Platform

Internal Network
Penetration Testing

What happens after an attacker breaches your perimeter, or when an insider goes rogue? Canima deploys hundreds of specialized AI agents that systematically map your internal infrastructure, attack Active Directory, execute lateral movement, and escalate privileges to domain admin. Every credential, every pivot, every escalation step is documented with proof.

canima-agent
$ canima agent deploy --scope internal
[*] Deploying 47 agents to 10.0.0.0/16
[*] AD Enumeration: 2,847 objects indexed
[+] Kerberoastable SPN: [email protected]
[+] TGS hash captured → Hashcat mode 13100
[+] Cracked: svc_backup:Summer2024!
[*] Lateral movement → DC01 via PSRemoting
[+] DCSync: krbtgt hash extracted
[!] DOMAIN ADMIN achieved in 4 pivots
01 / DEEP INTERNAL COVERAGE

From Initial Foothold to Domain Compromise

Real attackers do not stop at one exploited host. Neither do we. Canima chains together credential attacks, service exploitation, and privilege escalation paths to show you exactly how far an adversary can reach inside your network.

01

Active Directory Attack Surface

Full AD enumeration including users, groups, trusts, GPOs, delegation configurations, and ACL-based privilege escalation paths. Identifies Kerberoastable SPNs, AS-REP roastable accounts, unconstrained delegation, and resource-based constrained delegation misconfigurations that real attackers chain together for domain compromise.

Kerberoasting AS-REP Roasting RBCD DCSync
02

Credential Attacks & Hash Cracking

Lockout-aware password spraying across LDAP, SMB, RDP, and Kerberos. LLMNR/NBT-NS poisoning for NTLMv2 capture. Offline hash cracking with Hashcat against captured Kerberos TGS tickets and NTLM hashes. Every cracked credential feeds back into the knowledge graph for downstream agents to leverage.

Password Spraying LLMNR Poisoning NTLMv2 Hashcat
03

Lateral Movement & Pivoting

Pass-the-hash, pass-the-ticket, overpass-the-hash, and credential forwarding across your network. The lateral movement agents consume cracked credentials and session tokens from the knowledge graph in real time, pivoting through hosts to reach high-value targets like database servers, file shares, and domain controllers.

Pass-the-Hash Pass-the-Ticket WMI Exec PSRemoting
04

NTLM Relay & Protocol Exploitation

Identifies and validates NTLM relay opportunities across SMB, LDAP, and HTTP. Tests for coercion vulnerabilities like PetitPotam and PrinterBug to force authentication from privileged accounts. Covers SMB signing enforcement, LDAP signing, EPA configuration, and channel binding gaps.

NTLM Relay PetitPotam PrinterBug SMB Signing
05

Local Privilege Escalation

On every compromised host, agents enumerate kernel vulnerabilities, misconfigured services, unquoted service paths, writable DLL directories, token impersonation opportunities (SeImpersonate, SeAssignPrimaryToken), and AlwaysInstallElevated policies. Each escalation path is validated, not just flagged.

Token Impersonation Service Misconfig Kernel Exploits UAC Bypass
06

Network & Service Enumeration

Complete internal network mapping across subnets and VLANs. Deep service enumeration on SMB, LDAP, SNMP, SSH, RDP, FTP, MySQL, PostgreSQL, MSSQL, MongoDB, and Oracle. Tests for default credentials, anonymous access, and known CVEs (EternalBlue, SMBGhost, ZeroLogon, BlueKeep) with controlled exploitation.

EternalBlue ZeroLogon BlueKeep Default Creds
Specialized AI Agents
100s
AD Attack Chain Coverage
Full
Findings With PoC Evidence
100%
Credential Correlation
Real-time
02 / ASSESSMENT PIPELINE

How the Internal Assessment Works

A coordinated multi-stage pipeline where each phase feeds intelligence into the next through a shared knowledge graph. No vulnerability exists in isolation. Every finding is connected to the attack paths it enables.

01

Reconnaissance & Mapping

Network discovery agents map all reachable subnets, hosts, and services. Active Directory enumeration agents pull users, groups, trusts, SPNs, delegation settings, and GPOs. Everything is indexed into the knowledge graph with relationship edges connecting hosts run which services, which accounts have which privileges.

02

Vulnerability & Credential Attacks

Specialized agents launch in parallel: Kerberos agents roast SPNs and AS-REP accounts, credential agents spray passwords with lockout-aware throttling, LLMNR agents poison multicast requests, and vulnerability scanners cross-validate CVEs. Cracked hashes and captured credentials are immediately pushed to the graph for all agents to consume.

03

Exploitation & Lateral Movement

Exploit agents validate confirmed vulnerabilities with controlled payloads. Lateral movement agents read the credential graph and pivot through hosts using pass-the-hash, pass-the-ticket, and relay attacks. Each new session and credential is added to the graph, expanding the attack surface for the next iteration, mirroring how real adversaries operate.

04

Privilege Escalation & Reporting

Privilege escalation agents target the highest-value paths: DCSync, golden ticket, trust exploitation. Every step from initial foothold to domain admin is documented as a complete attack chain with proof-of-concept evidence. QA agents validate each finding before it enters the final report with CVSS scoring, remediation guidance, and executive summary.

03 / PROJECT KNOWLEDGE GRAPH

Every Agent Shares One Intelligence Layer

Canima builds a live graph database using Cypher queries that maps every host, credential, service, and attack path. When the Kerberos agent cracks a hash, the lateral movement agent knows about it instantly. This is how real attack chains emerge, not from isolated scans, but from correlated intelligence.

cypher query
MATCH (agent:KerberosAgent)
  -[:DISCOVERED]->(spn:Service)
  -[:RUNS_AS]->(account:ADUser)
WHERE account.kerberoastable = true
MATCH (cracker:HashcatAgent)
  -[:CRACKED]->(hash:NTLMHash)
  -[:BELONGS_TO]->(account)
RETURN agent, spn, account, hash,
  account.groups AS privileges

Real-Time Credential Propagation

Cracked hashes and captured tokens are written to the graph immediately. Downstream agents query for new credentials on every iteration, enabling attack chain progression without human intervention.

Attack Path Correlation

The graph tracks relationships between hosts, services, credentials, and privileges. Agents traverse these edges to find multi-hop attack paths that single-tool scanners miss entirely.

Contextual Agent Decisions

Each agent queries the graph before acting. A lateral movement agent does not just try every host. It queries for hosts reachable with its current credentials and prioritizes high-value targets by their graph centrality.

04 / WHY CANIMA

Built Different From Traditional Pentesting

Traditional internal pentests give you a snapshot from one consultant with limited time. Canima gives you exhaustive coverage from hundreds of domain-specific AI agents that coordinate, share intelligence, and chain attacks like a real adversary.

01

Domain-Specific Agent Architecture

Every vulnerability class gets a dedicated AI agent fine-tuned for that domain. The Kerberos agent thinks only about Kerberos. The NTLM relay agent focuses solely on relay paths. No context rot, no generic scanning. Expert-level depth across every attack surface.

02

Knowledge Graph Intelligence

A live Neo4j-style graph database connects every finding. Agents write discoveries as nodes and edges, then query the graph to make informed decisions. This is how a cracked SPN hash leads to a lateral movement path that leads to domain admin, automatically.

03

Full Attack Chain Documentation

Every path from initial access to domain compromise is documented end-to-end with timestamps, credentials used, tools invoked, and proof-of-concept evidence. Your report does not just list vulnerabilities. It shows exactly how they chain together.

Capability comparison: Canima versus other tools
Capability Canima Others
Hundreds of specialized agents Yes No
Live knowledge graph correlation Yes No
Automated attack chain building Yes No
Real-time credential propagation Yes No
Full AD attack surface coverage Yes No
Controlled exploit validation Yes No
Agent activity logs with proof Yes No
Cross-assessment trending Yes No
05 / GET STARTED

Ready to test your internal defenses?

Start your free 7-day demo to see how Canima maps your Active Directory attack surface, chains credential attacks, and documents every path to domain compromise.

  • 7-day access to demo environment
  • See a full AD attack chain walkthrough
  • Understand credential propagation through the knowledge graph
  • No commitment required