Web Infrastructure & External Perimeter Security Testing

A service for CTO, DevOps and compliance teams that need to know exactly what they expose to the internet. We map the entire external perimeter using a recon → enumerate → validate methodology and surface the real entry vectors before an attacker finds them — every finding manually verified, not raw scanner output.

What we test

External attack surface & exposed services

We map every internet-facing host, port and service, then hunt for what should never be reachable: forgotten admin panels, staging/dev hosts, unauthenticated data stores (Redis, Elasticsearch, MongoDB, Memcached) and exposed RDP/SSH/database ports.

Subdomain enumeration & takeover

Passive and active subdomain discovery via Certificate Transparency logs, DNS brute-forcing and permutation, checking every dangling CNAME for subdomain takeover against deprovisioned S3, Azure, GitHub Pages and similar providers.

DNS hygiene & zone exposure

AXFR zone-transfer attempts, wildcard and stale record review, open-resolver checks, DNSSEC validation, and detection of internal hostnames and IPs leaking through public DNS.

CDN / WAF posture & origin exposure

We test whether the real origin IP can be reached directly, bypassing the CDN/WAF, plus WAF rule evasion and missing or weak security headers (HSTS, CSP, X-Frame-Options).

Email security (SPF/DKIM/DMARC)

Full validation of SPF (RFC 7208 — including the 10-lookup limit and a dangerous +all), DKIM key strength, and DMARC policy (p=none vs quarantine/reject) to confirm the domain resists spoofing and phishing.

Cloud storage exposure

Enumeration of S3, Azure Blob and GCS buckets tied to the organization for public listing, anonymous read/write and misconfigured ACLs or bucket policies that leak data.

Known-CVE stack components

Version fingerprinting of web servers, load balancers, frameworks and TLS libraries, correlated to known CVEs and safely validated — no blind reliance on banner version strings.

TLS/SSL config & DDoS resilience basics

Weak protocols and ciphers, expired/mismatched or over-shared wildcard certificates, missing HSTS, plus a review of rate-limiting, origin shielding and amplification exposure for DDoS resilience.

Methodology

  1. 1

    Scoping & Rules of Engagement

    We agree the exact in-scope domains, IP ranges and test windows, sign written authorization, and set escalation contacts, following NIST SP 800-115 pre-test planning.

  2. 2

    Passive Reconnaissance (OSINT)

    Zero-touch collection from Certificate Transparency logs, passive DNS, WHOIS/ASN/BGP and search engines to build the asset picture without alerting the target.

  3. 3

    Active Enumeration & Fingerprinting

    Controlled port scanning, service and version detection, subdomain brute-forcing and technology fingerprinting to enumerate the live attack surface.

  4. 4

    Vulnerability Validation

    Every candidate finding is manually verified with a safe proof-of-concept to eliminate scanner false positives — no destructive or denial-of-service payloads against production.

  5. 5

    Risk Analysis & Scoring

    Findings are rated with CVSS v3.1/v4.0 and re-weighted by real business exposure and exploitability, not raw scanner severity.

  6. 6

    Reporting & Retest

    You receive a prioritized report with reproduction steps and fixes, then a verification retest confirming each remediation held.

Standards & references

NIST SP 800-115 — Technical Guide to Information Security Testing and AssessmentNIST SP 800-53 Rev.5 — SC & SI control familiesCIS Controls v8 — Control 4 (Secure Configuration), 7 (Continuous Vulnerability Management), 12 (Network Infrastructure Management)CIS BenchmarksOWASP WSTG — Information Gathering (WSTG-INFO) & Configuration (WSTG-CONF)PTES — Penetration Testing Execution Standard (Intelligence Gathering)MITRE ATT&CK — Reconnaissance (TA0043)CVSS v3.1 / v4.0; RFC 7208 (SPF), RFC 6376 (DKIM), RFC 7489 (DMARC)

What you get

  • Executive summary A board-ready risk overview in business language, with an overall posture rating and the top exposures ranked by impact.
  • Attack surface inventory A living map of every discovered domain, subdomain, IP, open port and service — your external footprint as an attacker sees it.
  • Technical findings report Each issue with its CVSS score, affected asset, reproduction steps, evidence and concrete, prioritized remediation.
  • Remediation retest One round of verification testing after your fixes, confirming each finding is closed, with an updated status.
  • Attestation letter A signed statement of work performed and current posture, suitable for clients, auditors and compliance (SOC 2, ISO 27001, insurers).

FAQ

How long does an assessment take?+

A typical external web infrastructure assessment runs 5–10 business days depending on the number of live domains, subdomains and exposed services. You get a status update mid-engagement and the draft report within 2 business days of testing completion.

What do you need from us to start?+

Just the root domains and/or IP ranges in scope, a signed authorization form, and any test-window constraints. No source code or credentials are required for the external perimeter — this is a black-box, outside-in assessment.

Will testing disrupt our production systems?+

No. Enumeration and validation are non-destructive by design: we do not run DDoS or stress payloads, or exploit anything that could take a service down. Any potentially intrusive check is agreed in advance and run inside your approved window.

Is this legal?+

Yes, when authorized. We only test assets you own or are contractually permitted to test, under a signed authorization and defined rules of engagement. That written scope is exactly what separates a penetration test from an attack.

How is this different from an automated vulnerability scan?+

A scanner produces raw output full of false positives and no business context. We manually validate every finding, chase real exploit paths a scanner misses (subdomain takeover, origin bypass, bucket exposure), and rate risk against your actual environment.

Do you offer re-testing and continuous monitoring?+

Yes. One remediation retest is included in the engagement. Because your external surface changes constantly, we also offer scheduled reassessments and continuous attack-surface monitoring as an add-on.

Book an external attack surface assessment and see your perimeter the way an attacker does — request scoping today.