External Network Penetration Testing
Test your internet-facing perimeter the way a real threat actor would - with OSINT, exposed service discovery, and exploit chaining against live targets.
What This Engagement Covers
The Service
Your external attack surface is everything an adversary can discover and target without crossing your perimeter firewall - and in modern enterprises, it grows constantly. Acquired cloud tenancies, development subdomains, legacy VPN concentrators, exposed remote desktop interfaces, and unpatched edge appliances provide fertile ground for initial compromise. Our external network penetration test conducts passive OSINT, active service fingerprinting, and chained exploit validation against live perimeter assets to evaluate whether your defenses can withstand real-world targeting.
What We Test
We thoroughly assess all internet-facing assets in scope: public IP ranges, domains and subdomains, perimeter firewalls, VPN endpoints (Pulse Secure, Fortinet, Cisco AnyConnect, Palo Alto GlobalProtect), remote management interfaces (RDP, SSH, IPMI), DNS servers, mail infrastructure (SPF, DKIM, DMARC), cloud ingress points, API gateways, and web servers.
Components Evaluated in Scope
Our testers systematically inspect the following architectural layers and attack vectors during the assessment.
How We Run It
We begin with passive open-source intelligence gathering and certificate transparency analysis to uncover shadow IT and unmonitored assets. We then perform non-intrusive service fingerprinting to identify vulnerable software versions, misconfigured access controls, and authentication bypasses. When vulnerabilities are discovered, we safely demonstrate exploitability with proof-of-concept evidence before presenting clear remediation paths.
OSINT & Attack Surface Discovery
Passive reconnaissance utilizing certificate logs, Shodan, Censys, DNS records, and breach data to locate all corporate assets.
Active Port & Service Enumeration
Port scanning and banner grabbing across in-scope IPs to identify running daemons, application stacks, and exposed protocols.
Vulnerability & Patch Assessment
Correlating identified versions against known CVEs, vendor advisories, and exploit databases for precise vulnerability mapping.
Authentication & Access Evaluation
Inspecting remote login interfaces, VPN portals, and admin dashboards for brute-force resistance and MFA enforcement.
Exploit Chaining & Foothold Testing
Controlled exploitation of validated security flaws to assess whether an attacker could gain an initial foothold on the perimeter.
Email & DNS Security Review
Checking SPF, DKIM, DMARC, and DNSSEC configurations for email spoofing susceptibility and domain hijacking risks.
Cloud Perimeter Analysis
Reviewing public cloud ingress points, load balancers, and container registries exposed to the public internet.
Remediation Roadmapping & Reporting
Compiling CVSS v3.1 scored findings, reproduction proof-of-concept steps, and prioritised engineering remediation guidance.
What You Receive
Findings land in your tracker as you go, not only in a PDF at the end. Free retesting is included in scope, not billed as a change order.
- Complete external attack surface inventory and asset discovery log
- Detailed technical vulnerability report with CVSS v3.1 ratings
- Exploit evidence and reproduction proof-of-concept logs
- Email security and perimeter gateway configuration review
- Prioritised remediation roadmap with urgent patch priorities
- Executive presentation summarizing overall perimeter risk posture
- Free retesting of all critical and high findings within 48 hours
- Letter of Attestation suitable for clients, underwriters, and auditors
What We Usually Find
The issues this engagement surfaces most often. Your environment will differ, but this reflects typical exposure patterns.
Who This Is For
Findings are mapped directly to PCI-DSS v4.0, SOC 2 Type II, ISO 27001, OSFI B-13, PIPEDA, NIST CSF, allowing your team to drop the report into an audit package without manual translation.
Calgary & Toronto Security Specialists
Canadian enterprises managing customer data under PIPEDA, Quebec Law 25, or Alberta PIPA are obligated to maintain reasonable security safeguards against external intrusion. Lorikeet Security Canada conducts external penetration assessments adhering to international standards (PTES, NIST SP 800-115) to satisfy Canadian auditor and insurance underwriter mandates.
Common Questions
An automated scan only reports banner matches and basic signatures, resulting in high false positives and no insight into whether flaws can actually be chained together. Our penetration testers manually validate vulnerabilities, attempt non-destructive exploitation, and evaluate the business impact of chained flaws.
We need your authorized IP addresses, domain names, and written permission. Our reconnaissance often discovers subsidiary domains and uncatalogued IP ranges, which we confirm with your team prior to active testing.
Our testing methodologies prioritize system stability and avoid denial-of-service vectors. All tests are conducted with controlled payloads, and we maintain direct communication channels with your infrastructure operations team.
Yes. Our external penetration tests fulfill PCI-DSS v4.0 Requirement 11.4.3 for annual perimeter penetration testing, providing the required testing methodology, evidence of exploitation attempts, and clean retest validation.
Trusted by Fast-Growing Companies
We came to Lorikeet Security with not so small task of tracking down the source of a cyber incident. Lorikeet Security looked at attack vectors and they set up a full test environment and really showed they knew what they were doing. With amazing analytics reports on down to the minute of login attempts. The level of detail that Cyber Insurance Companies wish they had in house - Those reports are an invaluable tool and give confidence and value add to the executive level for pre or post ransomware attacks.
We used Lorikeet Security for a PTaaS pentest and briefly tried their ASM tool - both were amazing. Fast tests, accurate findings, and everything handled through a modern interface. The report summary, live chat, asset management, and live quoting features of the portal really stand out. Their 'white glove' touch contributed to a 10/10 experience. They're truly changing the pentest game with the new portal clients can use.
Scope It in One Call
Tell us what is in scope and we come back with a fixed flat-rate price and a verified start date. No discovery-call maze, no hourly estimates that move.