External Security Assessment
An External Security Assessment examines your organization's publicly accessible attack surface from an outside perspective.
The goal is simple:
Identify what is exposed, determine what can be learned about it, and identify security issues worth addressing.
-
We identify publicly associated infrastructure and build an inventory of externally accessible assets.
This may include:
Domains and subdomains
Public IP addresses
Internet-facing hosts
DNS records
Web applications
Other publicly attributable infrastructure
-
Identified hosts are evaluated for externally accessible services and protocols.
We examine:
Open TCP and UDP ports
Running services
Service and software versions
Unnecessary external exposure
Internet-facing administrative interfaces
-
Public-facing web applications are reviewed for common security issues and areas of concern.
Testing may include:
Security configuration review
Common web application vulnerabilities
Authentication and authorization observations
Security headers
Information disclosure
Exposed files and resources
Technology and framework identification
-
Identified software and services are evaluated against publicly known vulnerabilities and security advisories.
Findings are reviewed in context rather than simply reporting automated scanner output.
-
We examine information that a potential attacker can obtain through publicly accessible systems and services.
This can include:
Technology and infrastructure disclosures
Publicly exposed files
DNS and certificate information
Software fingerprints
Other information that meaningfully expands the external attack surface
-
Every assessment produces a written report containing:
01 — Executive Summary
A concise overview of the organization's external security posture and significant findings.02 — External Asset Inventory
The internet-facing assets identified during the assessment.03 — Findings
Documented security issues with severity, affected assets, evidence, and technical explanation.04 — Remediation Recommendations
Practical steps for reducing exposure and addressing identified issues. -
External assessments are performed against publicly accessible infrastructure authorized by the client.
Included:
External reconnaissance, enumeration, vulnerability identification, and security testing of authorized public-facing assets.Not included:
Internal network penetration testing, credentialed testing, social engineering, physical security testing, or attempts to obtain unauthorized internal access.All testing is performed according to an agreed scope and rules of engagement.