External ethical hacking: what an attacker can see and exploit from the internet

By the QuantumSec team

An attacker targeting your company from the internet doesn't start with access or information: they start with a domain name and a search engine. External ethical hacking simulates exactly that starting point to answer the question that actually matters: what can someone achieve with zero prior advantage? This guide explains what it involves and how it differs from a conventional network pentest.

What external ethical hacking is (and how it differs from a pentest)

A pentest usually has a defined scope: one application, one API, a specific IP range. External ethical hacking starts without that predefined scope — just the organization's name — and its first job is discovering the entire exposed attack surface: domains, subdomains, IPs, services and technologies, exactly as a real attacker would before deciding where to break in. It's a broader assessment than a one-off pentest, because it simulates the full reconnaissance phase of a real attack campaign.

OSINT: the phase most audits skip

Before touching any system, a real attacker gathers open-source intelligence: employees and their roles on LinkedIn, technologies in use (visible in job postings or metadata), employee credentials appearing in public data breaches, and accidentally exposed documents or metadata. This OSINT phase doesn't just flag social engineering risk: leaked credentials are, in practice, one of the most common initial access vectors in real incidents, and very few technical audits include it with the depth it needs.

The most common findings in an external perimeter assessment

Forgotten subdomains running outdated applications nobody remembers are still live. Subdomain takeover: a DNS record pointing to a service (a cloud account, a repository) that no longer exists, which an attacker can claim to serve malicious content under your own domain. Publicly accessible admin panels that should only be reachable from the internal network. Expired or misconfigured SSL/TLS certificates that leak information. And missing SPF, DKIM or DMARC, which allows spoofing emails from your domain for targeted phishing campaigns.

What you get once the assessment is finished

A complete map of your external attack surface (assets your own IT team probably didn't even have inventoried), an executive report with overall perimeter risk, a technical report with proof of concept for every exploited vulnerability, a dedicated OSINT report on exposed organizational and employee data, and a prioritized remediation plan. A re-test to confirm critical findings are closed is included.

FAQ

What's the difference between external ethical hacking and a network pentest?

External ethical hacking focuses exclusively on what is visible from the internet, starting from zero with no credentials or prior access, and includes a full OSINT phase. A network pentest can cover both the external perimeter and the internal network, but usually starts from an already-defined scope.

Does it include OSINT on my employees?

Yes, within the agreed scope. We identify what employee data is exposed in breaches, LinkedIn and other open sources that a real attacker would use for targeted phishing or credential stuffing attacks.

Can this assessment take down my production systems?

By default we avoid any action carrying real risk to availability (denial-of-service attacks, data deletion). If any test carries potential risk, it is agreed with you before running it.