Skip to content
AttackVector

Can an outsider get in?

External penetration test

An external penetration test is a manual, adversary-style assessment of every system your organization exposes to the internet. It answers one question with evidence: can an attacker with no prior access get in, and how far would they get?

Point in timeTargets: TechnologyTypically 1 to 2 weeks of testing

What you get

  • Exploitable perimeter weaknesses, confirmed by hand
  • Exposed services and credentials you did not know about
  • A prioritized fix list for the paths that lead inside

Overview

We attack your public footprint the way a real adversary would: web servers, VPN gateways, firewalls, exposed services, and the applications behind them. Anything reachable from the internet is in scope, and anything we can exploit we prove.

Scope

What is typically in scope. The final list is agreed with you before testing starts.

  • Public IP ranges, domains, and subdomains you own
  • VPN, remote access, and email gateways
  • Firewalls, load balancers, and edge appliances
  • Internet-facing web applications and APIs at the perimeter level
  • Exposed cloud storage and services tied to your domains
  • Leaked credentials and secrets found in public sources
  • Optional: password spraying against external authentication within agreed limits

Methodology

Phases run in this order. Each one produces evidence that feeds the next.

  1. Reconnaissance

    We enumerate your attack surface from open sources and active scanning, including assets nobody remembers deploying.

  2. Enumeration and analysis

    Every exposed service is fingerprinted, version-checked, and reviewed for misconfiguration and weak authentication.

  3. Exploitation

    Confirmed weaknesses are exploited by hand and chained together to reach the inside, always within the agreed rules of engagement.

  4. Post-exploitation

    From any foothold we show what an attacker could reach next: data, internal networks, or identity systems.

  5. Reporting and debrief

    Findings are ranked by real business impact and walked through live with your team.

Deliverables

  • Executive summary written for leadership and auditors
  • Technical findings with evidence, severity, and CVSS score
  • Attack narrative showing how findings chain together
  • Asset inventory of what we found exposed
  • Prioritized remediation roadmap
  • Attestation letter suitable for customers, auditors, and insurers
  • One retest of remediated findings

Sample report excerpt

One finding, in the structure every finding follows. The content is illustrative.

AttackVector · External penetration test · Technical findingsIllustrative excerpt
CriticalFinding 1 of 19

Exposed management interface with default credentials

Severity
Critical
Status
Open, retest pending
Affected assets
Listed in appendix A

Impact

An unauthenticated internet user could log in to a network appliance with vendor default credentials and gain administrative control of a device that routes traffic into the internal network.

Evidence

Authenticated session captured against the appliance login page using the vendor default account, followed by a configuration export containing internal addressing.

Screenshot and request/response evidence appear here

Remediation

Restrict management interfaces to the internal management network or VPN, rotate all default accounts, enforce MFA where the vendor supports it, and add the device to the patch and credential rotation process.

Verification

Retested after remediation. Result and date are recorded here and reflected in the attestation letter.

Every finding follows this structure.Download the full sample report

Timeline

Typical duration

Typically 1 to 2 weeks of testing, report within 5 business days

What affects it

Small perimeters finish in a week. Larger estates, or scopes that include password spraying, take longer. Retest is scheduled when your fixes are ready.

Compliance drivers

Need this for an audit or renewal? This test provides accepted evidence for PCI DSS, HIPAA, SOC 2, ISO 27001, Cyber insurance, CMMC, NYDFS.

See the full requirement mapping

Frequently asked questions

How long does an external penetration test take?

Typically one to two weeks of active testing followed by report delivery within five business days. The exact duration depends on the number of live hosts and applications in scope.

Is a retest included?

Yes. One retest of remediated findings is included, and we update the report and attestation letter to reflect the closed items.

What do we need to provide?

A list of IP ranges and domains you own, a point of contact for emergencies, any testing windows or systems to exclude, and written authorization. We handle the rest.

How is this different from a vulnerability scan?

A scan lists known vulnerabilities by version. A penetration test verifies which ones are actually exploitable in your environment, chains them together, and shows the real impact. The report contains proof, not possibilities.

Will testing disrupt production?

We avoid denial of service techniques by default and agree on testing windows for sensitive systems. Exploitation is controlled and coordinated with your named contact.

Ready to scope a external penetration test?

Tell us about your environment and timelines. You will talk to the people who run the engagement and hear back within one business day.