Core Service
FILE · OIU-SVC

Test the Perimeter the Way Attackers Find It.

Adversaries do not start with your asset inventory. They start with certificate transparency logs, Shodan, and forgotten subdomains. We map your perimeter from the outside in, the same way they discover it.

Definition External network penetration testing is manual adversarial assessment of internet-facing infrastructure that combines open-source intelligence, perimeter enumeration, service-level exploitation, and post-exploitation to map real intrusion paths.

Last reviewed:

File 01 · Definition

What It Is

It begins with reconnaissance, not a target list. We build the picture of your perimeter that an attacker would, from certificate transparency logs and OSINT through perimeter enumeration, then test what we find against the assets you handed us and the ones you did not. Service-level exploitation and post-exploitation turn that map into real intrusion paths.

Every exploit is proven against the live service, scored on the foothold it grants, and written up so your IR team can see exactly how the perimeter was crossed.

Findings come with the evidence your insurer and auditors ask for: exploit-validated, not a CVE list.

The gap between what you think you expose and what you actually expose is where breaches start, and edge devices, VPN concentrators, and forgotten cloud workloads are exploited within days of CVE publication. A perimeter that has only been scanned has not been tested, and an annual scan does not move at the speed an attacker reaches a freshly disclosed edge-device flaw.

File 02 · Threat Model

Why Companies Need This

  • 01 You have grown by acquisition. Acquired infrastructure is the most-forgotten attack surface in mid-market security.
  • 02 Your environment includes legacy edge appliances. Citrix, Ivanti, Fortinet, and SonicWall devices are recurring entry points for ransomware crews.
  • 03 You operate hybrid cloud. Internet-facing services span on-prem and multi-cloud. An automated scan rarely covers the full footprint.
  • 04 Your insurer asked for an external pentest. They want exploit-validated findings, not a CVE list.

File 03 · Deliverables

What You Get

Unlimited remediation validation included. No time cap, no per-finding charge. How it works

Detailed technical report

CVSS scoring, attack narratives, and proof-of-concept evidence

Executive summary

Findings translated into business risk, not CVSS noise.

Remediation guidance

Prioritized, actionable fixes, not just a list of CVEs

Real-time comms

Dedicated Slack channel for the engagement.

Compliance documentation

Mapped to SOC 2, PCI DSS, HIPAA, ISO 27001, and CMMC

File 04 · Methodology

Our Process

01 MAP

OSINT & Asset Discovery

Subdomain enumeration, certificate transparency, code-repo leakage, third-party exposure, employee OSINT for credential targeting.

02 MAP

Perimeter Enumeration

Port and service discovery, technology fingerprinting, vulnerability triage against the live internet-facing footprint.

03 EXPLOIT

Exploitation

Manual exploitation of identified weaknesses: edge-device CVEs, misconfigurations, authentication flaws, exposed admin interfaces.

04 EXPLOIT

Post-Exploitation

Foothold validation, internal reconnaissance from the breach point, privilege escalation, demonstration of business impact.

05 VALIDATE

Reporting & Retest

Attack-path narratives, executive impact summary, remediation guidance, verification retest.

File 05 · Intel Brief

Frequently Asked Questions

Q1 Will this test impact production systems?

External pentests are scoped to avoid availability impact. Exploitation against production is coordinated in advance and run during agreed windows.

Q2 Do you include phishing or social engineering?

External network pentests focus on the technical perimeter. Social engineering is a separate engagement and is often combined as part of a red team.

Q3 How often should we run external pentests?

Quarterly continuous testing is the modern standard for internet-facing infrastructure. Annual point-in-time tests miss the velocity of edge-device CVEs.

Talk to an Operator

The Surface Is Already Exposed. Test It First.

Send your root domain. We will show you what the internet already sees: the subdomains, exposed services, and edge devices that did not make your asset inventory.