What is an external network penetration test?
An external network penetration test assesses everything your organisation exposes to the internet: domains and subdomains, servers, VPN gateways, mail infrastructure, cloud services, admin panels and the forgotten staging box from 2019. We first discover what's actually out there — which is almost always more than you think — and then manually attack it to determine what a real adversary could achieve from the outside.
What we do
- Deep reconnaissance. Exhaustive subdomain and asset discovery, certificate transparency mining, cloud asset enumeration and historical data analysis. This is our home turf — our team has written some of the most widely used open-source reconnaissance tools in the industry.
- Exposed service analysis. Every open port and service identified, versioned and assessed: admin interfaces, databases, file shares, VPNs, mail and DNS infrastructure.
- Leaked credential hunting. Credentials and secrets exposed in breaches, paste sites, public code repositories and configuration files.
- Shadow IT discovery. SaaS tenants, forgotten cloud resources, third-party-hosted assets and dev/staging environments outside your standard build process.
- Manual exploitation. Where rules of engagement allow, we exploit what we find — demonstrating real impact rather than reporting theoretical risk.
What you walk away with
A complete inventory of your external attack surface (most clients keep using it long after the test), a prioritised set of findings with evidence and remediation guidance, an executive summary you can hand to the board, and a free retest of fixed issues within 90 days.
External testing pairs naturally with cloud penetration testing and is the most common starting point for organisations doing their first security assessment.
FAQ
Frequently asked questions
How much does an external network penetration test cost?
A typical external engagement runs 4–7 testing days, usually landing between AU$6,000 and AU$12,000 depending on the size of your internet-facing footprint. We provide a fixed quote within one business day of a scoping call.
What do you need from us to start?
Usually just your primary domain names and written authorisation. We discover the rest — that's the point. If you have an existing asset inventory we'll happily take it, then show you what it's missing.
How is this different from a vulnerability scan?
A scanner checks a list of IPs you give it against known vulnerability signatures. An external penetration test starts by finding the assets you didn't know to scan, then manually attacks them — chaining weaknesses, abusing misconfigurations and hunting leaked credentials. Most of our highest-impact external findings would never appear in a scan report.
Is external penetration testing safe for production systems?
Yes. Reconnaissance is largely passive, and active testing follows rules of engagement we agree up front. Anything potentially disruptive is coordinated with your team before we touch it.
How often should we run an external penetration test?
At least annually, and after significant infrastructure changes — a migration, an acquisition, or a major new product launch. Your external attack surface changes constantly even when you think it doesn't; annual testing is also the cadence auditors and enterprise customers expect.
Contact
Talk to us
Tell us what you're trying to protect, secure or build. We'll come back with a plan.
Want to see what attackers see?
Drop your email and we'll come back with a plan within one business day.