EspañolEnglish

External network pentest

Everything an attacker sees before they knock.

An external penetration test takes your internet-facing infrastructure from an attacker’s seat: what is exposed, what is outdated, what is leaking, and what of it can actually be broken into. OSINT-driven recon, active enumeration, and exploit validation against your real perimeter.

Up to 50 live hosts. Remote. From €5,900.

What an external pentest answers.

Your perimeter grows every quarter: a forgotten subdomain, a staging box left public, a VPN a version behind, a set of credentials in a public breach. An external test finds what is reachable from the internet, confirms what is genuinely exploitable, and hands you the list before someone else finds it.

Why it matters.

The surface you forgot you had

Shadow IT, abandoned subdomains, exposed admin panels, dev environments indexed by accident. We enumerate the whole footprint, not just the assets you remembered to list.

Exploitable, not theoretical

A scanner reports a version number and a CVE. We confirm whether it actually breaks, so you spend remediation effort on what is real, not on a wall of unvalidated criticals.

Credentials already in the wild

Leaked passwords, exposed API keys, tokens in public repos. We check what of your exposure an attacker could use today without touching a single exploit.

How we come at it.

The way a real external operator would, with no prior access.

Black box

No credentials, no asset list beyond the domains in scope. We discover the surface the way an attacker does.

OSINT-led

Public breaches, code repositories, certificate transparency, DNS, and metadata, before a single packet touches your infrastructure.

Validated exploitation

Where scope allows, confirmed exploitation and safe post-exploitation, so a finding is proven rather than asserted.

How it runs.

From the domains in scope to proven access.

  1. 01

    Footprinting and OSINT

    Domains, subdomains, IP ranges, cloud assets, exposed credentials, and leaked information. The picture an attacker assembles first.

  2. 02

    Enumeration

    Live hosts, open ports, services, technologies, and versions across the full surface.

  3. 03

    Vulnerability validation

    CVE confirmation, misconfiguration, weak authentication, and exposed interfaces, verified by hand, not by a scanner’s guess.

  4. 04

    Exploitation

    Controlled exploitation of confirmed weaknesses, within the rules of engagement.

  5. 05

    Impact and access

    What the exploited weakness actually grants: a foothold, data, or a route inward. Evidenced and reversible.

What gets tested.

The whole internet-facing footprint.

  • Subdomain and service enumeration
  • Exposed admin and management interfaces
  • CVE validation on perimeter services
  • VPN, RDP, and remote access exposure
  • Email security (SPF, DKIM, DMARC)
  • Cloud assets and storage exposure
  • Leaked credentials and API keys
  • TLS and certificate configuration
  • Web servers and reverse proxies
  • Forgotten and staging environments

What we usually find.

  • A staging server, public by accident, running a database with no password.
  • A VPN appliance one CVE away from pre-auth remote code execution.
  • A developer’s API key committed to a public repository, still valid.
  • A subdomain pointing at a deprovisioned cloud bucket, ready to be taken over.

What you get.

  • A full attack-surface inventory
  • Verified findings and exposed credentials
  • Every finding scored, with reproduction steps
  • Remediation prioritized by real exploitability
  • Free retest of Critical findings within 30 days

The base external pentest covers up to 50 live hosts from €5,900. See services and pricing.

Questions.

How is this different from a vulnerability scan?

A scan lists what might be wrong from version numbers. An external pentest confirms what actually is, by hand, and chains findings into real access. You get a short list of proven issues instead of a long list of maybes.

Do you need our asset list?

It helps, but we do not rely on it. Half the value is finding the assets you forgot, so we start from your domains and discover the rest.

Will it take services down?

No. Exploitation is controlled and destructive techniques need explicit sign-off. Anything critical is escalated the same day.

How many hosts does the base scope cover?

Up to 50 live hosts. Larger perimeters are scoped on the call and priced from the day rate.

External perimeter

See your perimeter the way an attacker does.

Thirty minutes, NDA first. A written proposal within 48 hours if you want one.

Book a free scoping call

Prefer email? engagements@redghostops.com