Web Infrastructure & External Perimeter Security Testing
A service for CTO, DevOps and compliance teams that need to know exactly what they expose to the internet. We map the entire external perimeter using a recon → enumerate → validate methodology and surface the real entry vectors before an attacker finds them — every finding manually verified, not raw scanner output.
What we test
External attack surface & exposed services
We map every internet-facing host, port and service, then hunt for what should never be reachable: forgotten admin panels, staging/dev hosts, unauthenticated data stores (Redis, Elasticsearch, MongoDB, Memcached) and exposed RDP/SSH/database ports.
Subdomain enumeration & takeover
Passive and active subdomain discovery via Certificate Transparency logs, DNS brute-forcing and permutation, checking every dangling CNAME for subdomain takeover against deprovisioned S3, Azure, GitHub Pages and similar providers.
DNS hygiene & zone exposure
AXFR zone-transfer attempts, wildcard and stale record review, open-resolver checks, DNSSEC validation, and detection of internal hostnames and IPs leaking through public DNS.
CDN / WAF posture & origin exposure
We test whether the real origin IP can be reached directly, bypassing the CDN/WAF, plus WAF rule evasion and missing or weak security headers (HSTS, CSP, X-Frame-Options).
Email security (SPF/DKIM/DMARC)
Full validation of SPF (RFC 7208 — including the 10-lookup limit and a dangerous +all), DKIM key strength, and DMARC policy (p=none vs quarantine/reject) to confirm the domain resists spoofing and phishing.
Cloud storage exposure
Enumeration of S3, Azure Blob and GCS buckets tied to the organization for public listing, anonymous read/write and misconfigured ACLs or bucket policies that leak data.
Known-CVE stack components
Version fingerprinting of web servers, load balancers, frameworks and TLS libraries, correlated to known CVEs and safely validated — no blind reliance on banner version strings.
TLS/SSL config & DDoS resilience basics
Weak protocols and ciphers, expired/mismatched or over-shared wildcard certificates, missing HSTS, plus a review of rate-limiting, origin shielding and amplification exposure for DDoS resilience.
Methodology
- 1
Scoping & Rules of Engagement
We agree the exact in-scope domains, IP ranges and test windows, sign written authorization, and set escalation contacts, following NIST SP 800-115 pre-test planning.
- 2
Passive Reconnaissance (OSINT)
Zero-touch collection from Certificate Transparency logs, passive DNS, WHOIS/ASN/BGP and search engines to build the asset picture without alerting the target.
- 3
Active Enumeration & Fingerprinting
Controlled port scanning, service and version detection, subdomain brute-forcing and technology fingerprinting to enumerate the live attack surface.
- 4
Vulnerability Validation
Every candidate finding is manually verified with a safe proof-of-concept to eliminate scanner false positives — no destructive or denial-of-service payloads against production.
- 5
Risk Analysis & Scoring
Findings are rated with CVSS v3.1/v4.0 and re-weighted by real business exposure and exploitability, not raw scanner severity.
- 6
Reporting & Retest
You receive a prioritized report with reproduction steps and fixes, then a verification retest confirming each remediation held.
Standards & references
What you get
- Executive summary — A board-ready risk overview in business language, with an overall posture rating and the top exposures ranked by impact.
- Attack surface inventory — A living map of every discovered domain, subdomain, IP, open port and service — your external footprint as an attacker sees it.
- Technical findings report — Each issue with its CVSS score, affected asset, reproduction steps, evidence and concrete, prioritized remediation.
- Remediation retest — One round of verification testing after your fixes, confirming each finding is closed, with an updated status.
- Attestation letter — A signed statement of work performed and current posture, suitable for clients, auditors and compliance (SOC 2, ISO 27001, insurers).
FAQ
How long does an assessment take?+
A typical external web infrastructure assessment runs 5–10 business days depending on the number of live domains, subdomains and exposed services. You get a status update mid-engagement and the draft report within 2 business days of testing completion.
What do you need from us to start?+
Just the root domains and/or IP ranges in scope, a signed authorization form, and any test-window constraints. No source code or credentials are required for the external perimeter — this is a black-box, outside-in assessment.
Will testing disrupt our production systems?+
No. Enumeration and validation are non-destructive by design: we do not run DDoS or stress payloads, or exploit anything that could take a service down. Any potentially intrusive check is agreed in advance and run inside your approved window.
Is this legal?+
Yes, when authorized. We only test assets you own or are contractually permitted to test, under a signed authorization and defined rules of engagement. That written scope is exactly what separates a penetration test from an attack.
How is this different from an automated vulnerability scan?+
A scanner produces raw output full of false positives and no business context. We manually validate every finding, chase real exploit paths a scanner misses (subdomain takeover, origin bypass, bucket exposure), and rate risk against your actual environment.
Do you offer re-testing and continuous monitoring?+
Yes. One remediation retest is included in the engagement. Because your external surface changes constantly, we also offer scheduled reassessments and continuous attack-surface monitoring as an add-on.