These are conducted from inside an organisation, over their Local Area Network. Tests will determine if it is possible to gain access to sensitive information, including Applications, Databases, HR information and ERP type resources. Internal tests will assess whether a user can escalate their network privileges and gain copies of usernames and passwords for other business users. Internal tests will also assess whether it is possible to remove data from the corporate environment without triggering alarms, or leaving an audit trail of what was taken, and where it was moved to. Internal tests will assess whether a user can circumvent existing security controls to grant themselves inbound access to the infrastructure through remote access and trojaning techniques
