External ethical hacking: perimeter assessment from the internet

An attacker with no credentials or prior access can compromise your organization from the internet. We assess your entire external attack surface from a real adversary's perspective.

What does an attacker see when they target your company from the internet?

Services exposed without your knowledge, forgotten subdomains running outdated applications, employee credentials in data breaches, expired certificates, admin panels reachable from the internet: this is the reality of the perimeter at most companies. External ethical hacking simulates a real attack from the internet to identify and demonstrate exactly what an attacker can achieve without prior access.

Scope

  • Advanced OSINT: reconnaissance of employees, domains, technologies and leaks
  • Enumeration of subdomains, IPs and the external attack surface
  • Assessment of every exposed service: web, email, VPN, RDP, SSH
  • Vulnerability testing on perimeter web applications
  • Credential stuffing attacks using breach data (with authorization)
  • Email security assessment: SPF, DKIM, DMARC, mail spoofing
  • Subdomain takeover and dangling DNS detection
  • SSL/TLS certificate analysis and information exposure
  • PTES (Penetration Testing Execution Standard) + OWASP methodology

Methodology

  1. OSINT and reconnaissance: Gathering open-source intelligence: employees, technologies, leaks, exposed infrastructure.
  2. Active enumeration: Identification of every external asset: subdomains, IPs, open ports and services.
  3. Vulnerability assessment: Analysis of each exposed service looking for known vulnerabilities and insecure configurations.
  4. Exploitation: Controlled exploitation of the vulnerabilities found to demonstrate real impact: access to systems, data or the internal network.
  5. Report: Complete map of the external attack surface with findings classified, attack chains and a remediation plan.

Deliverables

  • Complete external attack surface map
  • Executive report with overall perimeter risk
  • Technical report with PoC for each exploited vulnerability
  • OSINT report: exposed organization and employee data
  • Prioritized remediation plan
  • Re-test included

Use cases

  • Companies that want to know their real exposure before a formal audit
  • Organizations that have suffered an external incident and want to understand the entry vector
  • Companies complying with NIS2 that need to assess their perimeter risk management
  • Startups about to receive investment who need to demonstrate security maturity
  • Any organization with an internet presence and data to protect

Frequently asked questions

What's the difference between external ethical hacking and a network pentest?

External ethical hacking focuses exclusively on what's visible from the internet, starting from zero (no credentials or prior access), including OSINT. A network pentest covers both the external perimeter and the internal network.

Does it include OSINT on employees?

Yes, within the agreed scope. We identify employee data exposed in breaches, LinkedIn and other sources that a real attacker would use for targeted attacks or credential stuffing.

Can it detect if we've already been compromised?

An active compromise assessment is a different service. However, if during reconnaissance we detect indicators of prior compromise, we notify you immediately.