External Infrastructure Penetration Test
A black-box penetration test of your internet-facing infrastructure, run from the position of an outside attacker with no credentials and no prior knowledge of the estate.
Nobody in the company can say with confidence what is exposed to the internet right now. Forgotten subdomains, a management interface left reachable, an unpatched service behind a hostname no one remembers registering. An attacker does not need a vulnerability in the platform you built; they need one exposed service you did not know was there.
What the test covers
AZRE Consulting performs a black-box external penetration test of the in-scope infrastructure, conducted from the perspective of an unauthenticated attacker on the public internet with no prior knowledge of the estate. The objective is to identify exposed services, unpatched or misconfigured components, and weak authentication that could allow an attacker to gain an initial foothold, and to determine what that foothold would reach.
- External estate: the on-premise or hosted infrastructure behind your platform, with hosts and address ranges confirmed in writing before kick-off
- External perimeter: the public IP ranges and domains associated with the platform, allow-listed before testing begins
- Internal network: not included. An internal or assumed-breach engagement is scoped separately if required
- Access provided: none. No credentials and no documentation, consistent with an external adversary's position
Key testing areas
- Perimeter discovery and attack surface mapping: passive and active reconnaissance of the in-scope ranges and domains, including subdomain enumeration, host and port discovery, service fingerprinting, and identification of shadow or forgotten assets exposed alongside the primary platform
- Service and patch-level assessment: identification of outdated, unpatched, or end-of-life software across exposed services, correlated against known exploitable vulnerabilities and validated manually to eliminate false positives
- Data and information exposure: directory listings, exposed backups, configuration and source artefacts, verbose error handling, metadata leakage, and credentials or keys inadvertently published on internet-facing hosts
- Exposed services and network controls: management and administrative interfaces reachable from the internet, remote access and file-transfer services, database and cache ports, firewall rule effectiveness, and separation between production and non-production exposure
- Authentication and credential attacks: weak, default, and reused credentials on exposed services, tested within agreed rate limits and lockout thresholds to avoid denial of service against live systems
- Exploitation and escalation paths: controlled, pre-authorised exploitation of confirmed vulnerabilities to demonstrate real impact, followed by analysis of what an attacker could reach from that foothold, including internal segments, credential harvesting, and pivot opportunities toward the application tier
- Logging and monitoring: coverage and retention of infrastructure audit logs, alerting on high-risk activity, and your ability to detect and reconstruct the testing activity performed
Methodology
All activities follow recognised security testing and risk management frameworks, including NIST SP 800-115 and SP 800-53, CIS Benchmarks, and the security control expectations defined under ISO/IEC 27001 and SOC 2. Testing combines deep manual exploration with targeted automated analysis, and every finding is manually validated to eliminate false positives. Exploitation is controlled and pre-authorised, and credential testing stays within agreed rate limits so live systems are never put at risk.
How the engagement runs
The engagement follows a four-step process designed to fit existing operations without friction or downtime.
- Alignment and onboarding: a dedicated engagement lead and testing team; a kick-off to confirm the in-scope ranges and domains in writing, agree no-go zones and testing windows, and complete allow-listing
- Active testing and live collaboration: reconnaissance, assessment, and controlled exploitation, in constant contact with your technical leads; any critical or high-risk finding is reported immediately so remediation can begin in parallel
- Analysis and technical debrief: a comprehensive preliminary report with proof-of-concept evidence and actionable hardening recommendations, followed by a findings walkthrough with your infrastructure and security teams
- Verification and closure: targeted re-testing once fixes are implemented, confirming that exposures are closed and no regressions were introduced, then the final certified report and archival of all project data
- Immediate notification of every critical or high-risk finding, during testing
- Inventory of every internet-facing host, service, and domain discovered, including assets you did not know were exposed
- Preliminary report with proof-of-concept evidence and the escalation path from each confirmed foothold
- Risk-rated findings with actionable hardening recommendations
- Findings walkthrough with your infrastructure and security teams
- Targeted re-test of every remediated finding, then the final certified report
The outcome
You hold a verified picture of what the internet can see of your estate, what an attacker could do with it, and evidence that each exposure has been closed.
Start with a conversation, not a proposal.
Tell us what is happening in the business. If we are the wrong firm for it, we will say so and point you somewhere better. If we are the right firm, you will leave the conversation with a clearer read on the problem than you came in with.
Start a conversation