

I’ve done a lot of internal infrastructure pentests, for companies of various sizes, and there wasn’t a single pentest where spraying MonthYYYY for the past two months wouldn’t get at least one hit.
That, and the fact that every company has at least one server hidden somwhere that’s still vulnerable to MS17-010, that they can’t update or replace for one reason or the other.

To be fair, last internal pentest I was doing before switching jobs was like more than 5 years ago, so the situation might’ve changed.