-hash, pass-the-ticket, overpass-the-hash, and credential forwarding across your network. The lateral movement agents consume cracked credentials and session tokens from the knowledge graph in real time, pivoting through hosts to reach high-value targets like database servers, file shares, and domain controllers.
NTLM Relay & Protocol Exploitation
Identifies and validates NTLM relay opportunities across SMB, LDAP, and HTTP. Tests for coercion vulnerabilities like PetitPotam and PrinterBug to force authentication from privileged accounts. Covers SMB signing enforcement, LDAP signing, EPA configuration, and channel binding gaps.
Local Privilege Escalation
On every compromised host, agents enumerate kernel vulnerabilities, misconfigured services, unquoted service paths, writable DLL directories, token impersonation opportunities (SeImpersonate, SeAssignPrimaryToken), and AlwaysInstallElevated policies. Each escalation path is validated, not just flagged.
Network & Service Enumeration
Complete internal network mapping across subnets and VLANs. Deep service enumeration on SMB, LDAP, SNMP, SSH, RDP, FTP, MySQL, PostgreSQL, MSSQL, MongoDB, and Oracle. Tests for default credentials, anonymous access, and known CVEs (EternalBlue, SMBGhost, ZeroLogon, BlueKeep) with controlled exploitation.
How the Internal Assessment Works
A coordinated multi-stage pipeline where each phase feeds intelligence into the next through a shared knowledge graph. No vulnerability exists in isolation. Every finding is connected to the attack paths it enables.
Reconnaissance & Mapping
Network discovery agents map all reachable subnets, hosts, and services. Active Directory enumeration agents pull users, groups, trusts, SPNs, delegation settings, and GPOs. Everything is indexed into the knowledge graph with relationship edges connecting hosts run which services, which accounts have which privileges.
Vulnerability & Credential Attacks
Specialized agents launch in parallel: Kerberos agents roast SPNs and AS-REP accounts, credential agents spray passwords with lockout-aware throttling, LLMNR agents poison multicast requests, and vulnerability scanners cross-validate CVEs. Cracked hashes and captured credentials are immediately pushed to the graph for all agents to consume.
Exploitation & Lateral Movement
Exploit agents validate confirmed vulnerabilities with controlled payloads. Lateral movement agents read the credential graph and pivot through hosts using pass-the-hash, pass-the-ticket, and relay attacks. Each new session and credential is added to the graph, expanding the attack surface for the next iteration, mirroring how real adversaries operate.
Privilege Escalation & Reporting
Privilege escalation agents target the highest-value paths: DCSync, golden ticket, trust exploitation. Every step from initial foothold to domain admin is documented as a complete attack chain with proof-of-concept evidence. QA agents validate each finding before it enters the final report with CVSS scoring, remediation guidance, and executive summary.
Every Agent Shares One Intelligence Layer
Canima builds a live graph database using Cypher queries that maps every host, credential, service, and attack path. When the Kerberos agent cracks a hash, the lateral movement agent knows about it instantly. This is how real attack chains emerge, not from isolated scans, but from correlated intelligence.
MATCH (agent:KerberosAgent)
-[:DISCOVERED]->(spn:Service)
-[:RUNS_AS]->(account:ADUser)
WHERE account.kerberoastable = true
MATCH (cracker:HashcatAgent)
-[:CRACKED]->(hash:NTLMHash)
-[:BELONGS_TO]->(account)
RETURN agent, spn, account, hash,
account.groups AS privileges
Real-Time Credential Propagation
Cracked hashes and captured tokens are written to the graph immediately. Downstream agents query for new credentials on every iteration, enabling attack chain progression without human intervention.
Attack Path Correlation
The graph tracks relationships between hosts, services, credentials, and privileges. Agents traverse these edges to find multi-hop attack paths that single-tool scanners miss entirely.
Contextual Agent Decisions
Each agent queries the graph before acting. A lateral movement agent does not just try every host. It queries for hosts reachable with its current credentials and prioritizes high-value targets by their graph centrality.
Built Different From Traditional Pentesting
Traditional internal pentests give you a snapshot from one consultant with limited time. Canima gives you exhaustive coverage from hundreds of domain-specific AI agents that coordinate, share intelligence, and chain attacks like a real adversary.
Domain-Specific Agent Architecture
Every vulnerability class gets a dedicated AI agent fine-tuned for that domain. The Kerberos agent thinks only about Kerberos. The NTLM relay agent focuses solely on relay paths. No context rot, no generic scanning. Expert-level depth across every attack surface.
Knowledge Graph Intelligence
A live Neo4j-style graph database connects every finding. Agents write discoveries as nodes and edges, then query the graph to make informed decisions. This is how a cracked SPN hash leads to a lateral movement path that leads to domain admin, automatically.
Full Attack Chain Documentation
Every path from initial access to domain compromise is documented end-to-end with timestamps, credentials used, tools invoked, and proof-of-concept evidence. Your report does not just list vulnerabilities. It shows exactly how they chain together.
| Capability | Canima | Others |
|---|---|---|
| Hundreds of specialized agents | Yes | No |
| Live knowledge graph correlation | Yes | No |
| Automated attack chain building | Yes | No |
| Real-time credential propagation | Yes | No |
| Full AD attack surface coverage | Yes | No |
| Controlled exploit validation | Yes | No |
| Agent activity logs with proof | Yes | No |
| Cross-assessment trending | Yes | No |
Ready to test your internal defenses?
Start your free 7-day demo to see how Canima maps your Active Directory attack surface, chains credential attacks, and documents every path to domain compromise.
- 7-day access to demo environment
- See a full AD attack chain walkthrough
- Understand credential propagation through the knowledge graph
- No commitment required