An attacker who is already inside

External scanning answers "what can someone reach from the internet". It says nothing about the far more common scenario: a phished laptop, a contractor's VPN session, a compromised build agent — someone already on the network, looking for the path from there to domain admin.

Safe, Active, or Aggressive — you choose the blast radius

The reason internal testing is usually a once-a-year consulting engagement is that it can break things. Umbra makes that a setting rather than a leap of faith.

Read-only enumeration and configuration checks. Nothing writes, nothing authenticates repeatedly, nothing that could lock an account. Run it on a Tuesday afternoon.

Adds authenticated checks and controlled credential testing, with lockout-aware pacing — the techniques that touch account state are deliberately bounded, because a security assessment that locks out the finance department is not a security assessment.

Full exploitation attempts where a real proof requires them. For a maintenance window, a lab, or a segment you are willing to disturb.

54 techniques, named

Not a category list. These are the identifiers the agent dispatches, read straight out of its source, so you can see exactly what it does before you install it. The agent's proxy transport is dispatched by the same switch and is left out — it is how the techniques reach a host, not a technique.

Active Directory
  • ad_acl_audit
  • ad_ldap_collect
  • adcs_audit
  • coercion_probe
  • kerberos_roast
  • ldap_signing_audit
Windows services
  • rdp_audit
  • sccm_audit
  • smb_enum
  • winrm_exec
Databases
  • mssql_audit
  • oracle_probe
Cloud and containers
  • cloud_lateral_audit
  • k8s_audit
Credentials
  • cred_check
Discovery
  • discover_network
  • mdns_audit
  • netbios_audit
  • snmp_walk
  • tftp_config
Host and service
  • backup_audit
  • bmc_web_creds
  • capture_feasibility
  • ci_platform_audit
  • etcd_audit
  • exchange_audit
  • ftp_audit
  • gpp_audit
  • hybrid_id_audit
  • ics_probe
  • idp_audit
  • ipmi_audit
  • ms17010_audit
  • nfs_audit
  • ntp_audit
  • registry_audit
  • relay_audit
  • remote_access_audit
  • rpc_dump
  • secret_history_audit
  • secret_sprawl_audit
  • segmentation_audit
  • share_scan
  • smbghost_audit
  • smtp_audit
  • sql_default_creds
  • ssh_device_audit
  • storage_audit
  • tls_audit
  • unauth_db_audit
  • vmware_audit
  • vpn_audit
  • wifi_admin_audit
  • zerologon_audit

Findings, not a wall of output

Enumeration produces enormous volume. What makes it useful is the same thing that makes the rest of Umbra useful: a finding has to survive validation before it reaches you, and it arrives with the evidence that convinced the validator.

Read how that works on{" "} exploit validation .

Included from Standard

Internal pentest is part of the Standard plan and above — not a separate SKU, not a per-assessment charge.

Part of{" "} continuous security validation {" "} — discover, prove, fix, re-test.