EXTERNAL PENETRATION TESTING

Detect how an attacker breaks in from the outside.

Exploited vulnerabilities are now among the top ways breaches begin, and they nearly all start at the perimeter (Verizon DBIR 2024). Our external penetration testing attacks your internet-facing surface with no credentials and no whitelist, chains what we find, and proves which exposed asset leads to a foothold inside your network.

How an external pentest works
87%
of our clients renew annually
150+
organisations across multiple European countries
7/10
confirm findings their previous provider did not find
Want to know what’s exposed on the internet? Share your main concern and your email.

Protected by reCAPTCHA. The Google Privacy Policy and Terms of Service apply.

Trusted by companies in highly regulated environments

Reveal how an attacker breaks in from the internet.

ENCARGO · SIN CREDENCIALES NI LISTA BLANCA OBJETIVO · ENTRAR EN LA RED
INTERNET sin credenciales · sin lista blanca · tu dominio INTERNET
Reconocimiento · subfinder + amass + httpx
OSINT Y RECONOCIMIENTO DNS pasivo · logs CT · repos de código
Enumeración · nuclei + manual
SERVICIO EXPUESTO dev.acme.example · subdominio olvidado
Exploit · PoC validada, sin spray
CVE / MALA CONFIGURACIÓN Confluence CVE-2023-22515 · sin parchear
Pivote · port-forward al /24 interno
PIE DENTRO DE LA RED Jump host en DMZ · clave SSH reutilizada DENTRO
PIVOTE DE FUERA A DENTRO 4 SALTOS · ~22 MIN
exposed_assets342 hosts alcanzables desde internet
shadow_it8 subdominios fuera del CMDB
exploit_chainOSINT → CVE → dentro · 4 saltos
internal_pivotJump host en DMZ · port-forward

We begin with your apex domain and nothing else, the same position as a stranger on the internet. Tools map the obvious surface. The chain is human work.

The way in is rarely one obvious hole. It is a forgotten subdomain, an unpatched edge appliance, a secret pushed to a public repository, or a login portal with no lockout. We chain them and prove the path to a shell on something internal, with the exact request your team can replay.

WHAT WE TEST
  • Public websites and services
  • VPNs and edge appliances
  • Email and DNS spoofing
  • Cloud perimeter and storage
  • Forgotten subdomains
  • Leaked credentials and keys
  • Login portals and SSO
  • The route to an internal foothold
EXTERNAL VS INTERNAL PENTEST

Where each one fits.

An external pentest asks whether someone on the internet can break in. An internal pentest asks how far an attacker gets once inside.

YOU ARE HERE

External pentesting

Internal pentesting

Objective
External pentesting Map the internet-facing surface and prove what leads to a foothold.
Internal pentesting Prove what an attacker reaches once they are inside.
Starting point
External pentesting Internet, no access, no credentials, just your apex domain.
Internal pentesting A foothold: standard user, VPN, contractor laptop.
Assets in scope
External pentesting Public portals, exposed APIs, edge appliances, VPN, DNS, mail, cloud perimeter.
Internal pentesting Active Directory, ADCS, endpoints, file servers, internal apps.
Techniques
External pentesting OSINT, surface enumeration, CVE chaining, exposed-service exploitation.
Internal pentesting Kerberoast, ADCS abuse, ACL chains, NTLM relay, BloodHound paths.
Question it answers
External pentesting Can someone on the internet break in, and how fast?
Internal pentesting Once inside, how far do they get?
When it fits
External pentesting Reducing exposure, validating edge changes, meeting external audit clauses.
Internal pentesting Ransomware readiness, lateral movement, segmentation audit.

Why a CTO, CISO or CIO books an external pentest.

A customer questionnaire, an insurer renewal, an M&A diligence, a cloud migration or a public launch forces the date.

TAP A SITUATION
Compliance & audit NIS2 / DORA readiness

An auditor does not accept a marketing PDF.

When ISO 27001, ENS, PCI DSS, SOC 2, NIS2 or DORA is on the line, the report has to survive scrutiny: traceable scope, recognised methodology, signed retest, execution certificate.

  • Methodology mapped to PTES, NIST SP 800‑115 and MITRE ATT&CK
  • Segmentation tested and documented for PCI DSS scope
  • Execution certificate ready for the auditor folder
  • Retest evidence with timestamps and signoff
Board & customer Board asked for assurance

Someone with authority asked, and ‘we’re fine’ isn’t an answer.

When the ask is about what your organisation exposes to the internet, you need an external, expert-led pentest and a deliverable that maps to business impact in language a non-technical stakeholder can read.

  • Executive summary that lands without translation
  • Findings ranked by business impact and audit exposure
  • A second opinion that names what the previous report missed, and why
  • Independence: external and expert-led throughout
Change New remote-access or SSO rollout

The perimeter just changed shape. Verify what the change exposed.

Every change to the perimeter moves what an attacker can see from outside. We test with no credentials and no allowlist, against the surface as it stands after the change, and prove which exposed asset still leads inside.

  • Scope tuned to the change being shipped, tested from the outside in
  • Edge appliances, VPN and remote-access portals tested for known exploit chains
  • Forgotten and shadow subdomains hunted, not assumed decommissioned
  • Retest after the fix, so the change closes with the exposure closed
Incident-driven Ransomware near-miss

Something happened. You need to know what is still reachable.

The question is not ‘do we have findings’ but ‘are there other ways in’. We confirm from the outside that the entry path used, or feared, is closed, and map every adjacent asset that still leads to a foothold.

  • Targeted scope around the suspected entry path
  • Adjacent perimeter mapped: edge appliances, portals, DNS, exposed storage
  • Leaked credentials and secrets checked against your live login surface
  • Live findings to your responders, not the final report
Business event Newly acquired company

A transaction added a perimeter you did not build.

You inherit whatever the other side left facing the internet, including what nobody documented. We enumerate that perimeter from outside with no credentials and prove which asset leads to a foothold.

  • Enumeration of the inherited estate as it is, not as the asset list describes it
  • Shadow and forgotten subdomains treated as in scope by default
  • Findings ranked by business impact, in language a non-technical reader follows
  • Retest to closure, so the integration starts with the gaps closed

Ready to see where an attacker reaches?

Book a call
Thirty minutes with an experienced pentester.

Seven phases, from your domain to a foothold.

An attacker starts with your domain and nothing else. So do we. Your perimeter decides the path.

What you actually get, and why it is different.

Most external tests stop at a list of open ports. Here is where we go further.

Chains walked by a human, not dumped by a scanner

A senior specialist validates and chains every finding. No false positives, only what is real and reachable from the public internet.

The attack-surface map you did not have

Alongside the report, a live inventory of every internet-facing asset we found, including the shadow IT, expired vendors and forgotten subdomains your CMDB never tracked.

Ranked by foothold potential, not CVSS

A medium-severity CVE on an unpatched VPN that yields an internal shell outranks a dozen high-severity findings that lead nowhere. We rank by what actually gets an attacker in.

Detection-aware, if you want it

Optional purple-team mode: every step logged and timed, so your SOC, EDR and WAF are measured against the attack chain in parallel.

Want to see what your next external pentest with us would look like?

We at Etnia highly value our collaboration with Asperis Security.
Sergi Leno, Systems Manager · ETNIA Barcelona

Loved by engineering and security teams.

Names, roles and companies on the record.

We at Etnia highly value our collaboration with Asperis Security. Their professionalism, approachability, quick response and ability to adapt to our needs have been key in every project. The quality of service and continuous support always give us peace of mind. Without a doubt, it is a pleasure to have them as technology partners.
Sergi Leno, Systems Manager
ETNIA Barcelona
ASPERIS has worked alongside us to define and implement our cybersecurity roadmap in Microsoft 365 with a structured approach aligned to business objectives. Thanks to their advice, we took the strategic step of completing our Microsoft ecosystem and reinforcing it with CrowdStrike for advanced mobile device protection, significantly raising our security level.
Jordi Bondia, IT Director
SALVI
At NPAW we have collaborated with Asperis on various security initiatives and the experience has been very positive. We especially value their ability to adapt to our needs and the depth with which they approach each project. Results are clear, structured and useful for decision-making and continuous security improvement. We like working with Asperis for the judgment and value they bring to every collaboration. Their work has helped us strengthen our security level.
Sergi Laencina Verdaguer, CISO
NPAW
With Asperis you don’t hire a service. You hire a partner. They don’t look to bill a project. They look to establish a relationship of trust, caring about the key points that affect your organisation’s security. Professionalism, know-how and diligence.
Juan Valer Tecedor, Software Engineer
GNOSS
READY WHEN YOU ARE

Want a real External Pentesting scope?

Tell us your apex domain and where you want us to start. An experienced consultant replies with a tailored scope, a fixed quote and a timeline.

Questions that come up before signing.

An external penetration test is a controlled, manual attack on your internet-facing assets: domains, VPNs, edge appliances, mail, DNS and cloud perimeter, performed with no credentials to prove what an attacker could reach from outside. Unlike an internal test, it starts from the public internet with no prior access. The deliverable is a short list of validated attack chains, ranked by how close each one gets to a foothold inside your network, each with a reproducible proof of concept.

A vulnerability scan returns an automated list of open ports and possible CVEs, mostly unverified and uninterpreted. An external pentest is a specialist chaining OSINT, surface enumeration and controlled exploitation into a path that actually works against your specific perimeter. You get a short list of proven chains ranked by foothold potential and blast radius, not a raw scanner export. We use scanners to accelerate reconnaissance, never as the deliverable.

A focused external pentest of a single apex domain typically runs one to two weeks of active testing, plus scoping beforehand and the retest after your fixes. Larger multi-domain, multi-country or multi-cloud perimeters run two to four weeks. We deliver the proposal and timeline within 48 hours of the first call, so you know the dates before you commit.

No, not without your explicit consent. Every engagement ships with documented Rules of Engagement: test windows, permitted intensity, forbidden actions and a kill-switch contact. Our default posture on live assets is passive reconnaissance and validated proofs of concept, with no destructive testing and no password spraying unless you ask for it. Where production exploitation is agreed, it runs under rate limits with your team on standby, and we abort anything that risks availability.

Price follows scope, complexity and test type (black box, grey box or white box), and we quote a fixed price with no hidden fees and no obligation to renew. A focused assessment of a small apex domain sits at the bottom of the range; larger perimeters scale from there. The retest that confirms your fixes is always included in the price.

Grey box fits most first engagements: you give us your public asset inventory and scope boundaries, so we spend the time testing rather than rediscovering what you already know. Black box mirrors a real attacker with only your apex domain, best for the annual re-baseline. White box adds architecture diagrams and a technical contact for the deepest coverage. We will recommend the right one on the introductory meeting.

The senior specialist you meet on the first call runs it end to end. Our team holds OSCP, OSCE³, OSWE, OSEP, CRTO and CRTP credentials, most have worked inside enterprise security or red teams, and we are NASA Bug Bounty verified contributors with published CVEs against widely deployed edge appliances. The same person scopes, executes and retests. They are who you deal with from start to finish.

At least once a year as a compliance floor for ISO 27001, ENS, PCI DSS, SOC 2, NIS2 and DORA. Highly dynamic or highly exposed perimeters warrant every six months or a continuous programme. A fresh test is also warranted by any material change: a new VPN or SSO integration, a public go-live, an acquisition, a cyber-insurance renewal, or a breach in your sector.

Ready to identify where we will get to?

Start with a no-obligation introductory meeting. We will review your apex domain, your edge stack and your starting assumption, and define the right external pentest before the project begins.

Request an external pentest proposal.
An experienced pentester replies within one business day. You talk to the person who runs the test.

Protected by reCAPTCHA. The Google Privacy Policy and Terms of Service apply.

Or email [email protected] directly.

OUR CLIENTS HAVE ALREADY DONE IT

We at Etnia highly value our collaboration with Asperis Security.

Sergi Leno, Systems Manager
ETNIA Barcelona

ASPERIS has worked alongside us to define and implement our cybersecurity roadmap in Microsoft 365 with a structured approach aligned to business objectives.

Jordi Bondia, IT Director
SALVI

At NPAW we have collaborated with Asperis on various security initiatives and the experience has been very positive.

Sergi Laencina Verdaguer, CISO
NPAW

With Asperis you don’t hire a service. You hire a partner.