Penetration testing
External Network Testing
What an attacker on the internet can see, reach and exploit before anyone at your company notices.
Why it matters
What this protects you from
-
Your perimeter is larger than your inventory
Most organisations discover during testing that they are exposing hosts nobody remembered were running.
-
Exposure is continuous, testing is not
A service published for a migration two years ago is still published. Attackers scan for exactly that.
-
Credentials leak outside your network
Employee credentials surface in third-party breaches and get reused against your perimeter. That path needs no exploit at all.
-
The first foothold is the expensive one
Almost every serious incident starts with one externally reachable weakness. Everything after it is cleanup.
Coverage
What we test
-
Attack surface discovery
Subdomain enumeration, IP range validation, and identification of hosts and services you may not have inventoried.
-
Service enumeration and fingerprinting
Open ports, running services, software versions and end-of-life components across the confirmed scope.
-
Credential and information exposure
Public and breach-sourced credential exposure, exposed documents, metadata and other openly available intelligence.
-
Authentication surfaces
VPN portals, webmail, remote access and admin interfaces, tested for weak configuration and credential attacks within agreed limits.
-
Misconfiguration and exposed management
Default credentials, open administrative interfaces, permissive access rules and unnecessary exposure.
-
Exploitation of identified weaknesses
Confirmed exploitation where it is safe and in scope, to establish real impact rather than theoretical severity.
Approach
Three ways to run it
-
Black box
We start from your organisation name alone and discover the perimeter as an attacker would. The most realistic option.
-
Grey box
You supply a confirmed IP and domain inventory, and testing depth goes into the hosts rather than into finding them.
-
White box
Inventory plus network documentation and firewall rules, so exposure can be compared against what was intended.
Process
How the engagement runs
-
Scoping and authorisation
We agree address ranges, domains, exclusions and testing windows in writing, with authorisation confirmed before anything starts.
-
Discovery and enumeration
Full external discovery and enumeration to establish what is actually reachable, then validation of each host against the agreed scope.
-
Vulnerability identification
Automated and manual identification of weaknesses, with every automated result verified by hand before it reaches a report.
-
Targeted exploitation
Controlled exploitation of confirmed weaknesses to establish real impact. Denial of service is always excluded.
-
Reporting and remediation
Findings written with affected hosts, evidence and remediation steps, prioritised by what actually reduces exposure fastest.
-
Retest
After remediation we retest the affected hosts and issue a retest summary confirming closure.
Standards
What we test against
- NIST SP 800-115
- The assessment structure follows the NIST technical guide, which is what procurement and audit teams expect referenced.
- OSSTMM
- Methodology discipline and scope control, so testing stays inside agreed boundaries and results are repeatable.
- PTES
- Execution standard for intelligence gathering and exploitation phases, keeping discovery systematic rather than ad hoc.
- MITRE ATT&CK
- Findings are mapped to initial access techniques, so results line up with how your defensive team already models threats.
Deliverables
What lands in your inbox
- Executive summary
A plain-language account of perimeter exposure, written for the people who approve the remediation budget.
- Overall security grade
A single grade derived from the most severe confirmed finding, using published thresholds.
- Confirmed asset inventory
What we found exposed, which is frequently more than the inventory you started with.
- Detailed technical findings
Every finding with CVSS vector, CWE classification, affected hosts and reproduction steps.
- Proof-of-concept evidence
Evidence for each finding, captured from our declared testing IP range so every action is traceable.
- Retest summary
Issued after remediation, confirming what is closed and what remains exposed.