[ Infrastructure ]
External Network Penetration Testing
- Typical duration
- 3-7 days
- Starting price
- Scoped
- You provide
- IP ranges and domains
[ 01 / The engagement ]
Most external compromises start with an asset nobody remembered owning: a staging box, a migrated VPN appliance, a subdomain still pointing at a decommissioned bucket. We map your real perimeter first, not the one in your asset register, then test every service that answers, and tell you which of them a competent attacker would pick.
[ 02 / Coverage ]
What we test, in practice.
This is the working checklist, not a marketing list. Anything your scope adds gets written into the engagement letter before we start.
Methodology
- 01Full perimeter discovery and asset attribution
- 02Port, service and version enumeration across TCP and UDP
- 03Edge device exposure: VPN, firewall, mail and remote access
- 04Subdomain takeover and dangling DNS records
- 05TLS configuration, certificate hygiene and protocol downgrade
- 06Password spraying against exposed portals and mail
- 07Exploitation of known CVEs, confirmed rather than assumed
[ 03 / What you get ]
Four things land at the end of every engagement.
Technical report
Every finding with CVSS v4.0 score, evidence, reproduction steps and a specific fix, written for the engineer who has to close it.
Executive summary
Two pages your board can read. Risk in business terms, with the three things that matter most called out.
Letter of attestation
A shareable document proving the test happened and what it covered, for customers and auditors who should not see the full report.
Free retest
Once you have fixed things, the same tester verifies each finding and reissues the report. Included for 90 days.
[ 04 / Questions ]
Before you commit.
A scan tells you a version number looks old. We confirm whether it is actually exploitable in your configuration, chain it as far as it goes, and drop the false positives before you ever see them.
No. Denial-of-service testing is excluded by default and only ever runs on explicit written request against an agreed target and window.
Often scoped together
All services →Internal Network Penetration Testing
We assume the perimeter already failed, and see how far one foothold travels.
Active Directory Security Assessment
The attack paths from any user to Domain Admin, mapped and proven.
Cloud Penetration Testing
AWS, Azure and GCP, IAM paths, workload escape and the blast radius of one key.
Scope a external network penetration testing.
Send us the target and the deadline. You get a written scope and a fixed price, usually within one working day.