External Penetration Testing

See your perimeter the way an attacker on the internet does

Hand the platform a scope of CIDRs, IPs, ASNs, or domains and pick a depth. A lead orchestrator agent runs a phased external pentest by spawning phase subagents that drive recon, discovery, assessment, and proof-of-concept tools over SSH on a hardened Kali worker. Every host, service, finding, and command lands on a live timeline you can audit phase by phase.

Start an external engagement View all features

From a scope textarea to a confirmed finding pack

No VPN to a jump box, no operator wiring up tooling from scratch. You define the scope, the orchestrator picks up a Kali worker, and the engagement runs end to end on a methodology you can read.

1
Define scope and authorize
Paste CIDRs, IPs, ASNs, or domains. Accept the Rules of Engagement, attest that you are authorized to test these targets, and sign. A whitelist grammar validates every token, so free text never reaches the engine.
2
Pick a depth
Recon, Assessment, or Exploitation. The depth sets the time budget, the phases that run, and how aggressive the operator is allowed to be. An admin cap can clamp the budget down for your workspace.
3
The operator runs the phases
An orchestrator agent spawns phase subagents that expand the scope, discover live hosts and services, scan for vulnerabilities, and, at the top tier, prove a finding without breaking anything. All over SSH on a shared Kali worker.
4
Get a finding pack you can act on
Hosts, services, findings, and a full event timeline land in one workspace. The phase gate refuses to close the engagement until every required checkpoint has been addressed, so you never get a half-finished test dressed up as a clean report.

What an engagement actually looks like

Two views from a sample Assessment-depth engagement: what the operator recorded in each methodology phase, and the external attack surface it built up while walking the playbook.

Recorded per phase

Each bar shows how many timeline events the operator wrote during a phase, split by outcome. Skipped checkpoints stay visible so you can see where the operator stood down and why.

Completed Failed (attempted) Skipped (with reason) Findings logged

External attack surface built from recon

A live graph of what the operator found. The scope expands into live hosts, hosts expose services, and the red edge is the single non-destructive proof of exploitation against a confirmed weakness.

Engagement scope Live host Exposed service Confirmed finding

Sample timeline excerpt

00:02:31 recon ASN AS64500 resolved to 203.0.113.0/24 and 198.51.100.0/24 via whois completed
00:09:48 recon Subdomain enum on acme.com, 38 names, 11 resolving to in-scope hosts completed
00:24:05 discovery Port and service scan, 17 live hosts, 41 exposed services fingerprinted completed
01:06:52 assessment Exposed management portal on 8443 with default credentials accepted finding
01:38:20 assessment testssl audit, legacy TLS 1.0 still enabled on the mail gateway finding
02:55:14 exploitation Nuclei flagged CVE-2023-1234 on the app load balancer, version confirmed finding
03:21:40 exploitation Single non-destructive proof of concept, read-only response captured completed
03:44:09 wrap-up 6 findings recorded, host and service inventory reconciled with the DB completed

Four ways to describe what is in bounds

The scope textarea accepts four token types. ASNs and domains are expanded on the Kali worker during recon, so the platform carries no whois or DNS dependency of its own.

CIDR 203.0.113.0/24
A network range. The operator enumerates it to live hosts during discovery before any service scanning begins.
IP 198.51.100.10
A single address, used exactly as given. Useful for a known edge device, a VPN concentrator, or one exposed service.
ASN AS64500
An autonomous system number. Resolved to its announced prefixes on the worker, so a single token can cover an entire org footprint.
Domain acme.com
Resolved to IPs and expanded to subdomains on the worker with subfinder, amass, and dnsx, then folded back into the host inventory.

Built like a real external engagement, not a one-shot scanner

Orchestrator and phase subagents
A lead agent owns the engagement and spawns a dedicated subagent per phase. Each runs its own tools over SSH on the worker, records what it finds, and hands control back. The orchestrator keeps the methodology honest from recon to wrap-up.
Phase-gated methodology
Recon, discovery, assessment, exploitation, and wrap-up each carry a required checklist. The engagement cannot close until every checkpoint has been addressed, the recorded findings cross-check against the database, and the top tier shows a real exploitation attempt.
Non-destructive by contract
No denial of service, no data modification, no persistence, and no lateral movement beyond proving a single confirmed finding. The boundary is written into the operator prompt and enforced by the depth-gated phase set, so only the exploitation tier can run active checks.
Scope expansion on the worker
ASNs resolve to their announced prefixes and domains expand to live subdomains during recon, all on the Kali box. You write one ASN or one domain and the operator turns it into the real list of hosts to assess.
Semantic finding dedup
Findings are deduplicated by category, host, target, and technique rather than by raw text, so the same exposed service reported twice collapses into one row. Critical and high findings raise a notification the moment they land.
Authorization built in
Every engagement requires acceptance of the Rules of Engagement, an authorization attestation, and a typed signature before it can launch. Cloud metadata endpoints, link-local ranges, and the platform's own host are blocked outright.

Pick the engagement that matches your authorization

Same scope, same worker, different aggressiveness. The depth you pick is the depth the operator executes, and the phase set is gated to it so there is no scope creep.

Recon
90minutes
Passive OSINT plus DNS and subdomain enumeration plus light host and port discovery. Maps the attack surface without any intrusive scanning.
  • Scope expansion (ASN, domain)
  • OSINT and subdomain enumeration
  • Light live-host and port discovery
Assessment
6hours
Everything in Recon plus a full port and service scan, nuclei vulnerability scanning, and TLS, web-exposure, and default-credential checks. Non-destructive throughout.
  • Full port and service detection
  • Nuclei vulnerability scanning
  • TLS audit and web exposure checks
  • Default-credential checks
Exploitation
18hours
Everything in Assessment plus active, non-destructive proof-of-concept exploitation of confirmed vulnerabilities, with the impact written up against each finding.
  • Active proof of concept, read-only
  • Confirmed exploitability per finding
  • Impact write-up, no persistence

Your perimeter changes every week, so should your test

Know what you actually expose
A forgotten staging host, an old VPN appliance, a management portal that should never have been public. External engagements rebuild the live picture of what an attacker can reach, every time you run one, instead of once a year.
Catch exposure the moment it appears
A new service goes live, a certificate lapses, a default credential ships to production. Run a Recon or Assessment engagement on a schedule and the change shows up while it still matters, not after an incident.
Validate findings without a consultancy
At the Exploitation tier the operator proves a finding is real with a single read-only proof of concept. You get exploitability you can trust and a clear impact statement, without scheduling and paying for a separate engagement each time.
Baseline an acquisition or a vendor
Onboarding a new company or a supplier and want a real read on their internet-facing risk? Point an engagement at their ASN or domain, with authorization in hand, and get a finding pack in hours instead of weeks.

What the operator runs on the worker

The recon, scanning, and exploitation tooling runs on the Kali worker, the same shared pool that drives DAST. Here is the toolkit the operator reaches for.

ASN to prefix resolution whois and BGP lookups subfinder amass dnsx Live-host discovery nmap service detection masscan httpx whatweb fingerprinting Nuclei vulnerability scan testssl TLS audit Web exposure checks Default-credential checks Exposed-service review Information-leak detection Non-destructive PoC exploitation CVE confirmation

Map your external attack surface today

Define a scope of CIDRs, IPs, ASNs, or domains, pick a depth, and let an AI operator run the engagement over a hardened Kali worker.

Have questions? Get in touch →