Skip to main content
Home/Services/External Network Penetration Testing
Perimeter & External Attack Surface

External Network Penetration Testing

Test your internet-facing perimeter the way a real threat actor would - with OSINT, exposed service discovery, and exploit chaining against live targets.

PCI-DSS v4.0 SOC 2 Type II ISO 27001 OSFI B-13 PIPEDA NIST CSF
engagement log External Network Penetration Testing testing
day 01 recon OSINT & passive certificate transparency mapping mapped
day 01 scan perimeter port scanning & service fingerprinting complete
day 02 finding exposed legacy SSL-VPN portal missing multi-factor auth high
day 02 finding unauthenticated RCE on edge gateway appliance (CVE-2024) critical
day 03 exploit chained exploit demonstrated to obtain perimeter shell confirmed
day 04 triage findings verified and reviewed by senior pentester published
day 04 deliver deliverables package issued with remediation steps 201
after retest perimeter retest verified at no additional charge retested
retest included human countersigned report your auditor accepts
1 weektypical duration $5,500fixed scope, from 8deliverables 8methodology stages
Scope

What This Engagement Covers

The Service

Your external attack surface is everything an adversary can discover and target without crossing your perimeter firewall - and in modern enterprises, it grows constantly. Acquired cloud tenancies, development subdomains, legacy VPN concentrators, exposed remote desktop interfaces, and unpatched edge appliances provide fertile ground for initial compromise. Our external network penetration test conducts passive OSINT, active service fingerprinting, and chained exploit validation against live perimeter assets to evaluate whether your defenses can withstand real-world targeting.

What We Test

We thoroughly assess all internet-facing assets in scope: public IP ranges, domains and subdomains, perimeter firewalls, VPN endpoints (Pulse Secure, Fortinet, Cisco AnyConnect, Palo Alto GlobalProtect), remote management interfaces (RDP, SSH, IPMI), DNS servers, mail infrastructure (SPF, DKIM, DMARC), cloud ingress points, API gateways, and web servers.

Targets

Components Evaluated in Scope

Our testers systematically inspect the following architectural layers and attack vectors during the assessment.

Public IP addresses, ranges, and CIDR blocks
Domain names, subdomains, and DNS record infrastructure
VPN concentrators and remote access gateways
Perimeter firewall rule verification and port filtering
Remote desktop (RDP), SSH, and administrative portals
Web applications and API endpoints exposed externally
Mail server configuration (SPF, DKIM, DMARC, open relays)
Certificate transparency and historical data leak intelligence
Cloud edge ingress and public load balancers
Authentication services and single sign-on (SSO) portals
Method

How We Run It

We begin with passive open-source intelligence gathering and certificate transparency analysis to uncover shadow IT and unmonitored assets. We then perform non-intrusive service fingerprinting to identify vulnerable software versions, misconfigured access controls, and authentication bypasses. When vulnerabilities are discovered, we safely demonstrate exploitability with proof-of-concept evidence before presenting clear remediation paths.

01

OSINT & Attack Surface Discovery

Passive reconnaissance utilizing certificate logs, Shodan, Censys, DNS records, and breach data to locate all corporate assets.

02

Active Port & Service Enumeration

Port scanning and banner grabbing across in-scope IPs to identify running daemons, application stacks, and exposed protocols.

03

Vulnerability & Patch Assessment

Correlating identified versions against known CVEs, vendor advisories, and exploit databases for precise vulnerability mapping.

04

Authentication & Access Evaluation

Inspecting remote login interfaces, VPN portals, and admin dashboards for brute-force resistance and MFA enforcement.

05

Exploit Chaining & Foothold Testing

Controlled exploitation of validated security flaws to assess whether an attacker could gain an initial foothold on the perimeter.

06

Email & DNS Security Review

Checking SPF, DKIM, DMARC, and DNSSEC configurations for email spoofing susceptibility and domain hijacking risks.

07

Cloud Perimeter Analysis

Reviewing public cloud ingress points, load balancers, and container registries exposed to the public internet.

08

Remediation Roadmapping & Reporting

Compiling CVSS v3.1 scored findings, reproduction proof-of-concept steps, and prioritised engineering remediation guidance.

Deliverables

What You Receive

Findings land in your tracker as you go, not only in a PDF at the end. Free retesting is included in scope, not billed as a change order.

  • Complete external attack surface inventory and asset discovery log
  • Detailed technical vulnerability report with CVSS v3.1 ratings
  • Exploit evidence and reproduction proof-of-concept logs
  • Email security and perimeter gateway configuration review
  • Prioritised remediation roadmap with urgent patch priorities
  • Executive presentation summarizing overall perimeter risk posture
  • Free retesting of all critical and high findings within 48 hours
  • Letter of Attestation suitable for clients, underwriters, and auditors
Typical Results

What We Usually Find

The issues this engagement surfaces most often. Your environment will differ, but this reflects typical exposure patterns.

Exposed Management Consoles (RDP, IPMI, SSH) Unpatched Edge Devices & VPN Gateway CVEs Lack of Multi-Factor Authentication on External Portals Weak SSL/TLS Cipher Suites & Deprecated Protocols Subdomain Takeover Risks on Abandoned DNS Records Information Disclosure via Exposed Git Repositories Misconfigured SPF/DMARC Permitting Domain Spoofing Default or Easily Guessable Administrative Credentials
Fit

Who This Is For

Organizations with Public IP Ranges and Internet-Facing Services
SaaS Providers Protecting Production Infrastructure
Enterprises Meeting Annual PCI-DSS External Pentesting Rules
Canadian Businesses Seeking Cyber Insurance Coverage
Companies Undergoing Digital Transformation or Cloud Migrations
Firms Complying with SOC 2 CC6.6 External Security Requirements
Standards this assessment supports

Findings are mapped directly to PCI-DSS v4.0, SOC 2 Type II, ISO 27001, OSFI B-13, PIPEDA, NIST CSF, allowing your team to drop the report into an audit package without manual translation.

Canadian Operations

Calgary & Toronto Security Specialists

Canadian enterprises managing customer data under PIPEDA, Quebec Law 25, or Alberta PIPA are obligated to maintain reasonable security safeguards against external intrusion. Lorikeet Security Canada conducts external penetration assessments adhering to international standards (PTES, NIST SP 800-115) to satisfy Canadian auditor and insurance underwriter mandates.

Calgary OfficeAlberta Operations
Toronto OfficeOntario Operations
FAQ

Common Questions

How does an external pentest differ from an automated vulnerability scan? +

An automated scan only reports banner matches and basic signatures, resulting in high false positives and no insight into whether flaws can actually be chained together. Our penetration testers manually validate vulnerabilities, attempt non-destructive exploitation, and evaluate the business impact of chained flaws.

What information do you require to begin external scoping? +

We need your authorized IP addresses, domain names, and written permission. Our reconnaissance often discovers subsidiary domains and uncatalogued IP ranges, which we confirm with your team prior to active testing.

Can external penetration testing affect our website or service uptime? +

Our testing methodologies prioritize system stability and avoid denial-of-service vectors. All tests are conducted with controlled payloads, and we maintain direct communication channels with your infrastructure operations team.

Does this assessment satisfy PCI-DSS Requirement 11.4? +

Yes. Our external penetration tests fulfill PCI-DSS v4.0 Requirement 11.4.3 for annual perimeter penetration testing, providing the required testing methodology, evidence of exploitation attempts, and clean retest validation.

Client Stories

Trusted by Fast-Growing Companies

JBWeb

Digital Agency

“From Pentest to malware analysis these guys know what they're doing.”

We came to Lorikeet Security with not so small task of tracking down the source of a cyber incident. Lorikeet Security looked at attack vectors and they set up a full test environment and really showed they knew what they were doing. With amazing analytics reports on down to the minute of login attempts. The level of detail that Cyber Insurance Companies wish they had in house - Those reports are an invaluable tool and give confidence and value add to the executive level for pre or post ransomware attacks.

SOCaaS Incident Response
Flowtriq

SaaS Platform

“Streamlined Security Testing with White Glove Service”

We used Lorikeet Security for a PTaaS pentest and briefly tried their ASM tool - both were amazing. Fast tests, accurate findings, and everything handled through a modern interface. The report summary, live chat, asset management, and live quoting features of the portal really stand out. Their 'white glove' touch contributed to a 10/10 experience. They're truly changing the pentest game with the new portal clients can use.

Penetration Testing Continuous Assessments
Next

Scope It in One Call

Tell us what is in scope and we come back with a fixed flat-rate price and a verified start date. No discovery-call maze, no hourly estimates that move.